landing_page-logo
  1. Home
  2. »All Job Categories
  3. »Information Technology Jobs

Auto-apply to these information technology jobs

We've scanned millions of jobs. Simply select your favorites, and we can fill out the applications for you.

Information Security Officer-logo
Information Security Officer
XpansivNew York, NY
Xpansiv, a trailblazer in the energy and environmental commodities market, operates the integrated, open, and neutral market platform designed to accelerate the global energy transition. Xpansiv provides thousands of market participants and intermediaries with access to the widest possible range of energy transition markets, through its suite of solutions, including the world's largest environmental commodities trading platform, where billions of assets cross per year. Xpansiv's end-to-end technology platform services the entire life cycle of environmental commodities, connecting diverse markets and market participants across the world and enabling stakeholders to deliver transparent and trusted environmental claims to address the growing demand for energy transition. Leveraging its extensive industry knowledge and proven technology portfolio, Xpansiv assists companies seeking to identify and mitigate risk, streamline the management of their environmental assets, and comply with regulations, caps and commitments. Position Summary: Xpansiv is looking for an Information Security Officer to join the Global Risk and Compliance team. This role will be key in the future development and execution of the information security program working directly with the Chief Risk Officer (CRO), CTO, engineers, risk, legal, and the lines of business, as well as with executive management. The ISO will drive and refine the company's information security strategic goals with responsibility for executing Xpansiv's information security program. The ISO will set the strategic direction and day to day execution of the information security program. The ideal candidate will be able to balance the need to be hands on and manage a team, as well as partnering with other part of the organization. Essential Functions: Responsible for further development and execution of Xpansiv's information security strategic plan in partnership with the Chief Risk Office, Chief Technology Officer and other security, business and technology team members. Continue to develop a comprehensive information security program to safeguard Xpansiv. Propose enhancements to the Information Security policies, standards and procedures. Update the Information Security Program based on regulatory changes, threats, best practices, business needs and feedback from management. Job Requirements: Conduct risk assessments to identify potential changes to the security posture and recommend appropriate ways to address and gaps. Determine acceptable risk levels for the Information Security and ensure threats to the company are mitigated in alignment with the company's risk appetite. Support audits and regulatory exams. Coordinate management's responses to information security-related findings. Lead responses to customers' information security inquiries into Xpansiv's security posture. Deep knowledge across the security tools and frameworks with an understanding which works best in different industries and environments. Drive and deliver the development and implementation of the appropriate and effective controls to protect the organization's assets. Participate in the preparation of risk assessments to evaluate new technologies, applications, and devices. Build out the information security awareness training for employees and Board of Directors with a detailed deep dive for Cyber Security Awareness month. Support or execute security related testing as needed for material technology driven changes. Ensure the remediation teams have sound plans and execute those in a timely manner. Collaborate with the business and/or Information Technology to select appropriate technology vendors that support regulatory requirements and best practices. Familiarity with key security solutions. Understanding of international security obligations. Refine a company-wide data loss prevention program to protect customer and company confidential information. Provide guidance on projects, new implementations, or upgrades in adherence with the Information Security Program. Run the Business Continuity Program, which includes working closely with business lines to ensure business impact analyses are comprehensive. This includes running incident response actions and driving follow up activity to closure. Other Knowledge, Skills and Abilities: Bachelor's degree in computer science, information systems or equivalent work experience is required. Industry standard certification in information security, such as CISSP, CISM, CRISC, or acquisition within one year of hire. Five years of experience supporting security architectures and applying security best practices across enterprise environments. Highly familiar with cloud-based solutions Possess excellent analytical, organizational and documentation skills. Strong knowledge of both cybersecurity and IT risk management programs based on industry recognizable frameworks. Strong collaboration and communication skills with the ability to tailor messages to the audience. Equally comfortable working independently as with a team while building and maintaining collegial relationships across the company including with the commercial and technical teams. Persuasive leader who can serve as an effective member of the management team and is able to communicate security-related concepts to a broad range of technical and non-technical staff. Practical experience with vulnerability scanning and auditing tools. Knowledge of DevOps application security. Experience with cloud security best practices. Ready to work in a highly dynamic and exciting environment. What can you expect throughout the interview process: Step 1- Shortlisting of resume & Recruiter screening Step 2- "Get to know you" interview with the hiring manager Step 3- Meeting with team & key leaders Base Salary Compensation for this role will vary among specific regions due to geographic differentials in the labor market, actual pay will be determined considering factors such as relevant skills and experience, knowledge, education and training. However, the base compensation in New York is expected to be as follows: $250,000 -$270,000 Here at Xpansiv, we cultivate diversity, celebrate individuality, and believe unique perspectives are key to our collective success in building trust and transparency in global efforts toward net-zero future. Xpansiv is committed to equal employment opportunity regardless of race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, protected veteran status, or any status protected by applicable federal, state, or local law. Note to Recruiters: Xpansiv does not accept unsolicited resumes or referrals from placement agencies, staffing vendors or other external parties seeking recruiting fees without a signed formal agreement.

Posted 3 weeks ago

Security Analyst, Information Security Awareness-logo
Security Analyst, Information Security Awareness
Chemical Abstracts Service, a Division of the American Chemical SocietyWashington, DC
Responsible for the strategic vision, execution and implementation of the organization's Security Awareness program's daily operations, goals and objectives by developing and monitoring security standards and best practices for the organization. Recommend security enhancements as needed and build solutions to meet those needs as appropriate. Design and develop comprehensive security awareness programs, including training materials, presentations, and interactive activities. Conduct security awareness training sessions for employees at all levels, utilizing various formats such as in-person workshops, webinars, and e-learning modules. Create engaging and informative content related to cybersecurity topics, including newsletters, posters, videos, and intranet articles. Plan and execute security awareness campaigns to promote key security initiatives and reinforce secure behaviors. Identify and assess potential security risks related to employee behavior and recommend mitigation strategies. Develop and track metrics to measure the effectiveness of security awareness programs and report findings to management. Ensure that security awareness programs comply with relevant regulations, standards, and best practices. Assist in the investigation and response to security incidents, providing insights into employee-related security issues. Work closely with other departments, including IT, HR, and Legal, to integrate security awareness into broader organizational initiatives. Stay current with the latest cybersecurity trends and threats, and continuously improve the security awareness program based on new information and feedback. Actively engages in the greater information security and privacy community (e.g., peer groups, seminars, conferences, etc.) to help identify new technologies, new techniques and new partners. Demonstrates a positive, proactive, and thought leadership attitude to CAS and the greater security community. Ability to document technical processes to ensure accuracy and sustainability of job-related processes. Experience in implementing security awareness controls outlined in industry frameworks in existing programs. Other duties as required. Qualifications: 3 years of experience in related field. Bachelor's degree in Computer Science, Information Systems, Computer Engineering, Information Security or equivalent is required. Cyber Security Certifications (e.g., CISSP, GIAC certifications, etc.) are preferred, but not required. Demonstrate understanding and/or experience with CIS Critical Controls, NIST CSF and ISO 27001 frameworks are preferred, but not required. Technical Knowledge, Skills, and Abilities: Strong understanding of cybersecurity principles and best practices. Working knowledge of information security risk and control frameworks including NIST 800-171, CMMC, NIST CSF, and CIS Critical Controls Excellent written and verbal communication skills, with the ability to communicate security concepts to technical and non-technical stakeholders Excellent written and verbal communication skills. Ability to create engaging and informative content. Proficiency in using e-learning platforms and tools. Strong analytical and problem-solving skills. Demonstrated experience working with a team to solve technical problems Demonstrated experience working with a team to solve process problems Able to work independently and as part of a team High level of attention to detail and accuracy in analysis Experience with and ability to implement security best practices Ability to focus on and achieving results Demonstrated reliability and follow-through on commitments and assignments Demonstrate professionalism and courtesy in all interactions Work well under pressure Ability to balance several tasks simultaneously This role is based in our Washington, D.C. office. A reasonable rate of compensation for this position is between $90,000-$95,000 per year.

Posted 5 days ago

Sr. Information Systems Support Manager (5718)-logo
Sr. Information Systems Support Manager (5718)
MetroStar SystemsQuantico, VA
As Sr. Information Systems Support Manager, you'll oversee the end-to-end SDLC process for enhancements, modifications, and cloud migration of logistics support systems following Agile and DevSeCOps approaches with a large cross-functional team. You'll bring broad and deep experience with Oracle EBS, Oracle Cloud Infrastructure (OCI), and related security services. The ideal candidate would have technical leadership experience managing large and complex systems involving ERP and cloud computing environments with the Department of Defense and possesses in-depth knowledge of and implementation experience of cybersecurity standards such as NIST 800-53. We know that you can't have great technology services without amazing people. At MetroStar, we are obsessed with our people and have led a two-decade legacy of building the best and brightest teams. Because we know our future relies on our deep understanding and relentless focus on our people, we live by our mission: A passion for our people. Value for our customers. If you think you can see yourself delivering our mission and pursuing our goals with us, then check out the job description below! What you'll do: Brings technical leadership to architect, design, and lead end-to-end implementation of Oracle EBS and OCI-based solution Collaborate with government technical and functional SMEs to plan, prioritize, develop roadmap and support implementation of systems consolidation, modernization, and cloud migration initiatives Manage a large cross-functional team to enhance, modify, and resolve issues related to logistics functions using Oracle EBS ERP and other software in both on-prem and OCI following Agile methodology Establish DevSecOPs process, tools and oversee its adoption across the teams Collaborate with IT and cloud teams to design and deploy secure system architectures. Evaluate and recommend new security technologies and tools to enhance the organization's security posture Implement and monitor security controls to ensure compliance with applicable frameworks and regulations and develop Authorities to Operate (ATO) for existing and future systems. Support change management across the organization in support of new and enhanced systems and functionality rollout What you'll need to succeed: Active DoD Secret security clearance Master's Degree in Information Systems or Business Administration, or equivalent experience. You currently hold the following certifications: CISSP or CISM, CISSM or CASP and can obtain DoD 8140 IAM/IAT Level III certifications. 7+ years of technical leadership experience with large scale Oracle EBS implementation in Department of Defense. 7+ years of experience in information assurance, cybersecurity, or related roles, including experience with large-scale systems and cloud computing environments. Demonstrated experience implementing and managing cybersecurity frameworks and compliance requirements within a Federal Government environment. 3+ years of experience implementing security requirements for Government public cloud platforms such as AWS, Azure, or Google Cloud, including their security features and controls. Strong knowledge of Risk Management Framework (RMF), NIS 800-53, and DoD cybersecurity principles, technologies, and best practices, including cloud security. Strong understanding of incident response, threat analysis, and vulnerability management. Excellent communication and collaboration skills. Strong analytical and problem-solving skills. Ability to work independently and take ownership of projects.

