landing_page-logo
  1. Home
  2. »All Job Categories
  3. »Security Jobs

Auto-apply to these security jobs

We've scanned millions of jobs. Simply select your favorites, and we can fill out the applications for you.

Information Security Assurance Analyst-logo
Information Security Assurance Analyst
Randolph Brooks Federal Credit UnionSan Antonio, TX
Job Description and Requirements Randolph-Brooks Federal Credit Union is currently searching for an experienced and talented Information Security Assurance Analyst to join our amazing IT Security team! The Information Security Assurance Analyst will have the ability to work a hybrid schedule (remote/onsite) after a period of training (time frame may vary). Training will take place at the RBFCU Administrative Service Center: 1 Ikea-RBFCU Pkwy, Live Oak, Texas 78233. All applicants must reside within the state of Texas and have the capability of performing all of the work from their home in Texas. To successfully work from home, employees must have access to a minimum internet connection as noted by RBFCU. Must have a reliable home internet provider and the ability to hard wire a connection directly to modem (Ethernet cable provided). Must be able to provide a workspaces at home that is safe, suitable for work, and within a distraction free environment The Information Security Assurance Analyst strengthen the organization's information security posture through the construction, socialization and performance measurement of policies and procedures based on best practices, adopted frameworks, and risk assessment activities. Essential Functions and Responsibilities: Contribute to the strategic and tactical initiatives involving activities associated with managing IT Risk. Assist with auditing systems, processes and users to ensure compliance with the organization's information security policies and procedures. Assist in the creation and analysis of information security reports on the performance of controls across the enterprise. Assist with documenting an organization's information security requirements in a business context and participate in high-level discussions to identify and respond to business risks. Assist with security reviews with stakeholders throughout the organization, identifying gaps and developing risk mitigation plans. Provides ongoing support of an effective disaster recovery/incident response program. Works with management to ensure that disaster recovery/incident response plans drive proper strategy and procedures. Assist with the development and execution of testing processes utilized to validate the disaster recovery/incident response plans. Schedule and lead all tabletop exercises. Develop and understand all testing necessary for a successful execution. Works with the IT staff to ensure that disaster/incident response solutions are adequate, in place, maintained, and tested as part of the regular operational life cycle. Assist with the development and deployment of training documentation and communication of incident procedures to the organization. Assist with vendor risk assessments. With guidance, produce deliverables, specifically process flows, procedure documentation, writing specialized assessment reports, related to process, tools, and metrics and communication activities. All other duties as assigned (note: essential functions and responsibilities may change or new ones may be assigned at any time with or without notice). Requirements: High School Diploma or GED. Bachelor's degree in information technology preferred Minimum of one year experience in IT Operations, Security, Risk, and/or Audit Technical Project Management and/or Business Analysis experience desired Understanding of technical concepts including system, application and network functions and design Understanding of financial institution governance and regulations including SSAE16/18, FFIEC, GLBA and NCUA Experience documenting, coordinating and executing incident test plans Must have high level of communications skills to communicate with all levels of management Experience supporting technical projects with technical and non-technical participants Experience directly supporting an organization's information security program through development and implementation of policies, standards and procedures Strong oral/written communication, organization, time management and interpersonal skills Highly proficient with Microsoft Office software Highly self-motivated, able to multi-task and manage deadlines well Knowledge of regulations and best practices for information security including guidance published by NIST, FFIEC, and CIS Preferred Bachelor's degree Security certificates, CISA other IT governance related certifications All qualified applicants will receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity, religion, national origin, disability, veteran status, or other legally protected status.

Posted 1 week ago

Sr. Information Systems Security Officer (Isso)-logo
Sr. Information Systems Security Officer (Isso)
Contact Government ServicesRochester, NY
Sr. ISSO Employment Type:Full-Time, Experienced /p> Department: Information Technology CGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment documentation to support Dept. of Commerce systems and efforts to achieve their Authorization to Operate (ATO). This position is located at the client site in the Herbert Hoover building in Washington, DC. The scope of this position includes full life-cycle Assessment and Authorization (A&A) management through all 6 Steps of the RMF process in support of the Government ISSM.In this role, you'll conduct security assessment, and information system security oversight activities in accordance with NIST 800.53 that support systems from the perspective RMF requirements. CGS brings motivated, highly skilled, and creative people together to solve the government's most dynamic problems with cutting-edge technology. To carry out our mission, we are seeking candidates who are excited to contribute to government innovation, appreciate collaboration, and can anticipate the needs of others. Here at CGS, we offer an environment in which our employees feel supported, and we encourage professional growth through various learning opportunities. Skills and attributes for success: Review systems to identify potential security weaknesses and recommend improvements to amend vulnerabilities, implement changes, and document upgrades. Maintain responsibility for managing cybersecurity risk from an organizational perspective. Identify organizational risks, prioritize those risks, and maintain a risk registry for escalating and presenting those risks to senior leadership. Provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies. Providing configuration management (CM) recommendations for information system security software, hardware, and firmware and coordinating changes and modifications with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO). Maintain vulnerability scanning tool compliance, such as HBSS or ACAS, and patch management, such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance with all applicable directives, manage system changes, and assess the security impact of those changes. Support security authorization activities, including transitioning from the legacy Information Assurance Certification and Accreditation Process (DIACAP) to compliance with the DoC RMF. Provide subject matter expertise for cyber security and trusted system technology. Apply advanced technical knowledge and analysis of specialized functional areas in task requirements to develop solutions to complex problems. Research, write, review, disposition feedback, and finalize recommendations regarding cyber security policy, assessment and authorization assessments (A&As), security test and evaluation reports, and security engineering practices and processes. Conduct research and write risk assessment reports to include risk thresholds, evaluation, and scoring. Support analysis of the findings and provide expert technical guidance for mitigation strategies, including implementation advice on the cyber security risk findings, and other complex problems. Qualifications: Bachelor's Degree. A minimum of five (5) years experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development, including generating security documentation for requirements, security control assessment, STIG and IAVA compliance, Standard Operating Procedures, test results, etc. eMASS experience. Professional security certification such as: CCNA Security, CySA+, GICSP, GSEC, CompTIA Security+ CE, SSCP, or higher. Strong desktop publishing skills using Microsoft Word and Excel. Experience with industry writing styles such as grammar, sentence form, and structure. Ability to multi-task in a deadline-oriented environment. Ideally, you will also have: CISSP, CASP, or a similar certificate is preferred. Master's Degree in Cybersecurity or related field. Strong initiative, detail orientation, organizational skills, and aptitude for analytical thinking. Demonstrated ability to work well independently and as a part of a team. Excellent work ethic and a high commitment to quality. Our Commitment: Contact Government Services (CGS) strives to simplify and enhance government bureaucracy through the optimization of human, technical, and financial resources. We combine cutting-edge technology with world-class personnel to deliver customized solutions that fit our client's specific needs. We are committed to solving the most challenging and dynamic problems. For the past seven years, we've been growing our government contracting portfolio, and along the way, we've created valuable partnerships by demonstrating a commitment to honesty, professionalism, and quality work. Here at CGS we value honesty through hard work and self-awareness, professionalism in all we do, and to deliver the best quality to our consumers mending those relations for years to come. We care about our employees. Therefore, we offer a comprehensive benefits package. Health, Dental, and Vision Life Insurance 401k Flexible Spending Account (Health, Dependent Care, and Commuter) Paid Time Off and Observance of State/Federal Holidays Contact Government Services, LLC is an Equal Opportunity Employer. Applicants will be considered without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Join our team and become part of government innovation! Explore additional job opportunities with CGS on our Job Board: https://cgsfederal.com/join-our-team/ For more information about CGS please visit: https://www.cgsfederal.com or contact: Email: info@cgsfederal.com $118,560 - $171,253.33 a year

Posted 30+ days ago

Info Security Engineer-logo
Info Security Engineer
US BankMinneapolis, MN
At U.S. Bank, we're on a journey to do our best. Helping the customers and businesses we serve to make better and smarter financial decisions and enabling the communities we support to grow and succeed. We believe it takes all of us to bring our shared ambition to life, and each person is unique in their potential. A career with U.S. Bank gives you a wide, ever-growing range of opportunities to discover what makes you thrive at every stage of your career. Try new things, learn new skills and discover what you excel at-all from Day One. Job Description The Information Security Mergers & Acquisitions (M&A) Technology Engineer plays a crucial role in the hands-on execution of security integration activities during mergers and acquisitions. Working closely with the Security Architect, this role focuses on the practical implementation of security controls and solutions to ensure the secure integration of acquired companies into the organization's IT environment. This requires a strong technical background, a deep understanding of security technologies, and the ability to work effectively in a fast-paced and dynamic environment. The role offers a hybrid/flexible schedule, which means there's an in-office expectation of 3 or more days per week and the flexibility to work outside the office location for the other days at one of the following locations: Cincinnati, OH Minneapolis, MN Preferred Skills/Experience: Typically a Bachelor's degree, or equivalent work experience Typically three to five years of technical assessments, security configuration and implementation and deployment experience. Intermediate technical and functional subject matter expert knowledge across security domain areas . Responsibilities: Implementation & Deployment: Implement and deploy security solutions during M&A integrations, including network connectivity, identity and access management systems, endpoint security tools, data protection mechanisms, and security monitoring platforms. Technical Assessments: Conduct technical assessments of the target company's security infrastructure, applications, and systems to identify vulnerabilities and security gaps. Security Configuration: Configure and maintain security devices and software, such as firewalls, intrusion detection/prevention systems, SIEM, and endpoint protection tools, to ensure alignment with the organization's security standards. Integration Support: Provide technical support during the integration process, troubleshooting security issues and ensuring seamless connectivity between the acquired company's systems and the organization's network. Automation & Scripting: Automate security tasks and processes using scripting languages (e.g., Python, PowerShell) to improve efficiency and consistency. Documentation: Develop and maintain detailed documentation for security configurations, integration procedures, and troubleshooting steps. Collaboration & Communication: Collaborate effectively with cross-functional teams, including IT, legal, finance, and the acquired company's technical staff. Communicate technical issues and solutions clearly and concisely. Security Testing: Conduct security testing, including vulnerability scanning and penetration testing, to validate the effectiveness of security controls and identify potential weaknesses. Incident Response: Participate in incident response activities related to M&A integrations, helping to contain and remediate security incidents. Knowledge Sharing: Share knowledge and expertise with other team members, contributing to the development of best practices for M&A security integrations. Additional experience should include: 3-5 years of experience in information security, with a focus on M&A security preferred. Proven experience in implementing and managing security technologies, such as firewalls, intrusion detection/prevention systems, SIEM, endpoint protection, and vulnerability management tools. Strong understanding of networking protocols and security concepts. Experience with scripting and automation tools (e.g., Python, PowerShell, Ansible). Knowledge of security standards and regulations (e.g., NIST, GDPR, HIPAA, PCI DSS, SOC2). Excellent troubleshooting and problem-solving skills. Strong communication and interpersonal skills. Ability to work effectively in a fast-paced and dynamic environment. Experience with cloud security and cloud integration strategies. Knowledge of M&A due diligence processes. Experience with specific industry regulations and compliance requirements relevant to the organization's industry. Relevant certifications (e.g., Security+, CCNA Security, CySA+). If there's anything we can do to accommodate a disability during any portion of the application or hiring process, please refer to our disability accommodations for applicants. Benefits: Our approach to benefits and total rewards considers our team members' whole selves and what may be needed to thrive in and outside work. That's why our benefits are designed to help you and your family boost your health, protect your financial security and give you peace of mind. Our benefits include the following (some may vary based on role, location or hours): Healthcare (medical, dental, vision) Basic term and optional term life insurance Short-term and long-term disability Pregnancy disability and parental leave 401(k) and employer-funded retirement plan Paid vacation (from two to five weeks depending on salary grade and tenure) Up to 11 paid holiday opportunities Adoption assistance Sick and Safe Leave accruals of one hour for every 30 worked, up to 80 hours per calendar year unless otherwise provided by law U.S. Bank is an equal opportunity employer. We consider all qualified applicants without regard to race, religion, color, sex, national origin, age, sexual orientation, gender identity, disability or veteran status, and other factors protected under applicable law. E-Verify U.S. Bank participates in the U.S. Department of Homeland Security E-Verify program in all facilities located in the United States and certain U.S. territories. The E-Verify program is an Internet-based employment eligibility verification system operated by the U.S. Citizenship and Immigration Services. Learn more about the E-Verify program. The salary range reflects figures based on the primary location, which is listed first. The actual range for the role may differ based on the location of the role. In addition to salary, U.S. Bank offers a comprehensive benefits package, including incentive and recognition programs, equity stock purchase 401(k) contribution and pension (all benefits are subject to eligibility requirements). Pay Range: $98,175.00 - $115,500.00 - $127,050.00 U.S. Bank will consider qualified applicants with arrest or conviction records for employment. U.S. Bank conducts background checks consistent with applicable local laws, including the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act as well as the San Francisco Fair Chance Ordinance. U.S. Bank is subject to, and conducts background checks consistent with the requirements of Section 19 of the Federal Deposit Insurance Act (FDIA). In addition, certain positions may also be subject to the requirements of FINRA, NMLS registration, Reg Z, Reg G, OFAC, the NFA, the FCPA, the Bank Secrecy Act, the SAFE Act, and/or federal guidelines applicable to an agreement, such as those related to ethics, safety, or operational procedures. Applicants must be able to comply with U.S. Bank policies and procedures including the Code of Ethics and Business Conduct and related workplace conduct and safety policies. Posting may be closed earlier due to high volume of applicants.

