Software Security Engineer, Experienced or Senior (Virtual)
Boeing 4.6
Security engineer job at Boeing
Company:
The Boeing Company
The Boeing Company is currently seeking Software SecurityEngineer, (Experienced or Senior) (Virtual) to support our Open Source Program Office located in Orlando, Florida (Virtual). This position will focus on supporting the Products and Capabilities team.
The Open Source Program Office's mission is to champion open-source engagement across the enterprise and deliver a world class open-source management experience with flawless compliance. To fulfill that mission, we are looking for a Software SecurityEngineer to evaluate and mitigate security risks within the enterprise's use and contribution of open-source software, perform product security risk, vulnerability analyses, and security audits. The individual selected will also be automating security assessments and translating the Chief Engineer's strategic security analysis (risk assessments, policy definitions) into automated and integrated open-source security practices for the rest of the company.
This position has been identified as a virtual opportunity and will not require the selected candidate to relocate.
Position Responsibilities:
Operationalize the open-source policy and process through automation
Independently investigate, analyze, and resolve licensing issues, driving for business-based outcomes
Automate Software Composition Analysis (SCA) through a combination of COTS, open source, and in-house tooling. Conduct trade studies and work with Product Owners to meet requirements for a broad range of stakeholders
Manage the configuration and output of dependency scanners, triage critical open-source software vulnerabilities, and ensure timely remediation with development teams.
Translate approved legal/license policies into code-based checks and automated tooling to prevent incompatible license usage in new projects.
Engineer and maintain security and license scanning tools; enforce compliance by ensuring automated build failures upon policy violation.
Document all automated processes and serve as the technical liaison, transferring security analysis into scalable, repeatable engineering practices across the enterprise.
Collaborate with the Product Owner on the backlog and technical roadmap
Seek out additional automation opportunities
Track and improve KPIs
Basic Qualifications (Required Skills/ Experience):
1+ years' experience with software licensing and knowledge of issues with the use of third party and open-source software
2+ years' experience in the application of software cybersecurity principles and techniques
3+ years' experience in software development lifecycle
Ability to obtain a U.S. Security Clearance for which the U.S. Government requires U.S. Citizenship
Bachelor of Science degree from an accredited course of study in engineering, engineering technology (includes manufacturing engineering technology), chemistry, physics, mathematics, data science, or computer science
Preferred Qualifications (Desired Skills/Experience):
Ability to independently make and execute Software product level licensing decisions
Ability to interact effectively with Legal, Ethics, and Program Management
Previous experience performing license assessments and working licensing issues
Excellent communication skills, both verbal and written
Travel:
10%
Drug Free Workplace:
Boeing is a Drug Free Workplace (DFW) where post offer applicants and employees are subject to testing for marijuana, cocaine, opioids, amphetamines, PCP, and alcohol when criteria is met as outlined in our policies.
Pay & Benefits:
At Boeing, we strive to deliver a Total Rewards package that will attract, engage and retain the top talent. Elements of the Total Rewards package include competitive base pay and variable compensation opportunities.
The Boeing Company also provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and a number of programs that provide for both paid and unpaid time away from work.
The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, and the applicability of collective bargaining agreements.
Pay is based upon candidate experience and qualifications, as well as market and business considerations.
Summary pay range for Experienced Level: $94,350 - $146,050
Summary pay range for Senior Level: $114,750 - $178,250
Language Requirements:
Not Applicable
Education:
Bachelor's Degree or Equivalent
Relocation:
Relocation assistance is not a negotiable benefit for this position.
Export Control Requirement:
This position must meet export control compliance requirements. To meet export control compliance requirements, a “U.S. Person” as defined by 22 C.F.R. §120.15 is required. “U.S. Person” includes U.S. Citizen, lawful permanent resident, refugee, or asylee.
Safety Sensitive:
This is not a Safety Sensitive Position.
Security Clearance:
This position requires the ability to obtain a U.S. Security Clearance for which the U.S. Government requires U.S. Citizenship. An interim and/or final U.S. Secret Clearance Post-Start is required.
Visa Sponsorship:
Employer will not sponsor applicants for employment visa status.
Contingent Upon Award Program
This position is not contingent upon program award
Shift:
Shift 1 (United States of America)
Stay safe from recruitment fraud! The only way to apply for a position at Boeing is via our Careers website. Learn how to protect yourself from recruitment fraud - Recruitment Fraud Warning
Boeing is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national origin, gender, sexual orientation, gender identity, age, physical or mental disability, genetic factors, military/veteran status or other characteristics protected by law.
EEO is the law
Boeing EEO Policy
Request an Accommodation
Applicant Privacy
Boeing Participates in E - Verify
E-Verify (English)
E-Verify (Spanish)
Right to Work Statement
Right to Work (English)
Right to Work (Spanish)
$114.8k-178.3k yearly Auto-Apply 16d ago
Looking for a job?
Let Zippia find it for you.
Epic Cadence & Security Analyst
Onpoint Search Consultants 4.2
Los Angeles, CA jobs
What you will find ...
100% REMOTE
exceptional benefits (pension plan options)
top ranked hospital in the U.S.
What you will do ...
design & build Epic Cadence
build Epic Security
break-fix & support Epic Cadence & Security
optimize Decision Tree for scheduling
liaison with operational stakeholders
Wish list ...
5+ years Epic Cadence & Security build
REQUIRED Epic Cadence Certification
REQUIRED Epic Security Certification
recent Epic Security work
Decision Tree a plus
$80k-116k yearly est. 3d ago
Princ Industrial Security Analyst/Sr. Principal Industrial Security Analyst
Northrop Grumman 4.7
Jessup, MD jobs
At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work - and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history.
Northrop Grumman is looking for a CSSO. The candidate must have relevant experience in industrial security programs. Strong working knowledge of Intelligence Community Directives (ICD) and the National Industrial Security Program (NISP). Candidate must have strong interpersonal skills to be able to communicate effectively and able to manage multiple tasks simultaneously, make decisions in the midst of ambiguity and meet deadlines. The successful candidate must be a self-starter that needs minimal supervision. Some travel may be required. Develops, and administers security programs and procedures for classified or proprietary materials, documents, and equipment. Studies and implements federal security regulations that apply to company operations. Obtains rulings, interpretations, and acceptable deviations for compliance with regulations from government agencies. Prepares manuals outlining regulations, and establishes procedures for handling, storing, and keeping records, and for granting personnel and visitors access to restricted records and materials. Conducts security education classes and security audits. Investigates security violations and prepares reports specifying preventive action to be taken.
This position can be filled at either a level 3 or level 4.
Basic Qualifications level 3:
Active TS/SCI Poly clearance.
5+ years A/CSSO or related experience with Bachelors; or 3+ years A/CSSO or related with Masters: an additional 4 years of applicable work experience may be substituted for a Bachelor's degree.
Basic Qualifications level 4:
Active TS/SCI Poly clearance.
8+ years A/CSSO or related experience with Bachelors; or 6+ years A/CSSO or related with Masters: an additional 4 years of applicable work experience may be substituted for a Bachelor's degree.
Preferred Qualifications:
Strongly preferred SCIF Management Experience.
Experience implementing multiple security disciplines to include Personnel, Physical, Communications and Operations Security programs and requirements.
Strong interpersonal skills to communicate effectively, ability to manage multiple tasks simultaneously, make decisions in the midst of ambiguity and meet deadlines.
Strong leadership skills to include: Self-starter with minimal supervision, high ethical standards.
Ability to display tact, discretion and diplomacy in dealing with all levels of employees.
Must be organized and efficient at time management.
Strong working knowledge of Intelligence Community Directives (ICD), Department of Defense (DoD) security requirements and National Industrial Security Programs (NISP).
Demonstrated, relevant experience in industrial security programs within the Intelligence Community.
Familiarity with ICD 705.
