Post job

Information Security Engineer jobs at Brown-Forman

- 10 jobs
  • Senior Cyber Security Engineer

    Markon 3.7company rating

    Springfield, VA jobs

    Eager to join a team where your skills are valued, your growth is nurtured, and your impact is profound? Look no further than Markon, a premier consulting firm deeply dedicated to advancing our nation's most critical missions. At Markon, we don't just offer jobs - we offer opportunities for personal and professional transformation. Empowering our employees to lead, innovate, and excel, we foster an environment where new ideas are not just welcomed but celebrated. As a perennial Washington Post Top Workplace, we prioritize the well-being and success of our team members, ensuring they can bring their best selves to work. Headquartered in Falls Church, Virginia, Markon has garnered national recognition for our unwavering dedication to excellence in serving the intelligence community, as well as federal civilian and defense agencies. Our growing reach extends across 17 states, 116 countries, and 5 continents, where our team of dynamic professionals collaborates to deliver unparalleled program and project management services. Markon values people and the tremendous impact each individual can make - which is why we're consistently recognized as one of the best places to work in federal government consulting. Here, you can help solve the nation's most important challenges, surrounded by colleagues who help you grow, advance, and succeed. We are deeply dedicated to what matters - bringing out the best in each other to advance our clients' missions. Join us and make a meaningful impact. Markon is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, national origin, age, protected veteran status, or disability status. This job posting will remain open until the position is filled. Benefits Offered: Medical, Dental, Vision, Life Insurance, Short-Term Disability, Long-Term Disability, 401(k) match, Flexible Spending Accounts, EAP, Training and Tuition Assistance, Paid Time Off, and Holidays Description Markon is seeking a Senior level Cyber Security Engineer to support our NGA client out of Springfield, VA. Responsibilities Technical Analysis & System Design Analyze user needs and software requirements to determine design feasibility within time and cost constraints. Evaluate information to recommend and plan computer specifications, system layouts, and peripheral equipment modifications. Review and refine existing programs to reduce operating time, increase efficiency, and improve techniques. Collaborate with systems analysts, engineers, programmers, and other stakeholders to design systems and define performance requirements, capabilities, and interfaces. Gather and assess information on reporting formats, costs, and security needs to determine optimal hardware configurations. Estimate software development costs and schedules. Consult with customers on software system design, development, and maintenance. Work with engineering teams to evaluate hardware/software interfaces, define specifications, set performance requirements, and resolve customer issues. Partner with data processing and project managers to understand project limitations, capabilities, and requirements. Prepare detailed reports and correspondence outlining project specifications, activities, progress, and status. Evaluate cost, reporting, and security factors to ensure hardware configurations align with project goals. Security System Design & Deployment Implement and upgrade new security assets-including software, hardware, and network security components-in virtual and/or physical environments. Security Maintenance Maintain and repair existing security systems, performing replacements or upgrades as needed. Vulnerability Management Conduct system scans and simulations to identify weaknesses in IT infrastructure and develop mitigation strategies. Reporting & Recommendations Document findings from security tests or breaches and present actionable recommendations for security enhancements to management. Policy & Procedure Development Develop, implement, and manage security policies and best practices to prevent future incidents and strengthen organizational resilience. Qualifications Required: An active TS/SCI with a CI Polygraph (preferrably from this client) Any clearances requiring a crossover to this agency must have a recent polygraph administered within the last 5 years. Ability to pass and maintain a CI polygraph examination may be considered for the right candidate. Bachelor's degree or higher in Systems Engineering or in related technical or scientific fields. 12+ years of total working experience (preferably in government) in one or more of the following work areas including: Engineering and Technology, This is the highly preferred skillset for this role, Policy and Administration, Program Management, Planning and Analysis, Training and Development, Facilities Management, Communications and Visual Design, Human Capital, Business Operations. Strong knowledge of: Network Protocols (TCP/IP, IPSec), Firewalls, Encryption, Intrusion detection systems. Experience in Remote Sensing, Photogrammetry, or Image Science. Demonstrated experience delivering strategic guidance and direction in high-technology programs. Previous NGA and/or NSG/ASG program/project work experience. Desired: Master's degree or higher in Remote Sensing, Photogrammetry, Image Science, Computer Science, Data Science, Engineering, Information Technology, Management Information Systems, Geographic Information Systems, Geography, or a related discipline. Additional Ceritifications: Security+, CISSP, Cloud Certifications (AWS, Azure), Server Certifications (Windows / Linux). Experience with Project management software (e.g., Microsoft Project, Primavera) Experience with Financial tracking tools Experience with Customer Relationship Management (CRM) systems Experience with Enterprise Resource Planning (ERP) systems Demonstrated knowledge of the current NSG/ASG and NRO enterprises. Advanced Experience: Senior-level experience in the engineering, design, and analysis of IT or related systems, including all phases of design, development, analysis, documentation, and creation of standards and guidelines. Senior-level experience with DoD/IC acquisition processes or Planning, Programming, Budgeting, and Execution System (PPBES). Working knowledge of Model-Based Systems Engineering (MBSE), including relevant processes, tools, and languages. Experience applying Agile software development methodologies. Salary Range USD $140,000.00 - USD $180,000.00 /Yr. The Markon pay range for this position is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
    $140k-180k yearly Auto-Apply 19d ago
  • Principal Security Architect