Posted 1 week ago

(Ma) Information Assurance Technician-logo
(Ma) Information Assurance Technician
DMS InternationalLackland Joint Base, TX
Data Management Services, Inc. (dba: DMS International) is a professional services firm headquartered in Silver Spring, Maryland, with work locations throughout the continental United States. We prepare managers and executives to lead their workforce through customized learning solutions that drive the standards of an ever-changing world. We build creative, unique and engaging learning experiences for commercial, civilian and defense organizations. Our high-caliber talent, delivery methodology and innovative solutions contribute to preparing a workforce that is ready for the future. You can join us on this journey to bring efficiency and creativity to our customers. At DMS International (DMS), we are the catalyst for effective workforce transformation. To achieve this, we hire professionals who take pride in doing quality work and who are excited about contributing to the professional development of tomorrow's leaders. DMS seeks candidates that possess and display the attributes that reflect our Core Values of: Quality in delivering solutions, Leadership, Innovation, Teamwork, Integrity in conduct, Responsiveness to our customer's mission DMS is currently seeking an Information Assurance Technician. The Information Assurance Technician will supervise contractor personnel involved in the logistics operations for the Expeditionary Combat Skills training program and coordinate facilities management for the learning activity. They work closely with other contractors, military, and government civilian personnel at Learning Site Gulfport, at CENSECFOR Headquarters, and with other agencies. The Information Assurance Technician must be familiar with applicable Navy rules, regulations, and other requirements listed in the contract's Performance Work Statement (PWS) and may be required to attend in-service training which is designed to update contractor personnel on Government rules, regulations, and other requirements. The Information Assurance Technician must: Be a US Citizen. Obtain a suitable evaluation for mandatory drug screenings. Possess a valid state driver's license. Possess excellent communication skills, both orally and in writing. Bachelor's degree in an approved program from an accredited University or baseline certification of CompTIA Security + (CE) (or equivalent) and a minimum of four (4) years in an information technology and security management capacity Ability to obtain a Favorable Tier 3 Background Investigation (See PWS Section 4) Per DoD Manual 8140.03 (Cyberspace Workforce Qualification and Management Program and Bachelor of Science degree in Industrial Engineering, Safety Management, or other technical areas. Practical experience may be substituted for formal education on a rate of two years' experience for one-year education. SECNAV M-5239.2 (Cyberspace Information Technology and Cybersecurity Workforce Management and Qualification Manual). The following technical requirements apply to the incumbent functioning as a DoD Cyberspace Workforce Framework (DCWF) Code 411, Technical Support Specialist: A minimum of four (4) years of experience in Information Assurance (IA) technology or a related field. Documented experience in a Computing Environment (CE) Capability to apply basic knowledge of IA concepts, practices, and procedures within the CE Be capable of functioning under the direction of the CE Manager Maintain Cyberspace IT and Cybersecurity Workforce (Cyber IT/CSWF) certification in accordance with DoD Manual 8140.03 (Cyberspace Workforce Qualification and Management Program) Already possess minimum baseline certification as described in SECNAV M 5239.2 CompTIA Security+ CE or have attained a bachelor's degree in an approved subject area, Candidates must obtain and maintain the following certifications or qualifications: Computing Environment Certification Acquire CE certification or qualification as described by DoDM 8140.03 and SECNAV 5239.2M, Maintain operating system (OS) and computing environment (CE) qualification as required. A valid training certificate or commercial certification is required as evidence. Update qualification or certification as OS and CE changes. Meet the Continuous Education or Sustainment Training requirements as appropriate for the aforementioned certifications, currently 20 hours per fiscal year or what is required to maintain certification; whichever is greater. At least ten years of direct experience in training and occupational safety program management in support of a Navy or Marine Corps training area. Have no record of criminal convictions. Additionally, the IAT must also: Be competent in all phases of systems analysis techniques, concepts, and methods and knowledge of available system software, computer equipment, and the regulations, structure, techniques, and management practices of one or more subject-matter areas. Since input data usually come from diverse sources, it is responsible for recognizing probable conflicts and integrating diverse data elements and sources. Possess general knowledge of the mission, objectives, terminology, and management practices in the activity, the agency, and the department to recognize probable areas of interaction and overlap between proposed applications and existing systems. Knowledge of state-of-the-art practices of data automation to advise on alternative approaches in application system development and/or problem resolution. Possess knowledge of department, agency, command, and installation information processing procedures and standards as they relate to coordination of requirements, processing requests, and documentation. Possess ability to communicate orally and in writing. Possess the ability to apply knowledge of current automation technology and practices. Possess knowledge of information processing standards and procedures. Possess ability to analyze data to troubleshoot problems, to evaluate established methods and procedures, and to perform similar analytical functions. Possess ability to interact with a diverse user community and respond to a wide range of requests. Must be able to resolve problems that involve routine operations and work with senior specialists on problems that are more complex. Possess knowledge of customer support and service principles and methods. Possess working knowledge of guidelines primarily consist of Federal, agency and local regulations, policies, standards, and objectives, and existing systems that provide useful models. The employee uses judgment in routine assigned projects. Guidelines also consist of local information systems standards, precedents, equipment manufacturer's manuals, systems software documentation, and activity established practices. The employee deals with a great variety of automation problems though, and must rely on his/her own judgment, initiative, and resourcefulness when guidance is not readily available, or when the guidance is not applicable or non-specific. Guidelines range from general to specific in nature with technical assistance available from senior analysts. The employee uses judgment in interpreting, adapting, and applying guidelines to specific assignments, then analyzes the result and recommends necessary changes. Possess an understanding of work schedules, special priority projects, and finished reports in terms of accuracy, soundness of decisions and recommendations, and overall completeness. The Training Occupational Safety and Health Specialist duties may include: Functions in an Information Assurance (IA) Workforce Technical capacity as an IAT Level I for NTTC Lackland legacy assets. In this role, the contractor will: Recognize a potential security violation, take appropriate action to report the incident as required by regulation, and mitigate any adverse impact, Apply instructions and pre-established guidelines to perform IA tasks within CE, Support, monitor, test, and troubleshoot hardware and software IA problems pertaining to their CE, Apply CE specific IA program requirements to identify areas of weakness, Apply appropriate CE access controls, Install and operate the IT systems in a test configuration manner that does not alter the program code or compromise security safeguards, Conduct tests of IA safeguards in accordance with established test plans and procedures, Implement and monitor IA safeguards for CE system(s) in accordance with implementation plans and standard operating procedures, Apply established IA security procedures and safeguard and comply with responsibilities of assignment, Comply with system termination procedures and incident reporting requirements related to potential CE security incidents or actual breaches, Implement applicable patches including IA vulnerability alerts (IAVA), IA vulnerability bulletins (IAVB), and technical advisories (TA) for the CE operating system(s), Install, test, maintain, and upgrade CE operating systems software and hardware to comply with IA requirements, Understand and implement technical vulnerability corrections, Enter assets in a vulnerability management system, Apply system security laws and regulations relevant to the CE being supported, Implement DoD and DoD Component password policy, Implement specific IA security requirements and countermeasures, As necessary, provide documentation, drawings and completes tests, patching, updating and other activities for systems, hardware and software to achieve Authority to Operate (ATO) through the Risk Management Framework. Function as Assistant Activity Customer Technical Representative (ACTR) for Navy and Marine Corps Intranet. In this role, the contractor will: Assist with Track "Move, Add, Change (MAC) Requests", Assist in the creation and deletion of NMCI accounts, provide end user with IT support for all CE operating systems, peripherals, and applications. Support includes specification, installation and installing of computer systems and peripherals with established standards and guidelines Assist with managing user-shared folders, groups, and email public folder permissions, Inventory NMCI assets and maintain user location, Assist users with general computer problems and coordinate with NMCI Help Desk and Base Operations personnel when additional assistance is required, Order, inventory, and dispense computer and printer consumables, Assist with imaging, deploying and updating mobile devices and tablets Inform and train users on NMCI policy changes, Assist with maintaining user and asset data in various NMCI management systems such as NET Assist with user support services such as data migration, Assist with local NMCI maintenance actions as NTTC Lackland is a NMCI remote site, Other NMCI duties and functions as required. Function as Alternate NTTC Lackland Navy representative with the Air Force Communications Squadron dealing with Telephones and telephone systems (TCO), Air Force ground radio program and Air Force Unit Communications Requirements Manager (UCRM), as necessary, in: Assist users with general computer problems and coordinate with Air Force Help Desk and Base Operations personnel when additional assistance is required Maintain records of Air Force radios as well as maintenance of Motorola radios. Function as a Resource Management Representative. In this role, the contractor will: Coordinate the procurement, maintenance, management and disposition of various peripheral data equipment and communication devices, Manage telecommunication systems and equipment to include Land Mobile Radio (LMR) handhelds, mobiles and infrastructure, Coordinate Video Teleconferences (VTC) services to include installation, setup and maintenance. Assists with other duties assigned to NTTC Lackland N6. In this role, the contractor will: Assist with the maintenance of the Command's NETC hosted public web site. Provide basic technical support for Command's My Navy Portal (MNP)/SharePoint page Assist with the naval messaging system to include the distribution and sending of naval messages. Provide technical support with PAO functions including pictures and videos Serve in the capacity of an IT functional representative to direct IT issues to the appropriate source. Provide system updates and information as appropriate to each end user. Coordinate maintenance of current equipment and future projects. Provide end user technical support and troubleshooting with network equipment to include NMCI, TRANET, and Legacy workstations, digital scanners, and printers. Initiate and track documents for access (SAAR-N and IAA Annual training) Submit requests to create, move, or delete accounts as necessary. Manage IT inventory for NTTC Lackland and coordinate moves or changes to existing and future equipment with CENSECFOR Headquarters (N6). Contractor and subcontractor employees currently performing work under this contract are required to sign a Non-Disclosure Agreement (NDA). The contractor shall maintain copies of all signed agreements and have the documents readily available at the COR's request. Refer to DFARS 252.204-7000, Disclosure of Information, and DFARS 252.204-7003, Control of Government Personnel Work Product. Location:NTTC Lackland AFB, TX.