Primary Level Salary Range: $91,200.00 - $136,800.00Secondary Level Salary Range: $113,500.00 - $170,300.00The above salary range represents a general guideline; however, Northrop Grumman considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills and current market conditions.Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. Annual bonuses are designed to reward individual contributions as well as allow employees to share in company results. Employees in Vice President or Director positions may be eligible for Long Term Incentives. In addition, Northrop Grumman provides a variety of benefits including health insurance coverage, life and disability insurance, savings plan, Company paid holidays and paid time off (PTO) for vacation and/or personal business.The application period for the job is estimated to be 20 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates.Northrop Grumman is an Equal Opportunity Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. For our complete EEO and pay transparency statement, please visit *********************************** U.S. Citizenship is required for all positions with a government clearance and certain other restricted positions.
$113.5k-170.3k yearly 1d ago
Information Security Analyst
Belcan 4.6
Mason, OH jobs
Job Title: Information Security Analyst
Zip Code: 45040
Duration: 6 months
Pay Rate: $33.33/hr.
Keyword's: #Masonjobs; #InformationSecurityAnalystjobs;
The IS Application Security Analyst will support the execution, planning, and administration of the Vulnerability Management function within Information Security (IS). The Vulnerability Management Analyst executes core processes in the vulnerability management program focused on vulnerability assessments, penetration testing and social engineering. Additionally, they will support the remediation of vulnerabilities resident within systems to minimize the organizations" potential attack surface for exploitation.
The Analyst will provide oversight, drive, facilitate and coordinate the management of vulnerabilities across the enterprise. The Analyst must understand underlying application code approaches in order to effectively review and respond to application security scans. While technical involvement is required, this role is not intended to perform direct remediation. The Analyst will support automated scans and may provide post-development testing assistance to validate that vulnerability remediation efforts are appropriately tested.
MAJOR DUTIES AND RESPONSIBILITIES
* Monitor and analyze vulnerability assessment data to identify and communicate technical risks to the organization
* Support the identification and impact classification for new vulnerabilities identified in the environment
* Execute and support vulnerability assessments, penetration testing and social engineering activities
* Provide the Information Security and IT Security team information on the emerging cyber threat landscape, including threat actor tactics, techniques, and procedures
* Review and interpret application security scan results with an understanding of underlying code structures to provide effective feedback
* Provide post-development testing support to ensure vulnerability remediation items are validated and tested appropriately
* Facilitate vulnerability management processes by tracking and coordinating remediation efforts across multiple teams
* Ensure timely closure of security gaps by working with application, infrastructure, and operations teams
* Support IS in achieving the vision and strategic objectives of the vulnerability program
* Conduct analysis, aggregate and report on vulnerability data from various scanning tools and platforms
* Manage and utilize IS tools such as DLP, Code scanner, external security profile, etc. to analyze gaps in security controls
* Participate in the IT SDLC program to ensure that security is included in project by default and by design
* Develop strong working relationships with other departments and potentially clients across the organization to ensure a high degree of security compliance client satisfaction
* Assist with regulatory and compliance requirements, contributing to security audits, assessments, attestations, certifications and client vulnerability inquires
* Brief IS leadership on vulnerability assessment results and potential risks
* Support leadership to identify capability gaps in vulnerability management services
* Collaborate with cross-functional teams to improve security posture and embed security into existing IT and operational workflows
* Continue self-development of knowledge, skills and abilities to better support execution of the Information Security (IS) function
BASIC QUALIFICATIONS
* Bachelor"s degree computer science, IT or equivalent
* 3+ years of experience in IT or IS or Compliance
* Experience with major standards such as: SOC 1-2, ISO 27001/2, PCI DSS, HITRUST, SANS, NIST
* Demonstrated experience in implementing compliance frameworks for financial services organization or organizations with similar information security needs and requirements
* Familiarity and understanding of broad range of IT hardware and software products
* Strong project management skills
* Excellent presentation, verbal communication, and written skills
* Excellent analytical and problem-solving skills
* Experience managing typical enterprise security and intrusion detection systems
* Ability to work in a collaborative environment across business and technology teams
* Ability to interpret application structures and code approaches at a high level in order to review and respond to scan results
PREFERRED QUALIFICATIONS
* Certified Information Systems Security Profession (CISSP), PCI DSS, Certified HIPAA Privacy Security Expert (CHPSE), Certified Information Security manager (CISM), Global Information Assurance Certification (GIAC), or related.
* Experience or knowledge with healthcare or health insurance
* Knowledge of CMS and HIPAA related vendor requirements
* Working knowledge of Security SDLC tools
Belcan is an equal opportunity employer. Your application and candidacy will not be considered based on race, colour, sex, religion, creed, sexual orientation, gender identity, national origin, disability, genetic information, pregnancy, veteran status or any other characteristic protected by federal, state or local laws.
$33.3 hourly 2d ago
Computer Network Defense Analyst
Verite Group, Inc. 4.1
Anchorage, AK jobs
Prime Time Consulting, a GRVTY Company, provides clients with expert intelligence analysis services. Our clients include defense contractors, industrial and service corporations, and departments and agencies of the U.S. Federal Government. Computer Network Defense Analyst We are actively searching for Computer Network Defense Analysts (CNDAs), located in Alaska, to support our team. We have varying levels of CNDAs, depending on years of experience and education.
Duties
* Conduct computer network defense.
* Conduct target development for use or decision by Government personnel.
* Analyze and produce intelligence information.
* Conduct computer/network security to provide advice to the Government.
* Create and maintain documentation of their analysis.
* Ensure to routinely follow oversight and compliance
* Acquire/share job knowledge/skill
* Partner with team members on the contract, including government personnel and other partner companies
Qualifications
* Degree in Computer Science or equivalent technical field
* Level 1 - 6 years of experience can replace 2 years of experience with AA degree
* Level 2 - 9 years of experience can replace 4 years of experience with BS degree
* Level 3 - 12 years of experience can replace up to 6 years of experience with MS degree
* Level 4 - 15 years of experience can replace up to 9 years with Doctorate degree
* Strong communication skills
* Works well in a team and alone
* Working knowledge of Microsoft Office Suite
Company Perks
* At PTC, a GRVTY Company, we believe that when our employees thrive, our company thrives. That's why we offer a comprehensive and competitive benefits package designed to support your well-being, growth, and work-life balance.
* Robust health plan including medical, dental, and vision
* Health Savings Account with company contribution
* Annual Paid Time Off and Paid Holidays
* Paid Parental Leave
* 401k with generous company match
* Training and Development Opportunities
* Award Programs
* Variety of Company Sponsored Events
Prime Time Consulting, a GRVTY Company, is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran and will not be discriminated against on the basis of disability. Anyone requiring reasonable accommodations should email ******************************* with requested details. A member of the HR team will respond to your request within 2 business days. Please review our current job openings and apply for the positions you believe may be a fit. If you are not an immediate fit, we will also keep your resume in our database for future opportunities.
$78k-93k yearly est. 5d ago
OT Security Cyber Prevention Engineer
Honda 4.8
Marysville, OH jobs
What Makes a Honda, is Who makes a Honda Honda has a clear vision for the future, and it's a joyful one. We are looking for individuals with the skills, courage, persistence, and dreams that will help us reach our future-focused goals. At our core is innovation. Honda is constantly innovating and developing solutions to drive our business with record success. We strive to be a company that serves as a source of "power" that supports people around the world who are trying to do things based on their own initiative and that helps people expand their own potential. To this end, Honda strives to realize "the joy and freedom of mobility" by developing new technologies and an innovative approach to achieve a "zero environmental footprint."
We are looking for qualified individuals with diverse backgrounds, experiences, continuous improvement values, and a strong work ethic to join our team.
If your goals and values align with Honda's, we want you to join our team to Bring the Future!
