Product Security Analyst (Mid-Senior)
Security system engineer job at Boeing
At Boeing, we innovate and collaborate to make the world a better place. We're committed to fostering an environment for every teammate that's welcoming, respectful and inclusive, with great opportunity for professional growth. Find your future with us.
Boeing Defense Space & Security (BDS) is seeking an innovative Product Security Analyst to join our team in Seattle, Washington. In this role, you will lead embedded system cybersecurity and resiliency efforts across the full product lifecycle-from requirements and design through testing, production, and sustainment-ensuring the security of Boeing's advanced aerospace products and services.
You will collaborate with a multidisciplinary, enterprise-wide Product Security community to develop and implement best practices, tools, and solutions that protect complex systems, including IT, embedded, and non-IT environments. This role offers the opportunity to solve high-impact security challenges, influence next-generation security engineering, and directly contribute to the resilience of Boeing's commercial and defense offerings.
Ideal candidates bring experience in software and system security, rapid prototyping, and supporting system development, integration, and testing. Strong communication, problem-solving skills, and the ability to work independently and collaboratively with diverse teams and customers are essential.
If you are passionate about advancing cybersecurity in aerospace and want to make a meaningful impact on the future of flight, we encourage you to apply.
Position Responsibilities:
In this position, you will engage in one or more of the following activities:
Support the development and enhancement of product security requirements and architectures to meet certification and customer requirements.
Conduct product security risk assessments, attack surface analyses, and vulnerability evaluations for embedded and IT systems.
Assist in security audits and assessments of applications, components, and subsystems integrated into Boeing products and services.
Coordinate with governments, customers, suppliers, and industry partners to identify risks and improve security standards and regulatory compliance.
Analyze and triage product security incidents, identifying attack indicators and escalating potential breaches.
Perform trend analysis and support the development of detection and mitigation capabilities against evolving threats.
Prepare and present technical reports and briefings tailored to technical teams and senior leadership.
Collaborate with cross-functional teams to integrate security practices into the product lifecycle, ensuring a holistic approach to security.
Stay current with emerging threats, vulnerabilities, and security technologies to continuously improve security posture.
Support research and development activities that result in innovative solutions to enhance product security.
Travel to other Boeing sites within the U.S. may be required (estimated to be 10% travel time).
Differentiators by Level:
Individual Contributor 3 (IC-3):
Focuses on researching and analyzing technical data, performing standard risk assessments, and supporting incident coordination. Prepares technical reports and briefings under guidance.
Individual Contributor 4 (IC-4):
Leads complex security analyses and incident coordination efforts. Provides technical leadership within teams and presents findings to senior management. Drives improvements in detection capabilities and security integration.
Individual Contributor 5 (IC-5):
Acts as a consultant and technical authority on product security integration and risk management. Oversees complex assessments and leads strategic initiatives to advance detection and mitigation capabilities. Communicates technical impacts to senior leadership and influences enterprise security posture.
This position is expected to be 100% onsite. The selected candidate will be required to work onsite at one of the listed location options.
This position requires a minimum active/current U.S. Secret Security Clearance for which the U.S. Government requires U.S. Citizenship.
Basic Qualifications (Required Skill/Experience):
Bachelor's degree in Cybersecurity, or related technical discipline.
Bachelor's degree and 5+ years' experience or Master's and 3+ years (IC-3); Bachelor's degree and 9+ years' experience or Master's and 7+ years (IC-4); Bachelor's degree and 14+ years' experience or Master's and 12+ years (IC-5)
3+ years of experience in product security analysis, risk assessment, vulnerability management, or related fields.
Must obtain a CompTIA Security+, a CISSP certification or equivalent Cyber Security certification within 6 months of employment in this role.
Preferred Qualifications (Desired Skills/Experience):
Experience leading security projects or teams (for levels IC-4 and IC-5).
Knowledge of system-level product security concepts and operational environments.
Familiarity with malware analysis, attack surface reduction, and security audit methodologies.
Experience with security incident response and trend analysis.
Ability to present complex technical information to diverse audiences, including senior leadership.
Strong analytical and problem-solving skills.
Effective written and verbal communication skills.
Ability to work collaboratively in cross-functional teams.
Drug Free Workplace:
Boeing is a Drug Free Workplace where post offer applicants and employees are subject to testing for marijuana, cocaine, opioids, amphetamines, PCP, and alcohol when criteria is met as outlined in our policies.
Relocation:
This position offers relocation based on candidate eligibility. Note: Basic relocation will be offered for eligible internal candidates.
Pay & Benefits:
At Boeing, we strive to deliver a Total Rewards package that will attract, engage and retain the top talent. Elements of the Total Rewards package include competitive base pay and variable compensation opportunities.
The Boeing Company also provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and a number of programs that provide for both paid and unpaid time away from work.
The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, and the applicability of collective bargaining agreements.
Pay is based upon candidate experience and qualifications, as well as market and business considerations.
Summary Pay Range:
Level 3: 119,000 - $161,000
Level 4: $148,750 - $201,250
Level 5: 181,900 - $246,100
Applications for this position will be accepted until Dec. 19, 2025
Export Control Requirements: This position must meet export control compliance requirements. To meet export control compliance requirements, a "U.S. Person" as defined by 22 C.F.R. 120.15 is required. "U.S. Person" includes U.S. Citizen, lawful permanent resident, refugee, or asylee.
Export Control Details: US based job, US Person required
Relocation
This position offers relocation based on candidate eligibility.
Security Clearance
This position requires an active U.S. Secret Security Clearance (U.S. Citizenship Required). (A U.S. Security Clearance that has been active in the past 24 months is considered active)
Visa Sponsorship
Employer will not sponsor applicants for employment visa status.
Shift
This position is for 1st shift
Equal Opportunity Employer:
Boeing is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national origin, gender, sexual orientation, gender identity, age, physical or mental disability, genetic factors, military/veteran status or other characteristics protected by law.
Cybersecurity - Associate Information System Security Officer (ISSO)
Security system engineer job at Boeing
Company:
The Boeing Company
The Boeing Company is currently seeking a Cybersecurity - Associate Information System Security Officer (ISSO) to support Department of Defense (DoD) and Special Program activities in Heath, OH.
The selected candidate will rely on Cybersecurity and Information Assurance (IA) background to be a technical leader and support Enterprise activities and Boeing customers throughout multiple classified computing domains. The ISSO is responsible for maintaining and implementing all Information System Security policies, standards, and directives to ensure assessment and authorization of information systems processing classified information.
Position Responsibilities:
Contribute to the development and deployment of program information security for assigned systems to meet the program and enterprise requirements, policies, standards, guidelines and procedures
Implement Assessment and Authorization (A&A) processes under the Risk Management Framework (RMF), as well as product development and product maintenance for assigned systems
Perform security compliance continuous monitoring (CONMON)
Participate in security assessments and audits
Prepare and present technical reports and briefings
Contribute to the identification of root causes, the prioritization of threats, and recommend/implement corrective action
Explore the enterprise and industry for the evolving state of industry knowledge and methods regarding information security best practices
Support development of enterprise-wide information security policies, standards, guidelines and procedures that may reach across multiple stakeholder organizations
Basic Qualifications (Required Skills/Experience):
IAM Level 1 DoD 8140.01 (previously 8570.01) compliant certification (i.e. CAP, Security+ CE, CISSP, CASP, CISM, GSLC)
Experience in cybersecurity policies and implementation of Risk Management Framework (RMF): e.g. DAAPM, CNSSI 1253, ICD-503, JSIG, or NIST SP 800 series
Ability to obtain access to Special Access Programs (SAP)
Preferred Qualifications (Desired Skills/Experience):
Experience as an information system security officer (ISSO) or information system security manager (ISSM) supporting classified programs
Experience utilizing security relevant tools, systems, and applications in support of Risk Management Framework (RMF) to include NESSUS, ACAS, DISA STIGs, SCAP, Audit Reduction, and HBSS
Experience assessing and documenting test or analysis data to show cyber security compliance
Drug Free Workplace:
Boeing is a Drug Free Workplace where post offer applicants and employees are subject to testing for marijuana, cocaine, opioids, amphetamines, PCP, and alcohol when criteria is met as outlined in our policies
.
Pay & Benefits:
At Boeing, we strive to deliver a Total Rewards package that will attract, engage and retain the top talent. Elements of the Total Rewards package include competitive base pay and variable compensation opportunities.
The Boeing Company also provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and a number of programs that provide for both paid and unpaid time away from work.
The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, and the applicability of collective bargaining agreements.
Pay is based upon candidate experience and qualifications, as well as market and business considerations.
Summary pay range: $74,800 - $101,200
Language Requirements:
Not Applicable
Education:
Not Applicable
Relocation:
This position offers relocation based on candidate eligibility.
Export Control Requirement:
This position must meet export control compliance requirements. To meet export control compliance requirements, a “U.S. Person” as defined by 22 C.F.R. §120.15 is required. “U.S. Person” includes U.S. Citizen, lawful permanent resident, refugee, or asylee.
Safety Sensitive:
This is not a Safety Sensitive Position.
Security Clearance:
This position requires an active U.S. Secret Security Clearance (U.S. Citizenship Required). (A U.S. Security Clearance that has been active in the past 24 months is considered active)
Visa Sponsorship:
Employer will not sponsor applicants for employment visa status.