Posted 30+ days ago

Intern - Information Security (Fall 2025)-logo
Intern - Information Security (Fall 2025)
Itron, Inc.Raleigh, NC
Itron is innovating new ways for utilities and cities to manage energy and water. We create a more resourceful world to protect essential resources for today and tomorrow. Join us. The work we do every day matters. From modernizing the grid and ensuring safe, reliable water delivery to creating smarter cities, you can make a global impact with Itron. Our Information Security team within corporate IT is looking for an intern to support Information Security compliance. This position provides the opportunity to gain experience in information security compliance and audit activities while completing your education. Duration: Must be available at least 20 hours/wk during the academic year, and located near an existing Itron office (Raleigh NC, Austin TX, San Antonio TX, Liberty Lake, WA). This is not a remote position. Job Duties & Responsibilities Support information security related tasks including management and documentation of Information Technology general-controls related to Sarbanes-Oxley (SOX) financial audits Support Information Security compliance including managing general controls and writing automated scripts Review information security policies and help manage policy review/update process Develop and grow understanding of risk compliance applications (e.g., Audit Board or Galvanize) Collaborate with internal and external stakeholders to achieve individual, team and company goals, including coordinating and leading meetings, with support from manager Utilize technology systems and tools to complete work tasks, including Oracle, Excel, Visual Basics Scripts (VBS) Education: Currently enrolled in a related degree program (Cybersecurity, Finance, Computer Science preferred) Required Skills & Experience Basic knowledge of information security technologies and compliance principles (SOX, NIST 800-53, ISO 27001) Ability to work well independently and with coworkers to share knowledge as part of a team Experience managing time independently and prioritizing tasks Strong problem-solving ability with the desire to take ownership of challenges and follow through to resolution Intermediate Excel abilities (formulas, functions, vlookup) Professional oral and written communication skills Preferred Skills & Experience Related academic projects or work experience Hands-on experience with Oracle administration and/or Linux OS Working knowledge and experience with PowerBI/PowerAutomate Academic or work experience in Oracle Understanding of Audit Control Language (ACL) and/or VBS scripting Travel: 1 - 10% Physical Demands: This is a typical office job, with no special physical requirements or unusual work environment. Hourly Range for Liberty Lake, WA - $15.87 - $44.23 Itron is committed to building an inclusive and diverse workforce and providing an authentic workplace experience for all employees. If you are excited about this role but your past experiences don't perfectly align with every requirement, we encourage you to apply anyway. In the end, you may be just who we are looking for! The successful candidate's starting wage will be determined based on permissible, non-discriminatory factors such as skills and experience. Itron is proud to be an Equal Opportunity Employer. If you require an accommodation to apply, please contact a recruiting representative at 1-800-635-5461 or email Accessibility@itron.com. Itron is transforming how the world manages energy, water and city services. Our trusted intelligent infrastructure solutions help utilities and cities improve efficiency, build resilience and deliver safe, reliable and affordable service. With edge intelligence, we connect people, data insights and devices so communities can better manage the essential resources they rely on to live. Join us as we create a more resourceful world: www.itron.com

Posted 1 week ago

Information Systems Security Officer-logo
Information Systems Security Officer
The Swift GroupLaurel, Maryland
OPS Consulting is seeking an Information Systems Security Officer to work in Laurel, MD . Job Descriptions: The Information Systems Security Officer (ISSO) shall provide support for the program, organization, system, and enclave’s information assurance program by performing vulnerability/ risk assessments, analysis, and configuration management for software, hardware, and firmware. The ISSO will provide support for proposing, coordinating, implementing, and enforcing information systems security policies, standards, and methodologies. The ISSO will maintain operation security posture for the program, assist with the management of security aspects of the information system and perform day to day security operations of the system. Responsibilities: Provide daily oversight and direction to ISSOs Interact with customers, IT staff, and high- level corporate officers to define and achieve required information assurance objectives. Plan and coordinate the IT security programs and policies. Manage and control changes to the system and assessing the security impact of those changes. Provide support for the program, organization, system, and enclave’s information assurance program. Serve as the Approval Authority for information security. Requirements: Level 0: Two (2) years’ experience as an ISSO on programs and contracts of similar scope, type, and complexity is required. Bachelor’s degree in Computer Science or related discipline from an accredited college or university is required. DoD 8570 compliance with Information Assurance Technical (IAT) Level 1 or higher is required. Two (2) years of additional experience as an ISSO may be substituted for a bachelor’s degree. Level 1: Five (5) years’ experience as an ISSO on programs and contracts of similar scope, type, and complexity is required. Experience is to include at least one (1) of the following areas: knowledge of current security tools, hardware/ software security implementation; communication protocols; and encryption techniques/ tools. Bachelor’s degree in Computer Science or related discipline from an accredited college or university is required. DoD 8570 compliance with Information Assurance Technical (IAT) Level 1 or higher is required. Four (4) years of additional experience as an ISSO may be substituted for a bachelor’s degree. Level 2: Ten (10) years’ experience as an ISSO on programs and contracts of similar scope, type, and complexity is required. Experience is to include at least two (2) of the following areas: knowledge of current security tools, hardware/ software security implementation; communication protocols; and encryption techniques/ tools. Bachelor’s degree in Computer Science or related discipline from an accredited college or university is required. DoD 8570 compliance with Information Assurance Management (IAM) Level 1 or higher is required. Four (4) years of additional experience as an ISSO may be substituted for a bachelor’s degree. Level 3: Fifteen (15) years’ experience as an ISSO on programs and contracts of similar scope, type, and complexity is required. Experience is to include at least three (3) of the following areas: knowledge of current security tools, hardware/ software security implementation; communication protocols; and encryption techniques/ tools. Bachelor’s degree in Computer Science or related discipline from an accredited college or university is required. DoD 8570 compliance with Information Assurance Management (IAM) Level 1 or higher is required. Four (4) years of additional experience as an ISSO may be substituted for a bachelor’s degree. Security Clearance: A current government clearance, background investigation, and polygraph are required. The Swift Group and Subsidiaries are an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status, or any other protected class. Pay Range: $49,996.80 - $290,004.00 Pay ranges are a general guideline and not intended as a guaranteed and/or implied final compensation or salary for this job opening. Determination of official compensation or salary relies on several different factors including, but not limited to: level of position, complexity of job responsibilities, geographic location, work experience, education, certifications, Federal Government contract labor categories, and contract wage rates. At The Swift Group and Subsidiaries, you will receive comprehensive benefits including but not limited to: healthcare, wellness, financial, retirement, education, and time off benefits.

Posted 30+ days ago

PBF Co-Op / Intern Information & Career Preferences-logo
PBF Co-Op / Intern Information & Career Preferences
PBF EnergyParsippany, New Jersey
PBF Co-Op / Intern Information & Career Preferences PBF Energy Inc. (NYSE:PBF) is one of the largest independent refiners in North America, operating through its subsidiaries, oil refineries and related facilities. We are always seeking talented new Engineers to join our team and play a key role here at PBF Energy. These roles are typically located onsite at one of our refinery locations. Please complete the brief questionnaire regarding your personal preferences for an engineering career at PBF Energy. This information will allow our Recruiting & Hiring Teams to identify positions across the organization that would be the best fit for you based on your responses, preferences, and prior work experience.

Posted 5 days ago

Actionet, Inc. Careers - Information System Security Officer (Isso)-logo
Actionet, Inc. Careers - Information System Security Officer (Isso)
ActioNet, Inc.San Diego, CA
Description ActioNet has an opportunity for an Information System Security Officer (ISSO) requiring a Secret clearance located in San Diego County, CA.. ActioNet is an IT service provider and solutions integrator headquartered in Vienna, VA that works with the Federal Government and Department of Defense. In this role, you will: Salary Range $118K-148K As the Information System Security Officer (ISSO), your tasks will include: Determine client security control requirements. Implement security controls Conduct annual review of each record's security controls (via testing, examining, or interviewing). Assess the effectiveness of cybersecurity measures utilized by system(s). Assess threats to and vulnerabilities of computer system(s) to develop a security risk profile. Identify and direct the remediation of technical problems encountered during testing and implementation of new systems (e.g., identify workarounds for communication protocols that are not interoperable). Identify, assess, and recommend cybersecurity or cybersecurity-enabled products for use within a system and ensure that recommended products comply with the organization's evaluation and validation requirements. Work with customer to determine functional needs, develop secure architectures, and communicate security best practices and policies. Document solutions for any network-related security configurations for network architecture or current fielded programs and experiments. Develop, implement, and document best practices for setting up and securing network devices, applications, servers, databases, and appropriate system components. Perform cybersecurity hardening and security monitoring on network infrastructures (STIGs, patching, ACAS scanning, etc.). Manage/maintain security related configurations within the network based on operational requirements. Incorporate cybersecurity vulnerability solutions into system designs (e.g., Cybersecurity Vulnerability Alerts). Provide guidelines for implementing developed systems to customers. Provide input to the Risk Management Framework (RMF) process activities and related documentation. Provide support to security/certification test and evaluation activities. Ensure that security design and cybersecurity development activities are properly documented. Basic Qualifications: CNSSI 4014-Information Systems Security Officers (ISSO). CompTIA Security+. Experience with Marine Corps Information Security programs, authorization procedures and requirements as well as interacting with higher military headquarter elements. Desired Position Qualifications: Bachelor's degree in Cybersecurity, Information Technology, or related field. Certified Authorization Professional (CAP). GIAC Security Leadership Certification (GSLC). CID M09BNJ1 Cybersecurity Technician. CNSSI 4013-System Administrators. NDU CISO certificate - Chief Information Security Officer (CISO). ActioNet is a CMMI-DEV Level 4, CMMI-SVC Level 4, ISO 20000, ISO 27001, ISO 9001, HDI-certified, woman-owned IT Solutions Provider with strong qualifications and expertise in Agile Software Engineering, Cloud Solutions, Cyber Security and IT Managed Services. With 25+ years of stellar past performance, ActioNet is the premier Trusted Innogrator! Core Capabilities: Advanced and Managed IT Services Agile Software Development DevSecOps Cybersecurity Health IT C4ISR & SIGINT Data Center Engineering & Operations Engineering & Installation Why ActioNet? At ActioNet, our Passion for Quality is at the heart of everything we do: Commitment to Employees: We are committed to making ActioNet a great place to work and continue to invest in our ActioNeters. Commitment to Customers: We are committed to our customers by driving and sustaining Service Delivery Excellence. Commitment to Community: We are committed to giving back to our community, helping others, and making the world a better place for our next generation. ActioNet is proud to be named a Top Workplace for the eleventh year in a row (2014 - 2024). We have a 98% customer retention rate. We are passionate about the inspirational missions of our customers, and we entrust our employees and teams to deliver exceptional performance to enable the safety, security, health, and well-being of our nation. What's in It For You? As an ActioNeter, you get to be part of an exceptional team and a corporate culture that nurtures mutual success for our customers, employees, and communities. We give you the tools to be successful; all you need to do is bring your best ideas, your energy, and a desire to develop your skills, experience, and career. Are you ready to make a difference? ActioNet is an equal-opportunity employer and values diversity at our company. We do not discriminate based on race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. Full-Time Employees are eligible to participate in our ActioNet's Benefits Program: Medical Insurance Vision Insurance Dental Insurance Life and AD&D Insurance 401(k) Savings Plan Education and Professional Training Flexible Spending Accounts (FSA) Employee Referral and Merit Recognition Programs Employee Assistance and Identity Theft Protection Paid Holidays: 11 per year Paid Time Off (PTO) Disability Insurance ActioNet is an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. Direct Applicants, only. No Agencies, No third-party recruiters, please

