landing_page-logo
  1. Home
  2. »All Job Categories
  3. »Security Jobs

Auto-apply to these security jobs

We've scanned millions of jobs. Simply select your favorites, and we can fill out the applications for you.

Workday Application Security & Controls Sr. Associate-logo
Workday Application Security & Controls Sr. Associate
PwCSeattle, WA
Industry/Sector Not Applicable Specialism Workday Management Level Senior Associate Job Description & Summary A career in Enterprise Application Risk will allow you to develop and apply strategies that help clients leverage enterprise technologies so they can get a higher return on their investment, mitigate risks, streamline processes, and find operational inefficiencies. The work revolves around creative problem solving and applying innovative technologies to enable strategies that increase the value of the applications that run our client's business. Our focus is on creating effective and efficient design for the most important business, security and compliance processes for our clients. We touch on aspects of application security and areas prone to fraud and financial misstatement and on streamlining processes that are part of our client's core business so they can get a higher return on this key investment. Using innovative, and proprietary technologies, we help to bridge the gap between business stakeholders, compliance functions, and Information Technology teams to assist in understanding how to embrace new ways of working while limiting their financial and operational risk profile. We use knowledge of financial system design, risk mitigation, business process design, data integrity, security, and use of data analytics. Our clients make large investments in enterprise financial systems, and they need to design those systems to meet the needs of their business while providing capabilities to improve end user experiences while managing risk. Our team helps companies manage risks on their journey to a more digitally integrated environment which enables them to better harness cloud technologies. As part of our team, you will focus on helping clients gain value across their technology ecosystem by addressing risks tied to systems, security, data, reporting, and programs. To really stand out and make us fit for the future in a constantly changing world, each and every one of us at PwC needs to be a purpose-led and values-driven leader at every level. To help us achieve this we have the PwC Professional; our global leadership development framework. It gives us a single set of expectations across our lines, geographies and career paths, and provides transparency on the skills we need as individuals to be successful and progress in our careers, now and in the future. As a Senior Associate, you'll work as part of a team of problem solvers, helping to solve complex business issues from strategy to execution. PwC Professional skills and responsibilities for this management level include but are not limited to: Use feedback and reflection to develop self awareness, personal strengths and address development areas. Delegate to others to provide stretch opportunities, coaching them to deliver results. Demonstrate critical thinking and the ability to bring order to unstructured problems. Use a broad range of tools and techniques to extract insights from current industry or sector trends. Review your work and that of others for quality, accuracy and relevance. Know how and when to use tools available for a given situation and can explain the reasons for this choice. Seek and embrace opportunities which give exposure to different situations, environments and perspectives. Use straightforward communication, in a structured way, when influencing and connecting with others. Able to read situations and modify behavior to build quality relationships. Uphold the firm's code of ethics and business conduct. Workday is what we do. As part of our Cyber Risk and Regulatory platform, we simplify Workday security and controls to protect businesses and their workforce. Our focus is on Workday security and internal control across finance and HR functions. We know Workday, and we use knowledge of financial system design, security, business processes, risk mitigation, and compliance to solve our customers' most important problems along their Workday journey. Job Requirements and Preferences: Basic Qualifications: Minimum Degree Required: Bachelor Degree Minimum Years of Experience: 3 year(s) of experience in ERP controls auditing, consulting and/or implementing with a minimum of 1 year of experience with Workday. Preferred Qualifications: Preferred Fields of Study: Accounting & Technology, Accounting, Business Application Programming, Business Administration/Management, Computer and Information Science, Computer and Information Science & Accounting, Computer Applications, Computer Engineering, Computer Management, Computer Programming, Computer Systems Analysis, Computer Systems Analysis & Accounting, Economics and Finance & Technology, Finance & Technology, Finance, Information CyberSecurity, Information Technology, Information Technology & Accounting, Management Information Systems, Management Information Systems & Accounting, Management of Technology, Risk Management, Systems Engineering, Systems Engineering & Accounting Certification(s) Preferred: CISA, CRISC or CGEIT CPA Workday Certification (HCM, FINS, Payroll, integrations, Extend, Reporting, PM) Preferred Knowledge/Skills: A Senior Associate works as part of a team of Workday certified experts helping to solve complex business issues. Candidates should demonstrate a thorough level of abilities with, and/or a proven record of success as both an individual contributor and team member designing, implementing, and/or assessing internal controls over Workday security and business cycles, to include: Knowledge of Workday configurable security, foundation data model (FDM), and module specific configurations; Experience interfacing with client roles across HR, IT, Finance, and Accounting to identify, evaluate and support the implementation of security and business process controls as part of a Workday implementation or post-deployment project; Knowledge of regulatory requirements with an emphasis on ICFR and industry specific control requirements, as aligned to controls over tenant security and business processes within Workday; Ability to collaborate with systems integrators in developing business requirements and business controls in Workday implementations; Ability to apply Workday security, configuration and control expertise to help customers protect their business and global workforce; Experience integrating internal control practices across Workday business cycles to mitigate risk and support compliance requirements; Experience working with customers to understand, document, and validate security objectives and internal control objectives; Experience supporting Workday security implementation and product configuration activities following the Workday deployment methodology; Experience actively participating in Workday Community by researching best practices and monitoring new and updated security functionality; Design, develop, test, and deploy Workday security required to meet business requirements; Design, document, test and monitor effective internal controls aligned to customer requirements and compliance stipulations; Plan, organize, and deliver Workday security and control solutions in a professional, client-focused manner; and, Earn and maintain Workday certifications in designated areas of expertise across Financial Management, HCM and other Workday areas. Travel Requirements Up to 40% Job Posting End Date Learn more about how we work: https://pwc.to/how-we-work PwC does not intend to hire experienced or entry level job seekers who will need, now or in the future, PwC sponsorship through the H-1B lottery, except as set forth within the following policy: https://pwc.to/H-1B-Lottery-Policy . As PwC is an equal opportunity employer, all qualified applicants will receive consideration for employment at PwC without regard to race; color; religion; national origin; sex (including pregnancy, sexual orientation, and gender identity); age; disability; genetic information (including family medical history); veteran, marital, or citizenship status; or, any other status protected by law. For only those qualified applicants that are impacted by the Los Angeles County Fair Chance Ordinance for Employers, the Los Angeles' Fair Chance Initiative for Hiring Ordinance, the San Francisco Fair Chance Ordinance, San Diego County Fair Chance Ordinance, and the California Fair Chance Act, where applicable, arrest or conviction records will be considered for Employment in accordance with these laws. At PwC, we recognize that conviction records may have a direct, adverse, and negative relationship to responsibilities such as accessing sensitive company or customer information, handling proprietary assets, or collaborating closely with team members. We evaluate these factors thoughtfully to establish a secure and trusted workplace for all. The salary range for this position is: $84,000 - $202,000, plus individuals may be eligible for an annual discretionary bonus. For roles that are based in Maryland, this is the listed salary range for this position. Actual compensation within the range will be dependent upon the individual's skills, experience, qualifications and location, and applicable employment laws. PwC offers a wide range of benefits, including medical, dental, vision, 401k, holiday pay, vacation, personal and family sick leave, and more. To view our benefits at a glance, please visit the following link: https://pwc.to/benefits-at-a-glance

Posted 1 week ago

Host-Based Security Engineer-logo
Host-Based Security Engineer
KBRPearl City, HI
Title: Host-Based Security Engineer Positions Contingent on Contract Award KBR is actively seeking skilled professionals across a variety of high-impact cybersecurity roles-from Incident Response and Cyber Hunt to Digital Forensics, Insider Threat, Continuous Monitoring, and Red/Blue Team Operations. Host-Based Security Engineer Job Description: The Host-Based Security Engineer is responsible for developing, implementing, and managing host-based security solutions to protect NIWC CSSP networks and endpoints. This role involves supporting endpoint security, intrusion detection/prevention, malware analysis, and security compliance enforcement in alignment with DoD cybersecurity policies. The engineer will also work with incident response teams to investigate security breaches and perform host-based forensic analysis. Key Responsibilities: Develop and maintain host-based security solutions using government-approved tools such as Host-Based Security System (HBSS), Endpoint Detection and Response (EDR), and Next-Gen Antivirus (NGAV). Create, test, and deploy custom host-based security signatures to detect and mitigate threats. Implement host-based intrusion detection/prevention systems (HIDS/HIPS) and fine-tune policies for maximum protection with minimal impact on system performance. Perform malware analysis and behavioral analysis to identify and neutralize malicious software threats. Conduct host-based forensic investigations to analyze security breaches, identify attack vectors, and collect digital evidence. Ensure compliance with DoD security standards such as DISA STIGs, DoD 8570, and RMF guidelines. Monitor and assess endpoint security logs from SIEM platforms to detect anomalies, investigate security alerts, and mitigate cyber threats. Develop security automation scripts to enhance endpoint protection and streamline response actions. Support incident response teams by providing host-based security expertise during cyber incidents. Stay current on emerging host-based attack techniques, malware, and adversarial Tactics, Techniques, and Procedures (TTPs) to enhance detection and prevention capabilities. Train and mentor junior security engineers on best practices for host-based security management. Qualifications Information Systems Security Specialist I-III Education / Experience Level I: High School Diploma or GED; Experience: Two (2) years of practical experience demonstrating competency in Cybersecurity or related experience. Clearance Requirement: Secret / Top Secret SCI Certification Requirements: 8570 Compliant IAT 2 or 3 Salary range: $65,200 - $97,700. The salary range posted is based on the national average. The offered rate will be based on the selected candidate's location, knowledge, skills, abilities, and/or experience, contract affordability, and in consideration of internal parity. Education / Experience Level II: High School Diploma or GED; Experience: Two (3) years of practical experience demonstrating competency in Cybersecurity or related experience. Clearance Requirement: Secret / Top Secret SCI Certification Requirements: 8570 Compliant IAT 2 or 3 and meet one of subsequent DoD 8140 manual of CND Auditor, CND Analyst, CNDSP Manager, CND Incident Responder, CND Infrastructure Support, IASAE I or IASAE II Salary range: $74,000 - $110,900. The salary range posted is based on the national average. The offered rate will be based on the selected candidate's location, knowledge, skills, abilities, and/or experience, contract affordability, and in consideration of internal parity. Education / Experience Level III: 5+ years with a Bachelor's degree or 7+ years with HS/GED in Cybersecurity or related experience. Clearance Requirement: Secret / Top Secret SCI Certification Requirements: 8570 Compliant IAT 2 or 3 and meet one of subsequent DoD 8140 manual of CND Auditor, CND Analyst, CNDSP Manager, CND Incident Responder, CND Infrastructure Support, IASAE I or IASAE II Salary range: $89,200 - $133,800. The salary range posted is based on the national average. The offered rate will be based on the selected candidate's location, knowledge, skills, abilities, and/or experience, contract affordability, and in consideration of internal parity. Cybersecurity Engineer I-III Education / Experience Level I: Bachelor's degree in Cybersecurity or related discipline. Experience: No Experience needed Clearance Requirement: Secret / Top Secret SCI Certification Requirements: 8570 Compliant IAT 2 or 3 Salary range: $80,700 - $121,000. The salary range posted is based on the national average. The offered rate will be based on the selected candidate's location, knowledge, skills, abilities, and/or experience, contract affordability, and in consideration of internal parity. Education / Experience Level II: Bachelor's degree in Cybersecurity or related discipline. Experience: 3 years of professional experience in a related cybersecurity / IT Field Clearance Requirement:Secret / Top Secret SCI Certification Requirements: 8570 Compliant IAT 2 or 3 Salary range: $99,300 - $149,000. The salary range posted is based on the national average. The offered rate will be based on the selected candidate's location, knowledge, skills, abilities, and/or experience, contract affordability, and in consideration of internal parity. Education / Experience Level III: Master's degree in Cybersecurity or related discipline. Experience: 10 years of professional experience in a related cybersecurity / IT Field Clear ance Requirement: Secret / Top Secret SCI Certification Requirements: 8570 Compliant IAT 2 or 3 Salary range: $139,700 - $209,600. The salary range posted is based on the national average. The offered rate will be based on the selected candidate's location, knowledge, skills, abilities, and/or experience, contract affordability, and in consideration of internal parity. Benefits: KBR offers a selection of competitive lifestyle benefits which could include a 401K plan with company match, medical, dental, vision, life insurance, AD&D, flexible spending account, disability, paid time off, or flexible work schedule. We support career advancement through professional training and development. Belong, Connect and Grow at KBR At KBR, we are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company. That commitment is central to our team of team's philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver - Together. KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.