Contingent Upon Award Program
This position is not contingent upon program award
Shift:
Shift 1 (United States of America)
Stay safe from recruitment fraud! The only way to apply for a position at Boeing is via our Careers website. Learn how to protect yourself from recruitment fraud - Recruitment Fraud Warning
Boeing is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national origin, gender, sexual orientation, gender identity, age, physical or mental disability, genetic factors, military/veteran status or other characteristics protected by law.
EEO is the law
Boeing EEO Policy
Request an Accommodation
Applicant Privacy
Boeing Participates in E - Verify
E-Verify (English)
E-Verify (Spanish)
Right to Work Statement
Right to Work (English)
Right to Work (Spanish)
Auto-ApplySystems Engineer
Orlando, FL jobs
What We're Doing At Lockheed Martin Rotary and Mission Systems, Training and Logistics Simulation, we are driven by innovation and integrity. We believe that by applying the highest standards of business ethics and forward-thinking, everything is within our reach - and yours as a Lockheed Martin employee. Lockheed Martin values your skills, training, and education.
Do you want to be part of the team that provides training systems for the world's most advanced aircraft - F-35 Joint Strike Fighter? Do you enjoy a dynamic, fast-paced work environment?
At Lockheed Martin, we believe that by applying the highest standards of business ethics and forward-thinking, everything is within our reach - and yours as a Lockheed Martin employee.
The Work
Lockheed Martin Rotary and Mission Systems has an opportunity in Orlando, Florida for a Systems Engineer supporting the F35 Pilot Training Devices Program.
As a key member of our Systems Engineering team, you can help us take on the world's most important and complex challenges by providing solutions to a variety of technical problems of moderate scope and complexity. In this important role, you will collaborate with a team of technical professionals and interact with outside customers. The successful candidate will be flexible, motivated, dedicated, detail-focused, team-oriented, and capable of multi-tasking.
As a key member of our Systems Engineer team, you will
• Perform under general supervision to complete milestones associated with specific projects
• Contribute to the creation of design solutions that address complex engineering problems across the full software cycle
• Develop operational scenarios, based on the customer's goals and contractual requirements
• Develop system requirements and architectures to ensure customer needs and contracts are appropriately translated into the products development cycle
• Develop the product design and delivery optimization requirements
• Participate as a member of a multi-disciplinary team that represents all capabilities within DevSecOps.
The successful candidate will be flexible, motivated, dedicated, detail-focused, team-oriented, and capable of multi-tasking.
Note: This position requires a candidate who is a U.S. Citizen and holds a Secret security clearance to start. The role is located at a facility that requires special access.
Why Join Us
Lockheed Martin offers a continuous learning environment with strong career growth and advancement opportunities over the long-term. As members of the DevOps Organization, engineers will engage in the development of solutions across components of software systems through design, integration, implementation, and support. Keeping up-to-date on emerging technologies and tools will be encouraged. Proficiency may develop in infrastructure, security, software development, database management systems, systems integration, and automation.
Joining Lockheed Martin means becoming part of a team that is pushing the boundaries of aerospace technology while making a tangible impact on global defense readiness. You'll work on some of the most advanced training systems in the world, collaborate with top engineering talent, and see your work directly contribute to mission-critical outcomes.
Basic Qualifications:
- Bachelor's degree in Systems Engineering, Computer Engineering, Electrical Engineering, Applied Mathematics, Physics or related technical field and 2 years of relevant work experience
- Experience developing or testing technical system requirements
- Experience creating or revising technical system documentation
- Active Secret Security Clearance
Desired Skills:
Individuals considered for this position may have experience in one or more of the following areas:
- Working knowledge of Model Based Engineering (MBE), DOORs, Enterprise Architect, Rhapsody
- Working knowledge of Agile development and Atlassian tool suite
- Experience with Integration and Test, developing/executing test procedures
- Experience with aircraft systems, sensors, pilot & maintenance training systems
Security Clearance Statement: This position requires a government security clearance, you must be a US Citizen for consideration.
Clearance Level: Secret with Investigation or CV date within 5 years
Other Important Information You Should Know
Expression of Interest: By applying to this job, you are expressing interest in this position and could be considered for other career opportunities where similar skills and requirements have been identified as a match. Should this match be identified you may be contacted for this and future openings.
Ability to Work Remotely: Part-time Remote Telework: The employee selected for this position will work part of their work schedule remotely and part of their work schedule at a designated Lockheed Martin facility. The specific weekly schedule will be discussed during the hiring process.
Work Schedules: Lockheed Martin supports a variety of alternate work schedules that provide additional flexibility to our employees. Schedules range from standard 40 hours over a five day work week while others may be condensed. These condensed schedules provide employees with additional time away from the office and are in addition to our Paid Time off benefits.
Schedule for this Position: 4x10 hour day, 3 days off per week
Lockheed Martin is an equal opportunity employer. Qualified candidates will be considered without regard to legally protected characteristics.
The application window will close in 90 days; applicants are encouraged to apply within 5 - 30 days of the requisition posting date in order to receive optimal consideration.
At Lockheed Martin, we use our passion for purposeful innovation to help keep people safe and solve the world's most complex challenges. Our people are some of the greatest minds in the industry and truly make Lockheed Martin a great place to work.
With our employees as our priority, we provide diverse career opportunities designed to propel, develop, and boost agility. Our flexible schedules, competitive pay, and comprehensive benefits enable our employees to live a healthy, fulfilling life at and outside of work. We place an emphasis on empowering our employees by fostering an inclusive environment built upon integrity and corporate responsibility.
If this sounds like a culture you connect with, you're invited to apply for this role. Or, if you are unsure whether your experience aligns with the requirements of this position, we encourage you to search on Lockheed Martin Jobs, and apply for roles that align with your qualifications.
Experience Level: Experienced Professional
Business Unit: RMS
Relocation Available: Possible
Career Area: Systems Engineering: Requirements Development
Type: Full-Time
Shift: First
Information Security Engineer - Applications
Oak Brook, IL jobs
In this role, you will work closely with IT teams to secure our applications throughout the development lifecycle. You'll help build a secure-by-design culture, drive security automation, and protect our systems against evolving threats. This position reports to the Manager of Information Security.
ESSENTIAL JOB FUNCTIONS:
Work with the Information Security Team to improve security for the company by configuring and administering security systems and tools
Monitor and respond to security events using SIEM and SOAR tools
Investigate security incidents to determine root cause and remediation tactics
Help automate security monitoring and remediation processes
Prepare and analyze security incident data and metrics for periodic reporting
Collaborate on vulnerability management, remediation, and penetration testing efforts
Implement and manage SAST, DAST, and Burp Suite across GitHub CI/CD pipelines and development workflows
Champion secure coding practices based on OWASP Top 10 and SSDF guidelines
Help secure cloud environments (Azure, AWS) and container-based deployments
Conduct regular security assessments to ensure alignment with SSDLC standards
After-hours configuration changes and on-call support required
MINIMUM QUALIFICATIONS:
Bachelor's degree in Computer Science, Information Systems (or related degree), or equivalent experience.
3+ years of experience in Application or Information Security
Strong understanding of SSDLC, NIST SSDF, and DevSecOps principles.
Experience with SAST/DAST tools (e.g., GitHub Advanced Security, BURP).
Solid knowledge of OWASP Top 10 and secure coding best practices.
Proficiency in GitHub for code review, pipeline security, and automation.
Hands-on with scripting (Python, PowerShell, Bash) and API security.
Experience in Azure and AWS cloud security, containers, and infrastructure-as-code.
Familiarity with SIEM/SOAR platforms and incident response workflows.
Experience with Windows, MacOS, and Linux operating systems
Proficient in Microsoft Office applications such as Microsoft Outlook, Word, Excel, PowerPoint, and SharePoint
** This is a full-time, W2 position with Hub Group - We are NOT able to provide sponsorship at this time **
Salary:
$95,000-150,000/year
+ bonus eligibility
**
This is an estimated range based on the circumstances at the time of posting, however, may change based on a combination of factors, including but not limited to skills, experience, education, market factors, geographical location, budget, and demand**
Benefits
We offer a comprehensive benefits plan including:
Medical
Dental
Vision
Flexible Spending Account (FSA)
Employee Assistance Program (EAP)
Life & AD&D Insurance
Disability
Paid Time Off
Paid Holidays
BEWARE OF FRAUD!
Hub Group has become aware of online recruiting related scams in which individuals who are not affiliated with or authorized by Hub Group are using Hub Group's name in fraudulent emails, job postings, or social media messages. In light of these scams, please bear the following in mind
Hub Group will never solicit money or credit card information in connection with a Hub Group job application.
Hub Group does not communicate with candidates via online chatrooms such as Signal or Discord using email accounts such as Gmail or Hotmail.
Hub Group job postings are posted on our career site: ********************************
About Us
Hub Group is the premier, customer-centric supply chain company offering comprehensive transportation and logistics management solutions. Keeping our customers' needs in focus, Hub Group designs, continually optimizes and applies industry-leading technology to our customers' supply chains for better service, greater efficiency and total visibility. As an award-winning, publicly traded company (NASDAQ: HUBG) with $4 billion in revenue, our 6,000 employees and drivers across the globe are always in pursuit of "The Way Ahead" - a commitment to service, integrity and innovation. We believe the way you do something is just as important as what you do. For more information, visit ****************
Application Security Architect - Hybrid
New Bremen, OH jobs
Crown Equipment Corporation is a leading innovator in world-class forklift and material handling equipment and technology. As one of the world's largest lift truck manufacturers, we are committed to providing the customer with the safest, most efficient and ergonomic lift truck possible to lower their total cost of ownership.