Posted 3 weeks ago

Management Information Systems (Mis) Intern With A Passion For AI (Summer 2025)-logo
Management Information Systems (Mis) Intern With A Passion For AI (Summer 2025)
LoftwarePortsmouth, NH
Who we are looking for: Students with passion for AI with related studies in Business, HR, technology, product and documentation. Location: Hybrid (Portsmouth, NH) Reports to: Business leader in HR, Product manager, Sales Operations, Technical Support, and Professional Services Industry: SaaS | Global Supply Chain Management Position Summary Loftware is seeking an ambitious and innovative undergraduate student with a strong interest in Artificial Intelligence to join us as an AI & Business Strategy Intern. This unique summer opportunity offers a hands-on role exploring how emerging AI tools can support and transform business operations across functional areas. You'll partner with cross-functional leaders to identify needs, research AI solutions, and present strategic recommendations with real business impact. Key Responsibilities Collaborate with business leaders to identify opportunities for AI enablement within their departments. Research, compare, and evaluate current AI tools and technologies relevant to operational needs. Analyze workflows and propose AI-driven improvements or efficiencies. Prepare reports and presentations outlining the business case for AI adoption. Present final recommendations to the leadership and executive teams at the conclusion of the internship. Ideal Candidate Profile Currently enrolled in a Bachelor's degree program in Business, Technology, or a related field. Completed at least two years of undergraduate coursework (rising juniors/seniors preferred). Demonstrated interest in AI through coursework, academic projects, or independent exploration. Strong analytical and research skills with attention to detail. Effective written and verbal communication skills, including the ability to present to senior stakeholders. Ability to work independently and collaboratively in a hybrid environment. Understanding of core business processes in at least one area (e.g., HR, Business, Technology, Product Management and Documentation). Internship Details Duration: 10-12 weeks (starting July 7, 2025) Schedule: Approximately 30 hours/week Location: Hybrid (2 days per week onsite in Portsmouth, NH) Mentorship: Interns will receive guidance from cross-functional mentors and work with executive stakeholders. Final Deliverable: Formal presentation of AI recommendations to Loftware's leadership team. Why Join Loftware? At Loftware, you won't be running errands, you'll be running ideas for future innovation. This internship offers a rare opportunity to contribute to impactful AI strategy work that can influence how a leading global SaaS company operates. You'll join a culture of innovation and collaboration while building experience that sets you apart in both business and technology. About Loftware Ever wonder how products get from the factory floor to your doorstep-or store shelf? Loftware makes that possible. As a global leader in enterprise labeling and artwork management solutions, we help companies manage complex supply chains, remain compliant, and deliver products safely and efficiently across industries like pharmaceuticals, consumer goods, manufacturing, and beyond. We make the supply chain work-and we're ready for you to help us make it even smarter. Come and #makeyourmark with Loftware this summer!

Posted 1 day ago

Information Security Analyst-logo
Information Security Analyst
Lyra Technology GroupNashville, TN
Information Security Subject Matter Expert, Lyra Technology Group Lyra Technology Group is looking for a full-time Information Security SME to join the team at one of our operating companies, ImageQuest in Franklin, TN. The Information Security SME will work to protect the client's data, infrastructure, reputation, and compliance with industry-applicable regulations by supporting the execution of the established Information Security Program. As a subject matter expert, the Information Security SME works to ensure the client's business remains compliant by gathering data, preparing reports, and preparing correct documentation. This role provides critical documentation support of information security operations in the areas of: Vendor Management, Security Awareness, and Cybersecurity Health Checks. A bit about Lyra… Lyra Technology Group is a private equity-backed holding company that invests and operates industry leading technology service businesses. Our companies are operated independently by exceptional management teams. Companies that join our group retain the employees, name, and culture that have made them successful. As a platform of Evergreen Services Group, we never divest from businesses we partner with and approach every decision with the goal of driving sustainable and healthy growth over the long term. A bit about ImageQuest… ImageQuest provides best-in-class IT services, IT consulting, IT support, and IT compliance and cybersecurity services to clients in Nashville, TN. Our Cloud Computing services are carefully designed solutions that keep your team productive, secure, and compliant - wherever they work. Our Cloud Computing solutions can reduce or eliminate your IT capital expenses, give what equipment you do have a longer life, and covert IT expenses into a predictable monthly cost. Your work as the Information Security Subject Matter Expert (SME), includes several components: Support the implementation of information security programs by pulling detailed and accurate data to allow for creation of timely and correct client reports. Collect data and prepare professional client-facing reports using ImageQuest approved presentation guidelines. Manage vendor relationships to ensure all data is received from client and their vendors to build vendor profile, gather reports, and complete preliminary documentation review for completeness and accuracy before submitting for risk rationale and final vendor executive summary package. Assist with internal process documentation to ensure procedures are up to date at all time. Work to gain and maintain strong regulatory knowledge (i.e.: HIPAA, GLBA, etc.) along with a well-organized repository of reference information to refer to as needed. For accounts with a Professional Services Agreement (PSA) in place, support information security operations with special projects as needed such as: o Transcribe incident response table-top exercises ensuring all details are captured accurately. o Investigate and resolve tedious and complex documentation issues with patience and diligence. o Administrative and technical projects assigned. Vendor Management o Conduct non-banking client vendor reviews, ensuring all documentation is current and compliant with company standards, and create summary for presentation to client. o For banking clients: Assist in gathering due-diligence documentation for assessments and audits. o Set up Vendor Profiles in Nvendor, complete with primary contact and fourth-party vendors. o Review SOC reports and complete Executive Summaries. o Extract User Entity Controls and work with vendor owner (relationship manager) to complete. o Prepare questions, follow up with vendors, and document their responses in preparation of handing off to Lead Advisor. o Conduct Vendor Performance Review process with Relationships Managers. Security Awareness o Work with Lead Advisor to support client's ongoing Security Awareness Training Program. o Extract data from client's KnowBe4 consoles to create comprehensive regularly scheduled reports. o Review established training program for gaps in learning and make recommendations to Lead Advisor. o Implement training program by setting up ongoing campaigns, smart groups, and phishing tests. o Monitor client's KnowBe4 console and interact with KnowBe4 to resolve any issues on behalf of client. o Notify clients of users who are past due on their training to increase completion rates. Cybersecurity Health Checks o Assist with internal health check data entry and management tasks to ensure the accuracy and completeness of information. o Pull, gather, and compile data for Health Check reports, ensuring all information is up-to-date and accurate. o Review Health Check reports to ensure cyber security initiatives are consistently followed (e.g., user access, patch reports, removing terminated employees from groups, etc.) and alert information security advisor of discrepancies. Our ideal Information Security Subject Matter Expert (SME), has the following qualifications: Bachelor's degree in English, Communications, Information Security, or a relevant technical and writing experience. Strong communication skills with excellent, professional writing skills required. Proven experience in information security, data management, or a similar role a plus. Patient and thorough with a keen eye for pattern recognition within data sets. Excellent organizational skills with strong attention-to-detail. Excellent listening skills, with the ability to understand and interpret technical information. Strong analytical and reading comprehension with a proven ability to exercise initiative, judgment, and discretion. Ability to multitask without errors and function well in a high-paced environment. Positive attitude with willingness to learn and adapt to new tools and technologies. Basic familiarity with Microsoft Office product family. Experience with KnowBe4 consoles and information security documentation a plus The targeted base compensation for this role is $55,000-65,000 per year and will operate out of the Franklin, TN office on a hybrid basis. If you're motivated by meaningful client relationships, strategic selling, and a dynamic work environment-we want to hear from you. Apply today to join the ImageQuest team and help deliver technology solutions that drive real business value!

Posted 2 weeks ago

Health Information Services Technician-logo
Health Information Services Technician
Trinity Health CorporationDetroit, MI
Employment Type: Full time Shift: Day Shift Description: The selected individual will be required to work at the job site for each scheduled workday. A remote working arrangement is not available for this role. Relocation assistance is not provided. Enters patient information/medical record information into customized databases. Generates reports from the cumulative data. Collaborates with physicians, nurses, and ancillary department personnel to ensure appropriate documentation supports data collection needs. Collaborates with appropriate Health Information Services personnel to assure data collection/abstraction is completed in a timely manner. Works with appropriate outside agencies (MDHHS, JCAHO, etc.) to assure that data collection is appropriate, accurate and timely. Conducts billing and revenue inquiries within electronic health record systems and with relevant third-party payers. Works with internal billing, revenue and financial assistant teams to ensure accurate documentation and claims creation. Follows up with appropriate staff to track medical records requiring abstraction to assure timeliness of data collection. Generates slides and data graphs for use at meetings, etc. as requested. Conducts and participates in medical record reviews (open and closed) in compliance with JCAHO standards. Coordinates the data collection provided through medical record review. Provides reports of this data with explanation to appropriate departments/committees. Data mining, coding, analysis, visualization, reporting, and communication using electronic medical records and health databases. Compile monthly data from different sources and run reports for billing compliance. Respond to data inquiries from clinical and administrative managers. Monitor timely and accurate receipt and transfer of data. Reconcile multiple and conflicting data sources and review disease dashboards. Perform basic statistical analysis and design data visualization solutions. Prepare reports for internal and external stakeholders. Create and run data reports from the electronic medical record and other sources. Generates patient data reports from databases for weekly, monthly and ad hoc review. This involves understanding of custom reports and being able to generate non-custom data reports as required. Works with appropriate departments to follow up on issues relative to record review findings. Transmit coded patient treatment information to payers and other recipients as needed. Coordinate insurance reimbursement of care providers from payers Review patient bills for accuracy and completeness and obtain any missing information Follow up on unpaid claims within standard billing cycle timeframe as needed. Utilizes a high level of interpersonal skills to work effectively with the variety of personnel interacting with and making requests of the databases. Maintains good rapport and cooperative relationships. Approaches conflict in a constructive manner. Helps to identify problems, offer solutions, and participates in their resolution. Required Education, Experience and Licensure Education: Associate's degree in health information technology (RHIT Certified) OR Associates Degree in an allied health field or clinically related field. Experience: 2+ years of related working experience. This position requires working on-site for each scheduled workday. The position is NOT remote and a remote work arrangement will NOT be considered Our Commitment to Diversity and Inclusion Trinity Health is one of the largest not-for-profit, Catholic healthcare systems in the nation. Built on the foundation of our Mission and Core Values, we integrate diversity, equity, and inclusion in all that we do. Our colleagues have different lived experiences, customs, abilities, and talents. Together, we become our best selves. A diverse and inclusive workforce provides the most accessible and equitable care for those we serve. Trinity Health is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other status protected by law.