    KFC 4.2company rating

    Louisville, KY jobs

    Yum! Brands is seeking a Principal-level Senior Security Architect to shape enterprise security architecture across our global ecosystem (KFC, Pizza Hut, Taco Bell, The Habit Burger Grill). In this role, you tackle unique, enterprise-wide problem spaces, anticipating future risks and setting strategic recommendations that guide multi-year roadmaps. You will operate with limited oversight, aligning outcomes through consultation with your coach and stakeholders. Your decisions will influence multiple functions and cross-brand programs. You will establish secure-by-design guardrails that accelerate delivery while reducing risk, and mentor Staff/Principal architects and senior engineers to raise the bar across the organization. Preferred Qualifications CISSP, CCSP, CISM, AWS/Azure/GCP Security Specialty, TOGAF, or SABSA certifications. Experience in regulated or high-scale environments (retail/QSR, payments, consumer data). Demonstrated impact establishing enterprise guardrails, control libraries, and architecture governance. Salary Range: $ 169,900-195,000 annually + bonus eligibility and stock-based compensation. This is the expected salary range for this position. Ultimately, in determining pay, we'll consider the successful candidate's location, experience, and other job-related factors. Key Responsibilities Security Architecture & Design Author reusable reference architectures, patterns, blueprints, and decision frameworks. Lead end-to-end reviews and threat modeling for complex, cross-brand initiatives; resolve novel challenges with broad business impact and drive clarity amid uncertainty. Establish pragmatic architecture governance (principles, patterns, review mechanisms) that balances innovation with risk reduction; translate strategy into roadmaps and measurable outcomes (OKRs/KPIs). Translate strategy into actionable roadmaps and multi-year control adoption plans; measure outcomes with meaningful KPIs. Cloud Security & DevSecOps Define enterprise guardrails for AWS/Azure/GCP (landing zones, identity boundaries, network baselines, encryption, logging) and guide adoption at scale. Integrate security into CI/CD (SAST, DAST, IaC scanning, policy-as-code, artifact signing, SBOMs); influence platform roadmaps for secure delivery velocity. Advance container/Kubernetes security (runtime controls, supply-chain security, secrets management) and coach platform/product teams on cloud-native practices. Serve as principal consultant for complex cloud decisions; decisions typically span multiple departments/functions. Identity, Access & Zero Trust Architect Zero Trust across workforce, workloads, and data; mature segmentation, continuous verification, and strong authentication. Guide enterprise IAM patterns (SSO, MFA, RBAC/ABAC, PAM) and standardize access models for least privilege at scale. Partner with platform and identity teams to modernize federation and entitlement lifecycle. Data, Network & Detection Define enterprise data protection strategy (classification, end-to-end encryption, tokenization, key management, data residency) with cross-functional impact. Lead segmentation and secure access patterns aligned to Zero Trust; evolve secure edge and private access. Raise the quality of telemetry and detection engineering (logging standards, SIEM/XDR) with detections mapped to MITRE ATT&CK. Risk, Compliance & Vendor/SaaS Align architectures to PCI, SOX, GDPR, and internal risk frameworks; recommend practical compensating controls when constraints exist. Lead security assessments for emerging technology and third-party platforms; negotiate security outcomes with vendors. Communicate tradeoffs and risks to senior technical and business leaders; influence investment decisions and sequencing. Leadership, Autonomy & Influence Serve as a primary representative for Security Architecture in enterprise forums and technical councils; decisions typically affect multiple functions. Operate with limited supervision, using judgment in ambiguous situations; outcomes are reviewed via consultation and alignment. Mentor Staff/Principal architects and senior engineers; lead communities of practice; drive continuous improvement with metrics, threat intelligence, and post-implementation reviews.
    $99k-141k yearly est. Auto-Apply 51d ago
  • Information Systems Security Engineer (ISSE)