The Honda Development and Manufacturing Production Engineering team is responsible for the operational technology
security of the manufacturing environment. The OT Security Cyber Prevention Engineer works across multiple technical
and business areas to develop, implement, and maintain procedures, standards, and controls to prevent the risk or
impact of a cyber incident. The scope of this function covers manufacturing equipment hardware/firmware/ software, OT
enterprise systems, data analysis and reporting, and collaboration with IT/business users to ensure secure operation
across all HDMA locations and equipment.
New equipment introduction - set OT standards for new equipment, integrate equipment into the OT
network, confirm vulnerabilities, perform risk assessments, and visibility of equipment within the asset
management system.
Training - support the creation, administration and maintenance of OT specific training material.
Policies/procedures/auditing - create, issue, maintain, and audit OT specific policies and procedures.
Access control (physical + logical) - set and implement technical standards for equipment level physical
access and control access to OT related systems and equipment.
OT standard creation - support the development, implementation, and maintenance of technical
standards for the OT equipment and networks
Risk metric management/assessments - establish company OT risk metrics and corresponding
assessments to determine OT risk, perform risk assessments, and establish tools for visibility and
reporting.
Sensing/industry benchmarking - research technical and business OT security industry benchmarks and
generate recommendations for adjustments to internal tools or practices to stay in alignment.
What differentiates Honda and makes us an employer of choice?
Total Rewards:
* Competitive Base Salary (pay will be based on several variables that include, but not limited to geographic location, work experience, etc.)
* Regional Bonus (when applicable)
* Manager Lease Car Program (No Cost - Car, Maintenance, and Insurance included)
* Industry-leading Benefit Plans (Medical, Dental, Vision, Rx)
* Paid time off, including vacation, holidays, shutdown
* Company Paid Short-Term and Long-Term Disability
* 401K Plan with company match + additional contribution
* Relocation assistance (if eligible)
Career Growth:
* Advancement Opportunities
* Career Mobility
* Education Reimbursement for Continued learning
* Training and Development Programs
Additional Offerings:
* Lifestyle Account
* Childcare Reimbursement Account
* Elder Care Support
* Tuition Assistance & Student Loan Repayment
* Wellbeing Program
* Community Service and Engagement Programs
* Product Programs
Honda is an equal opportunity employer and considers qualified applicants for employment without regard to race, color, creed, religion, national origin, sex, sexual orientation, gender identity and expression, age, disability, veteran status, or any other protected factor.
$87k-116k yearly est. 50d ago
Computer Network Defense Analyst
Verite Group, Inc. 4.1
Bluffdale, UT jobs
Prime Time Consulting, a GRVTY Company, provides clients with expert intelligence analysis services. Our clients include defense contractors, industrial and service corporations, and departments and agencies of the U.S. Federal Government. Computer Network Defense Analyst We are actively searching for Computer Network Defense Analysts (CNDAs), located in Utah, to support our team. We have varying levels of CNDAs, depending on years of experience and education.
Job Duties
* Conduct computer network defense.
* Conduct target development for use or decision by Government personnel.
* Analyze and produce intelligence information.
* Conduct computer/network security to provide advice to the Government.
* Create and maintain documentation of their analysis.
* Ensure to routinely follow oversight and compliance
* Acquire/share job knowledge/skill
* Partner with team members on the contract, including government personnel and other partner companies
Qualifications
* Degree in Computer Science or equivalent technical field
* Level 1 - 6 years of experience can replace 2 years of experience with AA degree
* Level 2 - 9 years of experience can replace 4 years of experience with BS degree
* Level 3 - 12 years of experience can replace up to 6 years of experience with MS degree
* Level 4 - 15 years of experience can replace up to 9 years with Doctorate degree
* Strong communication skills
* Works well in a team and alone
* Working knowledge of Microsoft Office Suite
Company Perks
* At PTC, a GRVTY Company, we believe that when our employees thrive, our company thrives. That's why we offer a comprehensive and competitive benefits package designed to support your well-being, growth, and work-life balance.
* Robust health plan including medical, dental, and vision
* Health Savings Account with company contribution
* Annual Paid Time Off and Paid Holidays
* Paid Parental Leave
* 401k with generous company match
* Training and Development Opportunities
* Award Programs
* Variety of Company Sponsored Events
Prime Time Consulting, a GRVTY Company, is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran and will not be discriminated against on the basis of disability. Anyone requiring reasonable accommodations should email ******************************* with requested details. A member of the HR team will respond to your request within 2 business days. Please review our current job openings and apply for the positions you believe may be a fit. If you are not an immediate fit, we will also keep your resume in our database for future opportunities.
$77k-106k yearly est. 5d ago
Cyber Security Engineer
Comtec Solutions 3.8
Rochester, NY jobs
CYBERSECURITY ENGINEER
Department: IT Services Group Billable Hours Goal: 80% of worked hours
Position Type: Full Time Travel Required: Minimal travel
The Cybersecurity Engineer will serve as a subject matter expert in many areas of security, needs to be able to describe and document in business terms the impact of security policies, standards, and architecture. This person plays a vital dual role in our organization, with time being spent facilitating our Cybersecurity offering as well as focusing on CMMC Compliance. The Cybersecurity Engineer provides security direction to the business and project stakeholders to ensure that security is a key focus for all projects and new business initiatives, as well as technical expertise on assigned clients, tickets, and CMMC Compliance projects.
REPORTS TO: Director, IT Services
DIRECT REPORTS: None
ESSENTIAL FUNCTIONS:
Project engagement during the initiation, requirements, and design stages to ensure that security has been considered and is included into the design at the appropriate level based on the risks
Security review and design of complex applications and technologies
Evaluation and maintenance of security system plans and procedures to safeguard internal information systems
Researching and recommendation/implementation of changes to procedures and systems to enhance security aligned with corporate policies
Accountable for ensuring that key risks and issues are identified, addressed and resolved in a manner that satisfies the business
Perform security risk assessments to determine level of security services to include:
Document Customers Systems
Liaison between ComTec and Cybersecurity Vendors
Weekly review and analysis of Cybersecurity Reports
ADDITIONAL RESPONSIBILITIES:
Monitor assigned tickets and tasks and provide service or escalation as necessary.
Develop tasks & milestones for security projects.
Able to translate business and non-functional requirements to establish security controls so that a proper security design can be architected and to document the security solution for communication and publication.
Demonstrated analytical skills continuously identifies problems, collect or interpret data, establish facts, anticipate obstacles, and develops plans to resolve; strong problem-solving skills while communicating in a clear and succinct manner effectively evaluating information and data to make decisions.
Proven understanding of the current vulnerabilities, response, and mitigation strategies used in Cybersecurity.
Experience of designing and incorporating technical security controls that align to NIST 800-171, and/or CMMC.
Prepared to challenge business and IT colleagues and have the difficult conversations where needed in the interests of the company.
Demonstrated customer focus evaluate decisions through the eyes of the customer; build strong customer relationships and create processes from the customer viewpoint.
Able to operate as a highly independent worker and as part of a strong team/collaborative approach.
Accurately enter and maintain ticket information including notes and resolution.
Adhere to departmental policies for reporting and managing requests and change controls.
Maintain daily timesheet and expense report entries and submit them accurately and timely.
Other duties as required.
Requirements:
Work Environment/Physical Demands:
Use of computer and office equipment.
Ability to remain calm in stressful situations
Performs all administrative functions expected at this level.
Minimum Qualifications:
TECHNICAL SKILLS:
Strong background in security architecture including a deep knowledge of IT network security (secure LAN, WAN, vLAN, MPLS, and secure network zoning and restricted network design) and cloud-based technologies.
Strong background in Network Engineering including a deep understanding of Windows Server architecture, Windows Virtualization, Networking, Backup Solutions, and Disaster Recovery
Strong background in Microsoft security architecture including a deep knowledge of server and workstation security.
