Senior Security Consultant jobs at Burns & McDonnell - 60 jobs
Information Security Analyst
HJ Staffing 3.9
California jobs
HJ Staffing is seeking an Information Security Analyst to join a prominent Managed Care Plan serving over 456,000 members. In this role, you will be the primary lead in analyzing security practices, investigating breaches, and ensuring the organization remains aligned with rigorous healthcare industry standards. We are looking for a technical expert who can bridge the gap between complex infrastructure and staff education to protect sensitive member data.
What You Will Do
Security Monitoring & Investigation: Monitor computer networks for security issues, lead the investigation of breaches in collaboration with the Information Security Manager, and document damage assessments.
Compliance & Auditing: Assess the efficacy of existing measures to ensure they meet HIPAA and FISCAM security standards; conduct proactive system vulnerability audits and manage annual penetration testing with vendors.
Solution Implementation: Participate in the evaluation, design, and implementation of new security solutions, including firewalls and data encryption programs, to protect the organization's computer networks from cyber-attacks.
Risk Advisory: Analyze software and systems requirements to provide objective advice on security risks and develop clear remediation options for management and senior ITS staff.
Policy & Documentation: Assist with the development of security policies, procedures, and standards; maintain comprehensive documentation of computer security procedures and tests.
Training & Phishing Defense: Develop high-impact training materials and presentations to educate the organization on data security, including frequent training on how to detect and avoid phishing attempts.
What You Will Bring
Education: Bachelor's degree in IT, Cybersecurity, Computer Science, or a related field (a Master's degree may substitute for 2 years of experience).
Experience: 8 years of professional-level IT experience, with at least 3 years specifically performing information security functions in a healthcare environment.
Certifications: Current CISSP, CISM, or CEH (Certified Ethical Hacker) certification is required.
Technical Knowledge: Strong understanding of firewalls, proxies, SIEM, antivirus, and IDPS concepts, along with proficiency in virtualization and Windows-based systems.
Regulatory Expertise: In-depth knowledge of HIPAA and FISCAM security guidelines and a working knowledge of frameworks such as NIST, ISO 27001, or COBIT.
You Will Be Successful If:
You are a Strategic Problem Solver: You can manage multiple priorities, meet strict deadlines, and adapt to shifting security needs.
You are an Effective Communicator: You possess clear writing skills and the ability to present complex technical content to non-technical audiences.
You are Collaborative & Diplomatic: You have the leadership ability to facilitate meetings and build strong relationships across infrastructure and administrative teams.
You are Proactive: You stay informed of emerging technologies (AI, IoT, blockchain) and look for ways to eliminate technical debt before it becomes a vulnerability.
You are Incident-Ready: You are willing to respond to after-hours information security incidents as needed.
Important Details
Residency Requirement: Candidate must reside in the state of California.
Work Status: 100% Remote; must be a US Citizen or Green Card holder.
Market Context: This is a competitive role for a major managed care plan; qualified candidates are encouraged to submit their credentials immediately.
$90k-131k yearly est. Auto-Apply 40d ago
Looking for a job?
Let Zippia find it for you.
Senior Cybersecurity Analyst / Information Security Manager - Top Secret Clearance
Nana Regional Corporation 4.2
Rockville, MD jobs
We are seeking a highly skilled Senior Cybersecurity Analyst / Information Security Manager with expertise in IT security, risk management, and policy development. The ideal candidate will have a minimum of five (5) years of experience implementing security measures to protect the confidentiality, integrity, and availability of information systems and data, along with at least two (2) years of supervisory experience in a cybersecurity or IT security role.
This individual will be responsible for developing, monitoring, and testing cybersecurity plans and controls using government-approved tools and methodologies while ensuring compliance with federal cybersecurity policies and frameworks.
Contingent upon contract award
Responsibilities
+ Plan, coordinate, and implement security measures to safeguard information systems and data.
+ Supervise cybersecurity personnel and oversee daily security operations.
+ Develop, monitor, and conduct testing of cybersecurity plans and controls using government-approved tools and methodologies.
+ Document test results, risk assessments, and residual risk reports, and provide recommendations for corrective actions.
+ Ensure compliance with cybersecurity policies and best practices, including National Institute of Standards and Technology (NIST) Special Publications.
+ Demonstrate expertise in Security Assessment and Authorization (SA&A), including NIST 800-37, NIST 800-53, CNSSI standards, and other federal cybersecurity requirements.
+ Develop and maintain EHSS Security Policies, including the EHSS Privacy Plan, EHSS Configuration Management Plan, and other security-related documentation.
+ Create and maintainbaseline documentation and oversee policy development and reviews for EHSS security programs.
+ Implement and support Incident Response, Vulnerability Management, and Plan of Action and Milestone (POA&M) management.
+ Apply expertise in Zero Trust Architecture, cloud security requirements, security assessments, and Continuous Diagnostics and Mitigation (CDM)/Continuous Monitoring.
Qualifications
+ Bachelor's degree in Information Technology, Cybersecurity, Information Assurance, or a related field from an accredited university or college.
+ Minimum of five (5) years of experience in IT security, risk management, and policy development.
+ Minimum of two (2) years of supervisory experience in a cybersecurity or IT security role.
+ Proficiency in NIST frameworks, risk assessments, security controls, and federal cybersecurity policies.