Remote Work: Crown offers hybrid remote work for this position. A reasonable commute is necessary as some onsite work is required. Relocation assistance is available.
Primary Responsibilities
Define security architecture standards and blueprints for web, mobile, cloud, and Application Programming Interface (API)-based applications.
Review design documents and perform architecture risk assessments for new and existing applications.
Collaborate with DevOps, Engineering, and Infrastructure teams to ensure architectures align with secure design principles.
Integrate automated security testing/scanning tools (Static Application Security Testing (SAST), Software Composition Analysis (SCA)) into Continuous Integration (CI) or Continuous Delivery (CD) pipelines.
Define and enforce secure coding standards and practices across development teams.
Provide training and guidance to developers on secure development principles and vulnerability prevention.
Conduct threat modeling and attack surface reviews for high-risk or critical applications.
Identify potential security flaws and recommend mitigations early in development process.
Track and communicate technical risk to product managers, developers, and leadership teams.
Develop and maintain application security policies, baselines, and architecture frameworks.
Ensure application security practices align with regulations including General Data Protection Regulation (GDPR) and Payment Card Industry Data Security Standard (PCI-DSS).
Support audit and compliance initiatives by providing documentation and evidence of secure development practices.
Minimum Qualifications
Bachelor's degree in Information Technology, Cyber Security, Computer Science, or related field is required, along with 2-4 years related experience.
Non-degree considered if 12+ years of related experience along with a high school diploma or GED
Preferred Qualifications
5+ years in cybersecurity with at least 3 years in application security or secure software development experience.
Secure Software Development Life Cycle (SDLC) in development. Deep knowledge of Open Web Application Security Project (OWASP) Top 10, National Institute of Standards and Technology (NIST), and secure coding frameworks.
Experience with Securing Secrets and Service Accounts desired.
Experience with Web Application Firewall (WAF) implementation/support preferred.
Familiarity with Identity and Access Management and cloud security practices (AWS, Azure).
Certified Information Systems Security Professional (CISSP), or similar certification (Certified Secure Software Lifecycle Professional, Certified Ethical Hacker (CEH) certified).
Familiarity with container security (Docker, Kubernetes).
Understanding of authentication protocols (Open Authorization (OAuth) and Security Assertion Markup Language (SAML)).
Experience with DevSecOps tools and container security tools desired.
Work Authorization:
Crown will only employ those who are legally authorized to work in the United States. This is not a position for which sponsorship will be provided. Individuals with temporary visas or who need sponsorship for work authorization now or in the future, are not eligible for hire.
No agency calls please.
Compensation and Benefits:
Crown offers an excellent wage and benefits package for full-time employees including Health/Dental/Vision/Prescription Drug Plan, Flexible Benefits Plan, 401K Retirement Savings Plan, Life and Disability Benefits, Paid Parental Leave, Paid Holidays, Paid Vacation, Tuition Reimbursement, and much more.
EOE Veterans/Disabilities
Senior Cloud Security Engineer (Infrastructure and Security) - New York - Competitive Salary + Competitive Package + Opportunity to work with an Ambitious, Young, Growing Organisation!
New York, NY jobs
This young and agile company, providing identity risk solutions is currently seeking a Senior Cloud Security Engineer with a focus on Infrastructure and Security to join their growing team.
You will assist with the continuous maturation of their Cloud Security services within the Security division.
This is an excellent opportunity for an experienced Cloud Security Engineer with experience in both Infrastructure and Security to take the next step into a challenging position with a company offering significant growth potential.
About the Company:
Founded in the last 10 years, they are one the fastest growing companies in their space.
They are a fast-growing company that have built a platform that allows finance organisations and fintechs to strengthen their security defences.
Their mission is to allow companies to manage their identity and fraud risk.
Everything they do is entrenched in achieving engineering excellence.
Their culture is not corporate, and they like to trust their employees to take on a lot of responsibility and have input into the shape of growth of the organisation.
About the Senior Cloud Security Engineer (Infrastructure and Security) Vacancy:
What you will be doing:
• Serve as a cloud security subject matter expert, advise on and implementing best practices
• Respond to security incidents and provide timely and appropriate solutions
• Conduct cloud security risk assessments and audits
• Conduct investigations into security incidents and potential threats
• Take part in on call rotations for incident response and remediation
• Assist with policy management, security audits, and due diligence for cloud security concerns
• Advise on, configuring, and managing a variety of security tools
• Keep informed about and respond to emerging security threats and vulnerabilities
• Assist with cloud security reviews of potential vendors
Ideal Requirements for the Senior Cloud Security Engineer (Infrastructure and Security) Vacancy:
• Several years of experience working in a similar role with a focus on Cloud Security in AWS
• Experience provisioning infrastructure in AWS using Terraform, CloudFormation, CDK, or similar tools
• Experience configuring VPCs, route tables, NACLs, Security Groups, iptables, Web Application Firewall, Config, GuardDuty, Inspector, KMS, IAM, etc.
• In depth knowledge of AWS security best practices around systems hardening, monitoring, and incident response
• Experience taking part in an on-call rotation
• You are passionate about securing infrastructure, reducing risk, and protecting data!
• You are a subject matter expert on cloud security in AWS
• You have a solid understanding of network architecture and protocols
• You can advise on cloud security policies and procedures
Apply to the Role:
Roles like these are snapped up very quickly, so act now if you do not want to miss out! Reply to this advert or email your CV to **********************
Senior Systems Engineer - Front Office Technology
New York, NY jobs
Job Title: Senior Systems Engineer - Front Office Technology
Employment Type: Full-Time, Direct Hire
About the Role
We are seeking a highly experienced Senior Systems Engineer to join our dynamic Front Office Technology team. This role is pivotal in designing and implementing cutting-edge solutions that support trading operations and compliance systems within a fast-paced buy-side financial environment. You'll work closely with traders, portfolio managers, and compliance officers to deliver robust, scalable, and intelligent systems.
Key Responsibilities
Architect, develop, and maintain mission-critical applications for front office trading and compliance workflows
Collaborate with cross-functional teams to gather requirements and deliver tailored solutions
Integrate AI/ML capabilities to enhance decision-making, automation, and predictive analytics
Optimize performance and reliability of systems using cloud-native technologies (AWS, Azure, GCP)
Ensure regulatory compliance and data integrity across all systems
Mentor junior engineers and contribute to engineering best practices
Required Qualifications
10+ years of professional software engineering experience
5+ years in financial services, specifically within buy-side environments
Strong programming expertise in C#, .NET, and SQL
Hands-on experience with cloud platforms: AWS, Azure, or GCP
Proven track record of AI/ML implementation and integration
Deep understanding of front office trading systems and compliance frameworks
Excellent communication and problem-solving skills
Preferred Skills
Experience with microservices architecture and containerization (Docker, Kubernetes)
Familiarity with FIX protocol and market data feeds
Exposure to agile methodologies and CI/CD pipelines
Network Security Engineer
Oak Brook, IL jobs
The Network Security Engineer will maintain and help deploy the Company's security platform and solution efforts as well as perform network and host threat assessments to identify, evaluate and mitigate security risks, threats and vulnerabilities. This position will primarily be responsible for the Palo Alto Firewalls, Fortigates, and F5 Load Balancers. The Network Security Engineer will work to develop action plans to mitigate identified vulnerabilities and promote security initiatives.
Essential Job Functions:
Work at the direction of the Security Manager to improve the security for the Company
Administration of all aspects of the Palo Alto Firewalls
Administration of all aspects of the FortiGate Firewalls and experience with FortiManager and FortiAnalyzer
Administration of all aspects of the F5 Load Balancers
Assist with the configuration and administration of security systems and tools
Respond to security incidents and report on incident handling and resolution
Assist with the enforcement of security policies and procedures by monitoring system activity
Review security violation reports and investigates possible security exceptions, updates, and maintains and documents security controls
After hours monitoring and on call support will also be required
Lead and mentor more junior network security engineers on projects and initiatives
Minimum Requirements:
Bachelor's Degree in Computer Science, Information Systems, or other related field
7+ years hands-on experience maintaining corporate firewalls (preferably with direct experience on Palo Alto Firewalls), Panorama Experience, Global Protect VPN configuration and management.
Hands-on experience maintaining corporate load balancers (preferably with direct experience on F5 load balancers)
Detailed knowledge of the OSI model and its application across corporate networks
Working knowledge of Windows, Red Hat Linux, and Oracle Linux operating systems
Proficient in Microsoft Word, Project, Excel, Access, Visio
Ability to manage multiple projects with competing priorities
Ability to work as part of a team
**
This is a full-time, W2 position with Hub Group - We are NOT able to provide sponsorship at this time
**
Salary Range:
$110,000 - $165,000/year base salary
+ bonus eligibility
**
This is an estimated range based on the circumstances at the time of posting, however, may change based on a combination of factors, including but not limited to skills, experience, education, market factors, geographical location, budget, and demand**
BEWARE OF FRAUD!
Hub Group Has Become Aware of Online Recruiting Related Scams in Which Individuals Who Are Not Affiliated with or Authorized by Hub Group Are Using Hub Group's Name in Fraudulent Emails, Job Postings, Or Social Media Messages. In Light of These Scams, Please Bear the Following in Mind
Hub Group will never solicit money or credit card information in connection with a Hub Group job application.
Hub Group does not communicate with candidates via online chatrooms such as Signal or Discord using email accounts such as Gmail or Hotmail.