Posted 3 days ago

Staff Security Architect, Enterprise-logo
Staff Security Architect, Enterprise
SofiSan Francisco, CA
Employee Applicant Privacy Notice Who we are: Shape a brighter financial future with us. Together with our members, we're changing the way people think about and interact with personal finance. We're a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we're at the forefront. We're proud to come to work every day knowing that what we do has a direct impact on people's lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world. About The role SoFi Cybersecurity Architecture team assists and partners with engineering, product and design organizations. Our mission is to build a secure and resilient enterprise that protects our employees, customers, and business operations. By embedding security into our infrastructure, cloud environments, and enterprise systems, we safeguard critical assets while enabling the business to operate efficiently and securely. As a Staff Security Architect, you will be responsible for the end-to-end security architecture of our platforms, products, and corporate services. You will work in conjunction with security, compliance, and risk teams to make decisions and help lead initiatives to ensure timely delivery of security solutions that support our business objectives. The ideal candidate will be highly collaborative, balancing the right level of security with business objectives, and working to creatively solve complex Corporate Security related problems in an agile environment. What you'll do: Be an Cybersecurity architect evangelist who can translate security concepts into language that is meaningful to our IT teams and engineering. Design and implement security architectures that align with business needs while ensuring robust protection across corporate environments. Architect and lead the implementation of a Zero Trust security model, ensuring secure access across users, devices, and services. Own and evolve IAM and PAM strategy, leveraging tools like Okta, Azure AD, and centralized secrets management to enforce least-privilege access. Architect and oversee the enterprise-wide endpoint security strategy, integrating solutions like CrowdStrike, JAMF, and Microsoft Defender to ensure consistent protection, visibility, and policy enforcement across all device platforms. Lead the design and rollout of network security controls using Zscaler (ZTNA, SWG), microsegmentation, and secure remote access patterns. Partner with engineering, IT, and compliance teams to embed security into infrastructure, device management, and enterprise tooling. Conduct architecture reviews, threat modeling, and drive remediation plans across cloud and on-prem systems. Build and automate security guardrails into CI/CD and infrastructure pipelines-Security as Code. Continuously evaluate emerging threats, tools, and technologies, translating insight into actionable strategy. What you'll need: Designed and implemented AWS-native security architectures with deep hands-on experience in IAM, KMS, GuardDuty, Security Hub, WAF, and enforcing least privilege across multi-account environments. Led Zero Trust strategy and execution, including identity-based access, device posture enforcement, and network segmentation across hybrid environments. Architected enterprise-wide IAM and PAM solutions using Okta, Azure AD, and integrated secrets management systems to enforce strong authentication, role-based access control, and session governance. Built and operationalized endpoint security frameworks using leading EDR/XDR platforms like CrowdStrike and Defender ATP, along with JAMF and Intune for device compliance and policy enforcement. Integrated Zscaler, CASB, and Secure Web Gateway (SWG) solutions into core network and user access flows, enabling secure access to cloud and SaaS resources in a Zero Trust model. Applied industry-standard frameworks such as MITRE ATT&CK, NIST, and CIS Controls to design scalable, auditable, and resilient security architectures. Excellent communication skills-you can explain security trade-offs clearly to engineers and executives alike. Ability to prioritize between and execute on multiple work streams Written and verbal skills for communicating security concepts and solutions Preferred Qualifications: Bachelor's degree in Computer Science or equivalent from a fully-accredited college or university 8+ Experience in Infrastructure and corporate security architecture Experience with cloud native products and in-depth understanding Zero Trust Principle + years of experience with cloud technologies preferably AWS Demonstrated ability to think strategically about business, product, and technical challenges Ability to manage relationships with other business units, external vendors and stakeholders when IT security risks are present and system or process changes must be made to mitigate risk Ability to work in a fast paced and Agile development environment Work and play well with others; SoFi is a collaborative environment Nice to have: CISSP, Zscaler Digital Transformation Administrator, Okta certified professional, AWS Certified Security Speciality Masters or PhD in Computer Science or Engineering Financial services experience Compensation and Benefits The base pay range for this role is listed below. Final base pay offer will be determined based on individual factors such as the candidate's experience, skills, and location. To view all of our comprehensive and competitive benefits, visit our Benefits at SoFi page! Pay range: $144,000.00 - $247,500.00 Payment frequency: Annual This role is also eligible for a bonus, long term incentives and competitive benefits. More information about our employee benefits can be found in the link above. SoFi provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion (including religious dress and grooming practices), sex (including pregnancy, childbirth and related medical conditions, breastfeeding, and conditions related to breastfeeding), gender, gender identity, gender expression, national origin, ancestry, age (40 or over), physical or medical disability, medical condition, marital status, registered domestic partner status, sexual orientation, genetic information, military and/or veteran status, or any other basis prohibited by applicable state or federal law. The Company hires the best qualified candidate for the job, without regard to protected characteristics. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. New York applicants: Notice of Employee Rights SoFi is committed to embracing diversity. As part of this commitment, SoFi offers reasonable accommodations to candidates with physical or mental disabilities. If you need accommodations to participate in the job application or interview process, please let your recruiter know or email accommodations@sofi.com. Due to insurance coverage issues, we are unable to accommodate remote work from Hawaii or Alaska at this time. Internal Employees If you are a current employee, do not apply here - please navigate to our Internal Job Board in Greenhouse to apply to our open roles.

Posted 4 days ago

Information System Security Engineering (Isse)-logo
Information System Security Engineering (Isse)
KBRWashington, MN
Title: Information System Security Engineering (ISSE) Belong. Connect. Grow. with KBR! KBR's National Security Solutions team provides high-end engineering and advanced technology solutions to our customers in the intelligence and national security communities. In this position, your work will have a profound impact on the country's most critical role - protecting our national security. Why Join Us? Innovative Projects: KBR's work is at the forefront of engineering, logistics, operations, science, program management, mission IT and cybersecurity solutions. Collaborative Environment: Be part of a dynamic team that thrives on collaboration and innovation, fostering a supportive and intellectually stimulating workplace. Impactful Work: Your contributions will be pivotal in designing and optimizing defense systems that ensure national security and shape the future of space defense. Key Responsibilities: Collaborate on design efforts, provide security engineering, and lead the engineering of RMF BOE artifacts of a large-scale enterprise Information Technology (IT) program. Provide ISSE expertise for all assigned engineering tasks and projects Provide guidance describing the system and its functions, information types, operating environments, and security requirements Review the adequacy of the security controls and their ability to protect the information system and its information; assist in tailoring security controls, as appropriate Assist in determining the assurance measures that can be used to meet assurance requirements Integrate ISSE team members into all Scrum and project teams to provide for all requisite RMF security related support Work collaboratively with Systems, Network, and other engineers throughout the service design lifecycle to design and implement security controls, and best practices such as Zero Trust Architecture, including engineering of assigned RMF BoE documentation. Conduct Assessment and Accreditation (A&A) activities, following security processes and coordinating with the Designated Authorizing Official (DAO) representatives and appropriate security teams. Create and update assigned RMF documentation and artifacts for each service, as required. Work Environment: Location: Annapolis Junction MD [On-site] Travel Requirements: Minimal 0-20% Travel Working Hours: Standard 40 hour per week Qualifications : Required: Clearance: Top Secret with SCI Requires 5 to 8 years with BS/BA or 3 to 5 years with MS/MA or 0 to 2 years with PhD. IAM Level III certification required Proven experience performing security engineering across enterprise systems and networks. Proven experience performing Systems Security tasks including: Security Information and Event Monitoring (Splunk); Endpoint security (HBSS); password and credential management (CyberArk); Compliance and vulnerability scanning (ACAS / Nessus); and Code Scanning (Fortify). Proven experience performing Network Security for Firewalls, Intrusion Detection Systems (IDS)/ Intrusion Prevention Systems (IPS) Proven experience with Cisco products (Cisco Security Manager, Cisco FireSight Management Center, Cisco Firewall Service Modules (FWSM), Cisco IPS/IDS modules, Cisco Firepower IDS/IPS, Advance Malware Protection (AMP) services, Cisco Identity Services Engine (ISE) services, etc. Familiar with RMF and DoDAF 2.0 processes and standards Familiar with Scrum methodologies Desired: ITILv4 Foundation Certification desired Basic Compensation: $100,000 to $140,000 This range is for the Maryland area only The offered rate will be based on the selected candidate's knowledge, skills, abilities and/or experience and in consideration of internal parity. Additional Compensation: KBR may offer bonuses, commissions, or other forms of compensation to certain job titles or levels, per internal policy or contractual designation. Additional compensation may be in the form of a sign on bonus, relocation benefits, short term incentives, long term incentives, or discretionary payments for exceptional performance. Ready to Make a Difference? If you're excited about making a significant impact in the field of space defense and working on projects that matter, we encourage you to apply and join our team at KBR. Let's shape the future together. KBR Benefits KBR offers a selection of competitive lifestyle benefits which could include 401K plan with company match, medical, dental, vision, life insurance, AD&D, flexible spending account, disability, paid time off, or flexible work schedule. We support career advancement through professional training and development. Belong, Connect and Grow at KBR At KBR, we are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company. That commitment is central to our team of team's philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver - Together. KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.