Posted 30+ days ago

Building Security Officer - 2Nd Shift (Part Time)-logo
Building Security Officer - 2Nd Shift (Part Time)
Arena Operations LLCAtlanta, GA
Who are we: A professional basketball team and state-of-the-art arena/entertainment venue that specializes in creating memorable experiences for each guest we interact with. Some of our favorite things are live sports, concerts, comedy shows, family shows, and most any other world-class event you can think of, and we're looking for someone who shares the same interests. We live for the fast-paced world of sports & live entertainment, and as such, we work hard, run fast, execute flawlessly, and party it up when it all comes together. Lastly, we strive to deliver wonderful experiences that create lasting memories, and we prefer to surround ourselves with those who are the best at what they do. Who are you: An enthusiastic lover of sports, live entertainment, and people. You have true passion for engaging in meaningful interactions and creating memorable experiences for all guests. You strive to be helpful, engaging, and knowledgeable of all things Atlanta Hawks and State Farm Arena. You enjoy being a part of an exciting and dynamic group, and you're committed to continuously enhancing the productivity and effectiveness of your team. Lastly, you enjoy working hard and celebrating hard, and you'd be shocked if guests weren't positively impacted by their interactions with you. Responsibilities/Duties: Thorough knowledge of policies and procedures Patrol interior/exterior and check for irregularities Monitor and operate CCTV cameras as well as other security and fire systems Lock/unlock areas as requested Respond to incidents and complete reports as necessary Control shipping and receiving of packages Creating a safe and comfortable working environment for employees and visitors Conducting searches of personnel, bags, and packages Monitor and control employee and visitor access to the building Attend Department in-service training as needed Maintain all security equipment through proper upkeep and maintenance Perform any other duties as assigned by their supervisor and not otherwise prohibited by law or Company policy Other duties that may be assigned Qualifications: High school diploma/GED Two years of security experience A clear criminal record check Good verbal and written communication skills Detail-oriented, professional image and integrity Be able to sit, stand and/or walk for extended periods of time Basic computer skills Valid GA Driver's License Must be able to work any shift including nights, weekends, holidays; and/or extended hours Must be physically able to demonstrate proficiency with all security equipment, as well as obtain and keep current First Aid Certification and pass written tests related to security policies and procedures on an annual basis We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, sex, sexual orientation, age, disability, gender identity, marital or veteran status, or any other protected class. If this opportunity looks exciting to you, please complete the application process. Go Hawks!

Posted 30+ days ago

Senior Product Security Engineer II-logo
Senior Product Security Engineer II
Credit KarmaOakland, CA
Intuit Credit Karma is a mission-driven company, focused on championing financial progress for our more than 140 million members globally. While we're best known for pioneering free credit scores, our members turn to us for everything related to their financial goals, including identity monitoring, applying for credit cards, shopping for insurance and loans (car, home and personal) and savings accounts and checking accounts* - all for free. Credit Karma has grown significantly through the years: we now have more than 1,700 employees across our offices in Oakland, Charlotte, Culver City, San Diego, London, Bangalore, and New York City. Banking services provided by MVB Bank, Inc., Member FDIC As a Product Security Engineer, you will conduct security reviews, and design and prototype new tooling and features across the organization. You will work with architects and engineering teams to guide the implementation of secure practices across different areas like cloud, API, applications and mobile devices. You will provide training in security best practices, and enforce our policies and standards. You will identify trends and risks across multiple platforms, and engage with senior leadership to provide action plans and strategy. What You'll Do: Provide security expertise for cloud, web and mobile projects, helping teams meet the enterprise and IT security policies, industry regulations, and best practices. Implement company-wide programs that deploy security patterns and controls across applications and computing environments, together with business resiliency, privacy, and compliance frameworks. Work with security and engineering teams to maintain a security architecture that provides security controls throughout all platforms to mitigate risk, and to meet goals and regulatory requirements. Ensure the quality of our applications and products by guiding them through the Secure Development Lifecycle (SDL) process. Advocate, research, develop new tools to support our security patterns and standards. Monitor our exposure to, and assess the impact of, new security threats, vulnerabilities and risks. What we are looking for: 4+ years' experience in the application security industry, solving security problems in large-scale systems. Experience with security design reviews, and threat-modeling exercises for both traditional and AI systems. Expertise in verifying and measuring common security vulnerabilities, and demonstrated ability in communicating these concepts to your partners in engineering. From the OWASP Top Ten to more advanced concepts, you've seen it before, and can describe it with ease. Familiarity with the responsibilities and workflow of software developers and machine learning engineers. The Product Security team works with engineering to meet both business needs and security requirements. You can speak their language, and sympathize with their challenges. Facility with implementing standards, e.g., PCI-DSS, ISO, OAuth, NIST Cyber Security framework. Basic working knowledge of one or more of the following languages: Java, Scala, Node JS, Typescript, Python, Golang, Rust. Strong knowledge of security frameworks and standards (NIST, CIS, MITRE ATT&CK). What we would like to see: Exposure to most of the following technologies: Google Cloud, iOS, Android, CircleCI, IAM, Snyk, Consul, Kubernetes, Hashicorp Vault, PKI, OPA, React, GraphQL, Thrift, Kafka, and Splunk. Familiarity with AI-specific threats and secure AI development practices. Working familiarity with one or more LLM platforms: GPT, Gemini, Claude, Llama Experience defining security architecture patterns and standards in a large enterprise organization. Knowledge of cryptography including algorithms, standards, and their practical applications such as TLS and HMAC. Experience performing threat modeling of applications to identify potential security issues. Pay Transparency Notice: Credit Karma's mission of championing financial progress for all starts from within. That's why we implemented role-based compensation, which ensures people who are in the same role receive the same pay with variations for geographic location only. It's all part of a more comprehensive DEI strategy that helps level the playing field. The base salary range for this role is $260,000 - $320,000, plus equity and benefits. Benefits at Credit Karma includes: Medical and Dental Coverage Retirement Plan Commuter Benefits Wellness perks Paid Time Off (Vacation, Sick, Baby Bonding, Cultural Observance, & More) Education Perks Paid Gift Week in December Equal Employment Opportunity: Credit Karma is proud to be an Equal Employment Opportunity Employer. We welcome all candidates without regard to race, color, religion, age, marital status, sex (including pregnancy, childbirth, or related medical condition), sexual orientation, gender identity or gender expression, national origin, veteran or military status, disability (physical or mental), genetic information or other protected characteristic. We prohibit discrimination of any kind and operate in compliance with applicable fair chance laws. Credit Karma is also committed to a diverse and inclusive work environment because it is the right thing to do. We believe that such an environment advances long-term professional growth, creates a robust business, and supports our mission of championing financial progress for everyone. We offer generous benefits and perks with a single eye to nourishing an inclusive environment that recognizes the contributions of all and fosters diversity by supporting our internal Employee Resource Groups. We've worked hard to build an intensely collaborative and creative environment, a diverse and inclusive employee culture, and the opportunity for professional growth. As part of the Credit Karma team, your voice will be heard, your contributions will matter, and your unique background and experiences will be celebrated. Privacy Policies: Credit Karma is strongly committed to protecting personal data. Please take a look below to review our privacy policies: GDPR Privacy Policy U.S. Job Applicant Privacy Notice

Posted 30+ days ago

Information Systems Security Officer (Isso)-logo
Information Systems Security Officer (Isso)
Contact Government ServicesEl Paso, TX
ISSO Employment Type: Full-Time, Experienced Department:Information Technology CGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment documentation to support Dept. of Commerce systems and efforts to achieve their Authorization to Operate (ATO). This position is located at the client site in the Herbert Hoover building in Washington, DC. The scope of this position includes full life-cycle Assessment and Authorization (A&A) management through all 6 Steps of the RMF process in support of the Government ISSM.In this role, you'll conduct security assessment, and information system security oversight activities in accordance with NIST 800.53 that support systems from the perspective RMF requirements. CGS brings motivated, highly skilled, and creative people together to solve the government's most dynamic problems with cutting-edge technology. To carry out our mission, we are seeking candidates who are excited to contribute to government innovation, appreciate collaboration, and can anticipate the needs of others. Here at CGS, we offer an environment in which our employees feel supported, and we encourage professional growth through various learning opportunities. Skills and attributes for success: Review systems to identify potential security weaknesses and recommend improvements to amend vulnerabilities, implement changes, and document upgrades. Maintain responsibility for managing cybersecurity risk from an organizational perspective. Identify organizational risks, prioritize those risks, and maintain a risk registry for escalating and presenting those risks to senior leadership. Provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies. Providing configuration management (CM) recommendations for information system security software, hardware, and firmware and coordinating changes and modifications with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO). Maintain vulnerability scanning tool compliance, such as HBSS or ACAS, and patch management, such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance with all applicable directives, manage system changes, and assess the security impact of those changes. Support security authorization activities, including transitioning from the legacy Information Assurance Certification and Accreditation Process (DIACAP) to compliance with the DoC RMF. Provide subject matter expertise for cyber security and trusted system technology. Apply advanced technical knowledge and analysis of specialized functional areas in task requirements to develop solutions to complex problems. Research, write, review, disposition feedback, and finalize recommendations regarding cyber security policy, assessment and authorization assessments (A&As), security test and evaluation reports, and security engineering practices and processes. Conduct research and write risk assessment reports to include risk thresholds, evaluation, and scoring. Support analysis of the findings and provide expert technical guidance for mitigation strategies, including implementation advice on the cyber security risk findings, and other complex problems. Qualifications: Bachelor's Degree. A minimum of five (5) years experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development, including generating security documentation for requirements, security control assessment, STIG and IAVA compliance, Standard Operating Procedures, test results, etc. eMASS experience. Professional security certification such as: CCNA Security, CySA+, GICSP, GSEC, CompTIA Security+ CE, SSCP, or higher. Strong desktop publishing skills using Microsoft Word and Excel. Experience with industry writing styles such as grammar, sentence form, and structure. Ability to multi-task in a deadline-oriented environment. Ideally, you will also have: CISSP, CASP, or a similar certificate is preferred. Master's Degree in Cybersecurity or related field. Strong initiative, detail orientation, organizational skills, and aptitude for analytical thinking. Demonstrated ability to work well independently and as a part of a team. Excellent work ethic and a high commitment to quality. Our Commitment: Contact Government Services (CGS) strives to simplify and enhance government bureaucracy through the optimization of human, technical, and financial resources. We combine cutting-edge technology with world-class personnel to deliver customized solutions that fit our client's specific needs. We are committed to solving the most challenging and dynamic problems. For the past seven years, we've been growing our government contracting portfolio, and along the way, we've created valuable partnerships by demonstrating a commitment to honesty, professionalism, and quality work. Here at CGS we value honesty through hard work and self-awareness, professionalism in all we do, and to deliver the best quality to our consumers mending those relations for years to come. We care about our employees. Therefore, we offer a comprehensive benefits package. Health, Dental, and Vision Life Insurance 401k Flexible Spending Account (Health, Dependent Care, and Commuter) Paid Time Off and Observance of State/Federal Holidays Contact Government Services, LLC is an Equal Opportunity Employer. Applicants will be considered without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Join our team and become part of government innovation! Explore additional job opportunities with CGS on our Job Board: https://cgsfederal.com/join-our-team/ For more information about CGS please visit: https://www.cgsfederal.com or contact: Email: info@cgsfederal.com $92,213.33 - $125,146.66 a year