Hub Group job postings are posted on our career site: ********************************
About Us
Hub Group is the premier, customer-centric supply chain company offering comprehensive transportation and logistics management solutions. Keeping our customers' needs in focus, Hub Group designs, continually optimizes and applies industry-leading technology to our customers' supply chains for better service, greater efficiency and total visibility. As an award-winning, publicly traded company (NASDAQ: HUBG) with $5 billion in revenue, our 6,000 employees and drivers across the globe are always in pursuit of "The Way Ahead" - a commitment to service, integrity and innovation. We believe the way you do something is just as important as what you do. For more information, visit ****************
Cyber Security Engineer
Rochester, NY jobs
Requirements
Work Environment/Physical Demands:
Use of computer and office equipment.
Ability to remain calm in stressful situations
Performs all administrative functions expected at this level.
Minimum Qualifications:
TECHNICAL SKILLS:
Strong background in security architecture including a deep knowledge of IT network security (secure LAN, WAN, vLAN, MPLS, and secure network zoning and restricted network design) and cloud-based technologies.
Strong background in Network Engineering including a deep understanding of Windows Server architecture, Windows Virtualization, Networking, Backup Solutions, and Disaster Recovery
Strong background in Microsoft security architecture including a deep knowledge of server and workstation security.
Ability to troubleshoot server-based software issues with:
Microsoft Windows Server operating systems
On Premise Microsoft Exchange and hosted Microsoft Office 365
Microsoft Remote Desktop Services
Microsoft Hyper-V and VMWare
Enterprise EDR and MDR solutions
Enterprise class backup solutions
Knowledgeable of various server/workstation peripherals such as NAS/SAN solutions.
In depth knowledge of workstation/server hardware and software troubleshooting abilities
Strong understanding of networking equipment such as Switches, Firewalls, and Wireless Access Points
SOFT SKILLS & ABILITIES:
Strong written and verbal communication skills.
Pleasant and professional demeanor in all client and internal communications.
Ability to multitask.
Independent worker and able to work effectively on daily tasks without direct supervision.
Strong organization skills and ability to operate efficiently throughout daily tasks.
Work well with clients at all levels, from executive to IT to end user
EDUCATION, EXPERIENCE, & KNOWLEDGE:
(5) years working in Information Technology
(2) years in Cybersecurity
(1) year in CMMC compliance
Information Security Qualifications such as CISSP, CISM, CISA, and ISSAP, a plus.
Certified CMMC Professional (CCP)
Familiarity with NIST SP 800-171
Additional Requirements
Ability to schedule for evening or weekend work occasionally
Valid driver's license in your state of residence and reliable personal vehicle
Remote option negotiable based on location
Salary Description 100,000-130,000
Cyber Security Engineer
Rochester, NY jobs
CYBERSECURITY ENGINEER
Department: IT Services Group Billable Hours Goal: 80% of worked hours
Position Type: Full Time Travel Required: Minimal travel
The Cybersecurity Engineer will serve as a subject matter expert in many areas of security, needs to be able to describe and document in business terms the impact of security policies, standards, and architecture. This person plays a vital dual role in our organization, with time being spent facilitating our Cybersecurity offering as well as focusing on CMMC Compliance. The Cybersecurity Engineer provides security direction to the business and project stakeholders to ensure that security is a key focus for all projects and new business initiatives, as well as technical expertise on assigned clients, tickets, and CMMC Compliance projects.
REPORTS TO: Director, IT Services
DIRECT REPORTS: None
ESSENTIAL FUNCTIONS:
Project engagement during the initiation, requirements, and design stages to ensure that security has been considered and is included into the design at the appropriate level based on the risks
Security review and design of complex applications and technologies
Evaluation and maintenance of security system plans and procedures to safeguard internal information systems
Researching and recommendation/implementation of changes to procedures and systems to enhance security aligned with corporate policies
Accountable for ensuring that key risks and issues are identified, addressed and resolved in a manner that satisfies the business
Perform security risk assessments to determine level of security services to include:
Document Customers' Systems
Liaison between ComTec and Cybersecurity Vendors
Weekly review and analysis of Cybersecurity Reports
ADDITIONAL RESPONSIBILITIES:
Monitor assigned tickets and tasks and provide service or escalation as necessary.
Develop tasks & milestones for security projects.
Able to translate business and non-functional requirements to establish security controls so that a proper security design can be architected and to document the security solution for communication and publication.
Demonstrated analytical skills - continuously identifies problems, collect or interpret data, establish facts, anticipate obstacles, and develops plans to resolve; strong problem-solving skills while communicating in a clear and succinct manner effectively evaluating information and data to make decisions.
Proven understanding of the current vulnerabilities, response, and mitigation strategies used in Cybersecurity.
Experience of designing and incorporating technical security controls that align to NIST 800-171, and/or CMMC.
Prepared to challenge business and IT colleagues and have the “difficult conversations” where needed in the interests of the company.
Demonstrated customer focus - evaluate decisions through the eyes of the customer; build strong customer relationships and create processes from the customer viewpoint.
Able to operate as a highly independent worker and as part of a strong team/collaborative approach.
Accurately enter and maintain ticket information including notes and resolution.
Adhere to departmental policies for reporting and managing requests and change controls.
Maintain daily timesheet and expense report entries and submit them accurately and timely.
Other duties as required.
Requirements
Work Environment/Physical Demands:
Use of computer and office equipment.
Ability to remain calm in stressful situations
Performs all administrative functions expected at this level.
Minimum Qualifications:
TECHNICAL SKILLS:
Strong background in security architecture including a deep knowledge of IT network security (secure LAN, WAN, vLAN, MPLS, and secure network zoning and restricted network design) and cloud-based technologies.
Strong background in Network Engineering including a deep understanding of Windows Server architecture, Windows Virtualization, Networking, Backup Solutions, and Disaster Recovery
Strong background in Microsoft security architecture including a deep knowledge of server and workstation security.
Ability to troubleshoot server-based software issues with:
Microsoft Windows Server operating systems
On Premise Microsoft Exchange and hosted Microsoft Office 365
Microsoft Remote Desktop Services
Microsoft Hyper-V and VMWare
Enterprise EDR and MDR solutions
Enterprise class backup solutions
Knowledgeable of various server/workstation peripherals such as NAS/SAN solutions.
In depth knowledge of workstation/server hardware and software troubleshooting abilities
Strong understanding of networking equipment such as Switches, Firewalls, and Wireless Access Points
SOFT SKILLS & ABILITIES:
Strong written and verbal communication skills.
Pleasant and professional demeanor in all client and internal communications.
Ability to multitask.
Independent worker and able to work effectively on daily tasks without direct supervision.
Strong organization skills and ability to operate efficiently throughout daily tasks.
Work well with clients at all levels, from executive to IT to end user
EDUCATION, EXPERIENCE, & KNOWLEDGE:
(5) years working in Information Technology
(2) years in Cybersecurity
(1) year in CMMC compliance
Information Security Qualifications such as CISSP, CISM, CISA, and ISSAP, a plus.
Certified CMMC Professional (CCP)
Familiarity with NIST SP 800-171
Additional Requirements
Ability to schedule for evening or weekend work occasionally
Valid driver's license in your state of residence and reliable personal vehicle
Remote option negotiable based on location
Salary Description 100,000-130,000
Systems Security Engineer
Onyx, CA jobs
Join Livingston and grow your career in the constantly changing world of international trade. Livingston is a market leader offering customs brokerage, international trade consulting, compliance and freight forwarding services around the world. Livingston has over 3,000 employees at more than 90 key border crossings, sea ports, airports and other strategic locations in North America, Europe and Asia.
Our fast-paced and collaborative environment offers you the opportunity to work with leaders in the industry, receive recognition for achievements and develop your expertise in the complex and evolving world of trade. Learn how you can make an impact at Livingston.
Job Type: Full Time
JOB SUMMARY
Help us secure the digital arteries of global commerce. As a Systems Security Engineer, you'll protect platforms, systems, and vendor networks from cyber threats that could disrupt operations. From endpoint hardening to real-time threat monitoring, your work ensures goods keep moving safely and efficiently across the globe. Because nothing should come between a truckload of avocados and its destination-not even a ransomware attack.
The Systems Security Engineer is responsible for securing the organization's infrastructure and core IT systems, focusing on hardening, monitoring, and ensuring alignment with best practices and compliance requirements. This role supports the implementation and maintenance of security tools and policies across network, endpoint, and server environments. It works closely with Infrastructure, Network, GRC, and Security teams to enforce technical controls. This role is remote and open to U.S. and Canada.
KEY DUTIES & RESPONSIBILITIES
* Implement and maintain system hardening standards across servers, endpoints, and network appliances.
* Monitor and analyze logs for indicators of compromise and system vulnerabilities.
* Support vulnerability and patch management efforts, and remediation workflows.
* Assist in the deployment and tuning of security technologies across infrastructure.
* Develop and maintain secure configurations and perform regular audits for compliance with internal policies and frameworks.
* Participate in incident response activities and forensic investigations.
KNOWLEDGE & SKILLS
* Deep understanding of Windows and Linux system administration and security.
* Experience with security tools such as SIEM, EDR, vulnerability scanners, and endpoint management platforms.
* Familiarity with network protocols, firewall configurations, and intrusion detection/prevention.
* Experience supporting audits or compliance frameworks (i.e. - SOC 2, NIST CSF, ISO 27001).
* Scripting skills (i.e. - PowerShell, Bash, Python) for automation and configuration enforcement.