Posted 3 days ago

Sr. Information Systems Security Officer (Isso)-logo
Sr. Information Systems Security Officer (Isso)
Contact Government ServicesTrenton, NJ
Sr. ISSO Employment Type:Full-Time, Experienced /p> Department: Information Technology CGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment documentation to support Dept. of Commerce systems and efforts to achieve their Authorization to Operate (ATO). This position is located at the client site in the Herbert Hoover building in Washington, DC. The scope of this position includes full life-cycle Assessment and Authorization (A&A) management through all 6 Steps of the RMF process in support of the Government ISSM.In this role, you'll conduct security assessment, and information system security oversight activities in accordance with NIST 800.53 that support systems from the perspective RMF requirements. CGS brings motivated, highly skilled, and creative people together to solve the government's most dynamic problems with cutting-edge technology. To carry out our mission, we are seeking candidates who are excited to contribute to government innovation, appreciate collaboration, and can anticipate the needs of others. Here at CGS, we offer an environment in which our employees feel supported, and we encourage professional growth through various learning opportunities. Skills and attributes for success: Review systems to identify potential security weaknesses and recommend improvements to amend vulnerabilities, implement changes, and document upgrades. Maintain responsibility for managing cybersecurity risk from an organizational perspective. Identify organizational risks, prioritize those risks, and maintain a risk registry for escalating and presenting those risks to senior leadership. Provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies. Providing configuration management (CM) recommendations for information system security software, hardware, and firmware and coordinating changes and modifications with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO). Maintain vulnerability scanning tool compliance, such as HBSS or ACAS, and patch management, such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance with all applicable directives, manage system changes, and assess the security impact of those changes. Support security authorization activities, including transitioning from the legacy Information Assurance Certification and Accreditation Process (DIACAP) to compliance with the DoC RMF. Provide subject matter expertise for cyber security and trusted system technology. Apply advanced technical knowledge and analysis of specialized functional areas in task requirements to develop solutions to complex problems. Research, write, review, disposition feedback, and finalize recommendations regarding cyber security policy, assessment and authorization assessments (A&As), security test and evaluation reports, and security engineering practices and processes. Conduct research and write risk assessment reports to include risk thresholds, evaluation, and scoring. Support analysis of the findings and provide expert technical guidance for mitigation strategies, including implementation advice on the cyber security risk findings, and other complex problems. Qualifications: Bachelor's Degree. A minimum of five (5) years experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development, including generating security documentation for requirements, security control assessment, STIG and IAVA compliance, Standard Operating Procedures, test results, etc. eMASS experience. Professional security certification such as: CCNA Security, CySA+, GICSP, GSEC, CompTIA Security+ CE, SSCP, or higher. Strong desktop publishing skills using Microsoft Word and Excel. Experience with industry writing styles such as grammar, sentence form, and structure. Ability to multi-task in a deadline-oriented environment. Ideally, you will also have: CISSP, CASP, or a similar certificate is preferred. Master's Degree in Cybersecurity or related field. Strong initiative, detail orientation, organizational skills, and aptitude for analytical thinking. Demonstrated ability to work well independently and as a part of a team. Excellent work ethic and a high commitment to quality. Our Commitment: Contact Government Services (CGS) strives to simplify and enhance government bureaucracy through the optimization of human, technical, and financial resources. We combine cutting-edge technology with world-class personnel to deliver customized solutions that fit our client's specific needs. We are committed to solving the most challenging and dynamic problems. For the past seven years, we've been growing our government contracting portfolio, and along the way, we've created valuable partnerships by demonstrating a commitment to honesty, professionalism, and quality work. Here at CGS we value honesty through hard work and self-awareness, professionalism in all we do, and to deliver the best quality to our consumers mending those relations for years to come. We care about our employees. Therefore, we offer a comprehensive benefits package. Health, Dental, and Vision Life Insurance 401k Flexible Spending Account (Health, Dependent Care, and Commuter) Paid Time Off and Observance of State/Federal Holidays Contact Government Services, LLC is an Equal Opportunity Employer. Applicants will be considered without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Join our team and become part of government innovation! Explore additional job opportunities with CGS on our Job Board: https://cgsfederal.com/join-our-team/ For more information about CGS please visit: https://www.cgsfederal.com or contact: Email: info@cgsfederal.com $118,560 - $171,253.33 a year

Posted 30+ days ago

Information Systems Security Manager - Level 2-logo
Information Systems Security Manager - Level 2
CACI International Inc.Annapolis Junction, MD
Information Systems Security Manager - Level 2 Job Category: Information Technology Time Type: Full time Minimum Clearance Required to Start: TS/SCI with Polygraph Employee Type: Regular Percentage of Travel Required: None Type of Travel: The Opportunity: We are seeking a highly skilled and experienced professional to provide comprehensive management support for an organization's Information Assurance (IA) program. The ideal candidate will play a key role in ensuring the security of information systems by overseeing the proposal, coordination, implementation, and enforcement of security policies, standards, and methodologies. Responsibility: The candidate will be responsible for managing the operational security posture of an Information System, ensuring compliance with established policies, procedures, and standards. In this role, the candidate will work closely with Information System Security Engineers (ISSEs) and Information System Security Officers (ISSOs) to evaluate security solutions and assess their effectiveness in protecting classified information. The candidate will also manage vulnerability and risk assessments, as well as contribute to security authorization activities, including preparation and review of critical documentation such as System Security Plans (SSPs), Risk Assessment Reports, and Certification and Accreditation (C&A) packages. The successful candidate will oversee configuration management (CM) processes, ensuring that security software, hardware, and firmware are up-to-date and secure. Additionally, they will be responsible for assessing the security impact of system changes and providing support in line with the Risk Management Framework (RMF) and DoD Information Assurance Certification and Accreditation Process (DIACAP). This position offers a unique opportunity to make a significant impact on the overall security of critical information systems and ensure compliance with all regulatory and security requirements. Qualifications: Required: Current Active TS/SCI with POLY Ten (10) years of work-related experience in the field of security authorization is required. Experience in the following areas is required: knowledge of current security tools, hardware/software security implementation; communication protocols; or encryption tools and techniques. Familiarity with commercial security products, security authorization techniques, security incident management, and PKI and authorization services. Bachelor's degree in Computer Science or a related field (e.g., General Engineering, Computer Engineering, Electrical Engineering, Systems Engineering, Mathematics, Computer Forensics, Cybersecurity, Information Technology, Information Assurance, Information Security, and Information Systems) is required. In lieu of a Bachelor's degree, an additional four (4) years of work-related experience may be substituted. DoD 8570 compliance with IAM II is required. Following certifications qualify: CAP, CASP+ CE, CISM, CISSP (or Associate), GSLC, CCISO, HCISPP Desired: Familiarity with Network Security Services and Chief Information Security Officer processes and procedures. This position is contingent on funding and may not be filled immediately. However, this position is representative of positions within CACI that are consistently available. Individuals who apply may also be considered for other positions at CACI. ____ What You Can Expect: A culture of integrity. At CACI, we place character and innovation at the center of everything we do. As a valued team member, you'll be part of a high-performing group dedicated to our customer's missions and driven by a higher purpose - to ensure the safety of our nation. An environment of trust. CACI values the unique contributions that every employee brings to our company and our customers - every day. You'll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality. A focus on continuous growth. Together, we will advance our nation's most critical missions, build on our lengthy track record of business success, and find opportunities to break new ground - in your career and in our legacy. Your potential is limitless. So is ours. Learn more about CACI here. ____ Pay Range: There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits. Learn more here. The proposed salary range for this position is: $103,800 - $218,100 CACI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any other protected characteristic.

Posted 1 week ago

Information Security Compliance Audit Associate-logo
Information Security Compliance Audit Associate
RELX GroupAlpharetta, GA
Are you ready to elevate your career by ensuring top-notch security compliance in a dynamic and innovative company? Do you have the expertise and passion to drive impactful security audits in a fast-paced environment? About the Team: Our Information Security Compliance team is dedicated to safeguarding the integrity and confidentiality of our organization's data. We are a dynamic group of professionals who thrive on collaboration and innovation. Our team is responsible for conducting thorough security audits, ensuring compliance with industry standards, and implementing best practices to protect our systems and information. About the Role: Execute test plans based on ISO27002:2013/ 2022 and reporting of internal testing for the FTC information security assessment for both RELX and ChoicePoint FTC Orders under the direction and supervision of the Head of Internal Audit and Assurance (IAA) and Head of FTC Information Security & Compliance. Execute and report information technology, security, privacy, and operational reviews with direct and indirect supervision from the Head of FTC Information Security & Compliance, Head of Internal Audit and Assurance and other team members. Execution of test plans will include data analysis of system user listings, log files, changes, network diagrams, system configurations, etc. to determine operating effectiveness of controls. Test plans will include detailed documentation including narratives of detailed test procedures, test results and description on internal controls as well as detailed explanations of any potential testing exceptions. Conduct one-on-one interviews with Information Technology control owners to gain an understanding of the underlying information technology control environment. These reviews will identify business, privacy, security, compliance, information technology and regulatory risks, in addition to identifying cost savings opportunities and typically include the following type of reviews: application audits; network reviews; information security audits; user access reviews; system development life cycle (SDLC) reviews; fraud detection & incident response reviews; regulatory and other compliance reviews (e.g., FCRA, DPPA, GLBA, HIPAA software licensing); and general information technology controls reviews. Work closely with the third party auditor to ensure document requests are returned in a timely manner, and the documentation meets the needs of the third party auditor. The role will also be responsible for setting up meetings with control owners, obtaining and providing audit evidence as well as preparing IAA work papers. Duties also include working with IAA management on existing and proposed information technology projects to integrate continuous auditing technologies such as audit hooks and integrated test facilities into these applications. Identify control gaps and process improvements and communicating such to the Head of Internal Audit and Assurance (IAA) and Head of FTC Information Security & Compliance. Work with the IADP Security Programs group for implementation of remediation and control improvement plans. Provide support, as needed, to the IADP Privacy Programs group regarding its maintenance of the inventory of applications and systems deemed in scope for the assessments, which will be updated at least annually. Required Skills: B.A. or B.S. Degree in MIS, Computer Science, Finance or Accounting IT or Security Experience (i.e. development, Q/A, sys admin, etc) Exceptional written and verbal communication skills Familiarity with researching applicable new technologies, system control and audit topics on the Internet (i.e., proficient in use of Internet search engines). Working Knowledge of Microsoft Access, Powerpoint, Excel and Word Working towards CISA or CIPP certification Work in a way that works for you: We promote a healthy work/life balance across the organization. We offer an appealing working prospect for our people. With numerous wellbeing initiatives, shared parental leave and study assistance we will help you meet your immediate responsibilities and your long-term goals. Working for you: We know that your wellbeing and happiness are key to a long and successful career. These are some of the benefits we are delighted to offer: Health Benefits: Comprehensive, multi-carrier program for medical, dental and vision benefits Retirement Benefits: 401(k) with match and an Employee Share Purchase Plan Wellbeing: Wellness platform with incentives, Headspace app subscription, Employee Assistance and Time-off Programs Short-and-Long Term Disability, Life and Accidental Death Insurance, Critical Illness, and Hospital Indemnity Family Benefits, including bonding and family care leaves, adoption and surrogacy benefits Health Savings, Health Care, Dependent Care and Commuter Spending Accounts In addition to annual Paid Time Off, we offer up to two days of paid leave each to participate in Employee Resource Groups and to volunteer with your charity of choice About the Business RELX is a global provider of information-based analytics and decision tools for professional and business customers. RELX serves customers in more than 180 countries and has offices in about 40 countries. It employs more than 36,000 people over 40% of whom are in North America. The headquarters is in London. The market capitalization is about £60bn ($80bn), making it one of the 10 largest listed companies in the UK. The company is listed on the London Stock Exchange, Euronext and NYSE. The company has four market segments. It develops information-based analytics and decision tools for professional and business customers in the Risk, Scientific, Technical & Medical, Legal, and Exhibitions sectors. RELX is an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law. We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Form: https://forms.office.com/r/eVgFxjLmAK , or please contact 1-855-833-5120. Please read our Candidate Privacy Policy.