Ability to troubleshoot server-based software issues with:
Microsoft Windows Server operating systems
On Premise Microsoft Exchange and hosted Microsoft Office 365
Microsoft Remote Desktop Services
Microsoft Hyper-V and VMWare
Enterprise EDR and MDR solutions
Enterprise class backup solutions
Knowledgeable of various server/workstation peripherals such as NAS/SAN solutions.
In depth knowledge of workstation/server hardware and software troubleshooting abilities
Strong understanding of networking equipment such as Switches, Firewalls, and Wireless Access Points
SOFT SKILLS & ABILITIES:
Strong written and verbal communication skills.
Pleasant and professional demeanor in all client and internal communications.
Ability to multitask.
Independent worker and able to work effectively on daily tasks without direct supervision.
Strong organization skills and ability to operate efficiently throughout daily tasks.
Work well with clients at all levels, from executive to IT to end user
EDUCATION, EXPERIENCE, & KNOWLEDGE:
(5) years working in Information Technology
(2) years in Cybersecurity
(1) year in CMMC compliance
Information Security Qualifications such as CISSP, CISM, CISA, and ISSAP, a plus.
Certified CMMC Professional (CCP)
Familiarity with NIST SP 800-171
Additional Requirements
Ability to schedule for evening or weekend work occasionally
Valid drivers license in your state of residence and reliable personal vehicle
Remote option negotiable based on location
Compensation details: 100000-130000 Yearly Salary
PI1554ad083211-31181-38837574
$80k-110k yearly est. 8d ago
Cyber Security SME
Precision Solutions 4.1
Sterling, VA jobs
Overview Cyber Security SME
Hybrid | 2-3 days on-site in Washington D.C.
Current TS/SCI required
The Cyber Security Subject Matter Expert (SME) will play a key role in ensuring the security and compliance of enterprise production applications within a cloud-based environment. The SME will work closely with the Development, Cloud, and DevSecOps teams, as well as the Information System Security Officer (ISSO), Information System Security Manager (ISSM), and Security Control Assessor (SCA), to support the full lifecycle of system authorization activities-including achieving and maintaining Authority to Operate (ATO) or Authority to Connect (ATC). The ideal candidate will provide expert guidance on cybersecurity architecture, coordinate CONOPS and design reviews, drive remediation of security findings, and develop cybersecurity standards and frameworks across the program-rooted in Zero Trust principles.
Responsibilities
ATO/ATC Support:
Lead and coordinate efforts to obtain and maintain ATO/ATC for production systems, ensuring compliance with applicable security frameworks.
Collaboration Across Teams:
Partner with Development, Cloud, and DevSecOps teams to integrate security throughout the SDLC and CI/CD pipelines, ensuring secure-by-design implementations.
Architecture & CONOPS Coordination:
Review and contribute to system architectures, data flows, and Concept of Operations (CONOPS) documents to ensure alignment with Zero Trust principles and organizational security policies.
Security Findings Management:
Support and track the remediation of vulnerabilities and deficiencies identified through scans, assessments, and audits; create and manage Plans of Action & Milestones (POA&Ms) as required.
Cybersecurity Standards Development:
Develop and maintain enterprise cybersecurity standards, guidelines, and best practices to ensure consistent implementation of security controls across all program systems.
Continuous Monitoring:
Support ongoing assessment and authorization (A&A) activities, including risk assessments, configuration management, and continuous monitoring reporting.
Zero Trust Implementation:
Guide teams in applying Zero Trust Architecture (ZTA) principles-identity-centric access control, micro-segmentation, least privilege, and continuous validation-to all system designs and processes.
Requirements
5+ years of progressive experience in cybersecurity, with at least 3 years supporting federal ATO/ATC processes.
In-depth knowledge of NIST RMF, FedRAMP, and Zero Trust Architecture frameworks.
Experience collaborating with ISSOs, ISSMs, SCAs, and engineering teams.
Familiarity with AWS cloud environments and DevSecOps pipelines.
Strong technical understanding of network security, IAM, encryption, and vulnerability management.
Excellent communication and coordination skills.
Preferred Qualifications
CISSP, CISM, CAP, or equivalent cybersecurity certification.
Experience with containerized applications, infrastructure as code (IaC), and continuous compliance tools.
Clearance Requirements
Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; Must have a current TS/SCI
Education/Certification Requirements
A Bachelor's degree in Computer Science, Information Systems, or a related field is required for this position
Other DutiesPlease note that this job description is not intended to be a comprehensive listing of all activities, duties, or responsibilities required of the employee in this role. Duties, obligations, and activities are subject to change at any time, with or without notice.
$75k-104k yearly est. Auto-Apply 44d ago
Anti Tamper System Security Analyst
Mag Aerospace 4.1
Lexington Park, MD jobs
At MAG, we provide and enable real-time situational awareness to help our customers make the world smaller and safer. We are laser focused on serving our customers by providing technical expertise, operational excellence, and flawless execution. Relentlessly driven by our dedication to service and performance, we have become the leading independent provider of manned/unmanned full-spectrum outsourced ISR services in the world. Our success is due entirely to the high caliber of employees we recruit, hire, and retain. At MAG, we look for individuals who thrive in a high-performance environment where challenges are the norm and success are expected.
MAG Aerospace is seeking a resourceful Anti Tamper System Security Analyst professional to implement and maintain security measures to protect systems from tampering and unauthorized access.
***Must be a US Citizen***
Must hold a current Top Secret with SSBI and SCI eligible
Essential Duties and Responsibilities
Conducting security assessments: Regularly evaluating the security posture of systems to identify vulnerabilities and potential threats.
Implementing security protocols: Developing and enforcing security policies, including firewalls, intrusion detection systems, and access controls.
Monitoring system integrity: Keeping track of system activities and responding to any suspicious or unauthorized access attempts.
Training and educating: Educating users and staff on best practices for data security and conducting regular training sessions.
Reporting and analysis: Preparing detailed reports on security incidents, including resolution steps and preventive measures.
Collaboration: Working with IT teams and other security professionals to secure network architecture and endpoint devices.
Requirements
Active TOP SECRET w/SSBI (within 5 years) required. SCI eligibility required.
Experience:
At least 10 years combined experience in testing and/or technical program management / management support and systems engineering and integration in major defense acquisition programs relating to aircraft / weapon system acquisition and development.
At least 5 yrs experience in technical program management and/or system development team leadership position.
Possess general knowledge and demonstrated proficiency in the following areas:
Experience with weapons system development desired.
Programmatic acquisition experience desired.
Demonstrated understanding of DoD (or appropriate policies and directives) acquisition policy and directives.
Knowledge and experience working with the Anti-Tamper Executive Agent and their processes is highly desired.
Education:
Bachelors degree in IT related field or have 3 years of additional applied work experience
Clearance:
Active TOP SECRET clearance with SSBI upgrade
Possess eligibility for access to be upgraded to a SCI in the NEAR future upon hire - (ALL HIRES WILL MAINTAIN AN SCI - MAG Will Upgrade your TS to TS/SCI - IF YOU POSSES THE BACKGROUND TO BE UPGRADED)
Personnel who are enrolled in CE will also be eligible
#LI-VF1
Special Note
The position is contingent upon candidate's ability to meet physical and medical requirements as needed by the position; including compliance with all applicable federal, state, and local jurisdictional requirements.
Benefits and Compensation At MAG Aerospace, we value your contributions providing our employees with a robust Total Rewards package that supports your total well-being. Full-time and part-time employees working at least 30 hours a week on a regular basis are eligible to participate in MAG's Total Rewards programs. Our offerings include health, life, disability, financial, and retirement benefits as well as paid leave, professional development, and tuition assistance. Individuals that do not meet the threshold are only eligible for select offerings not inclusive of health benefits. We encourage you to learn more about our Total Rewards Program by visiting the Resource page on our Careers site: ********************************** Salary at MAG Aerospace is determined by various factors including but not limited to location, the particular combination of education, knowledge, skills, competencies, and experience as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $80500 to $149500 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of MAG's total compensation package for employees. We can recommend jobs specifically for you! Click here to get started.