Posted 30+ days ago

Information System Security Manager (Issm) (Entry/Mid-Level)-logo
Information System Security Manager (Issm) (Entry/Mid-Level)
Applied Research Associates, Inc.Madison, AL
The Analytical Solutions Division (ASD) of Applied Research Associates (ARA), Inc (www.ara.com) has an exciting opportunity for a full-time Information System Security Manager (ISSM) on-site at our Huntsville, AL location. ISSM is responsible for overseeing security operations in compliance with the 32 CFR Part 117 National Industrial Security Program Operating Manual (NISPOM). Interface with the Defense Counterintelligence and Security Agency (DCSA), managing security policies, conducting assessments, and ensuring the integrity of security systems. Responsible for the planning, organization, maintenance, and compliance of multiple classified systems in accordance with NISPOM, risk management framework (RMF) requirements, and DCSA Assessment & Authorization Process Manual (DAAPM). Develop policy, guidance, and establish implementation and oversight plans to ensure compliance with Risk Management requirements. ISSM will also serve as the Facility Security Officer to handle personnel clearance processing and maintain facility clearance activities and provide administrative security support associated with the receipt, distribution, inventory, reproduction and disposition of classified material. For this position, ARA will only consider applicants with an active SECRET Security Clearance or higher. Position is not eligible for remote work schedule. Collaborate with Project Managers (PMs) or Information System Owners (ISO) in maintaining current authorization to operate, and approval to connect for all systems and networks, and in implementing corrective actions identified in the plan of action and milestones Conduct recurring Cybersecurity reviews on information systems in accordance with DoD RMF practices, DCSA Assessment and Authorization Process Manual (DAAPM), NIST 800-53 Special Publications, customer directives, and company policies as applicable. Audit information systems to ensure compliance with security policies and procedures Manage user access and conduct user briefings as required Schedule mandatory Information System patching, updating, and scanning based on vulnerabilities and threats or regulatory compliance; maintain the day-to-day security posture and continuous monitoring for all systems Investigate classified spills/incident response or other security-related incidents to DCSA and recommend corrective actions Apply physical security concepts to maintain current Facility Clearance Level (FCL) and approved safeguarding Manage the Access Control/Alarm System in accordance with DoD standards Must Haves as an ISSM: Must possess a U.S. Department of Defense (DoD) Secret security clearance with the ability to obtain Top Secret clearance Must be a U.S. Citizen 2+ years' experience as NISPOM ISSO/ISSM Experience with security assessment/hardening tools, i.e., STIGs, SCAP, GPO, NESSUS, etc. Possess strong understanding of computer operating systems (Windows and Linux), software and computer hardware Knowledge of current industry methods for evaluating, implementing, and disseminating information technology (IT) security assessment, monitoring, detection, and remediation tools and procedures utilizing standards-based concepts and capabilities. Must be able to initiate communication with management and various government agencies for support and/or compliance requirements Knowledgeable in all areas of security (physical, personnel, information, communication, insider threat etc.) specialties, concepts, principles, criteria, requirements, technology, tracking and electronic security practices Knowledgeable of NISPOM and DCSA reporting requirements specifically in regard to security incidents and violations Must have the following certificates, or must be completed within 6 months of hire: FSO Program Management for Possessing Facilities Curriculum (IS030.CU), ISSM Required Online Training DAAPM - 2.6 Program Risk Management Framework (CS100.CU), CompTIA Continuous Monitoring (CS200.16), Introduction to the Risk Management Framework (CS124.16), Introduction to Industrial Security (IS011.16), Introduction to Information Security (IF011.16), Introduction to Personnel Security (PS113.16), Introduction to Physical Security (PY011.16) This will "WOW" us if you have the following: Active DoD TS/SCI Clearance Possess a DoD 8570 IAM-I level professional certification, Security + or CISSP Proficient in IA Security specifications such as Risk Management Framework (RMF) and NIST SP 800-53 Working knowledge of eMASS application/DISS/NBIS Please apply at careers.ara.com for the Information System Security Manager (ISSM) position. #LI-AB1

Posted 3 weeks ago

Cyber Security Red Team Analyst, Senior-logo
Cyber Security Red Team Analyst, Senior
Huntington Bancshares IncPittsburgh, PA
Description Summary: The Cybersecurity Red Team Analyst - Senior will assist in developing and testing tools, tactics, and procedures to emulate adversarial threats actively in use targeting the financial services industry and performs the employment of these tools in the Huntington environment with minimal supervision. This capability provides Huntington with a means of testing security controls for effectiveness, discovering gaps in controls, and validating viability of threats for more effective prioritization of risks. Duties & Responsibilities: Develop and test threat actor emulation tools, tactics, and procedures for the Red Team to employ on-demand for assessments of security controls for application, systems, and network. Partner with threat intelligence team to ensure Red Team capabilities and tactics accurately emulate the current threat landscape. Consult with cross-functional teams in project testing phases to ensure controls are in place to remediate threats. Consult with cross-functional teams for architectural design and review sessions to ensure controls are in place to remediate threats. Coordinate and monitor 3rd-party penetration testing engagement staff to ensure engagements meet all requirements with appropriate communications and timely and accurate reporting of results. Generate and publish Red Team metrics and reporting. Lead efforts to track remediation of findings to completion through coordination with cross-functional teams for various application and technology system owners. Other duties as assigned. Basic Qualifications: 3 years Cyber Security experience 2 years Penetration testing/Red team experience Associates degree Preferred Qualifications: Ability to communicate clearly and concisely Understanding of Threat Actors and their tactics, techniques, and procedures Strong experience with Security Assessment Toolsets Strong experience in automation and scripting of applications and systems Advanced knowledge of relational databases and structured query language Advanced knowledge of client/server relationships and multi-tier environments OSCP, GPEN, OSCE, GCIH, GXPN #Hybrid #LI-SG1 #LI-BM1 Exempt Status: (Yes = not eligible for overtime pay) (No = eligible for overtime pay) Yes Workplace Type: Office Our Approach to Office Workplace Type Certain positions outside our branch network may be eligible for a flexible work arrangement. We're combining the best of both worlds: in-office and work from home. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. Remote roles will also have the opportunity to come together in our offices for moments that matter. Specific work arrangements will be provided by the hiring team. Huntington will not sponsor applicants for this position for immigration benefits, including but not limited to assisting with obtaining work permission for F-1 students, H-1B professionals, O-1 workers, TN workers, E-3 workers, among other immigration statuses. Applicants must be currently authorized to work in the United States on a full-time basis. Huntington is an Equal Opportunity Employer. Tobacco-Free Hiring Practice: Visit Huntington's Career Web Site for more details. Note to Agency Recruiters: Huntington will not pay a fee for any placement resulting from the receipt of an unsolicited resume. All unsolicited resumes sent to any Huntington colleagues, directly or indirectly, will be considered Huntington property. Recruiting agencies must have a valid, written and fully executed Master Service Agreement and Statement of Work for consideration.

Posted 3 weeks ago

Sr. Manager Information Security-logo
Sr. Manager Information Security
Cirrus AircraftDuluth, MN
The Sr. Manager, Information Security is responsible for overseeing a team of IT Security professionals and creating strategies to improve and monitor the security of Cirrus systems. The Sr. Manager, Information Security is responsible for developing, implementing, and maintaining an information security capability that protects the organization's information assets. This role involves overseeing security policies, risk management, compliance, incident response, and employee training. This leader will possess a deep understanding of information security frameworks and have a proven track record in managing security teams and projects. This role reports to the Executive Director, Digital Transformation & Technology. Duties and Responsibilities/Essential Functions To perform this job successfully, an individual must be able to perform each essential function satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable qualified individuals with disabilities to perform the essential functions. High Performing Team: Build high performing team of IT Security professionals that plan and design security solutions that enable the organization to identify, protect, detect, respond, and recover from cyber threats and vulnerabilities. Selects, develops and evaluates personnel to ensure the efficient operation of the function. Provides leadership and mentorship to the information security team, fostering a culture of security awareness. Vision/Strategy/Roadmap: Creates Information Security and Cybersecurity strategy, roadmap, goals, objectives and metrics to mitigate business threats, address opportunities and prioritize for protection of critical systems. Prioritize projects, financials, and KPIs to measure progress against the roadmap while leveraging both mainstream and emerging technologies to transform the information security capability. Prepare and present reports on security metrics, incidents, and compliance status to executive management. Security Architectures: Oversees the planning, design and build of security architectures. Ensures the implementation of network and computer security is compliant with corporate cybersecurity policies and procedures. Responsible for mitigating enterprise cybersecurity risks for local area networks (LANs), wide area networks (WANs), virtual private networks (VPNs), routers, firewalls, and related network devices. Configures and installs firewalls and intrusion detection systems. Implements software fixes (patches) to remove system vulnerabilities. Owns incident response planning, leads vulnerability audits and forensic investigations. Evaluates potential business impacts from security breaches and provides strategic and tactical guidance to Executive & business decision-makers. Responsible for security systems compliance policies and procedures. Vulnerability Assessments: Performs security assessments, penetration tests, vulnerability scans and risk analysis across the Cirrus ecosystem. Manage vulnerability assessments and security audits to identify cybersecurity risks. Drives improvements necessary to mitigate those risks. Performs technical analysis of vulnerabilities and leads in the development of vulnerability corrective action plans. Conducts a regular review of network, application and operation system security documents and procedures. Reviews results of vulnerability assessments and code reviews and informs management of vulnerabilities, risk and mitigation. Provides technical expertise to the vulnerability assessment team responsible for the testing, validating, and the security of the company's applications, servers, and networks. Cybersecurity Focus: Identifies cybersecurity architecture, goals, objectives and metrics; analyzes business needs and priorities for protection of critical systems. Keeps abreast of the latest intelligence from law enforcement and other sources of cyber threat information. Monitors systems for cybersecurity vulnerabilities, threats and events, oversees incident response planning, and leads vulnerability audits and forensic investigations. Evaluates potential business impacts from security breaches and provides strategic and tactical guidance to business decision-makers. Reviews, manages and approves the action plans for policy creation and governance, system hardening, monitoring, incident response, disaster recovery, and emerging cybersecurity threats. Security Controls: Manages the development, deployment and execution of controls and defenses to ensure the security and risk mitigation of company infrastructure technology, information systems and digital payment systems. This includes leading investigations with any suppliers that have security breaches. Establishes and implements operational policies and appropriate standards and criteria for hardware, software, email and web firewall, access verification and encryption requirements. Manage the administration and hardening of internal processes and systems against outside penetration and attack. Collaborate with IT, legal, and compliance teams to ensure security practices meet regulatory requirements Application Security Assessments: Approves the security requirements and the security integration plans to protect existing infrastructure and to incorporate future solutions by doing a thorough security assessment of software. Partners and collaborates with stakeholders to encourage the adoption of security-compatible software designs and best practices. Disaster Recovery Plan: Manages the design, implementation and communication of the IT disaster recovery plan. Oversees the risk analysis of critical operations and systems essential to continuing business operations in the event of a disaster. Monitors and tests the design and implementation of network and server backup solutions. Leads the IT disaster recovery program/project design function to ensure strategic goals are met. Partners with corporate disaster recovery and business continuity teams to include training, testing and communication of disaster procedures within the organization. Builds the necessary controls, infrastructure and procedural playbook to monitor, identify and provide proactive detection and response. Coordinates response to significant incidents and identifies cybersecurity risks and gaps. Reviews detailed incident reports and provides technical briefs to the IT security team. Vendor Management: Manages information security and cybersecurity vendor partnerships and associated contracts, including cybersecurity insurance vendors. Manages and directs the cybersecurity training vendor, prepares phishing simulations and reports results. Coordinates security training programs for employees to promote security awareness and best practices. Partners with a cybersecurity firm to implement two executive tabletops each year. Education and/or Experience: Certified Information Security Sr. Manager (CISM) or Certified Information Systems Security Professional (CISSP) helpful. Bachelor's degree in computer science, business administration or related field, or equivalent combination of education and experience. 10+ Years of building high performing Information Security teams and capabilities, leading cybersecurity implementation programs, vulnerability management, disaster recovery planning, coordinating security assessments and driving continuous improvement. Required experience managing information security vendor relationships, negotiating contracts and managing the vendor performance. Required experience building an information security capability from the ground up, including vision, strategy, goals, outcomes and roadmap. Required experience leading diverse and cross functional teams. Required experience in preparing and presenting reports on security metrics, incidents, and compliance status to executive management. Demonstrate experience partnering with front of the house functions such as sales, marketing and customer service through capabilities supporting the back of the house and through customer delivery. Demonstrated Proficiencies/Skills/Abilities: Exceptional leadership skills, with the ability to develop and communicate strategy, inspire and motivate the staff, and maintain alignment across the business. Guides, influences and persuades others internally and/or externally; Understands the importance of partnership and Cirrus' interdependencies A high degree of political savvy, astuteness and the ability to use informal power structure of the organization to achieve program success and overcome obstacles. Strong business acumen, including manufacturing industry and IT domain specific knowledge. Deep understanding of how organizations can use current technologies to drive digital business. Ability to develop programs and deliver them with financial and resource constraints. Strong communication skills and ability to translate between, and connect, business and technology Competencies To perform the job successfully, an individual should demonstrate the following competencies: Balances Stakeholders: Anticipates and balances the needs of multiple stakeholders. This competency includes building and maintaining effective relationships with stakeholders at all levels, both internal and external to the organization. It is demonstrated by understanding and proactively managing the expectations and needs of various stakeholders, balancing their interests and resolving conflicts to fairly meet the demands of all. Situational Adaptability: Adapts approach and demeanor in real time to match shifting demands of different situations. This competency includes leveraging emotional intelligence to pick up on situational cues and adjusting in the moment, as well as adapting to different personal, interpersonal and leadership styles. Leverages different approaches in different situation to drive to desired results. Builds Effective Teams: Builds strong effective teams that apply their diverse skills and perspectives to achieve common goals. This competency includes selecting individuals and building a team with appropriate and diverse mix of styles, perspectives, and experience. Creates a team environment via establishing common objectives and a shared mindset resulting in feeling of belonging and strong team morale. Recognizes and celebrates team wins. Fosters open dialogue and collaboration among the team. Ensures Accountability: Holds self and others accountable to meet commitments. This competency includes acting with a clear sense of ownership, following through on commitments and ensuring others do the same. Takes personal responsibility for self and team's decisions, actions and failures. Establishes clear responsibilities and processes for monitoring work and measuring results, including feedback loops. Drives Results: Consistently achieves results, even under tough circumstances. This competency includes engaging with the business unit on resolving trade-offs of scope, priority, business and technical risk, and business impact of dependencies among multiple Information Services. Ensures full transparency and no surprises, keeping stakeholders up to date with the latest delivery status and risks. Manages Complexity: Makes sense of complex, high quantity, and sometimes, contradictory information to effectively solve. Business Insight: Applies knowledge of business and the marketplace to advance the organizations goals. Other Duties Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this position. Duties, responsibilities and activities may change at any time with or without notice. Work beyond 40 hours per week may be required. Cirrus is dedicated to a drug free work environment promoting equal employment opportunity. Qualified applicants will receive consideration for employment without regard to race, sex, national origin, color, age, disability, religion, pregnancy, veteran status, marital and family status, sexual orientation, receipt of public assistance, genetic information or any other characteristic protected by applicable law. Our Benefits: Cirrus provides a range of exciting benefits, including: 401(k) Plan: Dollar-for-dollar match up to 5% after 90 days, with 100% vesting. Employer-Paid Coverages: Group term life, short- and long-term disability insurance. Comprehensive Health Coverage: Medical, vision, dental, with additional dependent coverage options. Free Health Tracking: With rewards for meeting health goals. Generous PTO: 160 hours accrued within the first year. Employee Referral Bonus: For referring talented candidates. Career Development: Tuition reimbursement and professional growth opportunities. Exclusive Discounts: Access to partner and marketplace discounts. Community & Engagement: Company and employee clubs at various locations. These benefits are designed to support your well-being, growth, and enjoyment at Cirrus!