    Markon 3.7company rating

    Chantilly, VA jobs

    Eager to join a team where your skills are valued, your growth is nurtured, and your impact is profound? Look no further than Markon, a premier consulting firm deeply dedicated to advancing our nation's most critical missions. At Markon, we don't just offer jobs - we offer opportunities for personal and professional transformation. Empowering our employees to lead, innovate, and excel, we foster an environment where new ideas are not just welcomed but celebrated. As a perennial Washington Post Top Workplace, we prioritize the well-being and success of our team members, ensuring they can bring their best selves to work. Headquartered in Falls Church, Virginia, Markon has garnered national recognition for our unwavering dedication to excellence in serving the intelligence community, as well as federal civilian and defense agencies. Our growing reach extends across 17 states, 116 countries, and 5 continents, where our team of dynamic professionals collaborates to deliver unparalleled program and project management services. Markon values people and the tremendous impact each individual can make - which is why we're consistently recognized as one of the best places to work in federal government consulting. Here, you can help solve the nation's most important challenges, surrounded by colleagues who help you grow, advance, and succeed. We are deeply dedicated to what matters - bringing out the best in each other to advance our clients' missions. Join us and make a meaningful impact. Markon is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, national origin, age, protected veteran status, or disability status. This job posting will remain open until the position is filled. Benefits Offered: Medical, Dental, Vision, Life Insurance, Short-Term Disability, Long-Term Disability, 401(k) match, Flexible Spending Accounts, EAP, Training and Tuition Assistance, Paid Time Off, and Holidays Description Markon is seeking an experienced Information Systems Security Engineer to support an Intelligence customer Responsibilities SME level knowledge of Risk Management Framework and manage [potential] systems through the full Lifecyle of RMF Communicate system complexities with Assessors and ISSMs Prepares security test and evaluation plans. Provides certification and accreditation support in the development of security and contingency plans and conducts complex risk and vulnerability assessments. Analyzes policies and procedures against Federal laws and regulations and provides recommendations for closing gaps. Recommends system enhancements to improve security deficiencies. Develops, tests, and integrates computer and network security tools. Secures system configurations and installs security tools, scans systems to determine compliancy and report results and evaluates products and various aspects of system administration. Conducts security program audits and develops solutions to lessen identified risks. Provides information assurance support for the development and implementation of security architectures to meet new and evolving security requirements. Performs vulnerability assessments including development of risk mitigation strategies. Prepares systems Assessment and Authorization (A&A) documents and procedures. Interface with other IA team members, other security disciplines (industrial security, physical security, special programs security, etc.), program personnel, and Government security representatives. Initiate vulnerability and compliance scan Manage rick/threat mitigation/remediation Tailor systems A&A documents to unique environments and requirements Successfully work through POAMs with Developers, Engineers, and various groups Conduct the full spectrum system Continuous Monitoring Experienced user of Splunk, Rapid7, and other monitoring and auditing systems or software Conduct various roles and responsibilities in Cloud computing environment Ensure the system security documentation, is developed, maintained, reviewed, and updated on a continuous basis Qualifications Bachelors and 8+ years of experience OR Masters and 6+ years of experience OR PhD and 3+ years of experience; an additional four years of experience may be considered in lieu of degree Risk Management Framework and Assessment and Authorization processes and related policies Exceptional written and verbal communication skills Familiarity with cloud computing and related security concepts Working knowledge of digital communications and related IT communications technologies Direct experience with patch management, continuous monitoring, and vulnerability scanning/remediation activities Active TS/SCI FS Polygraph Security clearance Salary Range USD $165,000.00 - USD $205,000.00 /Yr. The Markon pay range for this position is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
    $165k-205k yearly Auto-Apply 12d ago
  • Sr Target Security Specialist