Posted 2 weeks ago

Avp, Information Security Engineer-logo
Avp, Information Security Engineer
LPL Financial ServicesAustin, TX
What if you could build a career where ambition meets innovation? At LPL Financial, we empower professionals to shape their success while helping clients pursue their financial goals with confidence. What if you could have access to cutting-edge resources, a collaborative environment, and the freedom to make an impact? If you're ready to take the next step, discover what's possible with LPL Financial. Job Overview: LPL Financial is currently seeking an AVP to join its Information Security department. The ideal candidate will have a well-rounded IGA, security-focused, application technology background, as well as the ability to autonomously manage projects and provide thought leadership to junior team members. This is very technical, hands-on experience role. Responsibilities: Design, implement, administer, manage, troubleshoot, and support our IGA environment Evaluate IAM security posture and make recommendations to ensure compliance with organizational security standards Assess IAM security systems and processes to identify potential risk gaps and compliance issues Document IAM security solution architectures and identify control gaps Partner with Information Security teams to ensure proposed solutions adhere to defined specifications Conduct research to keep abreast of the latest industry trends, topics, and security issues Member of on-call rotation to support response to IAM incidents Performs other job-related duties or special projects as assigned What are we looking for? We're looking for strong collaborators who deliver exceptional client experiences and thrive in fast-paced, team-oriented environments. Our ideal candidates pursue greatness, act with integrity, and are driven to help our clients succeed. We value those who embrace creativity, continuous improvement, and contribute to a culture where we win together and create and share joy in our work. Requirements: Deep technical knowledge and hands-on experience with IGA UIs, configurations, connectors, JAVA, JIRA, and logging tools 8+ years of design, configuration, and delivery experience with Sailpoint, ForgeRock, Saviynt, or other Identity Management provisioning systems 8+ years of experience with IAM connectors and APIs Excellent ability to document and diagram solutions and infrastructure using Lucid or Visio Core Competencies: Excellent leadership and communication skill Excellent troubleshooting skills, ability to identify root causes of issues, provide solutions, and communicate to leadership Preferences: Financial Services Industry experience a plus. Foundational understanding of risk management and compliance frameworks such as NIST 800-53 or CSF, CIS, ISO 27001 Strong understanding of IAM architectures, design, and challenges Industry-relevant information security and IAM certifications strongly preferred, but not required #LI-Hybrid Pay Range: $117,225-$195,375/year Actual base salary varies based on factors, including but not limited to, relevant skill, prior experience, education, base salary of internal peers, demonstrated performance, and geographic location. Additionally, LPL Total Rewards package is highly competitive, designed to support your success at work, at home, and at play - such as 401K matching, health benefits, employee stock options, paid time off, volunteer time off, and more. Your recruiter will be happy to discuss all that LPL has to offer! Company Overview: LPL Financial Holdings Inc. (Nasdaq: LPLA) was founded on the principle that the firm should work for advisors and institutions, and not the other way around. Today, LPL is a leader in the markets we serve, serving more than 23,000 financial advisors, including advisors at approximately 1,000 institutions and at approximately 580 registered investment advisor ("RIA") firms nationwide. We are steadfast in our commitment to the advisor-mediated model and the belief that Americans deserve access to personalized guidance from a financial professional. At LPL, independence means that advisors and institution leaders have the freedom they deserve to choose the business model, services, and technology resources that allow them to run a thriving business. They have the flexibility to do business their way. And they have the freedom to manage their client relationships, because they know their clients best. Simply put, we take care of our advisors and institutions, so they can take care of their clients. Join LPL Financial: Where Your Potential Meets Opportunity At LPL Financial, we believe that everyone deserves objective financial guidance. As the nation's leading independent broker-dealer, we offer an integrated platform of cutting-edge technology, brokerage, and investment advisor services. Why LPL? Innovative Environment: We foster creativity and growth, providing a supportive and responsive leadership team. Learn more about our leadership team here! Limitless Career Potential: Your career at LPL has no limits, only amazing potential. Learn more about our careers here! Unified Mission: We are one team on one mission-taking care of our advisors so they can take care of their clients. Learn more about our mission and values here! Impactful Work: Our size is just right for you to make a real impact. Learn more here! Commitment to Equality: We support workplace equality and embrace diverse perspectives and backgrounds. Learn more here! Community Focus: We care for our communities and encourage our employees to do the same. Learn more here! Benefits and Total Rewards: Our Total Rewards package goes beyond just compensation and insurance. It includes a mix of traditional and unique benefits, perks, and resources designed to enhance your life both at work and at home. Learn more here! Join the LPL team and help us make a difference by turning life's aspirations into financial realities. Please log in or create an account to apply to this position. Principals only. EOE. Information on Interviews: LPL will only communicate with a job applicant directly from an @lplfinancial.com email address and will never conduct an interview online or in a chatroom forum. During an interview, LPL will not request any form of payment from the applicant, or information regarding an applicant's bank or credit card. Should you have any questions regarding the application process, please contact LPL's Human Resources Solutions Center at (855) 575-6947. EAC1.22.25

Posted 30+ days ago

Manager Of Human Resources Information System - FT - Day Shift-logo
Manager Of Human Resources Information System - FT - Day Shift
EcmcBuffalo, NY
SALARY RANGE: $80,750.00 - $109,250.00 DISTINGUISHING FEATURES OF THE CLASS: The work involves supervising the operation, development, and implementation of the Human Resources Information System (HRIS) in the Human Resources Department at the Erie County Medical Center. The incumbent oversees the effectiveness and efficiency of the HRIS by providing technical expertise and supervising system operations and maintenance as performed by lower-level staff. Work is performed under the direction of the Director of Compensation, Benefits, and Human Resource Information Systems with leeway for the use of independent judgment in carrying out the details of the work. Supervision is exercised over lower-level employees. Does related work as required. TYPICAL WORK ACTIVITIES: Assigns, supervises and evaluates the work of lower-level HRIS staff; Oversees HRIS software processes, implementation and system upgrades utilizing current and emerging technology and related processes; Oversees the development and implementation of new or updated systems, reports and dashboards, testing of system changes and analysis of data flows; Coordinates the proper operation of the HRIS, related systems and data transfer into and from the system and related interfaces; monitors operation for compliance with applicable legal and regulatory requirements; Provides overall project management for Human Resources initiatives related to HRIS; supports technical projects as assigned; Works with internal business partners to identify and recommend analytics needed for business objectives utilizing existing system capabilities; Establishes and maintains security and integrity controls by managing system access profiles for all users; Designs and leads HRIS change management programs; Creates training programs for system users on new or existing processes and procedures; Develops user procedures, guidelines and documentation for HR initiatives related to HRIS; Attends and participates in meetings, seminars and training sessions; Keeps abreast of current trends in computerized HRIS systems and maintains a strong vendor relationship. FULL PERFORMANCE KNOWLEDGES, SKILLS, ABILITITIES AND PERSONAL CHARACTERISTICS: Thorough knowledge of HRIS project development, implementation and management; thorough knowledge of processes and procedures of HRIS and their relation to other systems; thorough knowledge of HRIS systems and modules utilized at ECMCC; thorough knowledge of ECMCC organizational structure, departments and collective bargaining agreements; thorough knowledge of data integrity processes as they relate to benefits, compensation and payroll; good knowledge of applicable laws, rules and regulations, including New York State Civil Service Law; skill in advanced operation of Microsoft applications, including Excel and query/report development; strong analytical and critical thinking skills; ability to analyze and interpret complex data; ability to research and interpret industry trends; ability to write training materials and user instructions; ability to plan the work of and supervise lower-level staff; ability to train others; ability to communicate effectively, both orally and in writing; ability to establish and maintain effective working relationships with a diverse constituency; ability to utilize a variety of electronic software applications; sound professional judgment; capable of performing the essential functions of the position with or without reasonable accommodation. MINIMUM QUALIFICATIONS: A.) Graduation from a regionally accredited or New York State registered college or university with a Master's Degree and two (2) years of personnel experience, of which included one (1) year of utilizing a human resources information system to write and run data reports and analysis of HRIS workflow; or: B.) Graduation from a regionally accredited or New York State registered college or university with a Bachelor's Degree and four (4) years of personnel experience, of which included one (1) year of utilizing a human resources information system to write and run data reports and analysis of HRIS workflow; or: C.) An equivalent combination of experience and training as defined by the limits of (A) and (B). NOTE: Verifiable part time and/or volunteer experience will be pro-rated toward meeting full-time experience requirements.