$80.5k-149.5k yearly Auto-Apply 3d ago
Analyst, Information Security
Standard Aero 4.1
San Antonio, TX jobs
Build an Aviation Career You're Proud Of At StandardAero, we use our ingenuity and know-how to find solutions for the simple to the most complex challenges in aviation. Together, we get the job done and done well. Our stability, resources, and respectful culture supports you in building a solid career with a great team you can count on day in and day out for the long term.
Summary:
As an IT Security Analyst position is a critical role in protecting StandardAero's business and technology operations. In this role you will be accountable in securing the enterprise technology and operations against an ever evolving and growing threat landscape. The role is an integral position in supporting StandardAero's global cyber-security defenses, providing tactical cyber security objectives and implementing the security strategy across the organization.
What you'll do:
* Conduct risk and security assessments through vulnerability analysis and reporting
* Perform mitigation support for both internal and external security audits
* Investigate, analyze and document security incidents to identify and document the root cause
* Provides incident response support including mitigating actions to contain activity and facilitating forensics analysis when necessary
* Partner with IT Operation teams to remediate system vulnerabilities
* Participates in the production of documentation and management reporting
* Research security enhancements and make recommendations for improved policy and process
* Analyze IT requirements and provide objective advice on the use of new IT security offerings
* Stay up-to-date on information technology and cybersecurity trends and standards
* Other IT Security-related duties as required
* Capable of identifying, evaluating and mitigating significant risks within an enterprise.
* Strong working experience with Microsoft Office Suite.
* Strong oral and written communication skills and the ability to work well with people from many different disciplines with varying degrees of technical experience.
* Possess strong analytical skills attention to detail.
* Ability to prioritize assignments while working on multiple projects
* Ability to work independently and proactively to meet assigned objectives
* Flexible with the ability to multi-task, effectively prioritize and work under pressure
* Basic project management
* Design, implement, administer, support and maintain cybersecurity technology systems (Endpoint Protection, IDS/IPS, Web and Email Security, SIEM, Multi-Factor Authentication, Network Access Controls, DLP, etc.)
* Analyze, report and respond to security alerts within the various IT technologies and global locations
* Proactively remediate information technology security threats as a member of the security team
* Assist in the designing, documenting, architecting and implementing IT security measures and controls
* Provide support through 'Threat Hunting' against anomalous behavior within the enterprise. Correlates activity across assets (endpoint, network, apps) and environments to identify patterns of anomalous activity
* Conducts log-based and endpoint-based threat detection to detect and protect against threats coming from multiple sources
* Threat mitigation; malicious code detection, response and prevention; operating system security oversight
Minimum Qualifications:
* Bachelor's degree in Information Security, Computer Science, or a related field; equivalent experience may be considered.
* 5+ years of progressive experience in cybersecurity and IT, including hands-on security operations, threat detection, or engineering.
* 5+ years of experience in SIEM Administration, endpoint protection, vulnerability management tools, and security automation.
* 5+ years of experience of network and application security, threat actor tactics (MITRE ATT&CK), and incident response frameworks.
* 5+ years of experience working in regulated environments or with industry frameworks (e.g., NIST, ISO 27001, CIS, or CMMC).
Preferred Qualifications:
* IT Security Certification, specifically GSEC, CEH, CISSO, CISA or CISSP, GCIA, OSCP and ITIL
* SDLC, and understand application security.
* Containerization and Development Security Operations
Benefits that make life better:
* Comprehensive Healthcare
* 401(k) with 100% company match; up to 5% vested
* Paid Time Off starting on day one
* Bonus opportunities
* Health- & Dependent Care Flexible Spending Accounts
* Short- & Long-Term Disability
* Life & AD&D Insurance
* Learning & Training opportunities
Raising the Standard of Excellence since 1911
With over a century of proven excellence, StandardAero has become an industry leader in MRO services and customized solutions in the aerospace field. Our shared values and learning-based culture inspire our team to exceed their potential and power our customers' missions worldwide. With on-the-job training, advancement opportunities, and excellent benefits, StandardAero invites you to experience a fulfilling and meaningful career with us.
Inclusivity Is Our Standard
It is StandardAero's policy to provide equal employment opportunities to all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information. Our supportive environment celebrates diversity with no room for harassment or discrimination of any kind. We invite you to bring your authentic self to our team and experience our welcoming culture.
$80k-116k yearly est. Auto-Apply 60d+ ago
Computer Systems Security Analyst (Splunk)
Cybercore Technologies 4.2
Baltimore, MD jobs
JOIN THE CYBERCORE TECHNOLOGIES TEAM
.
We are Growing! Bring your Technical Capabilities, Enthusiasm, and Team Focus.
Seeking Candidates for a New Computer Systems Security Analyst (Splunk)
US Citizenship or Permanent Residency (Green Card holder) required.
Job Description:
•Write complex SPL to develop advanced Splunk dashboards and queries.
•Work with customers to develop custom content, maintaining consistently high-quality communications.
•Develop processes and schedule to review existing methodologies and queries for all divisional metrics.
•Become knowledgeable on the CDM technical requirements for the CDM Program.
•Understand role in CDM activities.
•Involved in a wide range of security issues including architectures, firewalls, electronic data traffic, and network access.
•Design, manage and maintain SIEM infrastructure to improve data ingestion processes, including architectural work on data pipelines to ensure optimal flow of data.
Maintenance, configuration and implementing products, appliances and devices on the network.
Required Candidate Qualifications:
United States Citizenship or Permanent Residency Required due to Clearance /Security /Government Needs.
Bachelor's degree and 7 years of related experience, Master's degree and 5 years of related experience, or 11 years of experience in lieu of degree.
At least 6 years' experience using Splunk, specifically Splunk scripting and on-boarding of large collection of meta data from different sources into Splunk
A minimum of 4 years of experience with:
In-depth knowledge of designing, upgrading, maintaining and implementing network devices on a large-scale enterprise.
Coordination and communication with other remotely deployed team members.
Developing documentation with processes and procedures.
Proposing, implementing automation features in a large enterprise environment.
Hold Active Splunk Core Certifications of User, Power User and Admin
Minimum of 3 year of experience in developing and tailoring reporting from network security tools.
Must be able to obtain and maintain US Public Trust Clearance.
.
At CyberCore, Our Goal is to Maintain a Healthy Work-Life Balance and Provide Interesting Work Supporting Our Nation's Security. For more information on CyberCore Technologies, go to
*********************
CyberCore Technologies is proud to be an Equal Opportunity Employer.
CyberCore has, on many occasions, expressed support and commitment to the principles of diversity and equal employment opportunity. It is CyberCore's policy to recruit, hire, train, and promote individuals, as well as administer all personnel actions, without regard to race, color, national or ethnic origin, age, religion, disability, sex, sexual orientation, gender identity and expression, veteran status or any other characteristic protected under applicable federal or state law. CyberCore will not tolerate unlawful discrimination and any such conduct is prohibited. CyberCore is committed to ensuring that CyberCore's workforce and volunteers reflect America's diverse population. CyberCore knows that such diversity will enrich the company with the talent, energy, perspective and inspiration we need to achieve our mission.
$82k-117k yearly est. Auto-Apply 60d+ ago
Computer Systems Security Analyst - Splunk
Cybercore Technologies 4.2
Baltimore, MD jobs
Write complex SPL to develop Advanced Splunk Dashboards and Queries.
Perform on-boarding of data via Splunk Tools and Automation method.
Work with customers to develop custom content, maintaining consistently high quality communications with the Client.
Create Splunk Dashboards and Queries
Familiar with automating in Splunk
Develop scripts and code with security tools.