    Dev 4.2company rating

    Minneapolis, MN jobs

    Company DescriptionJobs for Humanity is partnering with Target to build an inclusive and just employment ecosystem. Therefore, we prioritize individuals coming from the following communities: Refugee, Neurodivergent, Single Parent, Blind or Low Vision, Deaf or Hard of Hearing, Black, Hispanic, Asian, Military Veterans, the Elderly, the LGBTQ, and Justice Impacted individuals. This position is open to candidates who reside in and have the legal right to work in the country where the job is located. Company Name: Target Location: 1000 Nicollet Mall, Minneapolis, Minnesota, United States, 55403-2542 The pay range per hour is $19.23 - $34.62 Pay is based on several factors which vary based on position. These include labor markets and in some instances may include education, work experience and certifications. In addition to your pay, Target cares about and invests in you as a team member, so that you can take care of yourself and your family. Target offers eligible team members and their dependents comprehensive health benefits and programs, which may include medical, vision, dental, life insurance and more, to help you and your family take care of your whole selves. Other benefits for eligible team members include 401(k), employee discount, short term disability, long term disability, paid sick leave, paid national holidays, and paid vacation. Find competitive benefits from financial and education to well-being and beyond at ********************************************** Job Title: Sr Specialist - Corporate Security & Safety Classification: L2 Date: November 2023 About Us: As a Fortune 50 company with more than 350,000 team members worldwide, Target is an iconic brand and one of America's leading retailers. Working at Target means the opportunity to help all families discover the joy of everyday life. Caring for our communities is woven into who we are, and we invest in the places we collectively live, work and play. We prioritize relationships, fuel and develop talent by creating growth opportunities, and succeed as one Target team. At our core, our purpose is ingrained in who we are, what we value, and how we work. It's how we care, grow, and win together. To match the signature style and passion of Target's distinctive retail brand, Target Legal Affairs is a dynamic and deeply knowledgeable team of experts. Whether specializing in law, government affairs, employee relations, risk, compliance, ethics, security or food safety, we use our expertise and influence to advocate for Target, support Target's business and mitigate risk for the company. We work with both internal and external entities on key issues that affect Target's ability to productively, ethically and securely conduct business. Through our understanding of Target's business models and operations, we help facilitate Target's growth, and provide guidance that leaders rely on to make appropriate, well-informed decisions. Simultaneously, we help protect the business by applying our comprehensive understanding of risk and the law on issues that impact our brand, guests, team members, stores, distribution centers and corporate locations. Here, you'll enjoy working autonomously with a healthy work-life balance. Your passion for learning the business, collaborating with others and building relationships with senior leaders and key business partners that you support will be essential to tackling the ever-changing legal and risk-based challenges we face in a dynamic and fast-paced retail environment. A role within Corporate Security means working with a team dedicated to protecting the Target team, guests, property, and brand. You will use our comprehensive understanding and management of evolving security risks to protect our Target community throughout the world. You may support Target's Crisis and Threat Management, Preparedness and Continuity, Forensics, Intelligence, Physical Security and Safety, Executive Services, or Operations teams. As a Target Sr. Security Specialist, no two days are ever the same, but a typical day will most likely include the following responsibilities. You'll support safe and secure operations by engaging with team members, partners, and guests at entry points of our buildings. Leveraging Target's policies and procedures, you'll provision building access to all our Target community members. Using intelligence-led tactics and remaining situationally aware, you'll maintain safe and secure standards throughout our buildings and properties. In addition, you'll respond to and accurately document security incidents and activities, sharing your expertise to educate and empower team members on what to do during emergencies. Furthering our culture of ethical conduct, safety, and compliance, you'll encourage team members to report security concerns to Corporate Security. You'll also execute select security routines and projects that advance our goal to minimize risk at Target. Lastly, you'll provide a Target-brand experience and environment by supporting the needs of others. Core responsibilities of this job are described within this job description. Job duties may change at any time due to business needs. About you: High school diploma or equivalent. Possess a valid driver's license and ability to complete routines and patrols utilizing a company vehicle. Meet any state or local licensure and/or other legal requirements related to the position. Welcoming and helpful attitude towards team members, partners, and guests. Learn and adapt to current technology needs and changing work environments. Effective communication and de-escalation skills. Work both independently and with a team. Manage workload and prioritize tasks independently during crisis situations. Be reliable and dependable as it relates to assigned tasks. Trustworthy to work with highly confidential information. Climb up and down stairs and ladders. Provide life-saving actions, including CPR and other first aid. Ability to sit, stand, or be mobile for extended periods of time and effectively move items up to 40 pounds. Flexibility to work a set schedule and adjust as business needs dictate, with regular attendance necessary. Americans with Disabilities Act (ADA) Target will provide reasonable accommodations with the application process upon your request as required to comply with applicable laws. If you have a disability and require assistance in this application process, please visit your nearest Target store or Supply Chain Facility or reach out to Guest Services at ************** for additional information.
    $19.2-34.6 hourly 60d+ ago
  • Sr. Cyber Security Engineer NSE-710

    ICES 4.7company rating

    Chantilly, VA jobs

    Join ICES on a new contract impacting national security as a Sr. Cyber Security Engineer These positions are located in Chantilly, VA. All positions require an active/current TS/SCI security clearance and be willing and able to pass an additional polygraph as needed. As a Sr. Cyber Security Engineer, specific responsibilities include, but are not limited to: Duties: Guide and assist development teams working to design and develop information systems or upgrade legacy systems. Guide and assist product research and support AoA activities that independently identify the most appropriate security solutions. Develop system concepts, contribute to the capability phase of the systems development lifecycle, and translate technology and environmental conditions (e.g., law and regulation) into system security designs and processes. Guide and assist development and documentation of Security Architectures, Roadmaps, and investments. Interface directly with government and contractor cyber security personnel on behalf of the SAM Office. Develop cyber security documentation for SAM Tools in accordance with NGA cyber security processes as directed by NGA cyber security personnel on behalf of the SAM Office. Respond to NGA cyber security office inquiries and requests for documentation regarding SAM Tools and NGA's software inventory on behalf of the SAM Office. Required Qualifications: Bachelor's degree or higher in Engineering, Computer Science, Information Technology, Management Information Systems, or related STEM degree. Demonstrated senior-level experience in government or industry within Cyber Security Engineering. Possess a DoD 8570 Level II (IASAE) certification. Demonstrated senior-level experience in government and/or industry software procurement and management relevant work areas. Desired Qualifications: Master's degree or higher in Engineering, Computer Science, Information Technology, Management Information Systems, or related STEM degree. Demonstrated senior-level experience in government or industry supporting enterprise-level cyber security efforts involving architecting, designing, development, and configuration of cloud and on premise based systems and software. Demonstrated senior-level experience engineering Cyber Security solutions using structured and unstructured Big Data, AAA technologies, and Cloud Based technology, to include one or more of the following: Service Orientated Architecture (SOA), On-demand self-service, Broad network access, Resource pooling, Rapid elasticity, Measured Service, Software as a Service (SaaS), Platform as a Service (PaaS), Infrastructure as a Service (IaaS).
    $82k-108k yearly est. 60d+ ago
  • Senior Security Consultant Project Manager