Posted 30+ days ago

Information Systems Security Officer (Isso)-logo
Information Systems Security Officer (Isso)
Contact Government ServicesWinston Salem, NC
ISSO Employment Type: Full-Time, Experienced Department:Information Technology CGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment documentation to support Dept. of Commerce systems and efforts to achieve their Authorization to Operate (ATO). This position is located at the client site in the Herbert Hoover building in Washington, DC. The scope of this position includes full life-cycle Assessment and Authorization (A&A) management through all 6 Steps of the RMF process in support of the Government ISSM.In this role, you'll conduct security assessment, and information system security oversight activities in accordance with NIST 800.53 that support systems from the perspective RMF requirements. CGS brings motivated, highly skilled, and creative people together to solve the government's most dynamic problems with cutting-edge technology. To carry out our mission, we are seeking candidates who are excited to contribute to government innovation, appreciate collaboration, and can anticipate the needs of others. Here at CGS, we offer an environment in which our employees feel supported, and we encourage professional growth through various learning opportunities. Skills and attributes for success: Review systems to identify potential security weaknesses and recommend improvements to amend vulnerabilities, implement changes, and document upgrades. Maintain responsibility for managing cybersecurity risk from an organizational perspective. Identify organizational risks, prioritize those risks, and maintain a risk registry for escalating and presenting those risks to senior leadership. Provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies. Providing configuration management (CM) recommendations for information system security software, hardware, and firmware and coordinating changes and modifications with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO). Maintain vulnerability scanning tool compliance, such as HBSS or ACAS, and patch management, such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance with all applicable directives, manage system changes, and assess the security impact of those changes. Support security authorization activities, including transitioning from the legacy Information Assurance Certification and Accreditation Process (DIACAP) to compliance with the DoC RMF. Provide subject matter expertise for cyber security and trusted system technology. Apply advanced technical knowledge and analysis of specialized functional areas in task requirements to develop solutions to complex problems. Research, write, review, disposition feedback, and finalize recommendations regarding cyber security policy, assessment and authorization assessments (A&As), security test and evaluation reports, and security engineering practices and processes. Conduct research and write risk assessment reports to include risk thresholds, evaluation, and scoring. Support analysis of the findings and provide expert technical guidance for mitigation strategies, including implementation advice on the cyber security risk findings, and other complex problems. Qualifications: Bachelor's Degree. A minimum of five (5) years experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development, including generating security documentation for requirements, security control assessment, STIG and IAVA compliance, Standard Operating Procedures, test results, etc. eMASS experience. Professional security certification such as: CCNA Security, CySA+, GICSP, GSEC, CompTIA Security+ CE, SSCP, or higher. Strong desktop publishing skills using Microsoft Word and Excel. Experience with industry writing styles such as grammar, sentence form, and structure. Ability to multi-task in a deadline-oriented environment. Ideally, you will also have: CISSP, CASP, or a similar certificate is preferred. Master's Degree in Cybersecurity or related field. Strong initiative, detail orientation, organizational skills, and aptitude for analytical thinking. Demonstrated ability to work well independently and as a part of a team. Excellent work ethic and a high commitment to quality. Our Commitment: Contact Government Services (CGS) strives to simplify and enhance government bureaucracy through the optimization of human, technical, and financial resources. We combine cutting-edge technology with world-class personnel to deliver customized solutions that fit our client's specific needs. We are committed to solving the most challenging and dynamic problems. For the past seven years, we've been growing our government contracting portfolio, and along the way, we've created valuable partnerships by demonstrating a commitment to honesty, professionalism, and quality work. Here at CGS we value honesty through hard work and self-awareness, professionalism in all we do, and to deliver the best quality to our consumers mending those relations for years to come. We care about our employees. Therefore, we offer a comprehensive benefits package. Health, Dental, and Vision Life Insurance 401k Flexible Spending Account (Health, Dependent Care, and Commuter) Paid Time Off and Observance of State/Federal Holidays Contact Government Services, LLC is an Equal Opportunity Employer. Applicants will be considered without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Join our team and become part of government innovation! Explore additional job opportunities with CGS on our Job Board: https://cgsfederal.com/join-our-team/ For more information about CGS please visit: https://www.cgsfederal.com or contact: Email: info@cgsfederal.com $92,213.33 - $125,146.66 a year

Posted 30+ days ago

Security Operations Center Manager-logo
Security Operations Center Manager
AxonSan Francisco, CA
Join Axon and be a Force for Good. At Axon, we're on a mission to Protect Life. We're explorers, pursuing society's most critical safety and justice issues with our ecosystem of devices and cloud software. Like our products, we work better together. We connect with candor and care, seeking out diverse perspectives from our customers, communities and each other. Life at Axon is fast-paced, challenging and meaningful. Here, you'll take ownership and drive real change. Constantly grow as you work hard for a mission that matters at a company where you matter. Your Impact You will lead our security operations team as they increase the use of automation and adopt the use of AI. While doing so you will ensure a high bar of monitoring and detection securing mission critical software and services. We need a high-energy security professional to help expand and mature our security operations. What You'll Do Location:Work from home as much as you want, live nearby any of our awesome US R&D Hubs (Seattle, San Francisco, Scottsdale, Atlanta, or Boston) so you can easily collab in-person when it's helpful and be an active part of our vibrant Axon culture. Reports to: Director of Security Operations and Engineering Direct Reports: 7-8 Lead and manage the SOC team, including security engineers and analysts, fostering a collaborative and innovative environment. Oversee the design, deployment, and maintenance of SOC tools and technologies, ensuring they are optimized for performance and scalability. Develop and implement strategies for building new detection rules, use cases, and automation workflows to enhance threat detection and response capabilities. Coordinate and lead incident response efforts, ensuring timely and effective resolution of security incidents. Collaborate with other departments and stakeholders to align SOC initiatives with business objectives and ensure seamless integration of security processes. Set and guide the team towards ever evolving capabilities with a clear vision for the long term of the SOC. Measure and report the maturity and success of the SOC through metrics and analytical assessment. What You Bring Minimum of 5 years of experience in a security operations or incident response role, with at least 2 years in a leadership or management position. You have an engineering background building solutions to solve security problems Substantial experience with building and implementing detection rules, use cases, and automation workflows. Proficiency in scripting and automation languages such as Python, PowerShell, or similar. Strong communication and interpersonal skills, with the ability to effectively lead and motivate a team. Strong knowledge of security technologies, including SIEM, IDS/IPS, firewalls, endpoint protection, threat intelligence platforms and automation technologies. Experience working for a SaaS company within AWS or Azure. Benefits that Benefit You Competitive salary and 401k with employer match Discretionary paid time off Paid parental leave for all Medical, Dental, Vision plans Fitness Programs Emotional & Mental Wellness support Learning & Development programs And yes, we have snacks in our offices Benefits listed herein may vary depending on the nature of your employment and the location where you work. #LI-Hybrid The Pay: Axon is a total compensation company, meaning compensation is made up of base pay, bonus, and stock awards. The starting base pay for this role is between USD 104,475 in the lowest geographic market and USD 167,160 in the highest geographic market. The actual base pay is dependent upon many factors, such as: level, function, training, transferable skills, work experience, business needs, geographic market, and often a combination of all these factors. Our benefits offer an array of options to help support you physically, financially and emotionally through the big milestones and in your everyday life. To see more details on our benefits offerings please visit www.axon.com/careers/benefits. Don't meet every single requirement? That's ok. At Axon, we Aim Far. We think big with a long-term view because we want to reinvent the world to be a safer, better place. We are also committed to building diverse teams that reflect the communities we serve. Studies have shown that women and people of color are less likely to apply to jobs unless they check every box in the job description. If you're excited about this role and our mission to Protect Life but your experience doesn't align perfectly with every qualification listed here, we encourage you to apply anyways. You may be just the right candidate for this or other roles. Important Notes The above job description is not intended as, nor should it be construed as, exhaustive of all duties, responsibilities, skills, efforts, or working conditions associated with this job. The job description may change or be supplemented at any time in accordance with business needs and conditions. Some roles may also require legal eligibility to work in a firearms environment. Axon's mission is to Protect Life and is committed to the well-being and safety of its employees as well as Axon's impact on the environment. All Axon employees must be aware of and committed to the appropriate environmental, health, and safety regulations, policies, and procedures. Axon employees are empowered to report safety concerns as they arise and activities potentially impacting the environment. We are an equal opportunity employer that promotes justice, advances equity, values diversity and fosters inclusion. We're committed to hiring the best talent - regardless of race, creed, color, ancestry, religion, sex (including pregnancy), national origin, sexual orientation, age, citizenship status, marital status, disability, gender identity, genetic information, veteran status, or any other characteristic protected by applicable laws, regulations and ordinances - and empowering all of our employees so they can do their best work. If you have a disability or special need that requires assistance or accommodation during the application or the recruiting process, please email recruitingops@axon.com. Please note that this email address is for accommodation purposes only. Axon will not respond to inquiries for other purposes.