Posted 30+ days ago

Security GRC IT Controls Analyst-logo
Security GRC IT Controls Analyst
Core Scientific Inc.Miami, FL
Who We Are Bold. Unapologetic. Hardworking. We are building something special. We transform energy into high-value compute with superior efficiency at scale. Today that means powering and securing the Bitcoin Network and powering workloads in AI, HPC and other forms of high-value compute. Core Scientific is one of the largest bitcoin miners and hosts in North America. Our mission is to accelerate digital innovation by scaling high-value computing rapidly, efficiently, and responsibly. Our proprietary software stack optimizes bitcoin mining, pushes firmware, and monitors all aspects of our operations, ensuring we and our customers generate the highest possible ROI on our hardware investment. But what makes us different from others in our industry? We own and manage our infrastructure. That puts us in control of our operations and gives us an advantage that translates into higher productivity and efficiency. It also provides us with the ability to deploy rapidly the innovations developed by our deep-tech team. Come join us as we continue our journey and accelerate yours. We seek smart, creative, collaborative minds, who work hard and fast. Intrigued? Then apply and be a part of something truly special at Core Scientific. Title Security GRC IT Controls Analyst Reports To Manager, Governance Risk and Compliance (GRC) The Job We are seeking a detail-oriented and experienced Security GRC IT Controls Analyst to join our team. The ideal candidate will serve a critical role in ensuring the company's compliance with Sarbanes-Oxley (SOX) and SOC 2 requirements by evaluating, facilitating testing, and leading improvement opportunities associated with IT General Controls (ITGCs). This position involves close collaboration with Security, IT, Finance, and Compliance teams to strengthen the organization's internal control environment and risk posture. Key Responsibilities IT and Process Compliance Testing: Facilitate ITGC assessments, including testing of access controls, change management, and IT operations, to ensure compliance with SOX and SOC 2 requirements. Risk Assessment: Identify and assess IT risks and control design or operating effectiveness gaps in processes, systems, and infrastructure. Propose remediation strategies to address identified risks. Control Documentation: Develop and maintain documentation of ITGCs, control matrices, unified control frameworks, risk assessments, and testing methodology. Audit Support: Act as a key liaison between internal compliance department, and IT teams to facilitate SOX and SOC 2 testing and address any findings or inquiries. Process Improvement: Collaborate with stakeholders to design, implement, and optimize controls and processes to strengthen IT governance. Monitoring and Reporting: Track remediation efforts, escalate issues as needed, and report control statuses to management. Policy and Procedure Review: Help develop and maintain IT policies, procedures, and standards that align with SOX, SOC 2 and Enterprise Security Compliance objectives. Training and Guidance: Guide business teams on SOX and SOC 2 compliance requirements as well as corporate security policies and best practices. Qualifications Bachelor's degree in Information Technology, Accounting, Finance, or a related field. Strong analytical skills and ability to dive deep to get to Root Cause. Excellent communication and interpersonal skills 5-10 years of experience in external audit, internal audit, SOX/SOC 2 compliance, IT audit, IT Security or a related IT governance role. Strong understanding of ITGC frameworks and control areas (e.g., access management, change management, backup, recovery, and operations). Experience with SOX 404 compliance testing. Experience working in a BIG 4 firm leading IT compliance assessment initiatives strongly desired Experience managing supply chain risk management programs Certifications (preferred): CRISC, CISA, CISSP, CPA, or similar certifications. Perform other duties as assigned. Technical Skills: Proficiency in IT systems and/or data center environments Familiarity with GRC tools such as Drata, Archer, ServiceNow, or AuditBoard. Strong analytical, problem-solving, and project management skills. Excellent verbal and written communication abilities to effectively collaborate with technical and non-technical stakeholders. Detail-oriented with a commitment to delivering high-quality work within deadlines. Experience working with external audit partners Location: This role is a full-time, Monday-Friday position and will operate in a hybrid office environment in Austin, TX or Miami FL. Physical Demands: While performing the duties of this job, the employee is frequently required to sit; stand; walk; use hands; and lift up to 10 pounds. Travel: Minimal travel may be required.

Posted 2 weeks ago

Security Officer- Full Time-logo
Security Officer- Full Time
Barton HealthCare SystemSouth Lake Tahoe, CA
New Pay Grade for 2025! Hourly Range: $23.95 USD to $34.74 USD Summary of Position: The Security Officer maintains a safe and secure environment for Barton Health's employees, patients, and visitors by conducting patrols, inspections, and enforcement of applicable hospital policies and procedures. The Officer responds and provides assistance in both non-emergency and emergency situations. The Officer investigates critical incidents and interfaces with emergency response agencies. The Officer assures the physical security of Barton Health's building and grounds. Qualifications Education: High School Diploma, or GED preferred Experience: ● One (1) year experience as a security officer or prior military/law enforcement experience preferred. Knowledge/Skills/Abilities: ● Ability to work independently and make sound judgements during stressful circumstances. ● Must be able to speak English, communicate clearly orally, and in writing; understand and use de-escalation techniques. ● Ability to handle sensitive and confidential matters with discretion and work effectively with others. Certifications/Licensure: ● Valid CA BSIS Security Guard or Proprietary Private Security Officer license or ability to obtain prior to hire if employee is hired as CA employee, ● Valid CA BSIS Security Guard or Proprietary Private Security Officer license or must be obtained within 180 days from date of hire if employee is hired as NV employee. ● Current California or Nevada Driver's License with clean driving record. ● American Heart Association CPR/BLS Certification within 90 days of hire. Physical Demands The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. ● While performing the duties of this job, the employee is frequently required to walk, stand, sit, and talk or hear. ● The employee is occasionally required to use hands to finger, handle, feel or operate objects, tools, or controls; and reach with hands and arms. The employee is occasionally required to climb or balance; stoop, kneel, crouch, or crawl. ● Specific vision abilities required by this job include close vision, distance vision, peripheral vision, depth perception, the ability to adjust focus and color vision. ● The employee must frequently lift and/or move up to 50 pounds and occasionally lift and/or move more than 100 pounds. ● The employee may be occasionally required to exercise sudden physical exertion, such as running, restraining, or pushing heavy objects. Working Conditions The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. ● Routine Hospital/Healthcare & Office/Administrative conditions. ● Contact with patients and guests under a wide variety of circumstances. ● Regularly exposed to the risk of bloodborne diseases. ● Exposure to infections and contagious disease. ● Exposed to hazardous anesthetic agents, body fluids and waste. ● Subject to hazards of flammable and explosive gases. ● Subject to varying and unpredictable situations, including the handling of emergency or crisis situations. ● Subject to pressure due to irregular hours, frequent interruptions and stressful situations due to multiple demands. ● Occasional travel to various health system locations. ● While performing the duties of this job, the employee will be occasionally exposed to inclement weather condition. Essential Functions Provides consistently exceptional care at all times. Responds to emergency codes and calls for assistance. Assures incident data is collected and reported in a timely manner. Monitors access control, intrusion detection, and camera systems. Creates and issues staff identification and access control badges. Maintains and troubleshoots access control hardware. Recognizes irregular, unusual or unsafe situations and takes immediate action to resolve the issues wherever possible. Immediately reports such situations to appropriate first responders when it is not safe to intervene. Appropriately aids in the application of violent or non-violent restraints. Demonstrates the proper handling and storage of patient belongings, valuables, and Lost & Found items, per the Security Department Procedures. Investigates, reports, and follows-up on all reportable incidents that occur and/ or pertain to departmental calls for service in a thorough and timely manner. Submits well-written, complete, and detailed Security Incident Reports prior to the end of the shift. Controls traffic and parking; enforces parking laws, rules and regulations through verbal and written warnings as appropriate to circumstances. Conducts interior and exterior patrols of Barton Health facilities to detect and deter crime, theft, and vandalism. Greets, screens, and monitors entry of after hours visitors and vendors. Secures and/or unlocks offices and facilities. Reports maintenance concerns with buildings or grounds. Performs other related duties of a comparable level/type as assigned. Posts and assignments may vary. Responds to the needs of the department by performing other duties, as necessary.