Develop processes and schedule to review existing methodologies and queries for all divisional metrics.
Become knowledgeable on the CDM technical requirements for the CDM program.
Involved in a wide range of security issues including architectures, firewalls, electronic data traffic, and network access.
Design, manage, and maintain agency SIEM infrastructure to improve data ingestion processes, including architectural work on data pipelines to ensure optimal flow of data.
Maintenance, configuration, and implementing products, appliances and devices on the network.
Required Candidate Qualifications:
US Citizenship Required and ability to obtain and maintain a Public Trust
Bachelors Degree and 7 experience; or Masters Degree and 5 years of relevant Cyber Security experience; or 11 years experience in lieu of Degree.
Active Splunk Core Certifications of User, Power User and Admin
Minimum 3 years of experience developing and tailoring reporting from network security tools.
At least 6 years experience using Splunk (specifically Splunk Scripting and on-boarding of large collection of meta data from different sources into Splunk.
At least 4 years of experience with:
In depth knowledge of designing, upgrading, maintaining, and implementing network devices on a large scale enterprise.
Coordination and communication with other remotely deployed team members
Developing documentation with processes and procedures.
Proposing, implementing automation features in a large enterprise environment.
At least 2 years experience with:
Splunk Enterprise Security product.
Risk-based Alerting.
Analytics Driven Security
CyberCore has, on many occasions, expressed support and commitment to the principles of diversity and equal employment opportunity. It is CyberCore's policy to recruit, hire, train, and promote individuals, as well as administer all personnel actions, without regard to race, color, national or ethnic origin, age, religion, disability, sex, sexual orientation, gender identity and expression, veteran status or any other characteristic protected under applicable federal or state law. CyberCore will not tolerate unlawful discrimination and any such conduct is prohibited. CyberCore is committed to ensuring that CyberCore's workforce and volunteers reflect America's diverse population. CyberCore knows that such diversity will enrich the company with the talent, energy, perspective and inspiration we need to achieve our mission.
$82k-117k yearly est. Auto-Apply 60d+ ago
Computer Network Defense Analyst
Verite Group, Inc. 4.1
Dayton, OH jobs
Prime Time Consulting, a GRVTY Company, provides clients with expert intelligence analysis services. Our clients include defense contractors, industrial and service corporations, and departments and agencies of the U.S. Federal Government. Computer Network Defense Analyst We are actively searching for Computer Network Defense Analysts (CNDAs), located in Ohio, to support our team. We have varying levels of CNDAs, depending on years of experience and education.
Duties
* Conduct computer network defense.
* Conduct target development for use or decision by Government personnel.
* Analyze and produce intelligence information.
* Conduct computer/network security to provide advice to the Government.
* Create and maintain documentation of their analysis.
* Ensure to routinely follow oversight and compliance
* Acquire/share job knowledge/skill
* Partner with team members on the contract, including government personnel and other partner companies
Qualifications
* Degree in Computer Science or equivalent technical field
* Level 1 - 6 years of experience can replace 2 years of experience with AA degree
* Level 2 - 9 years of experience can replace 4 years of experience with BS degree
* Level 3 - 12 years of experience can replace up to 6 years of experience with MS degree
* Level 4 - 15 years of experience can replace up to 9 years with Doctorate degree
* Strong communication skills
* Works well in a team and alone
* Working knowledge of Microsoft Office Suite
Company Perks
* At PTC, a GRVTY Company, we believe that when our employees thrive, our company thrives. That's why we offer a comprehensive and competitive benefits package designed to support your well-being, growth, and work-life balance.
* Robust health plan including medical, dental, and vision
* Health Savings Account with company contribution
* Annual Paid Time Off and Paid Holidays
* Paid Parental Leave
* 401k with generous company match
* Training and Development Opportunities
* Award Programs
* Variety of Company Sponsored Events
Prime Time Consulting, a GRVTY Company, is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran and will not be discriminated against on the basis of disability. Anyone requiring reasonable accommodations should email ******************************* with requested details. A member of the HR team will respond to your request within 2 business days. Please review our current job openings and apply for the positions you believe may be a fit. If you are not an immediate fit, we will also keep your resume in our database for future opportunities.
$58k-81k yearly est. 5d ago
Information Security Specialist
Connecticut, Inc. 4.1
Wallingford, CT jobs
Community Health Network of Connecticut, Inc. (CHNCT) is currently seeking an Information Security Specialist. This is a full-time, hybrid position requiring 2 days per week onsite in our Wallingford, CT office.
Primary Responsibilities:
Under the direction of the Director of Information Security, the Information Security Specialist is responsible for operations, auditing, and technical monitoring of CHNCT's Information Security and related activities.
These activities include but are not limited to implementing and maintaining Information Security related systems, policies and processes in compliance with applicable security regulations (i.e., HIPAA and State of CT Security laws), and establishing and developing security-related operating procedures and standards.
Works directly with contracted vendors for the implementation and maintenance of security hardware, software and services.
Assists with the selection and evaluation of security related state-of-the-art systems.
Tasks Performed:
Monitors and maintains all aspects of the information security program.
As a COMPUTER SECURITY INCIDENT RESPONSE TEAMS (CSIRT) member, logs and responds to incidents including communication of potential violations of the company's information security policies to CHNCT's Chief Information Security Officer.
Independently acts to prevent or deter security breaches or intrusions that threaten the integrity of mission critical data or applications.
Monitors email and Data Loss Prevention logs and responds to potential policy or regulatory violations.
Monitors Phishing alerts and end user notifications.
Audits network and file permissions structure and password and account maintenance.
Assists in the development and testing of the Disaster Recovery and Business Continuity Plans.
Processes exception requests and performs risk analysis on these and other customer requests.
Actively reviews threat alerts and determines relevance and criticality to the organization.
Contributes to project activities as a project team member or ad-hoc as requested.
Other duties as assigned.
Essential Functions:
Implementation and maintenance of Information security related software, hardware and systems.
Systems include but are not limited to phishing identification and prevention, Internet content filtering, Data Loss Prevention (DLP), Intrusion Detection/Prevention (IDS/IPS), Endpoint Detection and Response (EDR), Log Management, and Advanced Threat Mitigation.
Duties include information security policy administration and configuration, security related server management, Disaster Recovery Planning, proactively identifying or rapidly responding to customer security issues and security events.
Desired Education: 2 years post-secondary schooling
Desired Degree: Associate's degree
Desired Major: Computer Assurance or Computer Science
Desired Job Experience: 3+ years' direct information security experience, preferably in healthcare
Other Qualifications: Security+ or other security-related certification. Hands on exposure to providing information security operational support in a medium to large scale healthcare organization preferred. Knowledgeable in the management and setup of security related software and hardware Working knowledge of security administration, DLP, or other information security systems. Knowledge of EDR, EPP, IDS/IPS, AD and network infrastructure. Detail oriented, with meticulous attention to system and procedure documentation.
CHNCT Offers Great Benefits:
Medical, dental and vision coverage options
Flexible spending and health savings accounts
Group term life insurance
A 401(k) plan with company-match and immediate vesting
Voluntary accidental injury coverage
Tuition reimbursement and continuing education opportunities
A generous paid-leave bank and company holidays
Wellness program
We are dedicated to having a workplace where everyone feels valued, respected, and empowered to succeed. We embrace a wide range of perspectives and backgrounds, ensuring fair treatment and opportunities for all employees. We value our team's rich array of experiences and viewpoints, which contribute to our innovative and collaborative environment.
$87k-120k yearly est. Auto-Apply 28d ago
Computer Network Defense Analyst
Verite Group, Inc. 4.1
Aurora, CO jobs
Prime Time Consulting, a GRVTY Company, provides clients with expert intelligence analysis services. Our clients include defense contractors, industrial and service corporations, and departments and agencies of the U.S. Federal Government. Computer Network Defense Analyst We are actively searching for Computer Network Defense Analysts (CNDAs), located in Colorado, to support our team. We have varying levels of CNDAs, depending on years of experience and education.