Posted 30+ days ago

Information Systems Security Officer (Isso)-logo
Information Systems Security Officer (Isso)
Contact Government ServicesSan Antonio, TX
ISSO Employment Type: Full-Time, Experienced Department:Information Technology CGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment documentation to support Dept. of Commerce systems and efforts to achieve their Authorization to Operate (ATO). This position is located at the client site in the Herbert Hoover building in Washington, DC. The scope of this position includes full life-cycle Assessment and Authorization (A&A) management through all 6 Steps of the RMF process in support of the Government ISSM.In this role, you'll conduct security assessment, and information system security oversight activities in accordance with NIST 800.53 that support systems from the perspective RMF requirements. CGS brings motivated, highly skilled, and creative people together to solve the government's most dynamic problems with cutting-edge technology. To carry out our mission, we are seeking candidates who are excited to contribute to government innovation, appreciate collaboration, and can anticipate the needs of others. Here at CGS, we offer an environment in which our employees feel supported, and we encourage professional growth through various learning opportunities. Skills and attributes for success: Review systems to identify potential security weaknesses and recommend improvements to amend vulnerabilities, implement changes, and document upgrades. Maintain responsibility for managing cybersecurity risk from an organizational perspective. Identify organizational risks, prioritize those risks, and maintain a risk registry for escalating and presenting those risks to senior leadership. Provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies. Providing configuration management (CM) recommendations for information system security software, hardware, and firmware and coordinating changes and modifications with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO). Maintain vulnerability scanning tool compliance, such as HBSS or ACAS, and patch management, such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance with all applicable directives, manage system changes, and assess the security impact of those changes. Support security authorization activities, including transitioning from the legacy Information Assurance Certification and Accreditation Process (DIACAP) to compliance with the DoC RMF. Provide subject matter expertise for cyber security and trusted system technology. Apply advanced technical knowledge and analysis of specialized functional areas in task requirements to develop solutions to complex problems. Research, write, review, disposition feedback, and finalize recommendations regarding cyber security policy, assessment and authorization assessments (A&As), security test and evaluation reports, and security engineering practices and processes. Conduct research and write risk assessment reports to include risk thresholds, evaluation, and scoring. Support analysis of the findings and provide expert technical guidance for mitigation strategies, including implementation advice on the cyber security risk findings, and other complex problems. Qualifications: Bachelor's Degree. A minimum of five (5) years experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development, including generating security documentation for requirements, security control assessment, STIG and IAVA compliance, Standard Operating Procedures, test results, etc. eMASS experience. Professional security certification such as: CCNA Security, CySA+, GICSP, GSEC, CompTIA Security+ CE, SSCP, or higher. Strong desktop publishing skills using Microsoft Word and Excel. Experience with industry writing styles such as grammar, sentence form, and structure. Ability to multi-task in a deadline-oriented environment. Ideally, you will also have: CISSP, CASP, or a similar certificate is preferred. Master's Degree in Cybersecurity or related field. Strong initiative, detail orientation, organizational skills, and aptitude for analytical thinking. Demonstrated ability to work well independently and as a part of a team. Excellent work ethic and a high commitment to quality. Our Commitment: Contact Government Services (CGS) strives to simplify and enhance government bureaucracy through the optimization of human, technical, and financial resources. We combine cutting-edge technology with world-class personnel to deliver customized solutions that fit our client's specific needs. We are committed to solving the most challenging and dynamic problems. For the past seven years, we've been growing our government contracting portfolio, and along the way, we've created valuable partnerships by demonstrating a commitment to honesty, professionalism, and quality work. Here at CGS we value honesty through hard work and self-awareness, professionalism in all we do, and to deliver the best quality to our consumers mending those relations for years to come. We care about our employees. Therefore, we offer a comprehensive benefits package. Health, Dental, and Vision Life Insurance 401k Flexible Spending Account (Health, Dependent Care, and Commuter) Paid Time Off and Observance of State/Federal Holidays Contact Government Services, LLC is an Equal Opportunity Employer. Applicants will be considered without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Join our team and become part of government innovation! Explore additional job opportunities with CGS on our Job Board: https://cgsfederal.com/join-our-team/ For more information about CGS please visit: https://www.cgsfederal.com or contact: Email: info@cgsfederal.com $92,213.33 - $125,146.66 a year

Posted 30+ days ago

Retail Security Lead-logo
Retail Security Lead
FunkoEverett, WA
The Retail Security Lead is responsible for overseeing daily security operations at a single retail location, ensuring a safe shopping environment for customers and a secure workplace for employees. This role involves overseeing security personnel, monitoring loss prevention measures, and enforcing safety policies. The Security Lead collaborates with store management, regional security leadership, and law enforcement to reduce risks, investigate incidents, and maintain a strong security presence. Your Superpowers in Action Lead store security personnel, ensuring proper staffing and adherence to security protocols. Conduct routine security checks, monitor surveillance systems, and enforce store access control policies. Document theft, violations of security, and what they observed on duty. Assist in the development and implementation of emergency response plans and security training programs. Serve as a point of contact for security-related issues within the store. Monitor suspicious activity, investigate theft incidents, and collaborate with law enforcement when necessary. Assist in internal investigations related to fraud, theft, or policy violations. Assist in handling workplace violence prevention and de-escalation situations. Conduct safety inspections and participate in workplace accident investigations. Ensure compliance with OSHA regulations, company safety policies, and emergency procedures. Ensure high-quality customer service standards are met, utilizing Funko's values for guidance. Address customer complaints and concerns with professionalism. Must-Have Superhero Gadgetry 2 or more years of prior security or military field experience High school diploma or equivalent Basic computer skills Knowledge of safety and security standards or loss prevention practices, and procedures Excellent attention to detail, observation, and recall skills Clear verbal and written communication skills required; Incident report writing preferred. Maintain professionalism and composure when dealing with an unusual, difficult, or stressful situation. Respond to situations in a timely manner and with a sense of urgency. Able to maintain confidentiality regarding employee, and visitor incidents and security matters. Maintain a neat and clean appearance to meet company standards and represent the company positively. Availability to workdays, weekends, including holidays and special events. Including the possibility of working back-to-back shifts Ability to stand and patrol for extended periods of time while maintaining radio communication with staff. Salary Information The base salary range for this position in the selected city is $24.25 - $30.00 hourly. Compensation may vary outside of this range depending on a number of factors, including a candidate's qualifications, skills, competencies and experience, and location. Base pay is one part of the Total Package that is provided to compensate and recognize employees for their work, and this role may be eligible for additional discretionary bonuses/incentives, and restricted stock units. Work Environment The noise level in the work environment is usually moderate. While performing the duties of this job, the employee is regularly required to sit; use hands to finger, handle, or feel and talk or hear. The employee is frequently required to reach with hands and arms. The employee is occasionally required to stand and walk. The employee must frequently lift and/or move up to 10 pounds and occasionally lift and/or move up to 25 pounds.

Posted 2 weeks ago

Smart Home Security Technician-logo
Smart Home Security Technician
Safe Streets USAPortland, OR
Our Smart Security Pro's mission is to show our residential customers that they are truly valued as we have a strong emphasis on providing an unparalleled 5-Star experience unmatched in the Smart Security industry. As an SSP, you'll play a pivotal role in what matters most to our customers: enhancing the safety and security of their families and homes. We know what it takes to be successful here at SafeStreets. If you have a passion for making a difference in people's lives, a strong sales background, and a winning mindset, we will assist you in creating a seamless transition into a new career. The process is simple. There is no cold calling or D2D sales involved. We get your foot in the door by connecting customers to you who are already interested in ADT home security. In-home appointments are scheduled and provided for you by our Inside Sales team. By helping customers review their security options on-site and move forward with a custom home security package designed by you, you will have the opportunity to earn uncapped sales commissions based on how the homeowner decides to protect their home. The best part is you control the process from start to finish, leaving the customer better protected than before you arrived. Looking to change industries? Feel confident in knowing that we have Pro's with backgrounds in every type of industry that have made a seamless and successful transition to the role of an SSP. With a paid training program provided, we have all the tools to teach you what you need to know. What do you need to be qualified for this position? Nothing more than a passion for customer service, a strong sales background, and a desire to help keep others safe and secure. We provide the tools/equipment, paid training, and post-training support you will need. We even hand deliver the customers to you - no need to go searching for your own leads! SafeStreets is always evolving! SafeStreets set out to make some big changes to kick off 2025 with how our Smart Security Pros are paid and we now have the best compensation plan in the industry! Here's what our SSP's look forward to: Highest sales commission opportunities in the industry with our technicians earning on average 25% commission - UNCAPPED! More than 30% of our field earned over $100k+ in 2024 Increased Mileage pay with pay kicking in nearly 3x earlier than previously Paid for every installation action taken on site Same-day and Holiday bonuses More upgrade commission options Doubled Referral pay opportunity Doubled our yearly loyalty bonuses Still not convinced? Our recruiters are standing by right now to talk more in depth about how SafeStreets can change your life! What we Offer: Competitive base salary with generous and uncapped commission structure Company-provided equipment and select tools Remote and independent work environment Ongoing training and professional development opportunities Opportunities for career advancement within a rapidly growing organization Scheduling flexibility Medical/Dental/Vision/Life Insurance/401K The Responsibilities: Helping homeowners create customized Smart Security solutions for their personal needs 5-star Customer interaction - every day is a new opportunity; you'll be the first face-to-face contact our customers have with SafeStreets! Customized installation, troubleshooting, and demonstration of ADT-monitored security systems Qualifications: Entrepreneurial and career oriented mindset Excellent communication, negotiation, and interpersonal skills Reliable vehicle and valid driver's license Proof of vehicle insurance (100/300/100 minimum) Smartphone/tablet SafeStreets values the safety of our employees and customers. That is why we are committed to providing personal protective equipment (PPE) or stipends to our technicians to further ensure their safety. This job entails meeting certain physical requirements, including the ability to work above head level, carry loads of 30-50 pounds (such as equipment boxes and ladders), operate power tools, and navigate confined spaces like attics and crawl spaces. Safe Streets is an equal opportunity employer. All aspects of employment including the decision to hire, promote, discipline, or terminate, will be based on merit, competence, performance, and business needs. Safe Streets does not discriminate on the basis of race, color, religion, sex (including pregnancy and gender identity), marital status, age, national origin, sexual orientation, disability, genetic information, military service, or any other status protected under federal, state, or local law. Applicants have rights under Federal Employment Laws. FMLA - https://www.dol.gov/agencies/whd/fmla EEO- https://www.eeoc.gov/history/equal-employment-opportunity-act-1972 EPPA - https://www.dol.gov/agencies/whd/polygraph