    GHD 4.7company rating

    Chantilly, VA jobs

    Organisations don't innovate, people do. As part of our digital transformation business, you'll help clients unlock innovation, embrace the future and change communities for good. And we'll help you stimulate new thinking, accelerate your career and connect you to projects that really matter. Join our team of over 600 data scientists, design thinkers, immersive digital consultants, project managers and innovators, all working to create positive change for generations to come. Who are we looking for? Our Southeast Property & Buildings business is looking for a Senior Security Consultant Project Manager based in Chantilly, VA or Washington, DC to designing cutting-edge Electronic Security Systems (ESS) that make a real impact. We're looking for a dynamic professional to lead the design and coordination of systems including Access Control (ACS), Video Surveillance (VASS/CCTV), Intrusion Detection (IDS), vehicle barrier controls, and 2-way intercoms. In this role, you'll collaborate with architectural and engineering teams to develop construction drawings, specifications, and cost estimates from conceptual design through construction documents, construction administration, and project closeout. You'll bring creative, project-specific solutions to life while managing multi-discipline projects and engaging with stakeholders across regions. From proposal development to execution, you'll play a key role in delivering high-quality, innovative security solutions that serve our clients and communities locally and globally. Responsibilities Recommendations: Recommend changes to policies, processes, standards, and practices that would improve operational support. Needs Assessment: Uncover emerging issues or needs, identifying potential causes, barriers, and key stakeholders, as well as related issues. Solutions Analysis: Identify and evaluate complex, expertise-led solutions against a range of criteria to find the ones that best meet business needs. Improvement/Innovation: Identify shortcomings in existing business practices, then suggest and implement improvements while developing and delivering projects or a work stream within the organization's change management program. Involves working with guidance from senior colleagues. Knowledge Management System: Manage the knowledge management system with guidance from senior colleagues. May involve responsibility for the development or operation of the system. Business Requirements Identification: Elicit complex business requirements using a variety of methods, such as interviews, document analysis, workshops, and workflow analysis, to express the requirements in terms of target user roles and goals. Feasibility Studies: Conduct complex feasibility studies from a technological and organizational perspective and document findings to complete cost-benefit analysis on implementing changes to business processes, products, or business unit structure. Contract Management: Manage a portfolio of contracts and negotiate service-level agreements. Will also plan, coordinate, and supervise activities relating to major contracts. Policy Development and Implementation: Develop procedures and interpret and apply policy for area of expertise to achieve specified outputs, or advise the wider business on application of policy, then monitor implementation of those procedures within the organization. Product and Solution Development: Analyze and evaluate the feasibility and relevance of proposed complex products and services and develop and amend, as necessary, with guidance from senior colleagues. May also be responsible for supervising activities performed by a product development or specialist team. Project Management: Manage a portfolio of projects while reporting to senior colleagues. Client & Customer Management (External): Manage important client relationships with guidance from senior colleagues, or oversee relationship management with a group of more transactional clients and customers. What will you bring to the team?: Bachelor's degree in related field or proven equivalent combination of education, skills, knowledge, abilities, and experience. Electrical Engineering degree a plus Ability to work independently in Autodesk Revit required, 5+ Years experience a plus ASIS PSP Required ASIS CPP a plus Completed the Software House C-Cure 9000 Applications Engineer/Consultant training 10+ years of relevant recent security consulting experience Experience with ATFP and CPTED Expert knowledge of industry leading access control, camera, NVR, video analytics, network, PLC, and intercom systems Strong project management skills, managing discipline specific and multi-disciplinary projects on time and within budget, while exceeding client expectations Working knowledge of state and national building and energy codes and standards Highly developed communication skills, both oral and written, including client facing engagement, working well within team structures, and a proven ability to develop, mentor and collaborate with technical teammates. Federal Government DoD and civilian agencies' project and client experience a plus Understanding of project management software tools; BST experience a plus Ability to be proactive and take ownership of the task involved Active member of relevant industry associations and communities Networking experience is a plus Limited travel outside of the Washington D.C. area is anticipated, but may be deemed necessary by project #LI-NB1 As a multicultural organization, we encourage individual achievement and recognize the strength of a diverse workforce. GHD is an equal opportunity employer. We provide equal employment opportunities to all qualified employees and applicants without regard to race, color, religion, genetic information, national origin, sex (including same sex), sexual orientation, gender identity, pregnancy, childbirth, or related medical conditions, age, disability or handicap, citizenship status, service member status, or any other category protected by federal, state, or local law.
    $105k-142k yearly est. Auto-Apply 60d+ ago
  • Lead Adversarial Security Engineer