Posted 3 weeks ago

Security Officer - Mercedes-Benz Stadium-logo
Security Officer - Mercedes-Benz Stadium
Blank Family Of BusinessesAtlanta, GA
Position Description The Security Officer plays a significant role in the ensuring a safe, secure and welcoming environment to all MBS employees and guests. MBS Security Officers are a friendly resource to individuals in need of assistance, crisis intervention, or information. MBS Security Officers respond quickly in emergency situations and as an integral associate, strive to protect property, guests, and employees of MBS stadium. MBS Security Officers provide prevention activities and contribute to the building safety and security by monitoring and reporting physical security and safety conditions. Roles and Responsibilities Foot Patrol and Building Security Checks. Visually inspect and monitor designated post area(s). Monitor performance of security/safety equipment. Investigate and report any unusual or unauthorized activity within the area. Conduct the building security checks as required. Be observant for fires and suspicious packages. Be observant for spills and alert to odors and unusual sounds. Check and report condition of area, exit and emergency lighting. Check external access to vital areas of the facility. Monitor access through designated doors as required. In the event of alarm conditions, assist in the safe and orderly evacuation of facility personnel if warranted. Respond to local audible alarms on HVAC and Electrical Equipment. Report and silence alarms as instructed by procedures and Facilities Department personnel during after-hours operations. Identify and turn-off electrical appliances such as space heaters, fans, coffeepots, etc. that might be left on after normal work hours and could pose a source of heat and ignition for fire. Be observant for trespassers and unauthorized persons. Inspect designated areas for unauthorized activity. Control access to the building, including registering and directing visitors. Visually inspect the ID card of each person entering the building and verify that the individual and the cardholder are the same. Issue temporary access badges to authorized personnel as required by procedures. Escort visitors and other personnel as required by procedures. Inspect packages and other designated items as required (including assignment as a searcher). Operate and monitor CCTV and access control systems where required. Operate computer-based security/safety related software and applications as required. Control access to the building utilizing access control system. Complete required testing of security and fire systems related equipment as required by security procedures. Operate and monitor alarm systems where required. Initiate appropriate response as required for various alarms. Initiate and maintain 24/7 communication with AMBSE Security Management Team Dispatch other Security Force personnel and/or check alarms as required. Qualifications Requirements Must be 18 years of age or older. Must have a high school education or have passed a General Educational Development (GED) equivalency test. Shall be knowledgeable and competent in speaking and writing English. Must have successfully completed medical examination to include a chemical and substance abuse test and analysis. Must have signed the Individual Confidentially Contract, the Release of Information Statement, and the Chemical Non-Abuse Statement.. Must have successfully undergone any and all background investigations required by AMBSE.

Posted 30+ days ago

Information Security Engineer-logo
Information Security Engineer
First Horizon Corp.Lafayette, LA
Locations: Onsite in Memphis, TN; Maryville, TN; Birmingham, AL; Lafayette, LA; New Orleans, LA; Charlotte, NC; Raleigh, NC; or Dallas, TX. Summary The Cyber Security Engineer - Threat Management is a mid-level Cyber Security Engineer responsible for second level security event/incident response along with the collection, analysis, and dissemination of cyber threat intelligence. These capabilities will include timely collection of advanced warning of impeding IT vulnerabilities or threats, a thorough correlation, analysis, and storage of threat intelligence information, and operational support of the incident response process. The candidate They will deliver and sustain the enterprise management strategy and solutions from a governance, process, discipline and technology standpoint, to support enterprise environments and our presence in various cloud instances and on-premises data centers covering threats / FIM / configuration management / incident response / vulnerability management. Secondary roles include IPS, EDR, TIP tools, and other information security solutions. Essential Functions of the Job: Responding to SOC alerts performing an analysis, and containment of security events. Provide tier II support for escalated security incidents. Support the Cyber Incident Response Team (CIRT) in the effective detection, analysis, and containment of attacks. Operate the configuration management program to track configuration drift over time, working with asset custodians to correct any configuration deviation from baseline. Operate the File Integrity Management program to track changes to file systems on critical systems. Operate the processes necessary to collect threat intelligence, analyze the data for patterns and actionable information, and create intelligence products for other teams to consume using MITRE ATT&CK Framework. Identifies security risks and exposures, determines the causes of security violations and suggests procedures to halt future incidents. Integrate appropriate systems and logs into the global threat management platform or Security Event and Incident Management system to properly protect critical assets. Design, test and develop specific content and alerting to identify threats against critical assets. Document incident response playbooks for new threat content and alerts. Maintain an understanding of attacks, vectors and emergent threats. Obtain and share cyber security intelligence with security partners, vendors and law enforcement as necessary. Produce weekly and monthly operational metrics. Work with vendors and internal customers to respond to escalations. Recommends Preventative Security Actions. Recommends Corrective Security Actions. Comprehension of basic banking systems. Job Requirements: High School Graduate or Equivalent. Bachelor's Degree Preferred but not required in Computer Engineering/Computer Science or related field. CISSP, GSEC, GCIH, CEH or other security certifications preferred, but not required. Three year minimum working in cyber threat or information security. Knowledge and Skills Requirements: Familiar with compliance regulations such as SOX, PCI-DSS, GLBA, and Federal Banking regulations. Proficient with cloud security and monitoring capabilities in Azure Proficient with Incident Response in Azure Proficient with configuration management scanning tools. Knowledgeable with Tripwire or other file integrity management tools. Excellent team skills and integrity in a professional environment. Ability to Map threats and vulnerabilities to MITRE. About Us First Horizon Corporation is a leading regional financial services company, dedicated to helping our clients, communities and associates unlock their full potential with capital and counsel. Headquartered in Memphis, TN, the banking subsidiary First Horizon Bank operates in 12 states across the southern U.S. The Company and its subsidiaries offer commercial, private banking, consumer, small business, wealth and trust management, retail brokerage, capital markets, fixed income, and mortgage banking services. First Horizon has been recognized as one of the nation's best employers by Fortune and Forbes magazines and a Top 10 Most Reputable U.S. Bank. More information is available at www.FirstHorizon.com. Benefit Highlights Medical with wellness incentives, dental, and vision HSA with company match Maternity and parental leave Tuition reimbursement Mentor program 401(k) with 6% match More -- FirstHorizon.com/First-Horizon-National-Corporation/Careers/Our-Benefits Follow Us Facebook X formerly Twitter LinkedIn Instagram YouTube

Posted 4 days ago

Senior Azure Cloud Security Analyst-logo
Senior Azure Cloud Security Analyst
CareBridgeWoburn, MA
Senior Azure Cloud Security Analyst Location: This role requires associates to be in-office 1 - 2 days per week, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life balance. This approach combines structured office engagement with the autonomy of virtual work, promoting a dynamic and adaptable workplace. Alternate locations may be considered. The Senior Azure Cloud Security Analyst is responsible for managing the delivery of information and network security systems and/or technology services, which may include server, desktop, software, network, and database components. How You Will Make An Impact: Provides trouble resolution on complex problems and leads implementations for system and network security technologies. Develops testing plans to ensure quality of implementation; coordinates and prepares the reporting of data security events and incidents. Provides system and network architecture support for information and network security technologies; provides technical support to business and technology associates in risk assessments and implementation of appropriate information security procedures. Standards and technologies; represents major upgrades and reconfigurations in change control; design & analyze mix of vendor services meeting business and information security requirements; maintains relationship with key vendors. Leads lights on initiatives to consolidate equipment and/or implement business relocations; determine and perform complex configuration changes to meet business and information security requirements; perform capacity analysis; recommend and implement capacity increases; serve as the technical escalation for results of preventative maintenance routines; supervise preventative maintenance. Represents infrastructure security support in significant projects and performs the most complex operations and administration tasks; respond to level 3 & 4 change and problem requests without supervision; lead level 1 & 2 incident recoveries and root cause analysis. Minimum Requirements: Requires a bachelor's degree or equivalent combination of education and experience that would provide the knowledge to perform such work. Experience must include a minimum of 2 to 3 years experience in a support & operations or design & engineering role in any of the following areas: access management or network security technologies, servers, networks, Network communications, telecommunications, operating systems, middleware, disaster recovery, collaboration technologies, hardware/software support or other infrastructure services role; or any combination of education and experience, which would provide an equivalent background. Requires experience providing top-tier support for 3 or more of the information security technology areas: 1) Access Control, 2) Application Security, 3) Business Continuity and Disaster Recovery Planning, 4) Cryptography, 5) Information Security and Risk Management 6) Legal, Regulations, 7) Compliance and Investigations, 8) Operations Security, 9) Physical (Environmental) Security, 10) Security Architecture and Design, 11) Telecommunications and Network Security. Preferred Skills, Capabilities and Experiences: Technical security certifications (e.g. Systems Security Certified Practitioner) strongly preferred. Please be advised that Elevance Health only accepts resumes for compensation from agencies that have a signed agreement with Elevance Health. Any unsolicited resumes, including those submitted to hiring managers, are deemed to be the property of Elevance Health. Who We Are Elevance Health is a health company dedicated to improving lives and communities - and making healthcare simpler. We are a Fortune 25 company with a longstanding history in the healthcare industry, looking for leaders at all levels of the organization who are passionate about making an impact on our members and the communities we serve. How We Work At Elevance Health, we are creating a culture that is designed to advance our strategy but will also lead to personal and professional growth for our associates. Our values and behaviors are the root of our culture. They are how we achieve our strategy, power our business outcomes and drive our shared success - for our consumers, our associates, our communities and our business. We offer a range of market-competitive total rewards that include merit increases, paid holidays, Paid Time Off, and incentive bonus programs (unless covered by a collective bargaining agreement), medical, dental, vision, short and long term disability benefits, 401(k) +match, stock purchase plan, life insurance, wellness programs and financial education resources, to name a few. Elevance Health operates in a Hybrid Workforce Strategy. Unless specified as primarily virtual by the hiring manager, associates are required to work at an Elevance Health location at least once per week, and potentially several times per week. Specific requirements and expectations for time onsite will be discussed as part of the hiring process. The health of our associates and communities is a top priority for Elevance Health. We require all new candidates in certain patient/member-facing roles to become vaccinated against COVID-19 and Influenza. If you are not vaccinated, your offer will be rescinded unless you provide an acceptable explanation. Elevance Health will also follow all relevant federal, state and local laws. Elevance Health is an Equal Employment Opportunity employer and all qualified applicants will receive consideration for employment without regard to age, citizenship status, color, creed, disability, ethnicity, genetic information, gender (including gender identity and gender expression), marital status, national origin, race, religion, sex, sexual orientation, veteran status or any other status or condition protected by applicable federal, state, or local laws. Applicants who require accommodation to participate in the job application process may contact elevancehealthjobssupport@elevancehealth.com for assistance. Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state, and local laws, including, but not limited to, the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act.