Posted 30+ days ago

Senior Software Engineer, Security Foundations (Networking Infrastructure Projects)-logo
Senior Software Engineer, Security Foundations (Networking Infrastructure Projects)
LyftSeattle, WA
At Lyft, our purpose is to serve and connect. To do this, we start with our own community by creating an open, inclusive, and diverse organization. Lyft's engineering team is growing rapidly, and we are looking for Software Engineers with a passion in Security to help us scale. About Our Org: The security team designs and builds Lyft's security architecture, consults with other teams as they build and launch new products and features, proactively plans for the unexpected, and responds to incidents that occur. We try to approach security from a software engineering standpoint. We believe in scaling security through automation and tooling and we ship frequently. Check out our blog posts at https://eng.lyft.com/tagged/security to learn more about some of the things we've built. About This Position: We're looking for an engineer with a strong networking background who's excited about growing and securing distributed systems throughout the company. You'll play a part in shaping how service networking works at Lyft, with significant impact and visibility. Responsibilities: Work on our network security initiative such as our Internet edge proxies (Envoy), Web Application Firewall, service-to-service authentication and authorization. Architect and build services that improve the security of our systems with an eye towards scalability and avoiding unnecessary friction. Evangelize our shared security responsibility model by collaborating with other Infrastructure teams at Lyft to ensure that our services and workflows are secure by default. Work on embedding security best practices such as least privilege, isolation, monitoring, authentication and authorization across our entire infrastructure (systems, application, networking). Develop critical services that Lyft depends on such as our credential management service that provides secrets to all our services at Lyft. Experience: Solid experience with a high level programming language (bonus points for experience with Python, Go-lang and shell scripts) Strong understanding of networking concepts (TCP/IP, HTTP, TLS, DNS) and working experience with edge or sidecar proxies. Identity and Access Management (IAM): provisioning least privilege access to users and services. Familiarity with authn/authz and frameworks and concepts related to SSO, SAML, OAuth, OpenID. Experience with Amazon Web Services (AWS) or another major cloud service provider Kubernetes and container security and running fleets of endpoints or servers in the cloud. Cryptography, PKI, or key/certificate distribution Running multi-tier or distributed web services at scale Soft Skills When facing a problem that's poorly defined or outside of your expertise, you can quickly learn what you need to dig in, make sense of the problem, and start working towards a solution You're a great communicator, and can advocate for your proposals while also empathizing with your teammates' goals and priorities You understand that security work must be prioritized because all teams have finite resources. You have good judgment and a sense of when to compromise and when to hold your ground Benefits: Great medical, dental, and vision insurance options with additional programs available when enrolled Mental health benefits Family building benefits Child care and pet benefits 401(k) plan to help save for your future In addition to 12 observed holidays, salaried team members have discretionary paid time off, hourly team members have 15 days paid time off 18 weeks of paid parental leave. Biological, adoptive, and foster parents are all eligible Subsidized commuter benefits Lyft Pink- Lyft team members get an exclusive opportunity to test new benefits of our Ridership Program Lyft is an equal opportunity employer committed to an inclusive workplace that fosters belonging. All qualified applicants will receive consideration for employment without regards to race, color, religion, sex, sexual orientation, gender identity, national origin, disability status, protected veteran status, age, genetic information, or any other basis prohibited by law. We also consider qualified applicants with criminal histories consistent with applicable federal, state and local law. Lyft highly values having employees working in-office to foster a collaborative work environment and company culture. This role will be in-office on a hybrid schedule- Team Members will be expected to work in the office 3 days per week on Mondays, Wednesdays, and Thursdays. Lyft considers working in the office at least 3 days per week to be an essential function of this hybrid role. Your recruiter can share more information about the various in-office perks Lyft offers. Additionally, hybrid roles have the flexibility to work from anywhere for up to 4 weeks per year. #Hybrid The expected base pay range for this position in the Seattle area is $136,160 - $170,200. Salary ranges are dependent on a variety of factors, including qualifications, experience and geographic location. Range is not inclusive of potential equity offering, bonus or benefits. Your recruiter can share more information about the salary range specific to your working location and other factors during the hiring process. Total compensation is dependent on a variety of factors, including qualifications, experience, and geographic location. Your recruiter can share more information about the salary range specific to your working location and other factors during the hiring process.

Posted 3 weeks ago

Principal, Security Architect-logo
Principal, Security Architect
Northern TrustChicago, IL
About Northern Trust: Northern Trust, a Fortune 500 company, is a globally recognized, award-winning financial institution that has been in continuous operation since 1889. Northern Trust is proud to provide innovative financial services and guidance to the world's most successful individuals, families, and institutions by remaining true to our enduring principles of service, expertise, and integrity. With more than 130 years of financial experience and over 22,000 partners, we serve the world's most sophisticated clients using leading technology and exceptional service. Title : Principal Security Architect Description Guides the development, specification and communication of application or infrastructure architectures used by multiple business or application systems. Provides extensive, in-depth, technical consultation to the clients, partners, and IT Management to develop plans and directions to assure the integration of corporate business area requirements. Acts as cybersecurity expert for cloud migration projects/programs Thoroughly understands decision process issues of technology choice, such as design, data security, client server communication, etc. Partner with Management in the building of new and on-going vendor relationships Evaluates and selects from existing and emerging technologies those options best fitting business/project needs Promotes sharing of expertise through consulting, presentations, and documentations, etc. Experienced, functional expert with technical and/or business knowledge and functional expertise Carries out complex initiatives involving multiple disciplines and/or ambiguous projects Displays a balanced, cross-functional perspective, liaising with the business to help improve efficiency, effectiveness, and productivity Strategic in developing, implementing, and administering programs within functional areas Provides guidance to team members, fostering an environment that encourages employee participation, teamwork, and communication Qualifications Bachelor's degree in computer science or a related discipline and experience in information security, or an equivalent combination of education and work experience. Deep knowledge of application or infrastructure systems architecture, usually having experience with multiple system technologies. Excellent consultative and communication skills, and the ability to work effectively with client, partner, and IT management and staff. Seven years of experience in the Information Security role. Three years of experience with cloud and/or technologies CISSP, CSSP, CCNP/CCIE Security, or Cloud security certification preferred Strong collaboration skills and a analytical ability Requirements/Responsibilities- In-depth knowledge of various cybersecurity frameworks, standards, and SSDLC Hands on experience working with IPS/IDS, Network load balancer, next generation firewalls, Z-Scaler, and networking technologies Experience in securing the cloud networking and hybrid configurations Experience working with teams that handle infrastructure components including Storage systems, database technologies, directory services, and virtualization Experience working with Microsoft Azure, AWS, hybrid, and multi-cloud systems Knowledge of network architecture concepts including topology, protocols, and components Experience working with tools related to Privilege access management, Threat hunting, data protection, encryption, Authentication/Authorization, Vulnerability management systems, Cloud Security Posture Management. Knowledge related to WAF, App Proxy, and CDN Knowledge of network traffic analysis methods In-depth understanding related to SEIM and strong experience related to Microsoft Defender, Entra, KQL, APIM, endpoint protection, scripting, CoPilot Ability to establish security patterns related to cloud/ hybrid architecture and work with various tech teams to assist with the implementation as needed Very good understanding of zero-trust architecture and working experience with relevant tools/technologies Knowledge related AI/ML, DevSecOps, CI/CD Pipeline, IaC, and relevant tools Very good understanding of concepts related to docker, container, serverless computing, and Kubernetes Must be able to represent the team in technical discussions and drive towards deliverables with minimal guidance Salary Range: $137,400 - 233,600 USD Salary range is a good faith estimate of base pay. Northern Trust provides a comprehensive benefits package including retirement benefits (401k and pension), health and welfare benefits (medical, dental, vision, spending accounts and disability), paid time off, parental and caregiver leave, life & accident insurance, and other voluntary and well-being benefits. Northern Trust also provides a discretionary bonus program that may include an equity component. Working with Us: As a Northern Trust partner, greater achievements await. You will be part of a flexible and collaborative work culture in an organization where financial strength and stability is an asset that emboldens us to explore new ideas. Movement within the organization is encouraged, senior leaders are accessible, and you can take pride in working for a company committed to assisting the communities we serve! Join a workplace with a greater purpose. We'd love to learn more about how your interests and experience could be a fit with one of the world's most admired and sustainable companies! Build your career with us and apply today. #MadeForGreater Reasonable accommodation Northern Trust is committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation for any part of the employment process, please email our HR Service Center at MyHRHelp@ntrs.com. We hope you're excited about the role and the opportunity to work with us. We value an inclusive workplace and understand flexibility means different things to different people. Apply today and talk to us about your flexible working requirements and together we can achieve greater.

Posted 6 days ago

Information Systems Security Officer (Isso)-logo
Information Systems Security Officer (Isso)
KBRKihei, HI
Title: Information Systems Security Officer (ISSO) Belong. Connect. Grow. with KBR! KBR's National Security Solutions team provides high-end engineering and advanced technology solutions to our customers in the intelligence and national security communities. In this position, your work will have a profound impact on the country's most critical role - protecting our national security. Why Join Us? Innovative Projects: KBR's work is at the forefront of engineering, logistics, operations, science, program management, mission IT and cybersecurity solutions. Collaborative Environment: Be part of a dynamic team that thrives on collaboration and innovation, fostering a supportive and intellectually stimulating workplace. Impactful Work: Your contributions will be pivotal in designing and optimizing defense systems that ensure national security and shape the future of space defense. Key Responsibilities: KBR was selected to support the US Space Force/Air Force Research Laboratory's ASTRO (Advanced Space Technology Research and Optimization) contract to provide mission equipment operations, maintenance, and upgrades to the USSF's AMOS site in Maui, Hawaii. The AMOS site plays a vital role in national security by monitoring man-made objects in space and continuously developing next-generation capabilities to keep pace with the expanding space domain. This presents an incredible opportunity to push the boundaries of space and telescope technologies. In this role, you'll use your expertise as an ISSO to maintain 24/7/365 readiness in support of USSF operations and specialized missions. Responsibilities: Qualifications: Bachelor Degree and a minimum of 10 years of related Information Systems experience; or an equivalent combination of related training and experience. Certification: Minimum IAM Level 2. Experience with and understanding of NIST 800 series Security+ or other relevant certifications Desired Qualifications: Experience with and understanding of ICD 503 Experience Military / DOD experience Clearance: Ability to obtain DoD TS/SCI Clearance, Active Secret required. WORK ENVIRONMENT: KBR supports work from home when compatible with meeting contract requirements. AMOS is a dynamic work environment and this contract supports routine operations of and maintenance of mission equipment, as well as the need to respond to real-world events. To the extent possible, schedules are forecasted in advance, but upgrades, maintenance or significant tests require personnel to be present in the telescope facilities on Haleakala or Government's Kihei office. Candidate must have effective verbal and written communication skills; must be able to adapt communication style to suit different audiences or facilitate group discussions; develop accurate written materials to communicate information clearly and concisely. Basic Compensation: $126k-190k The offered rate will be based on the selected candidate's knowledge, skills, abilities and/or experience and in consideration of internal parity. Additional Compensation: KBR may offer bonuses, commissions, or other forms of compensation to certain job titles or levels, per internal policy or contractual designation. Additional compensation may be in the form of sign on bonus, relocation benefits, short term incentives, long term incentives, or discretionary payments for exceptional performance. KBR Benefits KBR offers a selection of competitive lifestyle benefits which could include 401K plan with company match, medical, dental, vision, life insurance, AD&D, flexible spending account, disability, paid time off, or flexible work schedule. We support career advancement through professional training and development. Ready to Make a Difference? If you're excited about making a significant impact in the field of space defense and working on projects that matter, we encourage you to apply and join our team at KBR. Let's shape the future together. #ASTRO Belong, Connect and Grow at KBR At KBR, we are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company. That commitment is central to our team of team's philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver - Together. KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.