    Trellix 4.1company rating

    Richmond, VA jobs

    **_Job Title:_** Lead Adversarial Security Engineer **About** **Trellix:** **Trellix, the trusted CISO ally, is redefining the future of cybersecurity and soulful work.** Our comprehensive, GenAI-powered platform helps organizations confronted by today's most advanced threats gain confidence in the protection and resilience of their operations. Along with an extensive partner ecosystem, we accelerate technology innovation through artificial intelligence, automation, and analytics to empower over 53,000 customers with responsibly architected security solutions. We also recognize the importance of closing the 4-million-person cybersecurity talent gap. We aim to create a home for anyone seeking a meaningful future in cybersecurity and look for candidates across industries to join us in soulful work. More at ************************ . **_Role Overview:_** Trellix is seeking an Adversarial Security Engineer to lead the evolution of its cybersecurity posture. This is a senior, hands-on, remote-first role for a red/blue/purple expert who possesses a valuable blend of offensive tradecraft and defensive-engineering skills. **Role Overview:** As a lead member of the security operations team, and reporting to the Deputy CISO the mission of this role is to bridge the gap between "what if" and "what is" to continuously test the organization's defenses, find gaps, and personally lead the engineering effort to close them. By collaborating with the Security Operations Center (SOC), Threat Intelligence, and infrastructure teams, this expert will act as a force multiplier, mentoring junior security operations staff and providing the technical leadership to measurably improve the ability to detect and respond to advanced threats. **About the role:** + Plan and execute sophisticated, end-to-end red team engagements against our on-premise and cloud infrastructure. + Develop and validate new detection logic, transforming the results of your own attacks into high-fidelity alerts. + Lead continuous purple team exercises, acting as the primary bridge between the SOC, Threat Intelligence, and Detection Engineering teams. + Leverage Attack Surface Management (ASM) data to find "Shadow IT" and prioritize your offensive operations based on the most likely and impactful attack vectors. + Act as a senior technical leader, mentoring SOC analysts and junior engineers on advanced attack chains, detection theory, and defensive best practices. + Communicate complex findings and remediation strategies to a wide range of stakeholders, from highly technical engineers to executive leadership. **About you:** + You have a blended career path of 7+ years, demonstrating experience in both offensive security (like Red Teaming) and defensive operations (like Detection Engineering or Threat Hunting). + You possess exceptional communication skills, with an ability to create reports and presentations for both highly technical and executive audiences. + You are a U.S. citizen. + Your technical expertise is built on a deep, practical understanding of frameworks like MITRE ATT&CK and the Diamond Model. + You have proficiency in modern offensive tools and C2 frameworks (e.g., Cobalt Strike, Metasploit) and/or experience developing custom attack methods to evade EDR and network controls. + You are proficient in writing, tuning, and validating detection logic in SIEM and EDR platforms. + Your knowledge of automation is clear from your proficiency in any scripting languages such as Python or PowerShell. + You have practical experience assessing and defending modern cloud environments. + You may hold advanced offensive (e.g., OSCP, OSEP, GXPN) or defensive (e.g., GCIH, GDAT) certifications. + You may contribute to the community through public-facing research, conference talks, or open-source tools. **_Company Benefits and Perks:_** We believe that the best solutions are developed by teams who embrace each other's unique experiences, skills, and abilities. We work hard to create a dynamic workforce where we encourage everyone to bring their authentic selves to work every day. We offer a variety of social programs, flexible work hours and family-friendly benefits to all of our employees. + Retirement Plans + Medical, Dental and Vision Coverage + Paid Time Off + Paid Parental Leave + Support for Community Involvement We're serious about our commitment to a workplace where everyone can thrive and contribute to our industry-leading products and customer support, which is why we prohibit discrimination and harassment based on race, color, religion, gender, national origin, age, disability, veteran status, marital status, pregnancy, gender expression or identity, sexual orientation or any other legally protected status.
    $82k-108k yearly est. 37d ago
  • Security Engineer