Posted 30+ days ago

Tax Senior Manager - Global Information Reporting-logo
Tax Senior Manager - Global Information Reporting
PwCSilicon Valley, CA
Industry/Sector Not Applicable Specialism General Tax Consulting Management Level Senior Manager Job Description & Summary A career within Financial Markets Business Advisory services, will provide you with the opportunity to contribute to a variety of audit, regulatory, valuation, and financial analyses services to design solutions that address our clients' complex accounting and financial reporting challenges, as well as their broader business issues. To really stand out and make us fit for the future in a constantly changing world, each and every one of us at PwC needs to be a purpose-led and values-driven leader at every level. To help us achieve this we have the PwC Professional; our global leadership development framework. It gives us a single set of expectations across our lines, geographies and career paths, and provides transparency on the skills we need as individuals to be successful and progress in our careers, now and in the future. As a Senior Manager, you'll work as part of a team of problem solvers, helping to solve complex business issues from strategy to execution. PwC Professional skills and responsibilities for this management level include but are not limited to: Encourage everyone to have a voice and invite opinion from all, including quieter members of the team. Deal effectively with ambiguous and unstructured problems and situations. Initiate open and candid coaching conversations at all levels. Move easily between big picture thinking and managing relevant detail. Anticipate stakeholder needs, and develop and discuss potential solutions, even before the stakeholder realises they are required. Contribute technical knowledge in area of specialism. Contribute to an environment where people and technology thrive together to accomplish more than they could apart. Navigate the complexities of cross-border and/or diverse teams and engagements. Initiate and lead open conversations with teams, clients and stakeholders to build trust. Uphold the firm's code of ethics and business conduct. Job Requirements and Preferences: Basic Qualifications: Minimum Degree Required: Bachelor Degree Minimum Year(s) of Experience: 7 year(s) Certification(s) Required: CPA, Enrolled Agent or Active Member of the Bar Preferred Qualifications: Preferred Fields of Study: Accounting,Accounting & Finance,Taxation,Management Information Systems & Accounting Additional Educational Preferences: Bachelor's degree, and J.D., L.L.M. in Taxation from an accredited college/university; or Master's in Taxation (MST) from an accredited college/university Preferred Knowledge/Skills: PwC's Global Information Reporting (GIR) practice helps our clients comply with an international set of rules that are focused on information reporting and withholding tax requirements on payments to investors and vendors in line with a global initiative of creating tax transparency and cross-border sharing of information. Our tax practice helps our clients comply with complex information reporting and withholding rules under chapter 61, chapter 3, chapter 4 (Foreign Account Tax Compliance Act - FATCA), the Common Reporting Standard (CRS) and other regimes. Demonstrates intimate abilities and/or a proven record of success in the following areas: Provide guidance to clients regarding compliance with global tax information reporting and withholding rules; Research complex tax issues and reach appropriate conclusions for our clients; Apply tax technical skills in reviewing US Internal Revenue Service (IRS) tax forms including: Forms W-9, W-8BEN, W-8BEN-E, W-8ECI, W-8EXP and W-8IMY, related tax documentary evidence as well as Common Reporting Standard (CRS) self-certifications; Lead staff in preparing and filing information returns (e.g., Forms 1099 and 1042-S), FBAR, and Automatic Exchange of Information (FATCA & CRS) returns; Develop innovative technology solutions to increase efficiency, such as digital tools that capture and process information; Assist in the development of educational materials for information reporting and withholding requirements for both internal and client workshops; Train and manage local staff and contribute to the development of your team's technical acumen; Understand applicable US tax rules and requirements including IRS publications and tax form instructions; Execute client engagements to meet statutory, regulatory and project based deadlines; Have a fundamental understanding of the applicable US tax rules and requirements including IRS publications and tax form instructions; Be familiar with the the requirements under the Common Reporting Standard (CRS) as set out by the OECD and the Foreign Account Tax Compliance Act (FATCA); Possess written, organizational, and verbal communication skills; Possess analytical, problem solving, and project management skills; Drive success as both an individual contributor and team member; Identify and address our client needs by actively participating in client discussions and meetings; Manage multiple client engagements concurrently; Have a work ethic with attention to detail; Be proficient in Microsoft Excel, Word, and Powerpoint; Be proficient in Google Applications; and, Be willing to travel in a post-covid world. Travel Requirements Up to 20% Job Posting End Date Learn more about how we work: https://pwc.to/how-we-work PwC does not intend to hire experienced or entry level job seekers who will need, now or in the future, PwC sponsorship through the H-1B lottery, except as set forth within the following policy: https://pwc.to/H-1B-Lottery-Policy . As PwC is an equal opportunity employer, all qualified applicants will receive consideration for employment at PwC without regard to race; color; religion; national origin; sex (including pregnancy, sexual orientation, and gender identity); age; disability; genetic information (including family medical history); veteran, marital, or citizenship status; or, any other status protected by law. For only those qualified applicants that are impacted by the Los Angeles County Fair Chance Ordinance for Employers, the Los Angeles' Fair Chance Initiative for Hiring Ordinance, the San Francisco Fair Chance Ordinance, San Diego County Fair Chance Ordinance, and the California Fair Chance Act, where applicable, arrest or conviction records will be considered for Employment in accordance with these laws. At PwC, we recognize that conviction records may have a direct, adverse, and negative relationship to responsibilities such as accessing sensitive company or customer information, handling proprietary assets, or collaborating closely with team members. We evaluate these factors thoughtfully to establish a secure and trusted workplace for all. Applications will be accepted until the position is filled or the posting is removed, unless otherwise set forth on the following webpage. Please visit this link for information about anticipated application deadlines: https://pwc.to/us-application-deadlines The salary range for this position is: $119,300 - $328,000, plus individuals may be eligible for an annual discretionary bonus. For roles that are based in Maryland, this is the listed salary range for this position. Actual compensation within the range will be dependent upon the individual's skills, experience, qualifications and location, and applicable employment laws. PwC offers a wide range of benefits, including medical, dental, vision, 401k, holiday pay, vacation, personal and family sick leave, and more. To view our benefits at a glance, please visit the following link: https://pwc.to/benefits-at-a-glance

Posted 1 week ago

Information Systems Security Officer (Isso)-logo
Information Systems Security Officer (Isso)
Contact Government ServicesKansas City, MO
ISSO Employment Type: Full-Time, Experienced Department:Information Technology CGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment documentation to support Dept. of Commerce systems and efforts to achieve their Authorization to Operate (ATO). This position is located at the client site in the Herbert Hoover building in Washington, DC. The scope of this position includes full life-cycle Assessment and Authorization (A&A) management through all 6 Steps of the RMF process in support of the Government ISSM.In this role, you'll conduct security assessment, and information system security oversight activities in accordance with NIST 800.53 that support systems from the perspective RMF requirements. CGS brings motivated, highly skilled, and creative people together to solve the government's most dynamic problems with cutting-edge technology. To carry out our mission, we are seeking candidates who are excited to contribute to government innovation, appreciate collaboration, and can anticipate the needs of others. Here at CGS, we offer an environment in which our employees feel supported, and we encourage professional growth through various learning opportunities. Skills and attributes for success: Review systems to identify potential security weaknesses and recommend improvements to amend vulnerabilities, implement changes, and document upgrades. Maintain responsibility for managing cybersecurity risk from an organizational perspective. Identify organizational risks, prioritize those risks, and maintain a risk registry for escalating and presenting those risks to senior leadership. Provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies. Providing configuration management (CM) recommendations for information system security software, hardware, and firmware and coordinating changes and modifications with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO). Maintain vulnerability scanning tool compliance, such as HBSS or ACAS, and patch management, such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance with all applicable directives, manage system changes, and assess the security impact of those changes. Support security authorization activities, including transitioning from the legacy Information Assurance Certification and Accreditation Process (DIACAP) to compliance with the DoC RMF. Provide subject matter expertise for cyber security and trusted system technology. Apply advanced technical knowledge and analysis of specialized functional areas in task requirements to develop solutions to complex problems. Research, write, review, disposition feedback, and finalize recommendations regarding cyber security policy, assessment and authorization assessments (A&As), security test and evaluation reports, and security engineering practices and processes. Conduct research and write risk assessment reports to include risk thresholds, evaluation, and scoring. Support analysis of the findings and provide expert technical guidance for mitigation strategies, including implementation advice on the cyber security risk findings, and other complex problems. Qualifications: Bachelor's Degree. A minimum of five (5) years experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development, including generating security documentation for requirements, security control assessment, STIG and IAVA compliance, Standard Operating Procedures, test results, etc. eMASS experience. Professional security certification such as: CCNA Security, CySA+, GICSP, GSEC, CompTIA Security+ CE, SSCP, or higher. Strong desktop publishing skills using Microsoft Word and Excel. Experience with industry writing styles such as grammar, sentence form, and structure. Ability to multi-task in a deadline-oriented environment. Ideally, you will also have: CISSP, CASP, or a similar certificate is preferred. Master's Degree in Cybersecurity or related field. Strong initiative, detail orientation, organizational skills, and aptitude for analytical thinking. Demonstrated ability to work well independently and as a part of a team. Excellent work ethic and a high commitment to quality. Our Commitment: Contact Government Services (CGS) strives to simplify and enhance government bureaucracy through the optimization of human, technical, and financial resources. We combine cutting-edge technology with world-class personnel to deliver customized solutions that fit our client's specific needs. We are committed to solving the most challenging and dynamic problems. For the past seven years, we've been growing our government contracting portfolio, and along the way, we've created valuable partnerships by demonstrating a commitment to honesty, professionalism, and quality work. Here at CGS we value honesty through hard work and self-awareness, professionalism in all we do, and to deliver the best quality to our consumers mending those relations for years to come. We care about our employees. Therefore, we offer a comprehensive benefits package. Health, Dental, and Vision Life Insurance 401k Flexible Spending Account (Health, Dependent Care, and Commuter) Paid Time Off and Observance of State/Federal Holidays Contact Government Services, LLC is an Equal Opportunity Employer. Applicants will be considered without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Join our team and become part of government innovation! Explore additional job opportunities with CGS on our Job Board: https://cgsfederal.com/join-our-team/ For more information about CGS please visit: https://www.cgsfederal.com or contact: Email: info@cgsfederal.com $92,213.33 - $125,146.66 a year

Posted 30+ days ago

Sr. Information Systems Security Officer (Isso)-logo
Sr. Information Systems Security Officer (Isso)
Contact Government ServicesSeattle, WA
Sr. ISSO Employment Type:Full-Time, Experienced /p> Department: Information Technology CGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment documentation to support Dept. of Commerce systems and efforts to achieve their Authorization to Operate (ATO). This position is located at the client site in the Herbert Hoover building in Washington, DC. The scope of this position includes full life-cycle Assessment and Authorization (A&A) management through all 6 Steps of the RMF process in support of the Government ISSM.In this role, you'll conduct security assessment, and information system security oversight activities in accordance with NIST 800.53 that support systems from the perspective RMF requirements. CGS brings motivated, highly skilled, and creative people together to solve the government's most dynamic problems with cutting-edge technology. To carry out our mission, we are seeking candidates who are excited to contribute to government innovation, appreciate collaboration, and can anticipate the needs of others. Here at CGS, we offer an environment in which our employees feel supported, and we encourage professional growth through various learning opportunities. Skills and attributes for success: Review systems to identify potential security weaknesses and recommend improvements to amend vulnerabilities, implement changes, and document upgrades. Maintain responsibility for managing cybersecurity risk from an organizational perspective. Identify organizational risks, prioritize those risks, and maintain a risk registry for escalating and presenting those risks to senior leadership. Provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies. Providing configuration management (CM) recommendations for information system security software, hardware, and firmware and coordinating changes and modifications with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO). Maintain vulnerability scanning tool compliance, such as HBSS or ACAS, and patch management, such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance with all applicable directives, manage system changes, and assess the security impact of those changes. Support security authorization activities, including transitioning from the legacy Information Assurance Certification and Accreditation Process (DIACAP) to compliance with the DoC RMF. Provide subject matter expertise for cyber security and trusted system technology. Apply advanced technical knowledge and analysis of specialized functional areas in task requirements to develop solutions to complex problems. Research, write, review, disposition feedback, and finalize recommendations regarding cyber security policy, assessment and authorization assessments (A&As), security test and evaluation reports, and security engineering practices and processes. Conduct research and write risk assessment reports to include risk thresholds, evaluation, and scoring. Support analysis of the findings and provide expert technical guidance for mitigation strategies, including implementation advice on the cyber security risk findings, and other complex problems. Qualifications: Bachelor's Degree. A minimum of five (5) years experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development, including generating security documentation for requirements, security control assessment, STIG and IAVA compliance, Standard Operating Procedures, test results, etc. eMASS experience. Professional security certification such as: CCNA Security, CySA+, GICSP, GSEC, CompTIA Security+ CE, SSCP, or higher. Strong desktop publishing skills using Microsoft Word and Excel. Experience with industry writing styles such as grammar, sentence form, and structure. Ability to multi-task in a deadline-oriented environment. Ideally, you will also have: CISSP, CASP, or a similar certificate is preferred. Master's Degree in Cybersecurity or related field. Strong initiative, detail orientation, organizational skills, and aptitude for analytical thinking. Demonstrated ability to work well independently and as a part of a team. Excellent work ethic and a high commitment to quality. Our Commitment: Contact Government Services (CGS) strives to simplify and enhance government bureaucracy through the optimization of human, technical, and financial resources. We combine cutting-edge technology with world-class personnel to deliver customized solutions that fit our client's specific needs. We are committed to solving the most challenging and dynamic problems. For the past seven years, we've been growing our government contracting portfolio, and along the way, we've created valuable partnerships by demonstrating a commitment to honesty, professionalism, and quality work. Here at CGS we value honesty through hard work and self-awareness, professionalism in all we do, and to deliver the best quality to our consumers mending those relations for years to come. We care about our employees. Therefore, we offer a comprehensive benefits package. Health, Dental, and Vision Life Insurance 401k Flexible Spending Account (Health, Dependent Care, and Commuter) Paid Time Off and Observance of State/Federal Holidays Contact Government Services, LLC is an Equal Opportunity Employer. Applicants will be considered without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Join our team and become part of government innovation! Explore additional job opportunities with CGS on our Job Board: https://cgsfederal.com/join-our-team/ For more information about CGS please visit: https://www.cgsfederal.com or contact: Email: info@cgsfederal.com $118,560 - $171,253.33 a year