WORK EXPERIENCE - MINIMUM REQUIRED
5 years of related experience
EDUCATION
Required: Bachelors Degree or equivalent in Computer Science
CERTIFICATIONS DESCRIPTION
COMPETENCIES
Business Acumen and Straight Talk
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, or national origin.
For Canada: Livingston is an equal opportunity employer and committed to creating and sustaining an inclusive environment in which all individuals are treated with dignity, respect and one which reflects the diversity of the community in which we operate. Accommodations are available for applicants and employees with disabilities throughout the recruitment process. If you require accommodations for interviews or other meetings, please advise when submitting your application.
Sentinel - Systems Security Engineer - 16416
Roy, UT jobs
RELOCATION ASSISTANCE: Relocation assistance may be available CLEARANCE TYPE: SecretTRAVEL: Yes, 10% of the TimeDescriptionAt Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work - and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history.
Join Northrop Grumman on our continued mission to push the boundaries of possible across land, sea, air, space, and cyberspace. Enjoy a culture where your voice is valued and start contributing to our team of passionate professionals providing real-life solutions to our world's biggest challenges. We take pride in creating purposeful work and allowing our employees to grow and achieve their goals every day by Defining Possible. With our competitive pay and comprehensive benefits, we have the right opportunities to fit your life and launch your career today.
Northrop Grumman Defense Systems is seeking a Systems Security Engineer, (Level 2), that will support the Sentinel (GBSD) program performing Hardware Assurance.
This position will be located in Roy, UT and will support the Ground Based Strategic Deterrent (GBSD) program.
The Mission Defense Team (MDT) is seeking a highly motivated and qualified system engineer to serve as a Hardware Assurance Engineer, Level 2. You will be responsible for assessing and prioritizing a broad spectrum of hardware security threats. Key protection activities will involve vendor research, hardware assurance, program protection, counterfeit prevention, and supply chain security.
Additional Responsibilities include:
Assessment and analysis of threats, vulnerabilities, and risk for identified mission-critical functions and critical components
Support courses of action based on knowledge and experience, initiative, guidance, and established regulations and policies
Research, analyze data, and derive facts per identified vulnerabilities
Participate in a variety of working groups and customer meetings; ensure communication of risk environment with stakeholders
Contributes to program plans, goals, objectives, and milestones to for Hardware Assurance
Review technical security assessments of SSE environments to identify points of vulnerability, non-compliance with established standards and regulations and recommended mitigation strategies
Execute completion Statement of Work requirements, Program Milestone Exit Criteria, and program maturity commitments
Ensure the architecture and design of systems are functional and secure; support the design, development, implementation, and integration of security systems and system components
Self-starters compelled to take action in the workplace without requiring prompting from supervisors
Support MDT with other duties as assigned
In addition to technical skills, you will be a self-starter with strong time management skills. Your organizational skills and ability to anticipate future challenges will serve you well
Basic Qualifications
Must be a US Citizen with an active DoD Secret Clearance, at time of application, current and within scope, with an investigation date within the last 6 years
Must have the ability to obtain and maintain Special Access Program (SAP) approval within a reasonable period of time, as determined by the company to meet its business need
Requires a bachelor's degree in a STEM (Science, Technology, Engineering or Mathematics) discipline from an accredited university and 2 years of related experience; or a master's degree with 1 year
Minimum 2 years of applying and understanding Systems Security Engineering principles applicable to US Government Defense Programs
Minimum 2 years in showing the ability to communicate effectively and clearly present technical approaches and findings
Experience in any of the full product life cycles of: ASIC Design, FPGA Design
Experience in HDL (VHDL/Verilog), implementing designs using RTL
Ability to show self as team player, able to multi-task, able to generate quality work products independently, able to make excellent judgement and show interpersonal skills
Preferred Qualifications
Degree in Aerospace Engineering, Systems Engineering, Mechanical Engineering, Software Engineering, or similar
ICBM Experience
Experience developing Systems Security Engineering requirements for hardware and software assurance
Evaluating program processes and compliance strategies for large, complex multi-site programs
Demonstrated experience and familiarity with vulnerability management
Experience with Model-based Systems Engineering (MBSE) concepts and tools
A solid understanding of Program Protection applicable to US Government Defense Programs and applied knowledge in the application of SSE principles across a broad spectrum of security measures (Cybersecurity, Counterfeit Awareness, Anti-Tamper, HW/SW Assurance, OPSEC, etc.) to protect critical program information (CPI)
Top Secret clearance
Position Benefits
As a full-time employee of Northrop Grumman, you are eligible for our robust benefits package including:
Medical, Dental & Vision coverage
401k
Educational Assistance
Life Insurance
Employee Assistance Programs & Work/Life Solutions
Paid Time Off
Health & Wellness Resources
Employee Discounts
******************************************************************
This position's standard work schedule is a 9/80. The 9/80 schedule allows employees who work a nine-hour day Monday through Thursday to take every other Friday off.
This role may offer a competitive relocation assistance package.
#Sentinelsystems
Primary Level Salary Range: $77,200.00 - $115,800.00The above salary range represents a general guideline; however, Northrop Grumman considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills and current market conditions.Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. Annual bonuses are designed to reward individual contributions as well as allow employees to share in company results. Employees in Vice President or Director positions may be eligible for Long Term Incentives. In addition, Northrop Grumman provides a variety of benefits including health insurance coverage, life and disability insurance, savings plan, Company paid holidays and paid time off (PTO) for vacation and/or personal business.The application period for the job is estimated to be 20 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates.Northrop Grumman is an Equal Opportunity Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. For our complete EEO and pay transparency statement, please visit *********************************** U.S. Citizenship is required for all positions with a government clearance and certain other restricted positions.
Auto-ApplyStaff Systems Security Engineer
Rolling Meadows, IL jobs
RELOCATION ASSISTANCE: Relocation assistance may be available CLEARANCE TYPE: SAPTRAVEL: Yes, 10% of the TimeDescriptionAt Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work - and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history.
We are seeking capable, talented, and motivated team-contributors at our Northrop Grumman Rolling Meadows site. Our products range from advanced sensing technologies to state-of-the-art targeting and tracking systems that are deployed in Electro-Optical Infrared (EOIR) and Radio Frequency Electronic Warfare (RFEW) systems. These systems are designed, developed, built, integrated, and tested by the capable folks at our company to protect the lives of US and Allied warfighters in present and future conflicts. Enjoy a culture where your voice is valued and start contributing to our team of passionate professionals providing real-life solutions to our world's biggest challenges. We take pride in creating purposeful work and allowing our employees to grow and achieve their goals every day by Defining Possible. With our competitive pay and comprehensive benefits, we have the right opportunities to fit your life and launch your career today. If you are interested in consideration to be included as a part of this team, we would invite you to apply.
Northrop Grumman Mission Systems Sector (NGMS) is seeking a Staff Systems Security Engineer to join our Systems Security Engineering team. The Security Engineering team is cross-disciplinary across the security domain; encompassing embedded Systems Engineering, Cybersecurity, Software Security and Anti-Tamper Engineering.
Roles & Responsibilities:
· Design/develop system architectures and generate system designs to be implemented in a cost-effective manner.
Implement and ensure compliance with government policies (e.g., JSIG, DAAPM, NIST 800-53, CNSSI 1253, DODI 5200.39, etc.) by reviewing process tailoring needs and approving documented procedures.
Guide and monitor technical documentation/publication to document trades studies, system designs, analysis, and results related to a systems security posture such as identifying Critical Program Information (CPI) and creation of Anti-Tamper Plans
Develop an understanding of system interfaces and how to protect them.
Assist with the definition of key capabilities and performance requirements.
Adapt production and development products to meet unique customer needs and support the development of system security functions.
Collaborate with security engineering team(s), across a portfolio of programs, through the duration of program execution to solve issues and to prepare for requirements sell off.
Support technical work products developed by the larger engineering team in support of major milestone deliveries (e.g.: SRR, SVR, PDR, CDR, TRR, PRR).
Authoring technical documentation such as white papers, proposal technical volumes, and program milestone briefings.
Collaborate with security engineering team(s), across a portfolio of programs, through the duration of program execution to solve issues and to prepare for requirements sell off.
Other duties may include technical leadership, business capture activities, interfacing with industry partners and the USG.
This position will be full-time, on-site at our Rolling Meadows, IL location.
This position is contingent upon Funding/Contract award, special access program and acquiring and maintaining the necessary US Government security clearance per customers' requirements prior to start.
Basic Qualifications for a Staff Systems Security Engineer:
Bachelor's degree in Electrical Engineering, Software Engineering, Computer Engineering, Computer Science, Cybersecurity, or related technical fields with 12+years of related experience, a Master's degree in Electrical Engineering, Software Engineering, Computer Engineering, Computer Science, Cybersecurity, or related technical fields with 10+ years of related experience or a PhD in Electrical Engineering, Software Engineering, Computer Engineering, Computer Science, Cybersecurity, or related technical fields with 7+ years of related experience.
3 years of cumulative experience on DoD based platforms and/or systems regarding the application of Cybersecurity RMF or Anti-Tamper with competencies in security threat analysis, systems architecture, engineering design, requirements derivation, validation, and verification.
Must have demonstrated experience in leading teams to solve technical problems, including decomposition, root cause analysis, solution development, implementation and monitoring
Experience contributing to and/or making technical presentations to internal and external customers.
Ability to obtain and maintain a minimum of a Secret Clearance with additional customer specified clearance prior to start.
Preferred Qualifications for a Staff Systems Security Engineer:
Advanced degrees in Electrical Engineering, Software Engineering, Computer Engineering, Computer Science, Cybersecurity, or related technical fields.