Job Duties
* Conduct computer network defense.
* Conduct target development for use or decision by Government personnel.
* Analyze and produce intelligence information.
* Conduct computer/network security to provide advice to the Government.
* Create and maintain documentation of their analysis.
* Ensure to routinely follow oversight and compliance
* Acquire/share job knowledge/skill
* Partner with team members on the contract, including government personnel and other partner companies
Qualifications
* Degree in Computer Science or equivalent technical field
* Level 1 - 6 years of experience can replace 2 years of experience with AA degree
* Level 2 - 9 years of experience can replace 4 years of experience with BS degree
* Level 3 - 12 years of experience can replace up to 6 years of experience with MS degree
* Level 4 - 15 years of experience can replace up to 9 years with Doctorate degree
* Strong communication skills
* Works well in a team and alone
* Working knowledge of Microsoft Office Suite
Company Perks
* At PTC, a GRVTY Company, we believe that when our employees thrive, our company thrives. That's why we offer a comprehensive and competitive benefits package designed to support your well-being, growth, and work-life balance.
* Robust health plan including medical, dental, and vision
* Health Savings Account with company contribution
* Annual Paid Time Off and Paid Holidays
* Paid Parental Leave
* 401k with generous company match
* Training and Development Opportunities
* Award Programs
* Variety of Company Sponsored Events
Prime Time Consulting, a GRVTY Company, is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran and will not be discriminated against on the basis of disability. Anyone requiring reasonable accommodations should email ******************************* with requested details. A member of the HR team will respond to your request within 2 business days. Please review our current job openings and apply for the positions you believe may be a fit. If you are not an immediate fit, we will also keep your resume in our database for future opportunities.
$59k-82k yearly est. 5d ago
Information Security Analyst 2
Crown Equipment 4.8
Ohio jobs
:
Crown Equipment Corporation is a leading innovator in world-class forklift and material handling equipment and technology. As one of the world's largest lift truck manufacturers, we are committed to providing the customer with the safest, most efficient and ergonomic lift truck possible to lower their total cost of ownership.
Information Security Analyst 2
Job Duties
Governance, Risk, & Compliance (GRC) Application Subject Matter Expert - Operate and maintain Company's Governance, Risk and Compliance (GRC) platform, its libraries, reports, portals, and data integrations to effectively support operations, data accuracy and user processes. Serve as the primary liaison for GRC software vendors, by maintaining contact with vendor representatives, submitting troubleshooting tickets and software feedback to improve the user experience. Support Company's Enterprise Risk Management, Compliance, Vendor Management, Business Continuity Planning, Information Technology and Security, Project Management and Audit Programs with data entry, maintenance, and configuration. Develop, maintain, and distribute custom and ad hoc reporting of risk data including taxonomy analytics and Key Risk Indicators (KRI's).
Security Architecture & Control Design - Develop/integrate cybersecurity designs for systems and networks for the processing of company data. Document and address organization's information security, cybersecurity architecture, and systems securityengineering requirements. Ensure that acquired or developed systems and architectures are consistent with company's cybersecurity architecture guidelines.
Risk Assessment - Coordinate external risk assessments including audits, gap assessments, and penetration testing to evaluate security architectures and designs to determine the adequacy of security design and architecture. Determine protection needs (i.e., security controls) for company's information processing and document appropriately. Perform security reviews, identify gaps in security architecture, and develop a security risk management plan.
Incident Response Communication- Coordinate communication and information sharing aspects of incident response. Draft messages and updates to internal and external audiences for Incident Response Team (IRT) review, such as employees, customers, partners, media, or public. Handle crisis management issues and provides guidance and education on incident prevention and response best practices. Perform other duties as assigned.
Minimum Qualifications
2-4 years related experience
Associate's degree (Information Technology, Cyber Security, Computer Science)
Non-degree considered if 6+ years of related experience along with a high school diploma (GED)
Preferred Qualifications
Intermediate knowledge of various Information Security & Privacy Frameworks such as the Secure Controls Framework, NIST CSF, NIST 800-171, NIST 800-53, NIST Privacy Framework, ISO-27001, ISO-27701, GDPR, US & other global privacy regulations. Work experience in other Information Technology disciplines such as software development, help desk, networking, systems administration or similar in conjunction with professional certifications such as CASP+, CISSP Associate, or AWS Associate Level Certifications. Intermediate level of knowledge in at least one scripting or software development language such as PowerShell, Bash, Java, or Python. Good written and oral communication skills, deductive reasoning, and analytical investigative skills. Good interpersonal skills to facilitate positive relations between business groups. Requires excellent verbal and written communication skills, as well as a knowledge of company's culture and values.
Work Authorization:
Crown will only employ those who are legally authorized to work in the United States. This is not a position for which sponsorship will be provided. Individuals with temporary visas or who need sponsorship for work authorization now or in the future, are not eligible for hire.
No agency calls please.
Compensation and Benefits:
Crown offers an excellent wage and benefits package for full-time employees including Health/Dental/Vision/Prescription Drug Plan, Flexible Benefits Plan, 401K Retirement Savings Plan, Life and Disability Benefits, Paid Parental Leave, Paid Holidays, Paid Vacation, Tuition Reimbursement, and much more.
EOE Veterans/Disabilities
$81k-102k yearly est. 60d+ ago
Systems Security Engineer
Livingston Intl 4.7
Onyx, CA jobs
Join Livingston and grow your career in the constantly changing world of international trade. Livingston is a market leader offering customs brokerage, international trade consulting, compliance and freight forwarding services around the world. Livingston has over 3,000 employees at more than 90 key border crossings, sea ports, airports and other strategic locations in North America, Europe and Asia.
Our fast-paced and collaborative environment offers you the opportunity to work with leaders in the industry, receive recognition for achievements and develop your expertise in the complex and evolving world of trade. Learn how you can make an impact at Livingston.
Job Type: Full Time
JOB SUMMARY
Help us secure the digital arteries of global commerce. As a Systems SecurityEngineer, you'll protect platforms, systems, and vendor networks from cyber threats that could disrupt operations. From endpoint hardening to real-time threat monitoring, your work ensures goods keep moving safely and efficiently across the globe. Because nothing should come between a truckload of avocados and its destination-not even a ransomware attack.
The Systems SecurityEngineer is responsible for securing the organization's infrastructure and core IT systems, focusing on hardening, monitoring, and ensuring alignment with best practices and compliance requirements. This role supports the implementation and maintenance of security tools and policies across network, endpoint, and server environments. It works closely with Infrastructure, Network, GRC, and Security teams to enforce technical controls. This role is remote and open to U.S. and Canada.
KEY DUTIES & RESPONSIBILITIES
* Implement and maintain system hardening standards across servers, endpoints, and network appliances.
* Monitor and analyze logs for indicators of compromise and system vulnerabilities.
* Support vulnerability and patch management efforts, and remediation workflows.
* Assist in the deployment and tuning of security technologies across infrastructure.
* Develop and maintain secure configurations and perform regular audits for compliance with internal policies and frameworks.
* Participate in incident response activities and forensic investigations.
KNOWLEDGE & SKILLS
* Deep understanding of Windows and Linux system administration and security.
* Experience with security tools such as SIEM, EDR, vulnerability scanners, and endpoint management platforms.
* Familiarity with network protocols, firewall configurations, and intrusion detection/prevention.
* Experience supporting audits or compliance frameworks (i.e. - SOC 2, NIST CSF, ISO 27001).
* Scripting skills (i.e. - PowerShell, Bash, Python) for automation and configuration enforcement.
WORK EXPERIENCE - MINIMUM REQUIRED
5 years of related experience
EDUCATION
Required: Bachelors Degree or equivalent in Computer Science
CERTIFICATIONS DESCRIPTION
COMPETENCIES
Business Acumen and Straight Talk
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, or national origin.