    Apex Systems 4.6company rating

    Glen Allen, VA jobs

    WHO WE ARE Apex Systems is a leading global technology services business that incorporates industry insights and experience to deliver solutions that fulfill our clients' digital visions. We provide a continuum of services, including strategy and enablement, innovation and productivity, and technology foundations to drive better results and bring more value to our clients. Apex transforms our customers with modern enterprise solutions tailored to the industries we serve. Apex has a presence in over 70 markets across North America, Europe, and India. Apex is a part of the Commercial Segment of ASGN Incorporated (NYSE: ASGN). To learn more, visit ******************** At Apex Systems, we prioritize professional development, work-life balance, and fostering a collaborative culture. We value our teams well-being and recognize the importance of building strong relationships. Thats why we organize regular team-building events and philanthropic days to give back to the community - fostering a sense of purpose and fulfillment among our team. Join us for career advancement, innovative solutions, and a supportive environment focused on your success. JOB DESCRIPTION The Security Engineer at Apex Systems is responsible for designing, implementing, and maintaining advanced cybersecurity solutions to protect the organization's information systems and infrastructure. This role ensures that security is embedded throughout the lifecycle of hardware and software from evaluation and selection to installation and configuration by collaborating closely with IT teams and internal/external stakeholders. * Researches, designs, and implements information security solutions for Apex Systems' information systems and products in compliance with the organization's applicable security policies and standards. * Works with IT and internal/external customers to ensure that security is factored in the evaluation, selection, installation and configuration process of hardware and software. * Analyzes and makes recommendations to improve network, system, and applications. * Assists in the review and update of cyber security policies, architectures, and standards. * Assists in responding to audits, penetration tests and vulnerability assessments. * Designs and implements secure infrastructure solutions, including network security, configuration management, storage security, and identity and access management (IAM) based on security policies to prevent unauthorized access. * Conducts regular security assessments to identify vulnerabilities and potential risks. * Keeps abreast of the latest security threats, vulnerabilities, and attack methods. * Evaluates and implements new security technologies to address emerging threats. JOB REQUIREMENTS * Bachelor's Degree in Computer Science, Information Security, Cybersecurity, or related field OR equivalent combination of education and experience * 5+ years of experience in cybersecurity, previous experience in a security engineering role highly desired * Certified information systems security professional (CISSP) * Technical expertise in one or more of the following: VPN, firewall, network monitoring, intrusion detection, web server security and wireless security, and cloud technologies. * Practical experience with implementing security controls such as database security, web content filtering, anomaly detection and response, and vulnerability scanning * Understands business needs and has a commitment to delivering high-quality, prompt, and efficient service to the business * Understands organizational mission, values, and goals and consistently applies this knowledge * Experience with cybersecurity tools and techniques to automate security tasks, streamline incident response, and enhance overall security posture * Experience with relevant security standards and regulations that apply, such as the ISO family of standards and HIPAA. They should be able to assess compliance requirements and implement necessary controls to ensure adherence to these standards. * Strong knowledge of security engineering discipline in more than one of the following domains: network security, cloud-native security, endpoint security, or application security. * Strong decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate one * Strong problem-solving and troubleshooting skills * Experience with cybersecurity tools such as vulnerability scanners, network firewalls, cloud-native security, and penetration testing frameworks OUR COMPREHENSIVE BENEFITS * Competitive Salary * Health, Dental and Vision Insurance * Health Savings Accounts (HSA) with Employer Contribution * Flexible Spending Accounts * Long and Short-Term Disability * Life Insurance * Voluntary Benefits * Employee Assistance Program * Paid Parental Leave * Wellness Incentives * Vacation and Holiday Pay * 401(k) Retirement Plan with Employer Match * Employee Stock Purchase * Training and Advancement opportunities * Tuition Reimbursement * Birthdays Off * Philanthropic Opportunities * Referral Program * Partial Gym Membership Paid * Team Building Events * Discount Programs Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law. If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation in using our website for a search or application, please contact [email protected]. EEO Employer Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law. If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation in using our website for a search or application, please contact [email protected].
    $92k-129k yearly est. 60d+ ago
  • Lead Adversarial Security Engineer

    Trellix 4.1company rating

    Saint Paul, MN jobs

    **_Job Title:_** Lead Adversarial Security Engineer **About** **Trellix:** **Trellix, the trusted CISO ally, is redefining the future of cybersecurity and soulful work.** Our comprehensive, GenAI-powered platform helps organizations confronted by today's most advanced threats gain confidence in the protection and resilience of their operations. Along with an extensive partner ecosystem, we accelerate technology innovation through artificial intelligence, automation, and analytics to empower over 53,000 customers with responsibly architected security solutions. We also recognize the importance of closing the 4-million-person cybersecurity talent gap. We aim to create a home for anyone seeking a meaningful future in cybersecurity and look for candidates across industries to join us in soulful work. More at ************************ . **_Role Overview:_** Trellix is seeking an Adversarial Security Engineer to lead the evolution of its cybersecurity posture. This is a senior, hands-on, remote-first role for a red/blue/purple expert who possesses a valuable blend of offensive tradecraft and defensive-engineering skills. **Role Overview:** As a lead member of the security operations team, and reporting to the Deputy CISO the mission of this role is to bridge the gap between "what if" and "what is" to continuously test the organization's defenses, find gaps, and personally lead the engineering effort to close them. By collaborating with the Security Operations Center (SOC), Threat Intelligence, and infrastructure teams, this expert will act as a force multiplier, mentoring junior security operations staff and providing the technical leadership to measurably improve the ability to detect and respond to advanced threats. **About the role:** + Plan and execute sophisticated, end-to-end red team engagements against our on-premise and cloud infrastructure. + Develop and validate new detection logic, transforming the results of your own attacks into high-fidelity alerts. + Lead continuous purple team exercises, acting as the primary bridge between the SOC, Threat Intelligence, and Detection Engineering teams. + Leverage Attack Surface Management (ASM) data to find "Shadow IT" and prioritize your offensive operations based on the most likely and impactful attack vectors. + Act as a senior technical leader, mentoring SOC analysts and junior engineers on advanced attack chains, detection theory, and defensive best practices. + Communicate complex findings and remediation strategies to a wide range of stakeholders, from highly technical engineers to executive leadership. **About you:** + You have a blended career path of 7+ years, demonstrating experience in both offensive security (like Red Teaming) and defensive operations (like Detection Engineering or Threat Hunting). + You possess exceptional communication skills, with an ability to create reports and presentations for both highly technical and executive audiences. + You are a U.S. citizen. + Your technical expertise is built on a deep, practical understanding of frameworks like MITRE ATT&CK and the Diamond Model. + You have proficiency in modern offensive tools and C2 frameworks (e.g., Cobalt Strike, Metasploit) and/or experience developing custom attack methods to evade EDR and network controls. + You are proficient in writing, tuning, and validating detection logic in SIEM and EDR platforms. + Your knowledge of automation is clear from your proficiency in any scripting languages such as Python or PowerShell. + You have practical experience assessing and defending modern cloud environments. + You may hold advanced offensive (e.g., OSCP, OSEP, GXPN) or defensive (e.g., GCIH, GDAT) certifications. + You may contribute to the community through public-facing research, conference talks, or open-source tools. **_Company Benefits and Perks:_** We believe that the best solutions are developed by teams who embrace each other's unique experiences, skills, and abilities. We work hard to create a dynamic workforce where we encourage everyone to bring their authentic selves to work every day. We offer a variety of social programs, flexible work hours and family-friendly benefits to all of our employees. + Retirement Plans + Medical, Dental and Vision Coverage + Paid Time Off + Paid Parental Leave + Support for Community Involvement We're serious about our commitment to a workplace where everyone can thrive and contribute to our industry-leading products and customer support, which is why we prohibit discrimination and harassment based on race, color, religion, gender, national origin, age, disability, veteran status, marital status, pregnancy, gender expression or identity, sexual orientation or any other legally protected status.
    $73k-95k yearly est. 37d ago
  • Lead Adversarial Security Engineer