Experience with design verification testing, reverse engineering, embedded software development, Cybersecurity, or Anti-Tamper Possess a DoD 8140 certification, e.g. CompTIA Security+, CISSP, or similar. Experience with proposals and creating basis of estimates (BOEs)
Primary Level Salary Range: $163,200.00 - $244,800.00The above salary range represents a general guideline; however, Northrop Grumman considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills and current market conditions.Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. Annual bonuses are designed to reward individual contributions as well as allow employees to share in company results. Employees in Vice President or Director positions may be eligible for Long Term Incentives. In addition, Northrop Grumman provides a variety of benefits including health insurance coverage, life and disability insurance, savings plan, Company paid holidays and paid time off (PTO) for vacation and/or personal business.The application period for the job is estimated to be 20 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates.Northrop Grumman is an Equal Opportunity Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. For our complete EEO and pay transparency statement, please visit *********************************** U.S. Citizenship is required for all positions with a government clearance and certain other restricted positions.
Auto-ApplyAnalyst, Information Security
San Antonio, TX jobs
Build an Aviation Career You're Proud Of At StandardAero, we use our ingenuity and know-how to find solutions for the simple to the most complex challenges in aviation. Together, we get the job done and done well. Our stability, resources, and respectful culture supports you in building a solid career with a great team you can count on day in and day out for the long term.
Summary:
As an IT Security Analyst position is a critical role in protecting StandardAero's business and technology operations. In this role you will be accountable in securing the enterprise technology and operations against an ever evolving and growing threat landscape. The role is an integral position in supporting StandardAero's global cyber-security defenses, providing tactical cyber security objectives and implementing the security strategy across the organization.
What you'll do:
* Conduct risk and security assessments through vulnerability analysis and reporting
* Perform mitigation support for both internal and external security audits
* Investigate, analyze and document security incidents to identify and document the root cause
* Provides incident response support including mitigating actions to contain activity and facilitating forensics analysis when necessary
* Partner with IT Operation teams to remediate system vulnerabilities
* Participates in the production of documentation and management reporting
* Research security enhancements and make recommendations for improved policy and process
* Analyze IT requirements and provide objective advice on the use of new IT security offerings
* Stay up-to-date on information technology and cybersecurity trends and standards
* Other IT Security-related duties as required
* Capable of identifying, evaluating and mitigating significant risks within an enterprise.
* Strong working experience with Microsoft Office Suite.
* Strong oral and written communication skills and the ability to work well with people from many different disciplines with varying degrees of technical experience.
* Possess strong analytical skills attention to detail.
* Ability to prioritize assignments while working on multiple projects
* Ability to work independently and proactively to meet assigned objectives
* Flexible with the ability to multi-task, effectively prioritize and work under pressure
* Basic project management
* Design, implement, administer, support and maintain cybersecurity technology systems (Endpoint Protection, IDS/IPS, Web and Email Security, SIEM, Multi-Factor Authentication, Network Access Controls, DLP, etc.)
* Analyze, report and respond to security alerts within the various IT technologies and global locations
* Proactively remediate information technology security threats as a member of the security team
* Assist in the designing, documenting, architecting and implementing IT security measures and controls
* Provide support through 'Threat Hunting' against anomalous behavior within the enterprise. Correlates activity across assets (endpoint, network, apps) and environments to identify patterns of anomalous activity
* Conducts log-based and endpoint-based threat detection to detect and protect against threats coming from multiple sources
* Threat mitigation; malicious code detection, response and prevention; operating system security oversight
Minimum Qualifications:
* Bachelor's degree in Information Security, Computer Science, or a related field; equivalent experience may be considered.
* 5+ years of progressive experience in cybersecurity and IT, including hands-on security operations, threat detection, or engineering.
* 5+ years of experience in SIEM Administration, endpoint protection, vulnerability management tools, and security automation.
* 5+ years of experience of network and application security, threat actor tactics (MITRE ATT&CK), and incident response frameworks.
* 5+ years of experience working in regulated environments or with industry frameworks (e.g., NIST, ISO 27001, CIS, or CMMC).
Preferred Qualifications:
* IT Security Certification, specifically GSEC, CEH, CISSO, CISA or CISSP, GCIA, OSCP and ITIL
* SDLC, and understand application security.
* Containerization and Development Security Operations
Benefits that make life better:
* Comprehensive Healthcare
* 401(k) with 100% company match; up to 5% vested
* Paid Time Off starting on day one
* Bonus opportunities
* Health- & Dependent Care Flexible Spending Accounts
* Short- & Long-Term Disability
* Life & AD&D Insurance
* Learning & Training opportunities
Raising the Standard of Excellence since 1911
With over a century of proven excellence, StandardAero has become an industry leader in MRO services and customized solutions in the aerospace field. Our shared values and learning-based culture inspire our team to exceed their potential and power our customers' missions worldwide. With on-the-job training, advancement opportunities, and excellent benefits, StandardAero invites you to experience a fulfilling and meaningful career with us.
Inclusivity Is Our Standard
It is StandardAero's policy to provide equal employment opportunities to all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information. Our supportive environment celebrates diversity with no room for harassment or discrimination of any kind. We invite you to bring your authentic self to our team and experience our welcoming culture.
Auto-ApplyComputer Systems Security Analyst - Splunk
Baltimore, MD jobs
Write complex SPL to develop Advanced Splunk Dashboards and Queries.
Perform on-boarding of data via Splunk Tools and Automation method.
Work with customers to develop custom content, maintaining consistently high quality communications with the Client.
Create Splunk Dashboards and Queries
Familiar with automating in Splunk
Develop scripts and code with security tools.
Develop processes and schedule to review existing methodologies and queries for all divisional metrics.
Become knowledgeable on the CDM technical requirements for the CDM program.
Involved in a wide range of security issues including architectures, firewalls, electronic data traffic, and network access.
Design, manage, and maintain agency SIEM infrastructure to improve data ingestion processes, including architectural work on data pipelines to ensure optimal flow of data.
Maintenance, configuration, and implementing products, appliances and devices on the network.
Required Candidate Qualifications:
US Citizenship Required and ability to obtain and maintain a Public Trust
Bachelors Degree and 7 experience; or Masters Degree and 5 years of relevant Cyber Security experience; or 11 years experience in lieu of Degree.
Active Splunk Core Certifications of User, Power User and Admin
Minimum 3 years of experience developing and tailoring reporting from network security tools.
At least 6 years experience using Splunk (specifically Splunk Scripting and on-boarding of large collection of meta data from different sources into Splunk.
At least 4 years of experience with:
In depth knowledge of designing, upgrading, maintaining, and implementing network devices on a large scale enterprise.
Coordination and communication with other remotely deployed team members
Developing documentation with processes and procedures.
Proposing, implementing automation features in a large enterprise environment.
At least 2 years experience with:
Splunk Enterprise Security product.
Risk-based Alerting.
Analytics Driven Security
CyberCore has, on many occasions, expressed support and commitment to the principles of diversity and equal employment opportunity. It is CyberCore's policy to recruit, hire, train, and promote individuals, as well as administer all personnel actions, without regard to race, color, national or ethnic origin, age, religion, disability, sex, sexual orientation, gender identity and expression, veteran status or any other characteristic protected under applicable federal or state law. CyberCore will not tolerate unlawful discrimination and any such conduct is prohibited. CyberCore is committed to ensuring that CyberCore's workforce and volunteers reflect America's diverse population. CyberCore knows that such diversity will enrich the company with the talent, energy, perspective and inspiration we need to achieve our mission.
Auto-ApplyInformation Security Specialist
Wallingford, CT jobs
Community Health Network of Connecticut, Inc. (CHNCT) is currently seeking an Information Security Specialist. This is a full-time, hybrid position requiring 2 days per week onsite in our Wallingford, CT office.
Primary Responsibilities:
Under the direction of the Director of Information Security, the Information Security Specialist is responsible for operations, auditing, and technical monitoring of CHNCT's Information Security and related activities.
These activities include but are not limited to implementing and maintaining Information Security related systems, policies and processes in compliance with applicable security regulations (i.e., HIPAA and State of CT Security laws), and establishing and developing security-related operating procedures and standards.
Works directly with contracted vendors for the implementation and maintenance of security hardware, software and services.
Assists with the selection and evaluation of security related state-of-the-art systems.
Tasks Performed:
Monitors and maintains all aspects of the information security program.
As a COMPUTER SECURITY INCIDENT RESPONSE TEAMS (CSIRT) member, logs and responds to incidents including communication of potential violations of the company's information security policies to CHNCT's Chief Information Security Officer.
Independently acts to prevent or deter security breaches or intrusions that threaten the integrity of mission critical data or applications.
Monitors email and Data Loss Prevention logs and responds to potential policy or regulatory violations.
Monitors Phishing alerts and end user notifications.
Audits network and file permissions structure and password and account maintenance.
Assists in the development and testing of the Disaster Recovery and Business Continuity Plans.
Processes exception requests and performs risk analysis on these and other customer requests.
Actively reviews threat alerts and determines relevance and criticality to the organization.
Contributes to project activities as a project team member or ad-hoc as requested.
Other duties as assigned.
Essential Functions:
Implementation and maintenance of Information security related software, hardware and systems.
Systems include but are not limited to phishing identification and prevention, Internet content filtering, Data Loss Prevention (DLP), Intrusion Detection/Prevention (IDS/IPS), Endpoint Detection and Response (EDR), Log Management, and Advanced Threat Mitigation.