Posted 2 weeks ago

Head Of Product, Information Security And Identity-logo
Head Of Product, Information Security And Identity
UpholdNew York, NY
About Uphold Uphold is a financial technology company that believes on-chain services are the future of finance. It provides modern infrastructure for on-chain payments, banking, and investments. Offering Consumer Services, Business Services, and Institutional Trading, Uphold makes pioneering financial services easy and trusted for millions of customers in more than 140 countries. Uphold strips away the complexity and lack of transparency to open up Web3 finance for everyone. To learn more about Uphold, please visit https://uphold.com . The Opportunity Uphold is seeking a Head of Product, Information Security and Identity to lead the vision, strategy, and execution of its cybersecurity and Identity and Access Management (IAM) functions. This director-level, hybrid role-based in New York City with a required weekly in-office presence-blends product leadership with deep technical expertise to deliver secure, scalable solutions that protect users, systems, and data. The ideal candidate will have a strong background in fraud detection and prevention, with demonstrated experience designing, implementing, and managing IAM solutions that safeguard sensitive information while proactively mitigating access-related fraud risks. Expertise in authentication protocols, role-based access control, and privileged access management is essential, along with hands-on experience using IAM tools and analytics to detect anomalies and prevent identity-based threats. This role will collaborate closely with cybersecurity, compliance, and fraud teams to establish policies and controls that ensure secure and compliant access across the organization. Reporting to the VP of Product, the Head of Product will be responsible for defining product strategy, aligning cross-functional teams, and delivering solutions that meet the evolving needs of customers, regulatory frameworks, and emerging security threats-all while maintaining a seamless customer experience. What you'll be doing primarily: Define and lead the product vision, roadmap, and strategy for information security and identity products, including authentication, access management, data protection, and threat detection. Collaborate with Engineering, Security, Legal, and Compliance teams to ensure product security, privacy, and regulatory compliance (e.g., GDPR, SOC 2, CCPA). Own the product lifecycle from discovery through delivery, including customer research, requirements definition, prioritization, and go-to-market planning. Build and manage a high-performing product team with expertise in security, IAM, and cloud infrastructure. Analyze market trends, competitive landscape, and emerging technologies to inform product direction. Serve as the voice of the customer and advocate for intuitive, secure, and scalable identity experiences. Partner with internal stakeholders (IT, security operations, DevSecOps) to ensure enterprise-grade security standards are applied across products. Represent the product function in executive discussions, customer briefings, and industry forums. Required Qualifications: 10+ years of experience in product management with at least 5 years focused on information security, identity, or access management. Proven leadership experience managing product teams and cross-functional initiatives at scale. Ability to translate technical security concepts into user-friendly experiences through user stories, wireframing, and journey mapping. Experience using LLMs and other AI tooling to improve efficiency and productivity. Deep understanding of IAM protocols (e.g., OAuth, SAML, OpenID Connect), security frameworks (e.g., NIST, ISO 27001), and cloud-native security practices. Experience with enterprise SaaS platforms, security services, or developer-focused products. Strong analytical, communication, and stakeholder management skills. Bachelor's degree in Computer Science, Engineering, or a related field, or equivalent hands-on experience. Experience working in regulated industries (finance, healthcare, government) and coordination with control functions. Crypto industry experience is a big plus! Ability to travel globally as needed. Experience working with global teams. Self-starter: able to work asynchronously and independently. Hybrid role: This role requires you to be in person in our NY office weekly. Bonus if you have: Empathy for consumer and business user security experience and implementation considerations. Familiarity with DevSecOps, zero trust architecture, and security automation. Understanding threat modeling, data privacy, risk management, and fraud prevention. What we have to offer you: An amazing work environment in a company that continues to grow, driven by extraordinary and passionate people that keep up innovating and challenging more each day. An international team, in a cutting edge field, working on the most fascinating projects. Growth and career opportunities, and the chance to be proactive and creative. A flexible and enthusiastic work environment that offers you snacks, a lot of coffee and other great benefits. Open and transparent culture - we get together on a weekly basis to share updates, strategic plans, and engage with each other informally over food and drinks. Interesting events that keep you connected with the team and celebrate our success. Salary: $150K + DOE/Bonus/Options/Benefits/Lunch Provided in Office Join us to grow, innovate, and contribute meaningfully. Be part of our talented team! Visit our careers page for more exciting opportunities, if this role isn't the perfect fit. EEOC Employer We're proud to be an Equal Opportunity Employer and we celebrate our employees' differences, including race, color, religion, gender identity, national origin, age, military service eligibility, veteran status, sexual orientation, marital status, disability, and any other protected classes. Difference makes us stronger and better - together.

Posted 5 days ago

Security Officer 3-logo
Security Officer 3
Space Exploration TechnologiesHawthorne, CA
SpaceX was founded under the belief that a future where humanity is out exploring the stars is fundamentally more exciting than one where we are not. Today SpaceX is actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars. SECURITY OFFICER 3 Security Officers are dedicated security professionals with a demonstrated ability to work independently and as a member of a team in a fast-paced high-tech environment. Security Officers work as a team, patrolling the company's properties via vehicle and foot and/or ensuring security at a series of fixed locations in accordance with federal, state, and local laws as well as company regulations. RESPONSIBILITIES: Maintain proficiency/awareness of static guard post duties Plan and execute security support for SpaceX operations Plan and conduct advanced security training for all security officers Conduct advanced research and analysis in support of SpaceX security missions Mentor other security members to identify and report suspicious behavior to the operations center Maintain a professional appearance and demeanor Execute security support as dictated by SpaceX security leadership Execute roving patrols of assigned locations Conduct and review risk assessments of critical SpaceX facilities Provide mobile security support as directed by the operations center Respond to emergency situations and provide on-scene leadership to others (fire/medical/suspicious person/etc.) Develop and refine emergency response protocols based on data and experience Plan and coordinate domestic flight hardware transportation operations Learn advanced skillsets (EMT/investigations/surveillance/VIP escort/security hardware) Function as liaison with law enforcement, community leaders and key stakeholders in space industry BASIC QUALIFICATIONS: High school diploma or equivalency certificate 8+ years of experience in the military, law enforcement, overseas security contracting, or advanced corporate security realm 1+ year of executive protection, mobile asset protection, or emergency response team experience PREFERRED SKILLS AND EXPERIENCE: Bachelor's or advanced degree Military deployment and/or counterinsurgency experience History of critical incident handling experience Combat medic, EMT-B, or paramedic related experience Advanced medical emergency training (TCCC/TECC/Combat Lifesaver) Documented small unit leadership experience Impeccable character/integrity Excellent oral and written communication skills Ability to de-escalate disputes and/or conflict(s) History of critical incident handling experience Experience instructing security tactics/operations/procedures Computer based proficiency with Microsoft Windows and Microsoft Office, including Word, Excel, PowerPoint, and Outlook Extensive team-oriented experience An intense interest in protecting the future of spaceflight Foreign language proficiency ADDITIONAL REQUIREMENTS: Availability to work: Day shift: 6:00 AM - 6:00 PM Ability to work all shifts, weekends and holidays as needed Position is subject to pre-employment enhanced screening, including a background check, psychological test, bi-annual physical fitness test, and a drug and alcohol test Position is subject to random drug and alcohol testing Ability to wear approximately 20-30lbs of gear throughout a 12 hour shift Ability and willingness to occasionally stand in a static position for extended periods Willingness to travel up to 15% of time in support of SpaceX Security requirements should the need arise Valid driver's license Possess or be eligible for a valid state security officer license Eligible for a US Government security clearance COMPENSATION AND BENEFITS: Pay range: Security Officer /Level 3: $27.00/hour Your actual level and base salary will be determined on a case-by-case basis and may vary based on the following considerations: job-related knowledge and skills, education, and experience. Base salary is just one part of your total rewards package at SpaceX. You may also be eligible for long-term incentives, in the form of company stock, stock options, or long-term cash awards, as well as potential discretionary bonuses and the ability to purchase additional stock at a discount through an Employee Stock Purchase Plan. You will also receive access to comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, paid parental leave, and various other discounts and perks. You may also accrue 3 weeks of paid vacation & will be eligible for 10 or more paid holidays per year. ITAR REQUIREMENTS: To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here. SpaceX is an Equal Opportunity Employer; employment with SpaceX is governed on the basis of merit, competence and qualifications and will not be influenced in any manner by race, color, religion, gender, national origin/ethnicity, veteran status, disability status, age, sexual orientation, gender identity, marital status, mental or physical disability or any other legally protected status. Applicants wishing to view a copy of SpaceX's Affirmative Action Plan for veterans and individuals with disabilities, or applicants requiring reasonable accommodation to the application/interview process should reach out to EEOCompliance@spacex.com.

Posted 30+ days ago

Environmental Health, Safety And Security Sr. Manager-logo
Environmental Health, Safety And Security Sr. Manager
Mimedx Group Inc.Kennesaw, GA
POSITION SUMMARY: The Sr. Manager, Environmental Health, Safety & Sustainability (EHS&S) leads and oversees the strategic direction, development, implementation, compliance, and continuous improvement of EHS&S programs across all company facilities. This role ensures compliance with federal, state, and local regulations, minimizes risks, and fosters a safety-first culture. The Sr. Manager will also play a key role in sustainability initiatives, emergency preparedness, and regulatory compliance efforts to protect employees, the community, and the environment. This position requires proven leadership in managing a team, driving a proactive safety culture, and implementing best-in-class EHS&S programs that align with company goals. We are excited to add a new Environment, Health, Safety, & Sustainability Sr. Manager to our company! This role will pay a base salary between $116,000 - $190,000 based on previous experience, education and other factors. ESSENTIAL DUTIES AND RESPONSIBILITIES: Lead, develop, and build a team culture with the EHS&S team. Develop and implement strategic safety initiatives aligned with corporate objectives. Establish and track key performance indicators (KPIs) for safety and environmental compliance. Develop emergency response plans and drills, ensuring preparedness for workplace crises. Partner with senior leadership to drive a sustainability roadmap for waste reduction, energy efficiency, and environmental conservation. Provide regulatory guidance and reporting to ensure compliance with OSHA, EPA, NFPA, and local environmental laws. Engage site functional teams and leadership to prioritize initiatives and resources to achieve EHS objectives. Serve as a subject matter authority and administrator for assigned programs and support site internal/external/regulatory audits. Promote, reinforce, and sustain a safety-first culture through involvement, innovation, and engagement. Support management of site emergencies such as spills, evacuations and medical emergencies. Act as a liaison to employees needing ergonomic evaluations. Coordinate ergonomic evaluations and assist in improvement recommendations. Support contractor safety program by acquiring vital insurance, training, and permit information prior to commencement of work on site. Develop, review and refine EHS programs and processes to meet the changing needs of the business. Support management and record keeping of various production by-products and provide technical expertise and guidance to tackle site related hazards (chemical, biological, physical, electrical, slip/trip/fall, confined space, ergonomic, etc.). Partner with HR on onboarding and Processing Ops training management team to develop, refine, and deliver training content for EHS programs. Coordinate with outside vendors for site services as required. Use Lean tools and principles (Kaizen, Gemba, RCCM, etc.) to drive Continuous Improvement of EHS programs. Lead incident investigations, root cause analysis (RCCM), and corrective actions to prevent reoccurrences. Respond to departmental inquires and concerns in a timely manner while providing quality resolution. Develop and manage annual budget EDUCATION/EXPERIENCE: Bachelor's degree in Occupational Safety, Industrial Hygiene, Fire Protection, Environmental Science, Engineering or related discipline, preferred. 7 to 10 years' experience in direct Environmental, Industrial Hygiene, Occupational Health, Safety experience in a manufacturing environment. Currently or ability to certify in CPR/First Aid/Blood Borne Pathogen. Certified Safety Professional (CSP) or other safety certification preferred. Six Sigma (Green Belt or Black Belt) preferred. Direct EHS experience must include leading and influencing manufacturing sites and organizations, life science experience preferred. SKILLS/COMPETENCIES: Ability to communicate clearly and build relationships within the team and across various levels within the organization with a high level of focus on customer service and confidentiality Create accountability and sense of urgency. Ability to inspire others and energize team to meet the objectives of the business Strong analytical and critical thinking skills and ability to make data driven decisions Lead change and the ability to challenge and debate issues in a professional way Systems proficiency with technology based analytic tools A passion to develop people and ability to provide feedback including constructive criticism WORK ENVIRONMENT: The work is typically performed indoors and outdoors. Frequent travel between the Company's various office locations, all within 10-mile radius and possible external events as needed. Ability to wear personal protective equipment (PPE) as needed. PHYSICAL DEMANDS: Must be able to carry up to 50 lbs. Nothing in this job description restricts management's right to assign or reassign duties and responsibilities to, or requirements for, this job at any time.