Posted 30+ days ago

Sr. Information Systems Security Officer (Isso)-logo
Sr. Information Systems Security Officer (Isso)
Contact Government ServicesAnniston, AL
Sr. ISSO Employment Type:Full-Time, Experienced /p> Department: Information Technology CGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment documentation to support Dept. of Commerce systems and efforts to achieve their Authorization to Operate (ATO). This position is located at the client site in the Herbert Hoover building in Washington, DC. The scope of this position includes full life-cycle Assessment and Authorization (A&A) management through all 6 Steps of the RMF process in support of the Government ISSM.In this role, you'll conduct security assessment, and information system security oversight activities in accordance with NIST 800.53 that support systems from the perspective RMF requirements. CGS brings motivated, highly skilled, and creative people together to solve the government's most dynamic problems with cutting-edge technology. To carry out our mission, we are seeking candidates who are excited to contribute to government innovation, appreciate collaboration, and can anticipate the needs of others. Here at CGS, we offer an environment in which our employees feel supported, and we encourage professional growth through various learning opportunities. Skills and attributes for success: Review systems to identify potential security weaknesses and recommend improvements to amend vulnerabilities, implement changes, and document upgrades. Maintain responsibility for managing cybersecurity risk from an organizational perspective. Identify organizational risks, prioritize those risks, and maintain a risk registry for escalating and presenting those risks to senior leadership. Provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies. Providing configuration management (CM) recommendations for information system security software, hardware, and firmware and coordinating changes and modifications with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO). Maintain vulnerability scanning tool compliance, such as HBSS or ACAS, and patch management, such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance with all applicable directives, manage system changes, and assess the security impact of those changes. Support security authorization activities, including transitioning from the legacy Information Assurance Certification and Accreditation Process (DIACAP) to compliance with the DoC RMF. Provide subject matter expertise for cyber security and trusted system technology. Apply advanced technical knowledge and analysis of specialized functional areas in task requirements to develop solutions to complex problems. Research, write, review, disposition feedback, and finalize recommendations regarding cyber security policy, assessment and authorization assessments (A&As), security test and evaluation reports, and security engineering practices and processes. Conduct research and write risk assessment reports to include risk thresholds, evaluation, and scoring. Support analysis of the findings and provide expert technical guidance for mitigation strategies, including implementation advice on the cyber security risk findings, and other complex problems. Qualifications: Bachelor's Degree. A minimum of five (5) years experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development, including generating security documentation for requirements, security control assessment, STIG and IAVA compliance, Standard Operating Procedures, test results, etc. eMASS experience. Professional security certification such as: CCNA Security, CySA+, GICSP, GSEC, CompTIA Security+ CE, SSCP, or higher. Strong desktop publishing skills using Microsoft Word and Excel. Experience with industry writing styles such as grammar, sentence form, and structure. Ability to multi-task in a deadline-oriented environment. Ideally, you will also have: CISSP, CASP, or a similar certificate is preferred. Master's Degree in Cybersecurity or related field. Strong initiative, detail orientation, organizational skills, and aptitude for analytical thinking. Demonstrated ability to work well independently and as a part of a team. Excellent work ethic and a high commitment to quality. Our Commitment: Contact Government Services (CGS) strives to simplify and enhance government bureaucracy through the optimization of human, technical, and financial resources. We combine cutting-edge technology with world-class personnel to deliver customized solutions that fit our client's specific needs. We are committed to solving the most challenging and dynamic problems. For the past seven years, we've been growing our government contracting portfolio, and along the way, we've created valuable partnerships by demonstrating a commitment to honesty, professionalism, and quality work. Here at CGS we value honesty through hard work and self-awareness, professionalism in all we do, and to deliver the best quality to our consumers mending those relations for years to come. We care about our employees. Therefore, we offer a comprehensive benefits package. Health, Dental, and Vision Life Insurance 401k Flexible Spending Account (Health, Dependent Care, and Commuter) Paid Time Off and Observance of State/Federal Holidays Contact Government Services, LLC is an Equal Opportunity Employer. Applicants will be considered without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Join our team and become part of government innovation! Explore additional job opportunities with CGS on our Job Board: https://cgsfederal.com/join-our-team/ For more information about CGS please visit: https://www.cgsfederal.com or contact: Email: info@cgsfederal.com $118,560 - $171,253.33 a year

Posted 30+ days ago

Clarksville Security Officer (Armed License Required)-logo
Clarksville Security Officer (Armed License Required)
Walden SecurityClarksville, TN
Job Overview: Applicants must be in possession of an active armed security license for the state of TN to be eligible for this position. Unarmed or unlicensed candidates, please apply to our unarmed position for consideration. We are seeking motivated and vigilant Armed Security Professionals to join our security team. The ideal candidate will be responsible for ensuring the safety and security of the clients premises, personnel, and assets while adhering to all relevant laws, regulations, and company guidelines. The Armed Security Professional will respond to incidents, conduct patrols, and maintain a visible presence to deter potential threats. Please note. Applications submitted without a resume will not be considered for this position. Key Responsibilities: Monitor and patrol assigned areas to prevent and respond to security incidents. Respond to alarms and calls for assistance, assessing situations and determining appropriate actions. Enforce security policies and procedures, ensuring compliance with all local, state, and federal regulations. Conduct security assessments and report any safety hazards or security breaches. Utilize firearms responsibly and only when necessary, following all training and legal guidelines. Maintain detailed logs of incidents, observations, and daily activities. Collaborate with local law enforcement and emergency services as needed. Provide exceptional customer service while interacting with employees and visitors. Participate in ongoing training and professional development to stay current with security practices. Qualifications: Valid armed security license. High school diploma or equivalent. Strong observational skills and the ability to remain calm under pressure. Excellent communication and interpersonal skills. Ability to work independently and as part of a team. Must be able to pass criminal background check and motor vehicle record check if applicable. Same Day Offers: interview with the hiring team and receive an offer to join us the same day! Extensive Training: Our initial training paves the way for you to earn your Security Officer Certification. Walden Security has been recognized by Training Magazine as a Top 100 Award Winner which is awarded to companies with the most successful learning and development programs in the world! Unbelievable PERKS!: Save on phone, vacation, auto, retailers and more! Tuition Reimbursement: we believe in the professional development of our team members and provide annual reimbursement opportunities. Employee Family Scholarship: To date, Walden Security has awarded more than $300,000 in Employee Family Scholarships! Paid Time Off: offered to employees that average at least 32 hours per week Medical, Dental and Vision Insurance: multiple plan options for you and your dependents Health Savings Account: pay for health care more easily Voluntary Life Insurance: affordable plans available 401K: prepare for your retirement Employee Assistance Program: we offer free, confidential assistance for many of your life's needs Employee Recognition Programs: we believe in celebrating the "wins" with our Walden Security team. We reward the hard work and dedication of our employees through Tenure Recognition, On-The-Spot Bonuses, Officer of the Month and Officer of the Year recognitions which include awards and bonuses Culture of Caring: Walden Security supports many charitable organizations Award Winning Company: Walden Security has earned significant recognition for our better working environment for our officers, better service to our customers and a dedication to quality performance standards. Promote From Within Philosophy: Walden Security offers growth opportunities for our team members who are Setting the Standard by Setting the Example Flexible Schedules: We offer flexible scheduling with multiple shifts available including First, Second, Third and Weekend Shifts Competitive Pay! Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, status as a protected veteran, or any other protected category under applicable federal, state, and local laws.

Posted 4 days ago

Information Systems Security Manager - Level 3-logo
Information Systems Security Manager - Level 3
CACI International Inc.Annapolis Junction, MD
Information Systems Security Manager - Level 3 Job Category: Information Technology Time Type: Full time Minimum Clearance Required to Start: TS/SCI with Polygraph Employee Type: Regular Percentage of Travel Required: None Type of Travel: The Opportunity: We are seeking a highly skilled and experienced professional to provide comprehensive management support for an organization's Information Assurance (IA) program. The ideal candidate will play a key role in ensuring the security of information systems by overseeing the proposal, coordination, implementation, and enforcement of security policies, standards, and methodologies. Responsibilities: The candidate will be responsible for managing the operational security posture of an Information System, ensuring compliance with established policies, procedures, and standards. In this role, the candidate will work closely with Information System Security Engineers (ISSEs) and Information System Security Officers (ISSOs) to evaluate security solutions and assess their effectiveness in protecting classified information. The candidate will also manage vulnerability and risk assessments, as well as contribute to security authorization activities, including preparation and review of critical documentation such as System Security Plans (SSPs), Risk Assessment Reports, and Certification and Accreditation (C&A) packages. The successful candidate will oversee configuration management (CM) processes, ensuring that security software, hardware, and firmware are up-to-date and secure. Additionally, they will be responsible for assessing the security impact of system changes and providing support in line with the Risk Management Framework (RMF) and DoD Information Assurance Certification and Accreditation Process (DIACAP). This position offers a unique opportunity to make a significant impact on the overall security of critical information systems and ensure compliance with all regulatory and security requirements. Qualifications: Required: Current Active TS/SCI with POLY Twelve (12) years of work-related experience in the field of security authorization is required. Experience in the following areas is required: knowledge of current security tools, hardware/software security implementation; communication protocols; or encryption tools and techniques. Familiarity with commercial security products, security authorization techniques, security incident management, and PKI and authorization services. Bachelor's degree in Computer Science or a related field (e.g., General Engineering, Computer Engineering, Electrical Engineering, Systems Engineering, Mathematics, Computer Forensics, Cybersecurity, Information Technology, Information Assurance, Information Security, and Information Systems) is required. In lieu of a Bachelor's degree, an additional four (4) years of work-related experience may be substituted. DoD 8570 compliance with IAM III is required. The following certifications qualify: CISM, CISSP (or Associate), GSLC, CCISO Desired: Familiarity with Network Security Services and Chief Information Security Officer processes and procedures. This position is contingent on funding and may not be filled immediately. However, this position is representative of positions within CACI that are consistently available. Individuals who apply may also be considered for other positions at CACI. ____ What You Can Expect: A culture of integrity. At CACI, we place character and innovation at the center of everything we do. As a valued team member, you'll be part of a high-performing group dedicated to our customer's missions and driven by a higher purpose - to ensure the safety of our nation. An environment of trust. CACI values the unique contributions that every employee brings to our company and our customers - every day. You'll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality. A focus on continuous growth. Together, we will advance our nation's most critical missions, build on our lengthy track record of business success, and find opportunities to break new ground - in your career and in our legacy. Your potential is limitless. So is ours. Learn more about CACI here. ____ Pay Range: There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits. Learn more here. The proposed salary range for this position is: $120,800 - $265,800 CACI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any other protected characteristic.