For Canada: Livingston is an equal opportunity employer and committed to creating and sustaining an inclusive environment in which all individuals are treated with dignity, respect and one which reflects the diversity of the community in which we operate. Accommodations are available for applicants and employees with disabilities throughout the recruitment process. If you require accommodations for interviews or other meetings, please advise when submitting your application.
$113k-152k yearly est. 23d ago
Information Security Analyst 2
Crown Equipment Corporation 4.8
New Bremen, OH jobs
: Crown Equipment Corporation is a leading innovator in world-class forklift and material handling equipment and technology. As one of the world's largest lift truck manufacturers, we are committed to providing the customer with the safest, most efficient and ergonomic lift truck possible to lower their total cost of ownership.
Information Security Analyst 2
Job Duties
* Governance, Risk, & Compliance (GRC) Application Subject Matter Expert - Operate and maintain Company's Governance, Risk and Compliance (GRC) platform, its libraries, reports, portals, and data integrations to effectively support operations, data accuracy and user processes. Serve as the primary liaison for GRC software vendors, by maintaining contact with vendor representatives, submitting troubleshooting tickets and software feedback to improve the user experience. Support Company's Enterprise Risk Management, Compliance, Vendor Management, Business Continuity Planning, Information Technology and Security, Project Management and Audit Programs with data entry, maintenance, and configuration. Develop, maintain, and distribute custom and ad hoc reporting of risk data including taxonomy analytics and Key Risk Indicators (KRI's).
* Security Architecture & Control Design - Develop/integrate cybersecurity designs for systems and networks for the processing of company data. Document and address organization's information security, cybersecurity architecture, and systems securityengineering requirements. Ensure that acquired or developed systems and architectures are consistent with company's cybersecurity architecture guidelines.
* Risk Assessment - Coordinate external risk assessments including audits, gap assessments, and penetration testing to evaluate security architectures and designs to determine the adequacy of security design and architecture. Determine protection needs (i.e., security controls) for company's information processing and document appropriately. Perform security reviews, identify gaps in security architecture, and develop a security risk management plan.
* Incident Response Communication- Coordinate communication and information sharing aspects of incident response. Draft messages and updates to internal and external audiences for Incident Response Team (IRT) review, such as employees, customers, partners, media, or public. Handle crisis management issues and provides guidance and education on incident prevention and response best practices. Perform other duties as assigned.
Minimum Qualifications
* 2-4 years related experience
* Associate's degree (Information Technology, Cyber Security, Computer Science)
* Non-degree considered if 6+ years of related experience along with a high school diploma (GED)
Preferred Qualifications
Intermediate knowledge of various Information Security & Privacy Frameworks such as the Secure Controls Framework, NIST CSF, NIST 800-171, NIST 800-53, NIST Privacy Framework, ISO-27001, ISO-27701, GDPR, US & other global privacy regulations. Work experience in other Information Technology disciplines such as software development, help desk, networking, systems administration or similar in conjunction with professional certifications such as CASP+, CISSP Associate, or AWS Associate Level Certifications. Intermediate level of knowledge in at least one scripting or software development language such as PowerShell, Bash, Java, or Python. Good written and oral communication skills, deductive reasoning, and analytical investigative skills. Good interpersonal skills to facilitate positive relations between business groups. Requires excellent verbal and written communication skills, as well as a knowledge of company's culture and values.
Work Authorization:
Crown will only employ those who are legally authorized to work in the United States. This is not a position for which sponsorship will be provided. Individuals with temporary visas or who need sponsorship for work authorization now or in the future, are not eligible for hire.
No agency calls please.
Compensation and Benefits:
Crown offers an excellent wage and benefits package for full-time employees including Health/Dental/Vision/Prescription Drug Plan, Flexible Benefits Plan, 401K Retirement Savings Plan, Life and Disability Benefits, Paid Parental Leave, Paid Holidays, Paid Vacation, Tuition Reimbursement, and much more.
EOE Veterans/Disabilities
Nearest Major Market: Lima
Nearest Secondary Market: Findlay
Job Segment: Information Security, Testing, Help Desk, Information Technology, Data Entry, Technology, Administrative
$80k-102k yearly est. 60d+ ago
Information Security Analyst 2
Crown Equipment Corporation 4.8
New Bremen, OH jobs
: Crown Equipment Corporation is a leading innovator in world-class forklift and material handling equipment and technology. As one of the world's largest lift truck manufacturers, we are committed to providing the customer with the safest, most efficient and ergonomic lift truck possible to lower their total cost of ownership.
**Information Security Analyst 2**
**Job Duties**
+ Governance, Risk, & Compliance (GRC) Application Subject Matter Expert - Operate and maintain Company's Governance, Risk and Compliance (GRC) platform, its libraries, reports, portals, and data integrations to effectively support operations, data accuracy and user processes. Serve as the primary liaison for GRC software vendors, by maintaining contact with vendor representatives, submitting troubleshooting tickets and software feedback to improve the user experience. Support Company's Enterprise Risk Management, Compliance, Vendor Management, Business Continuity Planning, Information Technology and Security, Project Management and Audit Programs with data entry, maintenance, and configuration. Develop, maintain, and distribute custom and ad hoc reporting of risk data including taxonomy analytics and Key Risk Indicators (KRI's).
+ Security Architecture & Control Design - Develop/integrate cybersecurity designs for systems and networks for the processing of company data. Document and address organization's information security, cybersecurity architecture, and systems securityengineering requirements. Ensure that acquired or developed systems and architectures are consistent with company's cybersecurity architecture guidelines.
+ Risk Assessment - Coordinate external risk assessments including audits, gap assessments, and penetration testing to evaluate security architectures and designs to determine the adequacy of security design and architecture. Determine protection needs (i.e., security controls) for company's information processing and document appropriately. Perform security reviews, identify gaps in security architecture, and develop a security risk management plan.
+ Incident Response Communication- Coordinate communication and information sharing aspects of incident response. Draft messages and updates to internal and external audiences for Incident Response Team (IRT) review, such as employees, customers, partners, media, or public. Handle crisis management issues and provides guidance and education on incident prevention and response best practices. Perform other duties as assigned.
**Minimum Qualifications**
+ 2-4 years related experience
+ Associate's degree (Information Technology, Cyber Security, Computer Science)
+ Non-degree considered if 6+ years of related experience along with a high school diploma (GED)
**Preferred Qualifications**
Intermediate knowledge of various Information Security & Privacy Frameworks such as the Secure Controls Framework, NIST CSF, NIST 800-171, NIST 800-53, NIST Privacy Framework, ISO-27001, ISO-27701, GDPR, US & other global privacy regulations. Work experience in other Information Technology disciplines such as software development, help desk, networking, systems administration or similar in conjunction with professional certifications such as CASP+, CISSP Associate, or AWS Associate Level Certifications. Intermediate level of knowledge in at least one scripting or software development language such as PowerShell, Bash, Java, or Python. Good written and oral communication skills, deductive reasoning, and analytical investigative skills. Good interpersonal skills to facilitate positive relations between business groups. Requires excellent verbal and written communication skills, as well as a knowledge of company's culture and values.
**Work Authorization:**
Crown will only employ those who are legally authorized to work in the United States. This is not a position for which sponsorship will be provided. Individuals with temporary visas or who need sponsorship for work authorization now or in the future, are not eligible for hire.
No agency calls please.
**Compensation and Benefits:**
Crown offers an excellent wage and benefits package for full-time employees including Health/Dental/Vision/Prescription Drug Plan, Flexible Benefits Plan, 401K Retirement Savings Plan, Life and Disability Benefits, Paid Parental Leave, Paid Holidays, Paid Vacation, Tuition Reimbursement, and much more.
EOE Veterans/Disabilities