Posted 30+ days ago

Staff Cloud Security Engineer-logo
Staff Cloud Security Engineer
RobinhoodBellevue, WA
Join a leading fintech company that's democratizing finance for all. Robinhood Markets was founded on a simple idea: that our financial markets should be accessible to all. With customers at the heart of our decisions, Robinhood and its subsidiaries and affiliates are lowering barriers and providing greater access to financial information. Together, we are building products and services that help create a financial system everyone can participate in. With growth as the top priority... The business is seeking curious, growth-minded thinkers to help shape our vision, structures and systems; playing a key-role as we launch into our ambitious future. If you're invigorated by our mission, values, and drive to change the world - we'd love to have you apply. About the team + role The Cloud Security team is focused on protecting Robinhood's AWS cloud and providing engineers with foundational security capabilities. It is a major contributor to the company's least privilege objective to manage network traffic and reduce the level of access that employees have or could obtain through escalation. A Staff Security Engineer on the Cloud Security team is a well-rounded technologist and a deep subject matter expert in cloud security and building security controls on Amazon Web Services (AWS). The ideal candidate for this role will embody and exemplify our Safety First value. The role is located in the office location(s) listed on this job description which will align with our in-office working environment. Please connect with your recruiter for more information regarding our in-office philosophy and expectations. What you'll do As a Staff Security Engineer you will be part of a team which owns the security posture for cloud infrastructure on which all Robinhood products are built You will build and operate solutions that protect foundational infrastructure and make it easier for Robinhood developers to protect their applications What you bring Securing enterprise applications on AWS by building software, services, and automation that provide safe defaults, paved roads, and intuitive capabilities to other developers Proficiency with Golang (preferred) or Python and Infrastructure-as-Code (IaC) using Terraform Strong command of industry best practices like the AWS Well-Architected framework and CIS Benchmarks and have expert level knowledge of AWS security services like Identity & Access Management (IAM), Service Control Policies (SCPs), AWS WAF, and AWS Network Firewall What we offer Market competitive and pay equity-focused compensation structure 100% paid health insurance for employees with 90% coverage for dependents Annual lifestyle wallet for personal wellness, learning and development, and more! Lifetime maximum benefit for family forming and fertility benefits Dedicated mental health support for employees and eligible dependents Generous time away including company holidays, paid time off, sick time, parental leave, and more! Lively office environment with catered meals, fully stocked kitchens, and geo-specific commuter benefits Base pay for the successful applicant will depend on a variety of job-related factors, which may include education, training, experience, location, business needs, or market demands. The expected salary range for this role is based on the location where the work will be performed and is aligned to one of 3 compensation zones. This role is also eligible to participate in a Robinhood bonus plan and Robinhood's equity plan. For other locations not listed, compensation can be discussed with your recruiter during the interview process. Zone 1 (Menlo Park, CA; New York, NY; Bellevue, WA; Washington, DC) $217,000-$255,000 USD Zone 2 (Denver, CO; Westlake, TX; Chicago, IL) $190,000-$224,000 USD Zone 3 (Lake Mary, FL; Clearwater, FL; Gainesville, FL) $169,000-$199,000 USD Click here to learn more about available Benefits, which vary by region and Robinhood entity. We're looking for more growth-minded and collaborative people to be a part of our journey in democratizing finance for all. If you're ready to give 100% in helping us achieve our mission-we'd love to have you apply even if you feel unsure about whether you meet every single requirement in this posting. At Robinhood, we're looking for people invigorated by our mission, values, and drive to change the world, not just those who simply check off all the boxes. Robinhood embraces a diversity of backgrounds and experiences and provides equal opportunity for all applicants and employees. We are dedicated to building a company that represents a variety of backgrounds, perspectives, and skills. We believe that the more inclusive we are, the better our work (and work environment) will be for everyone. Additionally, Robinhood provides reasonable accommodations for candidates on request and respects applicants' privacy rights. Please review the specific Robinhood Privacy Policy applicable to the country where you are applying.

Posted 30+ days ago

Application Security Engineer-logo
Application Security Engineer
Palantir TechnologiesWashington, DC
A World-Changing Company Palantir builds the world's leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions, locate missing children, and more. The Role Our products support some of the most important and impactful work in the world, including defense, intelligence, and commercial applications. We are trusted by our customers to protect their mission-critical information in the face of advanced persistent threats. The mission of the Application Security Team is to enable developers to be highly productive, agile, and produce the most secure software possible. Given the mission critical work that Palantir does, investments in application security have never been more important. As an Application Security Engineer, you will be hands-on and have wide-ranging impact for the security of Palantir: Product security reviews. You will perform full-scope security reviews of our current and future product and service portfolio. This includes whitebox, greybox, and blackbox assessments. You will work with offensive security teams, engineering teams, and other members of the InfoSec organization to harden our products against our dedicated adversaries. Architecture and design. You will be the security subject matter expert for product architects and engineers. You will threat model, assess risks, and help implement security controls and mitigations to address identified issues. You will directly steer the design of our products to ensure we are secure-by-default. Strategic security initiatives. You will be empowered to own transformational security initiatives that impact the whole company. Members of the Application Security Team have implemented software supply chain security controls (e.g., in-toto), implemented hardware-backed GPG key signing for commits, developed new security services, implemented security automation, or worked on massive-scale security problems. Vulnerability identification and analysis. You will be responsible for finding new and novel ways to identify and resolve security vulnerabilities in our products. This includes static and dynamic code analysis, security scanning, investigation of security reports from InfoSec, our bug bounty program, or other trusted partners, and direct work with our incident response team on product security issues and incidents. This role has wide-reaching impact, strong autonomy, and the resources and empowerment to make significant security improvements across all Palantir. The skills and background of successful candidates may vary highly, but curiosity, tenacity, and a drive to be a world-class security engineer are the underpinnings of our team. Core Responsibilities Perform deep architecture and security reviews on highly complex products to identify vulnerabilities Lead engineering teams in feature design, threat modeling, and security-critical code and architecture Develop and implement automation to eliminate entire classes of weaknesses across the organization Drive decision-making by determining the tradeoffs between security and product design Lead implementation of strategic security initiatives that improve security across Palantir What We Value Self motivated, experience in solving complex problems History and experience designing and shipping production-ready software Strong communication and collaboration skills who feels comfortable working closely with engineering teams Ability to learn and apply new technologies quickly and in complex deployments What We Require Development or software engineering experience and a deep passion for information security Experience with a modern high-level programming language (e.g. Java, Golang, Javascript, Python, etc.) Demonstrated experience evaluating code for vulnerabilities and weaknesses Experience with complex architectures and codebases (e.g. SOA or micro-services) Experience utilizing/with CodeQL or other static code analysis platforms Experience performing black-box testing of web applications Salary The estimated salary range for this position is estimated to be $135,000 - $200,000/year. Total compensation for this position may also include Restricted Stock units, sign-on bonus and other potential future incentives. Further note that total compensation for this position will be determined by each individual's relevant qualifications, work experience, skills, and other factors. This estimate excludes the value of any potential sign-on bonus; the value of any benefits offered; and the potential future value of any long-term incentives. Our benefits aim to promote health and wellbeing across all areas of Palantirians' lives. We work to continuously improve our offerings and listen to our community as we design and update them. The list below details our available benefits and some of the perks that can be enjoyed as an employee of Palantir Technologies. Benefits Employees (and their eligible dependents) can enroll in medical, dental, and vision insurance as well as voluntary life insurance Employees are automatically covered by Palantir's basic life, AD&D and disability insurance Commuter benefits Relocation assistance Take what you need paid time off, not accrual based 2 weeks paid time off built into the end of each year (subject to team and business needs) 10 paid holidays throughout the calendar year Supportive leave of absence program including time off for military service and medical events Paid leave for new parents and subsidized back-up care for all parents Fertility and family building benefits including but not limited to adoption, surrogacy, and preservation Stipend to help with expenses that come with a new child Employees can enroll in Palantir's 401k plan Life at Palantir We want every Palantirian to achieve their best outcomes, that's why we celebrate individuals' strengths, skills, and interests, from your first interview to your longterm growth, rather than rely on traditional career ladders. Paying attention to the needs of our community enables us to optimize our opportunities to grow and helps ensure many pathways to success at Palantir. Promoting health and well-being across all areas of Palantirians' lives is just one of the ways we're investing in our community. Learn more at Life at Palantir and note that our offerings may vary by region. In keeping consistent with Palantir's values and culture, we believe employees are "better together" and in-person work affords the opportunity for more creative outcomes. Therefore, we encourage employees to work from our offices to foster connectivity and innovation. Many teams do offer hybrid options (WFH a day or two a week), allowing our employees to strike the right trade-off for their personal productivity. Based on business need, there are a few roles that allow for "Remote" work on an exceptional basis. If you are applying for one of these roles, you must work from the state in which you are employed. If the posting is specified as Onsite, you are required to work from an office. If you want to empower the world's most important institutions, you belong here. Palantir values excellence regardless of background. We are proud to be an Equal Opportunity Employer for all, including but not limited to Veterans and those with disabilities. Palantir is committed to making the application and hiring process accessible to everyone and will provide a reasonable accommodation for those living with a disability. If you need an accommodation for the application or hiring process, please reach out and let us know how we can help.

Posted 30+ days ago

Security Lead-logo
Security Lead
Snorkel AI Inc.Redwood City, CA
We're on a mission to democratize AI by building the definitive AI data development platform. The AI landscape has gone through incredible change between 2016, when Snorkel started as a research project in the Stanford AI Lab, to the generative AI breakthroughs of today. But one thing has remained constant: the data you use to build AI is the key to achieving differentiation, high performance, and production-ready systems. We work with some of the world's largest organizations to empower scientists, engineers, financial experts, product creators, journalists, and more to build custom AI with their data faster than ever before. Excited to help us redefine how AI is built? Apply to be the newest Snorkeler! We're seeking a Security Lead to establish a Security team for our fast growing Data as a Service Product. We are leveraging human expertise to build novel datasets for LLM providers but with that comes bad actors. As we are scaling out our product, this is an increasing problem that we need to get ahead of. You will be responsible for identifying and building systems and automations to eliminate Fraud within our systems and adapt with our ever changing product needs and as our bad actors become more sophisticated. You will also be responsible for evolving the security posture, owning the roadmap and working against it as priorities of security vectors evolve. You will work cross functionally with operations, recruiting, and other engineering teams to deeply understand our pipeline and unique constraints to remove internal and external threats to our system. Primary responsibilities Identify, prevent and operationalize removal of fraud from our expert community's contributions Define and execute against a security roadmap for the product including ensuring that product teams develop using security best practices Build out a team to work against roadmap to make sure our systems are secure and minimize amount of bad actors in our system Design, develop and refine scalable fraud detection systems and algorithms Preferred qualifications 5+ years of professional experience in security related domains 2+ years of professional experience in fraud Willing to roll up your sleeves and dive deep into the problem Experience leading individual contributors Knowledge of machine learning techniques and applications in fraud detection Understanding of security principles and data privacy best practices #LI-HS1 Be Your Best At Snorkel Snorkel AI is on a mission to make machine learning practical for everyone, and it starts with building a team that welcomes, represents and gives opportunity to all. We work at the frontier of AI and software engineering, and believe that underrepresented communities need to play a part in shaping the future of these fields. At Snorkel AI, we actively work to create an environment that values end-to-end ownership, diverse forms of impact, and opportunities for personal growth. Snorkelers are supported by an amazing team and an amazing set of benefits. For Full-time employees, we offer comprehensive medical, dental, and vision plans for Snorkelers and their families, plus a yearly wellness stipend. Our 401k program lets Snorkelers plan for their future and our parental leave program lets new parents take up to 20 weeks of paid time off. Learn more about these benefits and more - like our workstation setup allowance - on our Careers page. Snorkel AI is proud to be an Equal Employment Opportunity employer and is committed to building a team that represents a variety of backgrounds, perspectives, and skills. Snorkel AI embraces diversity and provides equal employment opportunities to all employees and applicants for employment. Snorkel AI prohibits discrimination and harassment of any type on the basis of race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local law. All employment is decided on the basis of qualifications, performance, merit, and business need. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.