    Trellix 4.1company rating

    Frankfort, KY jobs

    **_Job Title:_** Lead Adversarial Security Engineer **About** **Trellix:** **Trellix, the trusted CISO ally, is redefining the future of cybersecurity and soulful work.** Our comprehensive, GenAI-powered platform helps organizations confronted by today's most advanced threats gain confidence in the protection and resilience of their operations. Along with an extensive partner ecosystem, we accelerate technology innovation through artificial intelligence, automation, and analytics to empower over 53,000 customers with responsibly architected security solutions. We also recognize the importance of closing the 4-million-person cybersecurity talent gap. We aim to create a home for anyone seeking a meaningful future in cybersecurity and look for candidates across industries to join us in soulful work. More at ************************ . **_Role Overview:_** Trellix is seeking an Adversarial Security Engineer to lead the evolution of its cybersecurity posture. This is a senior, hands-on, remote-first role for a red/blue/purple expert who possesses a valuable blend of offensive tradecraft and defensive-engineering skills. **Role Overview:** As a lead member of the security operations team, and reporting to the Deputy CISO the mission of this role is to bridge the gap between "what if" and "what is" to continuously test the organization's defenses, find gaps, and personally lead the engineering effort to close them. By collaborating with the Security Operations Center (SOC), Threat Intelligence, and infrastructure teams, this expert will act as a force multiplier, mentoring junior security operations staff and providing the technical leadership to measurably improve the ability to detect and respond to advanced threats. **About the role:** + Plan and execute sophisticated, end-to-end red team engagements against our on-premise and cloud infrastructure. + Develop and validate new detection logic, transforming the results of your own attacks into high-fidelity alerts. + Lead continuous purple team exercises, acting as the primary bridge between the SOC, Threat Intelligence, and Detection Engineering teams. + Leverage Attack Surface Management (ASM) data to find "Shadow IT" and prioritize your offensive operations based on the most likely and impactful attack vectors. + Act as a senior technical leader, mentoring SOC analysts and junior engineers on advanced attack chains, detection theory, and defensive best practices. + Communicate complex findings and remediation strategies to a wide range of stakeholders, from highly technical engineers to executive leadership. **About you:** + You have a blended career path of 7+ years, demonstrating experience in both offensive security (like Red Teaming) and defensive operations (like Detection Engineering or Threat Hunting). + You possess exceptional communication skills, with an ability to create reports and presentations for both highly technical and executive audiences. + You are a U.S. citizen. + Your technical expertise is built on a deep, practical understanding of frameworks like MITRE ATT&CK and the Diamond Model. + You have proficiency in modern offensive tools and C2 frameworks (e.g., Cobalt Strike, Metasploit) and/or experience developing custom attack methods to evade EDR and network controls. + You are proficient in writing, tuning, and validating detection logic in SIEM and EDR platforms. + Your knowledge of automation is clear from your proficiency in any scripting languages such as Python or PowerShell. + You have practical experience assessing and defending modern cloud environments. + You may hold advanced offensive (e.g., OSCP, OSEP, GXPN) or defensive (e.g., GCIH, GDAT) certifications. + You may contribute to the community through public-facing research, conference talks, or open-source tools. **_Company Benefits and Perks:_** We believe that the best solutions are developed by teams who embrace each other's unique experiences, skills, and abilities. We work hard to create a dynamic workforce where we encourage everyone to bring their authentic selves to work every day. We offer a variety of social programs, flexible work hours and family-friendly benefits to all of our employees. + Retirement Plans + Medical, Dental and Vision Coverage + Paid Time Off + Paid Parental Leave + Support for Community Involvement We're serious about our commitment to a workplace where everyone can thrive and contribute to our industry-leading products and customer support, which is why we prohibit discrimination and harassment based on race, color, religion, gender, national origin, age, disability, veteran status, marital status, pregnancy, gender expression or identity, sexual orientation or any other legally protected status.
    $75k-98k yearly est. 37d ago

Learn more about Brown-Forman jobs