Posted 1 week ago

Forward Deployed Engineer - Security Clearance Required-logo
Forward Deployed Engineer - Security Clearance Required
VirtruReston, VA
About Virtru: Virtru is a leading data protection provider backed by some of the foremost venture capital firms in Silicon Valley and the Mid-Atlantic region, including Iconiq Capital, Bessemer Venture Partners, Foundry Capital, and Tiger Global. Today, more than ever, data demands respect, and that's why Virtru is committed to changing the rules for data privacy. At Virtru, we equip our customers to take granular control of their data-everywhere it's shared-through end-to-end encryption for Google, Microsoft, and other data sharing platforms. Our market-leading portfolio of data encryption and privacy enhancing applications are remarkably easy to use, fast to implement, affordable for all, and built on the Trusted Data Format (TDF) open standard. At Virtru, our motto is "Respect the people. Respect the data." Respecting data to us means keeping it secure and protected at all times across its entire lifecycle. We firmly believe that when you respect data, you're demonstrating respect for the people who own that data. Working at Virtru, you'll be inspired by colleagues who are passionate about the work they do. We are dedicated to creating an atmosphere that sparks creativity, connection, and professional growth while empowering each other to do our best work. We're building something special at Virtru. We hope you consider joining our team and helping us create a brighter future for data privacy. Compensation Range: $190,000 - 240,000 Base As a Forward Deployed Engineer (FDE) at Virtru, you will play a pivotal role in driving continuous improvements in observability, performance, and reliability across our platform infrastructure. Your mission will be to enhance the operational excellence of our systems, making a significant impact on data privacy and security initiatives within the federal government sector. Key Responsibilities: Monitor platform and containerized applications to ensure optimal performance and availability. Identify and mitigate performance and availability risks and issues in real-time. Contribute to the development and optimization of core platform functions to establish a robust infrastructure. Collaborate closely with internal teams and government clients on a daily basis. Requirements: Active U.S. TS/SCI Clearance required - ideally with CI poly or willingness to sit for one Minimum of 5+ years of experience as a cloud engineer, demonstrating a strong understanding of SRE principles for highly scalable and reliable systems. Bachelor's degree in Computer Science or related field. Proficiency in DevSecOps practices, with experience in source code repositories and CI/CD pipeline solutions such as Team Foundation Server/Azure DevOps, Bitbucket, and GitHub. Expertise in Infrastructure as Code (IaC) and best practices for managing cloud infrastructure. Familiarity with containerization, Kubernetes (k8s) and orchestration tooling such as OpenShift, Rancher, and Helm. Ability to excel both independently and as part of a collaborative team. Effective communication and collaboration skills with the on-site customer and the support team. Willingness to work onsite in Reston, Virginia, with occasional travel to client sites in downtown Washington, DC. Application: If you are an experienced engineer with a passion for driving excellence in data privacy and security, we encourage you to apply for this exciting opportunity at Virtru. Join us in our mission to redefine data protection standards and create a brighter future for digital privacy. Virtruvian qualities that will set you up for success: Thinking outside of the box to respectfully challenge your teammates and managers in the pursuit of excellence Strong sense of urgency with an action-oriented mindset Able to collaborate and adapt to shifting priorities as business needs evolve Comfortable with asynchronous communication including slack, email, zoom, etc. Perks & Benefits: At Virtru, we believe people do their best work when their wellbeing is put first. This is why we make your wellbeing our priority with a thoughtful and holistic program that encompasses Occupational, Mental, Social, Physical, and Environmental Wellness by offering benefits such as… A Flexible PTO policy - we strongly encourage you to take a minimum of 25 days off annually (in addition to 12 federal holidays) to ensure that you are getting the proper time needed to unplug and recharge. A $1,500 annual Learning & Development Stipend focused on providing you the resources to continually learn and professionally grow. Home-Office Stipend to help make your office space more comfortable and productive. Internal mobility options for those interested in exploring their skills in other areas of the business Frequent company-sponsored Team Celebrations that provide ample opportunities to connect with teammates and be social! Access to an Employee Assistance Program. Access to Headspace, a mental health app tailored to your specific needs. A high degree of flexibility - Have an appointment, errand, or family emergency to take care of? Hop to it! We give you the time and space to take care of you and your own first. In addition to wellbeing, Virtru places a strong emphasis on diversity, equity, inclusion, and belonging. Our DE&I Council is dedicated to fostering an inclusive workplace and making the psychological safety of each and every one of our teammates a top priority. The Council also hosts a range of events throughout the year focused on the continual education of our teammates on social justice issues, current events, and marginalized cultures and communities. Additional perks include: Competitive compensation Generous parental, medical, and bereavement policies Uncapped commissions for Sales roles 401K contribution and stock options Full medical, dental, and vision benefits New Hire Swag and IT Welcome boxes Structured semi-annual 360° performance reviews Transparency is at the core of how we operate and everything we do! There are plenty of opportunities to connect with the team in person throughout the year, both in and out of the office, whether they be team-specific or company-wide celebrations and events. Virtru is committed to building an inclusive environment for people of all backgrounds and everyone is encouraged to apply. Virtru is an Equal Opportunity Employer and does not discriminate on the basis of race, color, gender, sexual orientation, gender identity or expression, religion, disability, national origin, protected veteran status, age, or any other status protected by applicable national, federal, state, or local law.

Posted 1 week ago

Senior Information Security Engineer-logo
Senior Information Security Engineer
Southwest Business CorporationSan Antonio, TX
SWBC is seeking a talented individual to serve as a key Information Security Engineer empowered to leverage the industry's latest security principles, practices, and tools to improve the reliability, integrity, and security of on premise and cloud-hosted applications. Works by, with, and through internal and external DevOps stakeholders to incorporate security into all stages of the software development life cycle. Applies DevSecOps principles and applicable security standards to secure cloud services, cloud native applications, integrations, and supporting infrastructure through Continuous Integration (CI) and Continuous Delivery (CD) workflows, patterns, and tools. Analyzes cybersecurity, software development, infrastructure, software design, architecture and information technology best practices, threat intelligence, and emerging requirements to improve the security of the hosting environment and applications. Monitors cloud applications and services for indicators for compromise and compliance shortfalls and tracks issues for timely remediation. Implements administrative and technical controls to ensure security, privacy, and compliance of data stored, processed, or transmitted on Company owned or controlled cloud platforms. Monitors industry security updates, technologies, and best practices to ensure the Company's multi-cloud environment continues to provide adequate security and meet compliance requirements. Why you'll love this role: In this role, you will work with some of the top information security, technology, and business professionals in the financial services industry. As part of an agile and innovated security team, you will work closely with stakeholders at all levels and interact with the industry's top partners. You will employ advanced security technology and tactics to defend cutting-edge FINTECH and business technology. Beyond amazing career opportunities and singular experiences, our security team is diverse in all aspects; passionate about collaboration; leverages amazing technology and automation; laughs often; and celebrates our success as a team. Our leaders recognize that empowerment, autonomy, work-life balance, professional development, continuous improvement, and a commitment to shared values are key enablers of our success. We work hard, take care of each other, and deliver positive outcomes daily. This will be your best career decision. Essential duties include the following: Identifies, implements, maintains, and monitors risk-informed, standards-based, effective, and efficient security controls within a hybrid multi-cloud technology environment. Supports continuous integration and continuous development pipelines and processes that automatically build, test, and deploy infrastructure and containerized applications to ensure appropriate security checks are included automatically or manually. Reviews software releases and infrastructure changes for security vulnerabilities and risks prior to approval. Supports enterprise software development and cloud infrastructure projects and production applications that store, process, and transmit regulated data to ensure controls meet or exceed standards. Manages vulnerabilities and security testing for on premise and cloud-hosted applications and tracks issues to remediation. Supports audit and compliance efforts to ensure applications, infrastructure, and integrations meet applicable compliance and contractual standards. Identifies, recommends, and tests technical security standards and guidelines for software development, DevOps, and release management to ensure that all delivered solutions and architecture adhere to industry best-practices for availability, confidentiality, and integrity. Partners with internal and external development teams and other stakeholders to improve security and operational monitoring for cloud hosted workloads. Develops and tests incident response plans to prepare for, respond to, and recover from security incidents and operational issues as part of an incident response team. Supports efforts to provide for a secure integrated development environment for external and internal software and release management pipelines. Builds and tracks performance indicators and metrics to inform security control monitoring in cloud environments. Performs all other duties as assigned. Serious candidates will possess the minimum qualifications: Bachelor's Degree in Computer or Software Engineering, Information Security, Cybersecurity or related field from an accredited four year college or university required. Master's Degree preferred. AWS Certified Solutions Architect or DevOps Engineer Professional certification required. AWS Security Specialty certification highly desired. Certified Information Systems Security Professional (CISSP) and Certified Cloud Security Professional (CCSP) highly desired. Cloud Security Alliance (CSA) Certificate of Cloud Security Knowledge (CCSK) desired. GIAC Cloud Security Automation (GCSA) certification highly desired. Must be able to obtain certification within 6 months of hire. Minimum eight (8) years of extensive security engineering experience, including architectural design using AWS best practices and industry standards. Experience implementing and managing tools for security, availability, and compliance monitoring in a cloud environment which includes collecting data, parsing log files, capturing network traffic, setting alert thresholds, and notifying stakeholders. Experience and understanding of the DevOps deployment pipeline and security considerations for each step of the CI/CD processes. Experience with serverless architectures, their features, advantages, security concerns, and tactics for deploying effective security in serverless implementations. Experience with vulnerability management and virtual patching in the cloud. Experience with Amazon Web Services (AWS) cloud architecture components, security, identity, & compliance services, and knowledge of how to secure the environment. Familiar with DevOps toolsets to track work items, code, test, build, and release, and knowledge of how each stage is secured and automated. Familiar with tools to perform vulnerability assessments, threat detection, compliance benchmarking, audit logging, log evaluation, and network collection for cloud hosted applications. Familiar with basic web development practices, i.e. HTML, CSS, JavaScript, JQuery, etc. Familiar with team development tools and source control, including Azure DevOps, GIT, etc. Familiar with the principles of software development life cycle (SDLC) and separation of duties. Understanding of micro service architecture and implementation of appropriate security controls used in various architectural designs and conditions. Understanding of "As Code" processes and attack surfaces presented by CI, CD, and CM tools and familiarity with techniques for how to harden these tools. Understanding of the Secure DevOps auditing controls and how to leverage automated scanners to automate policy requirements. Demonstrated knowledge of how to configure security services and tools such as Web Application Firewalls, Content Delivery Networks, and Intrusion Monitoring to protect against common website attacks. Demonstrated knowledge of encryption and encryption key management using managed services and a dedicated cloud hardware security module. Knowledge of container security issues, hardening containerized environments, container orchestration tools, and running production workloads in the cloud. Knowledge of IT Security Operations. Knowledge of UI, AI, and Machine Learning. Knowledge the Payment Card Industry (PCI) Data Security Standard (DSS). Able to understand and write basic JSON programming language policies. Demonstrated ability to work as an essential part of a highly motivated business, technology, development teams. Proficient Microsoft Office skills, including Word and Excel. Written and verbal communication skills and the ability to work with teams and external stakeholders are essential. Strong problem resolution and interpersonal skills. Strong multi-tasking skills. Able to use general office equipment including copy machine and phone system. SWBC offers*: Competitive overall compensation package Work/Life balance Employee engagement activities and recognition awards Years of Service awards Career enhancement and growth opportunities Leadership Academy and Mentor Program Continuing education and career certifications Variety of healthcare coverage options Traditional and Roth 401(k) retirement plans Lucrative Wellness Program Based upon employee eligibility Additional Information: SWBC is a Substance-Free Workplace and requires pre-employment drug testing. Please note, SWBC does not hire tobacco users as allowed by law. To learn more about SWBC, visit our website at www.SWBC.com. If interested, please click the appropriate apply button.