Posted 30+ days ago

Information Systems Security Officer (Isso)-logo
Information Systems Security Officer (Isso)
Contact Government ServicesKnoxville, TN
ISSO Employment Type: Full-Time, Experienced Department:Information Technology CGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment documentation to support Dept. of Commerce systems and efforts to achieve their Authorization to Operate (ATO). This position is located at the client site in the Herbert Hoover building in Washington, DC. The scope of this position includes full life-cycle Assessment and Authorization (A&A) management through all 6 Steps of the RMF process in support of the Government ISSM.In this role, you'll conduct security assessment, and information system security oversight activities in accordance with NIST 800.53 that support systems from the perspective RMF requirements. CGS brings motivated, highly skilled, and creative people together to solve the government's most dynamic problems with cutting-edge technology. To carry out our mission, we are seeking candidates who are excited to contribute to government innovation, appreciate collaboration, and can anticipate the needs of others. Here at CGS, we offer an environment in which our employees feel supported, and we encourage professional growth through various learning opportunities. Skills and attributes for success: Review systems to identify potential security weaknesses and recommend improvements to amend vulnerabilities, implement changes, and document upgrades. Maintain responsibility for managing cybersecurity risk from an organizational perspective. Identify organizational risks, prioritize those risks, and maintain a risk registry for escalating and presenting those risks to senior leadership. Provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies. Providing configuration management (CM) recommendations for information system security software, hardware, and firmware and coordinating changes and modifications with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO). Maintain vulnerability scanning tool compliance, such as HBSS or ACAS, and patch management, such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance with all applicable directives, manage system changes, and assess the security impact of those changes. Support security authorization activities, including transitioning from the legacy Information Assurance Certification and Accreditation Process (DIACAP) to compliance with the DoC RMF. Provide subject matter expertise for cyber security and trusted system technology. Apply advanced technical knowledge and analysis of specialized functional areas in task requirements to develop solutions to complex problems. Research, write, review, disposition feedback, and finalize recommendations regarding cyber security policy, assessment and authorization assessments (A&As), security test and evaluation reports, and security engineering practices and processes. Conduct research and write risk assessment reports to include risk thresholds, evaluation, and scoring. Support analysis of the findings and provide expert technical guidance for mitigation strategies, including implementation advice on the cyber security risk findings, and other complex problems. Qualifications: Bachelor's Degree. A minimum of five (5) years experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development, including generating security documentation for requirements, security control assessment, STIG and IAVA compliance, Standard Operating Procedures, test results, etc. eMASS experience. Professional security certification such as: CCNA Security, CySA+, GICSP, GSEC, CompTIA Security+ CE, SSCP, or higher. Strong desktop publishing skills using Microsoft Word and Excel. Experience with industry writing styles such as grammar, sentence form, and structure. Ability to multi-task in a deadline-oriented environment. Ideally, you will also have: CISSP, CASP, or a similar certificate is preferred. Master's Degree in Cybersecurity or related field. Strong initiative, detail orientation, organizational skills, and aptitude for analytical thinking. Demonstrated ability to work well independently and as a part of a team. Excellent work ethic and a high commitment to quality. Our Commitment: Contact Government Services (CGS) strives to simplify and enhance government bureaucracy through the optimization of human, technical, and financial resources. We combine cutting-edge technology with world-class personnel to deliver customized solutions that fit our client's specific needs. We are committed to solving the most challenging and dynamic problems. For the past seven years, we've been growing our government contracting portfolio, and along the way, we've created valuable partnerships by demonstrating a commitment to honesty, professionalism, and quality work. Here at CGS we value honesty through hard work and self-awareness, professionalism in all we do, and to deliver the best quality to our consumers mending those relations for years to come. We care about our employees. Therefore, we offer a comprehensive benefits package. Health, Dental, and Vision Life Insurance 401k Flexible Spending Account (Health, Dependent Care, and Commuter) Paid Time Off and Observance of State/Federal Holidays Contact Government Services, LLC is an Equal Opportunity Employer. Applicants will be considered without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Join our team and become part of government innovation! Explore additional job opportunities with CGS on our Job Board: https://cgsfederal.com/join-our-team/ For more information about CGS please visit: https://www.cgsfederal.com or contact: Email: info@cgsfederal.com $92,213.33 - $125,146.66 a year

Posted 30+ days ago

Xpansiv logo
Information Security Officer
XpansivNew York, NY
Apply

Automate your job search with Sonara.

Submit 10x as many applications with less effort than one manual application.1

Reclaim your time by letting our AI handle the grunt work of job searching.

We continuously scan millions of openings to find your top matches.

pay-wall

Job Description

Xpansiv, a trailblazer in the energy and environmental commodities market, operates the integrated, open, and neutral market platform designed to accelerate the global energy transition. Xpansiv provides thousands of market participants and intermediaries with access to the widest possible range of energy transition markets, through its suite of solutions, including the world's largest environmental commodities trading platform, where billions of assets cross per year. Xpansiv's end-to-end technology platform services the entire life cycle of environmental commodities, connecting diverse markets and market participants across the world and enabling stakeholders to deliver transparent and trusted environmental claims to address the growing demand for energy transition. Leveraging its extensive industry knowledge and proven technology portfolio, Xpansiv assists companies seeking to identify and mitigate risk, streamline the management of their environmental assets, and comply with regulations, caps and commitments.

Position Summary:

Xpansiv is looking for an Information Security Officer to join the Global Risk and Compliance team. This role will be key in the future development and execution of the information security program working directly with the Chief Risk Officer (CRO), CTO, engineers, risk, legal, and the lines of business, as well as with executive management. The ISO will drive and refine the company's information security strategic goals with responsibility for executing Xpansiv's information security program. The ISO will set the strategic direction and day to day execution of the information security program. The ideal candidate will be able to balance the need to be hands on and manage a team, as well as partnering with other part of the organization.

Essential Functions:

  • Responsible for further development and execution of Xpansiv's information security strategic plan in partnership with the Chief Risk Office, Chief Technology Officer and other security, business and technology team members.
  • Continue to develop a comprehensive information security program to safeguard Xpansiv.
  • Propose enhancements to the Information Security policies, standards and procedures.
  • Update the Information Security Program based on regulatory changes, threats, best practices, business needs and feedback from management.

Job Requirements:

  • Conduct risk assessments to identify potential changes to the security posture and recommend appropriate ways to address and gaps.
  • Determine acceptable risk levels for the Information Security and ensure threats to the company are mitigated in alignment with the company's risk appetite.
  • Support audits and regulatory exams. Coordinate management's responses to information security-related findings.
  • Lead responses to customers' information security inquiries into Xpansiv's security posture.
  • Deep knowledge across the security tools and frameworks with an understanding which works best in different industries and environments.
  • Drive and deliver the development and implementation of the appropriate and effective controls to protect the organization's assets.
  • Participate in the preparation of risk assessments to evaluate new technologies, applications, and devices.
  • Build out the information security awareness training for employees and Board of Directors with a detailed deep dive for Cyber Security Awareness month.
  • Support or execute security related testing as needed for material technology driven changes. Ensure the remediation teams have sound plans and execute those in a timely manner.
  • Collaborate with the business and/or Information Technology to select appropriate technology vendors that support regulatory requirements and best practices.
  • Familiarity with key security solutions.
  • Understanding of international security obligations.
  • Refine a company-wide data loss prevention program to protect customer and company confidential information.
  • Provide guidance on projects, new implementations, or upgrades in adherence with the Information Security Program.
  • Run the Business Continuity Program, which includes working closely with business lines to ensure business impact analyses are comprehensive. This includes running incident response actions and driving follow up activity to closure.

Other Knowledge, Skills and Abilities:

  • Bachelor's degree in computer science, information systems or equivalent work experience is required.
  • Industry standard certification in information security, such as CISSP, CISM, CRISC, or acquisition within one year of hire.
  • Five years of experience supporting security architectures and applying security best practices across enterprise environments.
  • Highly familiar with cloud-based solutions
  • Possess excellent analytical, organizational and documentation skills.
  • Strong knowledge of both cybersecurity and IT risk management programs based on industry recognizable frameworks.
  • Strong collaboration and communication skills with the ability to tailor messages to the audience.
  • Equally comfortable working independently as with a team while building and maintaining collegial relationships across the company including with the commercial and technical teams.
  • Persuasive leader who can serve as an effective member of the management team and is able to communicate security-related concepts to a broad range of technical and non-technical staff.
  • Practical experience with vulnerability scanning and auditing tools.
  • Knowledge of DevOps application security.
  • Experience with cloud security best practices.
  • Ready to work in a highly dynamic and exciting environment.

What can you expect throughout the interview process:

Step 1- Shortlisting of resume & Recruiter screening

Step 2- "Get to know you" interview with the hiring manager

Step 3- Meeting with team & key leaders

Base Salary

Compensation for this role will vary among specific regions due to geographic differentials in the labor market, actual pay will be determined considering factors such as relevant skills and experience, knowledge, education and training. However, the base compensation in New York is expected to be as follows:

$250,000 -$270,000

Here at Xpansiv, we cultivate diversity, celebrate individuality, and believe unique perspectives are key to our collective success in building trust and transparency in global efforts toward net-zero future. Xpansiv is committed to equal employment opportunity regardless of race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, protected veteran status, or any status protected by applicable federal, state, or local law.

Note to Recruiters: Xpansiv does not accept unsolicited resumes or referrals from placement agencies, staffing vendors or other external parties seeking recruiting fees without a signed formal agreement.