Duties include information security policy administration and configuration, security related server management, Disaster Recovery Planning, proactively identifying or rapidly responding to customer security issues and security events.
Desired Education: 2 years post-secondary schooling
Desired Degree: Associate's degree
Desired Major: Computer Assurance or Computer Science
Desired Job Experience: 3+ years' direct information security experience, preferably in healthcare
Other Qualifications: Security+ or other security-related certification. Hands on exposure to providing information security operational support in a medium to large scale healthcare organization preferred. Knowledgeable in the management and setup of security related software and hardware Working knowledge of security administration, DLP, or other information security systems. Knowledge of EDR, EPP, IDS/IPS, AD and network infrastructure. Detail oriented, with meticulous attention to system and procedure documentation.
CHNCT Offers Great Benefits:
Medical, dental and vision coverage options
Flexible spending and health savings accounts
Group term life insurance
A 401(k) plan with company-match and immediate vesting
Voluntary accidental injury coverage
Tuition reimbursement and continuing education opportunities
A generous paid-leave bank and company holidays
Wellness program
We are dedicated to having a workplace where everyone feels valued, respected, and empowered to succeed. We embrace a wide range of perspectives and backgrounds, ensuring fair treatment and opportunities for all employees. We value our team's rich array of experiences and viewpoints, which contribute to our innovative and collaborative environment.
Auto-ApplyInformation Security Analyst 2
New Bremen, OH jobs
: Crown Equipment Corporation is a leading innovator in world-class forklift and material handling equipment and technology. As one of the world's largest lift truck manufacturers, we are committed to providing the customer with the safest, most efficient and ergonomic lift truck possible to lower their total cost of ownership.
Information Security Analyst 2
Job Duties
* Governance, Risk, & Compliance (GRC) Application Subject Matter Expert - Operate and maintain Company's Governance, Risk and Compliance (GRC) platform, its libraries, reports, portals, and data integrations to effectively support operations, data accuracy and user processes. Serve as the primary liaison for GRC software vendors, by maintaining contact with vendor representatives, submitting troubleshooting tickets and software feedback to improve the user experience. Support Company's Enterprise Risk Management, Compliance, Vendor Management, Business Continuity Planning, Information Technology and Security, Project Management and Audit Programs with data entry, maintenance, and configuration. Develop, maintain, and distribute custom and ad hoc reporting of risk data including taxonomy analytics and Key Risk Indicators (KRI's).
* Security Architecture & Control Design - Develop/integrate cybersecurity designs for systems and networks for the processing of company data. Document and address organization's information security, cybersecurity architecture, and systems security engineering requirements. Ensure that acquired or developed systems and architectures are consistent with company's cybersecurity architecture guidelines.
* Risk Assessment - Coordinate external risk assessments including audits, gap assessments, and penetration testing to evaluate security architectures and designs to determine the adequacy of security design and architecture. Determine protection needs (i.e., security controls) for company's information processing and document appropriately. Perform security reviews, identify gaps in security architecture, and develop a security risk management plan.
* Incident Response Communication- Coordinate communication and information sharing aspects of incident response. Draft messages and updates to internal and external audiences for Incident Response Team (IRT) review, such as employees, customers, partners, media, or public. Handle crisis management issues and provides guidance and education on incident prevention and response best practices. Perform other duties as assigned.
Minimum Qualifications
* 2-4 years related experience
* Associate's degree (Information Technology, Cyber Security, Computer Science)
* Non-degree considered if 6+ years of related experience along with a high school diploma (GED)
Preferred Qualifications
Intermediate knowledge of various Information Security & Privacy Frameworks such as the Secure Controls Framework, NIST CSF, NIST 800-171, NIST 800-53, NIST Privacy Framework, ISO-27001, ISO-27701, GDPR, US & other global privacy regulations. Work experience in other Information Technology disciplines such as software development, help desk, networking, systems administration or similar in conjunction with professional certifications such as CASP+, CISSP Associate, or AWS Associate Level Certifications. Intermediate level of knowledge in at least one scripting or software development language such as PowerShell, Bash, Java, or Python. Good written and oral communication skills, deductive reasoning, and analytical investigative skills. Good interpersonal skills to facilitate positive relations between business groups. Requires excellent verbal and written communication skills, as well as a knowledge of company's culture and values.
Work Authorization:
Crown will only employ those who are legally authorized to work in the United States. This is not a position for which sponsorship will be provided. Individuals with temporary visas or who need sponsorship for work authorization now or in the future, are not eligible for hire.
No agency calls please.
Compensation and Benefits:
Crown offers an excellent wage and benefits package for full-time employees including Health/Dental/Vision/Prescription Drug Plan, Flexible Benefits Plan, 401K Retirement Savings Plan, Life and Disability Benefits, Paid Parental Leave, Paid Holidays, Paid Vacation, Tuition Reimbursement, and much more.
EOE Veterans/Disabilities
Nearest Major Market: Lima
Nearest Secondary Market: Findlay
Job Segment: Information Security, Data Entry, Help Desk, Information Technology, Computer Science, Technology, Administrative
Information Security Analyst 2
New Bremen, OH jobs
: Crown Equipment Corporation is a leading innovator in world-class forklift and material handling equipment and technology. As one of the world's largest lift truck manufacturers, we are committed to providing the customer with the safest, most efficient and ergonomic lift truck possible to lower their total cost of ownership.
**Information Security Analyst 2**
**Job Duties**
+ Governance, Risk, & Compliance (GRC) Application Subject Matter Expert - Operate and maintain Company's Governance, Risk and Compliance (GRC) platform, its libraries, reports, portals, and data integrations to effectively support operations, data accuracy and user processes. Serve as the primary liaison for GRC software vendors, by maintaining contact with vendor representatives, submitting troubleshooting tickets and software feedback to improve the user experience. Support Company's Enterprise Risk Management, Compliance, Vendor Management, Business Continuity Planning, Information Technology and Security, Project Management and Audit Programs with data entry, maintenance, and configuration. Develop, maintain, and distribute custom and ad hoc reporting of risk data including taxonomy analytics and Key Risk Indicators (KRI's).
+ Security Architecture & Control Design - Develop/integrate cybersecurity designs for systems and networks for the processing of company data. Document and address organization's information security, cybersecurity architecture, and systems security engineering requirements. Ensure that acquired or developed systems and architectures are consistent with company's cybersecurity architecture guidelines.
+ Risk Assessment - Coordinate external risk assessments including audits, gap assessments, and penetration testing to evaluate security architectures and designs to determine the adequacy of security design and architecture. Determine protection needs (i.e., security controls) for company's information processing and document appropriately. Perform security reviews, identify gaps in security architecture, and develop a security risk management plan.
+ Incident Response Communication- Coordinate communication and information sharing aspects of incident response. Draft messages and updates to internal and external audiences for Incident Response Team (IRT) review, such as employees, customers, partners, media, or public. Handle crisis management issues and provides guidance and education on incident prevention and response best practices. Perform other duties as assigned.
**Minimum Qualifications**
+ 2-4 years related experience
+ Associate's degree (Information Technology, Cyber Security, Computer Science)
+ Non-degree considered if 6+ years of related experience along with a high school diploma (GED)
**Preferred Qualifications**
Intermediate knowledge of various Information Security & Privacy Frameworks such as the Secure Controls Framework, NIST CSF, NIST 800-171, NIST 800-53, NIST Privacy Framework, ISO-27001, ISO-27701, GDPR, US & other global privacy regulations. Work experience in other Information Technology disciplines such as software development, help desk, networking, systems administration or similar in conjunction with professional certifications such as CASP+, CISSP Associate, or AWS Associate Level Certifications. Intermediate level of knowledge in at least one scripting or software development language such as PowerShell, Bash, Java, or Python. Good written and oral communication skills, deductive reasoning, and analytical investigative skills. Good interpersonal skills to facilitate positive relations between business groups. Requires excellent verbal and written communication skills, as well as a knowledge of company's culture and values.
**Work Authorization:**
Crown will only employ those who are legally authorized to work in the United States. This is not a position for which sponsorship will be provided. Individuals with temporary visas or who need sponsorship for work authorization now or in the future, are not eligible for hire.
No agency calls please.
**Compensation and Benefits:**
Crown offers an excellent wage and benefits package for full-time employees including Health/Dental/Vision/Prescription Drug Plan, Flexible Benefits Plan, 401K Retirement Savings Plan, Life and Disability Benefits, Paid Parental Leave, Paid Holidays, Paid Vacation, Tuition Reimbursement, and much more.
EOE Veterans/Disabilities
Information Security Engineer
Greer, SC jobs
Proterra offers a dynamic and supportive workplace where our employees can thrive personally and professionally. With cutting-edge facilities and groundbreaking projects, Proterra offers unique opportunities to grow, collaborate, and lead transformative change in the electrification of heavy-duty transportation and equipment.
Our commitment to innovation extends beyond our battery solutions to our people, where we create an environment where everyone feels valued, supported, and empowered to drive change for the earth. Here at Proterra we strive to foster a culture of inclusivity, valuing diverse perspectives and encouraging bold ideas, allowing our employees to bring their full selves to work. Our employees benefit from competitive total rewards packages, and opportunities to develop professionally.