Posted 3 weeks ago

Security & Safety Monitor - Friday/Saturday & Sunday/Monday - Short Hour - Mental Health 614-logo
Security & Safety Monitor - Friday/Saturday & Sunday/Monday - Short Hour - Mental Health 614
Telecare Corp.Riverside, CA
Telecare's mission is to deliver excellent and effective behavioral health services that engage individuals in recovering their health, hopes, and dreams. Telecare continues to advance cultural diversity, humility, equity, and inclusion at all levels of our organization by hiring mental health peers, BIPOC, LGBTQIA+, veterans, and all belief systems. This is a 24-hour County-owned Restorative Transformation Center (RTC), Mental Health Rehabilitation Center (MHRC) (also referred to as RTC/MHRC) specializing in serving people who have been identified as being Incompetent to Stand Trial (IST) or are otherwise court ordered to treatment at this level of care. Services will be provided for a maximum of 30 residential beds, 24 hours a day, 365 days a year (24/7). The 30 beds can be used for male and female clients interchangeably. A maximum of 20 beds are specific for IST consumers identified by Superior Court, Riverside Sheriff's Office (RSO), or Riverside University Health System- Behavioral Health (RUHS-BH) teams. Ten beds are designated for consumers needing residential services with a secondary focus on consumers under Laura's Law/AOT, and Other RUHS-BH and Superior Court Diversion Programs. Shifts Available: Friday and Saturday 11:00 pm- 7:30 am (Short Hour) Friday and Saturday 3:00 pm- 11:30 pm (Short Hour) Sunday and Monday 7:00 am- 3:30 pm (Short Hour) Expected starting wage range is $21 - $23.09. Telecare applies geographic differentials to its pay ranges. The pay range assigned to this role will be based on the geographic location from which the role is performed. Starting pay is commensurate with relevant experience above the minimum requirements. POSITION SUMMARY The Security and Safety Monitor is responsible for the welcoming of new residents and day to day safety and security monitoring of the program. They may be called upon to assist program staff in providing direct and indirect services to members served. QUALIFICATIONS Required: High School Diploma or a G.E.D. One (1) year of direct service in providing security or other safety related roles and services One (1) year of direct service experience in mental health serving a similar program population A valid Security Guard Registration with California BSIS (Bureau of Security and Investigative Services) OR complete the required BSIS training course, submit application for license within 90 days of employment, and pass the BSIS exam. All additional training and continuing education requirements for BSIS must be maintained throughout employment. Must be at least 21 years of age Must be CPR, Crisis Prevention Institute (CPI), and First Aid certified on date of employment or within 60 days of employment and maintain current certification throughout employment All opportunities at Telecare are contingent upon successful completion and receipt of acceptable results of the applicable post-offer physical examination, 2-step PPD test for tuberculosis, acceptable criminal background clearances, excluded party sanctions, and degree or license verification. If the position requires driving, valid driver license, a motor vehicle clearance and proof of auto insurance is required at time of employment and must be maintained throughout employment. Additional regulatory, contractual or local requirements may apply Preferred: Associate degree from an accredited college in a related field ESSENTIAL FUNCTIONS Demonstrate the Telecare mission, purpose, values and beliefs in everyday language and contact with the internal and external stakeholders Routinely and frequently ensure overall safety and security of the program and physical environment Conduct safety rounds May assist and participate in the facilitation of the program's safety committee Assists in welcoming new residents to the program Notifies appropriate supervisors and agencies of any known or suspected incidents of abuse Completes adverse events report when warranted, including incident reports required by BSIS May participate as a member of the team and support residents' service plans when needed May be requested to assist in providing safe, effective, and efficient implementation of direct care in accordance with established policies, procedures and standards of care Ensures compliance with Telecare's policies and procedures Must assist with restraint of members served in the event of assaultive behavior and pass assault crisis/crisis prevention training Duties and responsibilities may be added, deleted and/or changed at the discretion of management. SKILLS Strong communication skills Ability to problem solve and team build Good customer relations skills PHYSICAL DEMANDS The physical demands here are representative of those that must be met by an employee to successfully perform the essential functions of this job. The employee is occasionally required to walk, sit, stand, bend, twist, reach, and lift and carry items weighing 50 pounds or less as well lift items up to 25 pounds overhead. They may also occasionally push, pull and do simple and power grasping. The position requires manual deviation, repetition and dexterity and to occasionally drive and be exposed to uneven walking ground. Visual requirements include computers and books exposure. EOE AA M/F/V/Disability If job posting references any sign-on bonus internal applicants and applicants employed with Telecare in the previous 12 months would not be eligible.

Posted 3 weeks ago

PwC logo
Workday Application Security & Controls Sr. Associate
PwCSeattle, WA
Apply

Automate your job search with Sonara.

Submit 10x as many applications with less effort than one manual application.1

Reclaim your time by letting our AI handle the grunt work of job searching.

We continuously scan millions of openings to find your top matches.

pay-wall

Job Description

Industry/Sector

Not Applicable

Specialism

Workday

Management Level

Senior Associate

Job Description & Summary

A career in Enterprise Application Risk will allow you to develop and apply strategies that help clients leverage enterprise technologies so they can get a higher return on their investment, mitigate risks, streamline processes, and find operational inefficiencies. The work revolves around creative problem solving and applying innovative technologies to enable strategies that increase the value of the applications that run our client's business.

Our focus is on creating effective and efficient design for the most important business, security and compliance processes for our clients. We touch on aspects of application security and areas prone to fraud and financial misstatement and on streamlining processes that are part of our client's core business so they can get a higher return on this key investment. Using innovative, and proprietary technologies, we help to bridge the gap between business stakeholders, compliance functions, and Information Technology teams to assist in understanding how to embrace new ways of working while limiting their financial and operational risk profile. We use knowledge of financial system design, risk mitigation, business process design, data integrity, security, and use of data analytics. Our clients make large investments in enterprise financial systems, and they need to design those systems to meet the needs of their business while providing capabilities to improve end user experiences while managing risk. Our team helps companies manage risks on their journey to a more digitally integrated environment which enables them to better harness cloud technologies. As part of our team, you will focus on helping clients gain value across their technology ecosystem by addressing risks tied to systems, security, data, reporting, and programs.

To really stand out and make us fit for the future in a constantly changing world, each and every one of us at PwC needs to be a purpose-led and values-driven leader at every level. To help us achieve this we have the PwC Professional; our global leadership development framework. It gives us a single set of expectations across our lines, geographies and career paths, and provides transparency on the skills we need as individuals to be successful and progress in our careers, now and in the future.

As a Senior Associate, you'll work as part of a team of problem solvers, helping to solve complex business issues from strategy to execution. PwC Professional skills and responsibilities for this management level include but are not limited to:

  • Use feedback and reflection to develop self awareness, personal strengths and address development areas.
  • Delegate to others to provide stretch opportunities, coaching them to deliver results.
  • Demonstrate critical thinking and the ability to bring order to unstructured problems.
  • Use a broad range of tools and techniques to extract insights from current industry or sector trends.
  • Review your work and that of others for quality, accuracy and relevance.
  • Know how and when to use tools available for a given situation and can explain the reasons for this choice.
  • Seek and embrace opportunities which give exposure to different situations, environments and perspectives.
  • Use straightforward communication, in a structured way, when influencing and connecting with others.
  • Able to read situations and modify behavior to build quality relationships.
  • Uphold the firm's code of ethics and business conduct.

Workday is what we do. As part of our Cyber Risk and Regulatory platform, we simplify Workday security and controls to protect businesses and their workforce. Our focus is on Workday security and internal control across finance and HR functions. We know Workday, and we use knowledge of financial system design, security, business processes, risk mitigation, and compliance to solve our customers' most important problems along their Workday journey.

Job Requirements and Preferences:

Basic Qualifications:

Minimum Degree Required:

Bachelor Degree

Minimum Years of Experience:

3 year(s) of experience in ERP controls auditing, consulting and/or implementing with a minimum of 1 year of experience with Workday.

Preferred Qualifications:

Preferred Fields of Study:

Accounting & Technology, Accounting, Business Application Programming, Business Administration/Management, Computer and Information Science, Computer and Information Science & Accounting, Computer Applications, Computer Engineering, Computer Management, Computer Programming, Computer Systems Analysis, Computer Systems Analysis & Accounting, Economics and Finance & Technology, Finance & Technology, Finance, Information CyberSecurity, Information Technology, Information Technology & Accounting, Management Information Systems, Management Information Systems & Accounting, Management of Technology, Risk Management, Systems Engineering, Systems Engineering & Accounting

Certification(s) Preferred:

  • CISA, CRISC or CGEIT
  • CPA
  • Workday Certification (HCM, FINS, Payroll, integrations, Extend, Reporting, PM)

Preferred Knowledge/Skills:

A Senior Associate works as part of a team of Workday certified experts helping to solve complex business issues. Candidates should demonstrate a thorough level of abilities with, and/or a proven record of success as both an individual contributor and team member designing, implementing, and/or assessing internal controls over Workday security and business cycles, to include:

  • Knowledge of Workday configurable security, foundation data model (FDM), and module specific configurations;
  • Experience interfacing with client roles across HR, IT, Finance, and Accounting to identify, evaluate and support the implementation of security and business process controls as part of a Workday implementation or post-deployment project;
  • Knowledge of regulatory requirements with an emphasis on ICFR and industry specific control requirements, as aligned to controls over tenant security and business processes within Workday;
  • Ability to collaborate with systems integrators in developing business requirements and business controls in Workday implementations;
  • Ability to apply Workday security, configuration and control expertise to help customers protect their business and global workforce;
  • Experience integrating internal control practices across Workday business cycles to mitigate risk and support compliance requirements;
  • Experience working with customers to understand, document, and validate security objectives and internal control objectives;
  • Experience supporting Workday security implementation and product configuration activities following the Workday deployment methodology;
  • Experience actively participating in Workday Community by researching best practices and monitoring new and updated security functionality;
  • Design, develop, test, and deploy Workday security required to meet business requirements;
  • Design, document, test and monitor effective internal controls aligned to customer requirements and compliance stipulations;
  • Plan, organize, and deliver Workday security and control solutions in a professional, client-focused manner; and,
  • Earn and maintain Workday certifications in designated areas of expertise across Financial Management, HCM and other Workday areas.

Travel Requirements

Up to 40%

Job Posting End Date

Learn more about how we work: https://pwc.to/how-we-work

PwC does not intend to hire experienced or entry level job seekers who will need, now or in the future, PwC sponsorship through the H-1B lottery, except as set forth within the following policy: https://pwc.to/H-1B-Lottery-Policy.

As PwC is an equal opportunity employer, all qualified applicants will receive consideration for employment at PwC without regard to race; color; religion; national origin; sex (including pregnancy, sexual orientation, and gender identity); age; disability; genetic information (including family medical history); veteran, marital, or citizenship status; or, any other status protected by law.

For only those qualified applicants that are impacted by the Los Angeles County Fair Chance Ordinance for Employers, the Los Angeles' Fair Chance Initiative for Hiring Ordinance, the San Francisco Fair Chance Ordinance, San Diego County Fair Chance Ordinance, and the California Fair Chance Act, where applicable, arrest or conviction records will be considered for Employment in accordance with these laws. At PwC, we recognize that conviction records may have a direct, adverse, and negative relationship to responsibilities such as accessing sensitive company or customer information, handling proprietary assets, or collaborating closely with team members. We evaluate these factors thoughtfully to establish a secure and trusted workplace for all.

The salary range for this position is: $84,000 - $202,000, plus individuals may be eligible for an annual discretionary bonus. For roles that are based in Maryland, this is the listed salary range for this position. Actual compensation within the range will be dependent upon the individual's skills, experience, qualifications and location, and applicable employment laws. PwC offers a wide range of benefits, including medical, dental, vision, 401k, holiday pay, vacation, personal and family sick leave, and more. To view our benefits at a glance, please visit the following link: https://pwc.to/benefits-at-a-glance