Posted 1 week ago

Security Officer II-logo
Security Officer II
Sutter HealthNovato, CA
We are so glad you are interested in joining Sutter Health! Organization: NCH-Novato Community Hospital Position Overview: Provides a secure and safe environment that allows patients, visitors, physicians, personnel and volunteers to deliver or receive quality services with minimal threats against their personal well-being and property. Is responsible for patrolling and monitoring facility premises, observing and reporting suspicious and unauthorized activities and unsafe conditions. Is responsible for access control, control of keys and emergency response and notification. Renders assistance and security related services to staff, physicians, patients, and visitors, including monitoring and restraining violent patients. Investigates and documents incidents relative to the facility and provides necessary liaison between staff and local law enforcement agencies. Job Description: EDUCATION: HS Diploma or General Education Diploma (GED) CERTIFICATION & LICENSURE: PSO - Proprietary Private Security Officer within 30 days of start date DL-Valid Driver's License if required to operate Sutter Health vehicles TYPICAL EXPERIENCE: 1 year recent relevant experience SKILLS AND KNOWLEDGE: General knowledge of the usual duty requirements of a security officer with an emphasis on the physical and emotional maturity required for the high degree of judgment and diplomacy necessary to work efficiently in a healthcare environment. Requires critical thinking skills, decisive judgment and the ability to work with minimal supervision. Ability to write incident reports and read business correspondence and procedure manuals. Ability to effectively present information and respond to questions from groups of managers, clients, customers and the general public. Ability to add, subtracts, multiply and divide in all units of measure, using whole numbers, common fractions and decimals. Ability to solve practical problems and deal with a variety of concrete variables in situations where only limited standardization exists. Ability to interpret a variety of instructions furnished in written, oral, diagram, or schedule form. Job Shift: Varied Schedule: Per Diem/Casual Shift Hours: 8 Days of the Week: Variable Weekend Requirements: As Needed Benefits: No Unions: No Position Status: Non-Exempt Weekly Hours: 0 Employee Status: Per Diem/Casual Sutter Health is an equal opportunity employer EOE/M/F/Disability/Veterans. Pay Range is $27.02 to $35.12 / hour The salary range for this role may vary above or below the posted range as determined by location. This range has not been adjusted for any specific geographic differential applicable by area where the position may be filled. Compensation takes into account several factors including but not limited to a candidate's experience, education, skills, licensure and certifications, department equity, training and organizational needs. Base pay is just one piece of the total rewards program offered by Sutter Health. Eligible roles also qualify for a comprehensive benefits package.

Posted 2 weeks ago

Information Systems Security Officer (Isso)-logo
Information Systems Security Officer (Isso)
Contact Government ServicesPlano, TX
ISSO Employment Type: Full-Time, Experienced Department:Information Technology CGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment documentation to support Dept. of Commerce systems and efforts to achieve their Authorization to Operate (ATO). This position is located at the client site in the Herbert Hoover building in Washington, DC. The scope of this position includes full life-cycle Assessment and Authorization (A&A) management through all 6 Steps of the RMF process in support of the Government ISSM.In this role, you'll conduct security assessment, and information system security oversight activities in accordance with NIST 800.53 that support systems from the perspective RMF requirements. CGS brings motivated, highly skilled, and creative people together to solve the government's most dynamic problems with cutting-edge technology. To carry out our mission, we are seeking candidates who are excited to contribute to government innovation, appreciate collaboration, and can anticipate the needs of others. Here at CGS, we offer an environment in which our employees feel supported, and we encourage professional growth through various learning opportunities. Skills and attributes for success: Review systems to identify potential security weaknesses and recommend improvements to amend vulnerabilities, implement changes, and document upgrades. Maintain responsibility for managing cybersecurity risk from an organizational perspective. Identify organizational risks, prioritize those risks, and maintain a risk registry for escalating and presenting those risks to senior leadership. Provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies. Providing configuration management (CM) recommendations for information system security software, hardware, and firmware and coordinating changes and modifications with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO). Maintain vulnerability scanning tool compliance, such as HBSS or ACAS, and patch management, such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance with all applicable directives, manage system changes, and assess the security impact of those changes. Support security authorization activities, including transitioning from the legacy Information Assurance Certification and Accreditation Process (DIACAP) to compliance with the DoC RMF. Provide subject matter expertise for cyber security and trusted system technology. Apply advanced technical knowledge and analysis of specialized functional areas in task requirements to develop solutions to complex problems. Research, write, review, disposition feedback, and finalize recommendations regarding cyber security policy, assessment and authorization assessments (A&As), security test and evaluation reports, and security engineering practices and processes. Conduct research and write risk assessment reports to include risk thresholds, evaluation, and scoring. Support analysis of the findings and provide expert technical guidance for mitigation strategies, including implementation advice on the cyber security risk findings, and other complex problems. Qualifications: Bachelor's Degree. A minimum of five (5) years experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development, including generating security documentation for requirements, security control assessment, STIG and IAVA compliance, Standard Operating Procedures, test results, etc. eMASS experience. Professional security certification such as: CCNA Security, CySA+, GICSP, GSEC, CompTIA Security+ CE, SSCP, or higher. Strong desktop publishing skills using Microsoft Word and Excel. Experience with industry writing styles such as grammar, sentence form, and structure. Ability to multi-task in a deadline-oriented environment. Ideally, you will also have: CISSP, CASP, or a similar certificate is preferred. Master's Degree in Cybersecurity or related field. Strong initiative, detail orientation, organizational skills, and aptitude for analytical thinking. Demonstrated ability to work well independently and as a part of a team. Excellent work ethic and a high commitment to quality. Our Commitment: Contact Government Services (CGS) strives to simplify and enhance government bureaucracy through the optimization of human, technical, and financial resources. We combine cutting-edge technology with world-class personnel to deliver customized solutions that fit our client's specific needs. We are committed to solving the most challenging and dynamic problems. For the past seven years, we've been growing our government contracting portfolio, and along the way, we've created valuable partnerships by demonstrating a commitment to honesty, professionalism, and quality work. Here at CGS we value honesty through hard work and self-awareness, professionalism in all we do, and to deliver the best quality to our consumers mending those relations for years to come. We care about our employees. Therefore, we offer a comprehensive benefits package. Health, Dental, and Vision Life Insurance 401k Flexible Spending Account (Health, Dependent Care, and Commuter) Paid Time Off and Observance of State/Federal Holidays Contact Government Services, LLC is an Equal Opportunity Employer. Applicants will be considered without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Join our team and become part of government innovation! Explore additional job opportunities with CGS on our Job Board: https://cgsfederal.com/join-our-team/ For more information about CGS please visit: https://www.cgsfederal.com or contact: Email: info@cgsfederal.com $92,213.33 - $125,146.66 a year

Posted 30+ days ago

Randolph Brooks Federal Credit Union logo
Information Security Assurance Analyst
Randolph Brooks Federal Credit UnionSan Antonio, TX
Apply

Automate your job search with Sonara.

Submit 10x as many applications with less effort than one manual application.1

Reclaim your time by letting our AI handle the grunt work of job searching.

We continuously scan millions of openings to find your top matches.

pay-wall

Job Description

Job Description and Requirements

Randolph-Brooks Federal Credit Union is currently searching for an experienced and talented Information Security Assurance Analyst to join our amazing IT Security team!

The Information Security Assurance Analyst will have the ability to work a hybrid schedule (remote/onsite) after a period of training (time frame may vary). Training will take place at the RBFCU Administrative Service Center: 1 Ikea-RBFCU Pkwy, Live Oak, Texas 78233. All applicants must reside within the state of Texas and have the capability of performing all of the work from their home in Texas.

To successfully work from home, employees must have access to a minimum internet connection as noted by RBFCU.

  • Must have a reliable home internet provider and the ability to hard wire a connection directly to modem (Ethernet cable provided).

  • Must be able to provide a workspaces at home that is safe, suitable for work, and within a distraction free environment

The Information Security Assurance Analyst strengthen the organization's information security posture through the construction, socialization and performance measurement of policies and procedures based on best practices, adopted frameworks, and risk assessment activities.

Essential Functions and Responsibilities:

  • Contribute to the strategic and tactical initiatives involving activities associated with managing IT Risk.

  • Assist with auditing systems, processes and users to ensure compliance with the organization's information security policies and procedures.

  • Assist in the creation and analysis of information security reports on the performance of controls across the enterprise.

  • Assist with documenting an organization's information security requirements in a business context and participate in high-level discussions to identify and respond to business risks.

  • Assist with security reviews with stakeholders throughout the organization, identifying gaps and developing risk mitigation plans.

  • Provides ongoing support of an effective disaster recovery/incident response program. Works with management to ensure that disaster recovery/incident response plans drive proper strategy and procedures.

  • Assist with the development and execution of testing processes utilized to validate the disaster recovery/incident response plans. Schedule and lead all tabletop exercises. Develop and understand all testing necessary for a successful execution.

  • Works with the IT staff to ensure that disaster/incident response solutions are adequate, in place, maintained, and tested as part of the regular operational life cycle.

  • Assist with the development and deployment of training documentation and communication of incident procedures to the organization.

  • Assist with vendor risk assessments.

  • With guidance, produce deliverables, specifically process flows, procedure documentation, writing specialized assessment reports, related to process, tools, and metrics and communication activities.

  • All other duties as assigned (note: essential functions and responsibilities may change or new ones may be assigned at any time with or without notice).

Requirements:

  • High School Diploma or GED. Bachelor's degree in information technology preferred

  • Minimum of one year experience in IT Operations, Security, Risk, and/or Audit

  • Technical Project Management and/or Business Analysis experience desired

  • Understanding of technical concepts including system, application and network functions and design

  • Understanding of financial institution governance and regulations including SSAE16/18, FFIEC, GLBA and NCUA

  • Experience documenting, coordinating and executing incident test plans

  • Must have high level of communications skills to communicate with all levels of management

  • Experience supporting technical projects with technical and non-technical participants

  • Experience directly supporting an organization's information security program through development and implementation of policies, standards and procedures

  • Strong oral/written communication, organization, time management and interpersonal skills

  • Highly proficient with Microsoft Office software

  • Highly self-motivated, able to multi-task and manage deadlines well

  • Knowledge of regulations and best practices for information security including guidance published by NIST, FFIEC, and CIS

Preferred

  • Bachelor's degree

  • Security certificates, CISA other IT governance related certifications

All qualified applicants will receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity, religion, national origin, disability, veteran status, or other legally protected status.