Position Overview:â¯
The Information Security Engineer will be responsible for developing, enhancing, and executing Information Security Operations at Proterra.⯠In this position you will assist with the maintenance and implementation of IT security systems to protect Proterra's corporate, manufacturing, cloud and IoT environments from cyber-attacks. You will maintain and lead incident response and escalations with our security operations center, be responsible for vulnerability management and participate in the creation or improvement of company security policies/ procedures.⯠You will be responsible for conducting/leading risk assessments and participating in and supporting security assessments and audits. Additionally, you will be assisting with evaluation, setup and utilization of new security products and technologies.â¯
About the Role - You will:â¯
Identify and analyze potential threat activity targeting client networks via monitoring systems, alerts, vulnerabilities, SIEM tools and network traffic and respond for immediate remediation.
Work with cross functional teams to support security requirements to protect organization's corporate, manufacturing, cloud and IoT environments from cyber-attacks.
Oversee and maintain existing security tools as well as overall enterprise security systems that include network and/or host-based intrusion detection systems, anti-virus/advanced EDR, SIEM/event correlation, file integrity monitoring, full packet captures, computer forensics, encryption, vulnerability management, data loss prevention and application scanning.â¯
Responsible for the coordination and actions needed for remediation generated by incident reports and manufacture recommended patching and hotfixes.
Identify and analyze potential threat activity targeting client networks via monitoring systems, alerts, vulnerabilities, SIEM tools and network traffic and respond for immediate remediation.
Work with cross functional teams to support security requirements to protect organization's corporate, manufacturing, cloud and IoT environments from cyber-attacksâ¯â¯
Oversee and maintain existing security tools as well as overall enterprise security systems that include network and/or host-based intrusion detection systems, anti-virus/advanced EDR, SIEM/event correlation, file integrity monitoring, full packet captures, computer forensics, encryption, vulnerability management, data loss prevention and application scanning.â¯
Responsible for the coordination and actions needed for remediation generated by incident reports and manufacture recommended patching and hotfixes.
Assist Crowdstrike Falcon Complete team in remediation of critical information security incidents in coordination with 3rd party SOC team.â¯
Implement and maintain security controls and have a suitable knowledge of existing cyber threats to infrastructure and clouded environments.â¯
Participate in scheduled security assessment activities and projects to ensure industry compliance.â¯
Initiate and maintain Security Incident Response Plan (SIRT) and After-Action Reports (AARs) to maintain operational continuityâ¯
Identify, analyze and interpret threat actors and malicious activity in client environments act upon and take the appropriate actions towards remediation and documentation.â¯
Differentiate between potential intrusion attempts and pinpoint false alarmsâ¯by working with EDR, Identity Protection and NextGen SIEM to develop resolution plans.
Perform 3rd party vendor assessments and fulfill Proterra security assessments requirements
Triage and respond to security events - serve as a primary responder for incidents, taking ownership of incidents and tracking through resolution.â¯
Performs other related duties as assigned.â¯
Your Experience Includes:
3-5 years of related information technology infrastructure experience⯠with identity and access management [IAM], SSO solutions including (SAML 2, OAuth 2, OIDC).
Some experience in securing enterprise networks, including firewalls, VPNs, intrusion detection/prevention systems (IDS/IPS), and secure network protocols (e.g., IPsec, SSL/TLS) heavy emphasis in SaaS apps such as Crowdstrike Falcon Complete, Netskope DLP, Nessus Tenable and asset management platforms such as Axionus.
Overall Knowledge of endpoint protection technologies (e.g., anti-malware, EDR, DLP), and experience in managing and securing workstations, mobile devices, and servers.
Have participated in penetration testing, vulnerability assessments, and red teaming exercises.
General understating of industry standards, compliance, and legal requirements (ISO 27001, FedRAMP, NIST 800-171, NIST 800-53, SOC2, etc.)â¯
Excellent trouble-shooting abilities in software and hardware and be able to lead outage calls and trouble-shooting conversations until resolved and provide detailed root cause analysis reports.â¯
Above average understanding in vulnerability reporting using Saas platforms such as Nessus Tenable.
Education:
Bachelor's degree in computer science, Information Security, Electrical Engineering or Management Information Systems preferred. Equivalent years of consecutive IT security experience with recognized industry certifications may be considered.
Certifications:
CISSP, CASP+, SSCP+, or other relevant security certificatesâ¯
Certified Ethical Hacking (CEH) CISSP, CISA
Network+, Security+, Linux+ or combination of similar certificates acceptable.
Applicants must be authorized to work for any employer in the U.S. There is no immigration sponsorship available for this role (ex: H1-B, OPT, CPT, TN or any other employment sponsorship).â¯
#LI-BJ1
Information Security Engineer
Greer, SC jobs
Proterra offers a dynamic and supportive workplace where our employees can thrive personally and professionally. With cutting-edge facilities and groundbreaking projects, Proterra offers unique opportunities to grow, collaborate, and lead transformative change in the electrification of heavy-duty transportation and equipment.
Our commitment to innovation extends beyond our battery solutions to our people, where we create an environment where everyone feels valued, supported, and empowered to drive change for the earth. Here at Proterra we strive to foster a culture of inclusivity, valuing diverse perspectives and encouraging bold ideas, allowing our employees to bring their full selves to work. Our employees benefit from competitive total rewards packages, and opportunities to develop professionally.
Position Overview:
The Information Security Engineer will be responsible for developing, enhancing, and executing Information Security Operations at Proterra. In this position you will assist with the maintenance and implementation of IT security systems to protect Proterra's corporate, manufacturing, cloud and IoT environments from cyber-attacks. You will maintain and lead incident response and escalations with our security operations center, be responsible for vulnerability management and participate in the creation or improvement of company security policies/ procedures. You will be responsible for conducting/leading risk assessments and participating in and supporting security assessments and audits. Additionally, you will be assisting with evaluation, setup and utilization of new security products and technologies.
About the Role - You will:
* Identify and analyze potential threat activity targeting client networks via monitoring systems, alerts, vulnerabilities, SIEM tools and network traffic and respond for immediate remediation.
* Work with cross functional teams to support security requirements to protect organization's corporate, manufacturing, cloud and IoT environments from cyber-attacks.
* Oversee and maintain existing security tools as well as overall enterprise security systems that include network and/or host-based intrusion detection systems, anti-virus/advanced EDR, SIEM/event correlation, file integrity monitoring, full packet captures, computer forensics, encryption, vulnerability management, data loss prevention and application scanning.
* Responsible for the coordination and actions needed for remediation generated by incident reports and manufacture recommended patching and hotfixes.
* Identify and analyze potential threat activity targeting client networks via monitoring systems, alerts, vulnerabilities, SIEM tools and network traffic and respond for immediate remediation.
* Work with cross functional teams to support security requirements to protect organization's corporate, manufacturing, cloud and IoT environments from cyber-attacks
* Oversee and maintain existing security tools as well as overall enterprise security systems that include network and/or host-based intrusion detection systems, anti-virus/advanced EDR, SIEM/event correlation, file integrity monitoring, full packet captures, computer forensics, encryption, vulnerability management, data loss prevention and application scanning.
* Responsible for the coordination and actions needed for remediation generated by incident reports and manufacture recommended patching and hotfixes.
* Assist Crowdstrike Falcon Complete team in remediation of critical information security incidents in coordination with 3rd party SOC team.
* Implement and maintain security controls and have a suitable knowledge of existing cyber threats to infrastructure and clouded environments.
* Participate in scheduled security assessment activities and projects to ensure industry compliance.
* Initiate and maintain Security Incident Response Plan (SIRT) and After-Action Reports (AARs) to maintain operational continuity
* Identify, analyze and interpret threat actors and malicious activity in client environments act upon and take the appropriate actions towards remediation and documentation.
* Differentiate between potential intrusion attempts and pinpoint false alarms by working with EDR, Identity Protection and NextGen SIEM to develop resolution plans.
* Perform 3rd party vendor assessments and fulfill Proterra security assessments requirements
* Triage and respond to security events - serve as a primary responder for incidents, taking ownership of incidents and tracking through resolution.
* Performs other related duties as assigned.
Your Experience Includes:
* 3-5 years of related information technology infrastructure experience with identity and access management [IAM], SSO solutions including (SAML 2, OAuth 2, OIDC).
* Some experience in securing enterprise networks, including firewalls, VPNs, intrusion detection/prevention systems (IDS/IPS), and secure network protocols (e.g., IPsec, SSL/TLS) heavy emphasis in SaaS apps such as Crowdstrike Falcon Complete, Netskope DLP, Nessus Tenable and asset management platforms such as Axionus.
* Overall Knowledge of endpoint protection technologies (e.g., anti-malware, EDR, DLP), and experience in managing and securing workstations, mobile devices, and servers.
* Have participated in penetration testing, vulnerability assessments, and red teaming exercises.
* General understating of industry standards, compliance, and legal requirements (ISO 27001, FedRAMP, NIST 800-171, NIST 800-53, SOC2, etc.)
* Excellent trouble-shooting abilities in software and hardware and be able to lead outage calls and trouble-shooting conversations until resolved and provide detailed root cause analysis reports.
* Above average understanding in vulnerability reporting using Saas platforms such as Nessus Tenable.
Education:
* Bachelor's degree in computer science, Information Security, Electrical Engineering or Management Information Systems preferred. Equivalent years of consecutive IT security experience with recognized industry certifications may be considered.
Certifications:
* CISSP, CASP+, SSCP+, or other relevant security certificates
* Certified Ethical Hacking (CEH) CISSP, CISA
* Network+, Security+, Linux+ or combination of similar certificates acceptable.
Applicants must be authorized to work for any employer in the U.S. There is no immigration sponsorship available for this role (ex: H1-B, OPT, CPT, TN or any other employment sponsorship).
#LI-BJ1