+ Must be knowledgeable in Incident Response practices, vulnerability management, Plan of Action and Milestone management, Zero Trust Architecture, cloud requirements and assessments Continuous Diagnostics Mitigations/Continuous Monitoring, Etc.
+ Strong understanding of Security Assessment and Authorization (SA&A) processes and federal security compliance requirements.
+ Top Secret clearance
Required Certifications:
+ GIAC Information Security Professional (GISP), ISC2 Certified Information Systems Security Professional, CISSP or equivalent.
Job ID
2025-15866
Work Type
On-Site
Pay Range
$150,000 -$190,000
Benefits
Regular - The company offers a comprehensive benefits program, including medical, dental, vision, life insurance, 401(k) and a range of other voluntary benefits. Paid Time Off (PTO) is offered to regular full-time and part-time employees.
Company Description
Work Where it Matters
Compass Point, an Akima company, is not just another federal IT contractor. As an Alaska Native Corporation (ANC), our mission and purpose extend beyond our exciting federal projects as we support our shareholder communities in Alaska.
At Compass Point, the work you do every day makes a difference in the lives of our 15,000 Iñupiat shareholders, a group of Alaska natives from one of the most remote and harshest environments in the United States.
For our shareholders , Compass Point provides support and employment opportunities and contributes to the survival of a culture that has thrived above the Arctic Circle for more than 10,000 years.
For our government customers , Compass Point delivers a broad range of skilled IT services, including data-centric services, software development, IT infrastructure modernization, managed IT services, and more.
As a Compass Point employee , you will be surrounded by a challenging, yet supportive work environment that is committed to innovation and diversity, two of our most important values. You will also have access to our comprehensive benefits and competitive pay in addition to growth opportunities and excellent retirement options.
We are an equal opportunity employer and comply with all applicable federal, state, and local fair employment practices laws. All applicants will receive consideration for employment, without regard to race, color, religion, creed, national origin, gender or gender-identity, age, marital status, sexual orientation, veteran status, disability, pregnancy or parental status, or any other basis prohibited by law. If you are an individual with a disability, or have known limitations related to pregnancy, childbirth, or related medical conditions, and would like to request a reasonable accommodation for any part of the employment process, please contact us at ******************** or ************ (information about job applications status is not available at this contact information).
$150k-190k yearly 49d ago
Corporate Security Engineer
Harvey 4.5
San Francisco, CA jobs
Why Harvey
At Harvey, we're transforming how legal and professional services operate - not incrementally, but end-to-end. By combining frontier agentic AI, an enterprise-grade platform, and deep domain expertise, we're reshaping how critical knowledge work gets done for decades to come.
This is a rare chance to help build a generational company at a true inflection point. With 1000+ customers in 58+ countries, strong product-market fit, and world-class investor support, we're scaling fast and defining a new category in real time. The work is ambitious, the bar is high, and the opportunity for growth - personal, professional, and financial - is unmatched.
Our team is sharp, motivated, and deeply committed to the mission. We move fast, operate with intensity, and take real ownership of the problems we tackle - from early thinking to long-term outcomes. We stay close to our customers - from leadership to engineers - and work together to solve real problems with urgency and care. If you thrive in ambiguity, push for excellence, and want to help shape the future of work alongside others who raise the bar, we invite you to build with us.
At Harvey, the future of professional services is being written today - and we're just getting started.
Role Overview
Some of the world's largest companies and their law firms use Harvey's AI capabilities to deliver world-class client services at unprecedented scale and efficiency. Harvey allows high-performing professionals to gain deep domain knowledge faster, understand the big picture, and tackle more complex challenges in less time.
Our customers depend on us to deliver a secure, trustworthy, and compliant platform. Earning the trust of our customers is a business enabler and we value it more than anything else.
In this role you will join our corporate security function which works to ensure that our IT and business systems are secure, compliant, and have a high degree of user satisfaction. This program is scaling quickly along with our company as we have been doubling in headcount every few quarters and continue to grow at a rapid pace.
Our security program at Harvey is driven by our commitment to securing the data entrusted to us by our customers as well as our corporate intellectual property. The corporate security team balances risk with user experience and provides a secure foundation for all other security and IT programs and the company as a whole. We seek not just to build security through industry best practice but to validate every assumption through threat modelling, real-world testing, and by incorporating lessons learned from breaches and attacks at other companies.
What You'll Do
Support implementation of our Identity Governance and Administration (IGA) application to ensure that employees can seamlessly gain the appropriate level of access for their role and we can efficiently meet compliance objectives for access approvals and revocation of access upon separation.
Evolve our corporate device trust program to ensure only compliant devices can access corporate and production systems.
Support endpoint security efforts including security policies, controls, and vulnerability management
Partner with our IT & Business Systems team and provide security expertise and oversight over the implementation and operations of SaaS applications and business systems
Partner with the Security Detection & Response team to ensure visibility into corporate systems including development of scripts and integrations as needed
Partner with the Trust & Compliance team to streamline or automate evidence collection to support internal and independent audits.
What You Have
Demonstrated experience deploying new IT systems and processes across the organization with high user satisfaction.
Demonstrated ability to identify risks and vulnerabilities in IT and business systems and to work cross-functionally throughout the company to balance risk with company priorities and effectively communicate risk to stakeholders.
Understanding of and ability to debug IT systems, including X.509, SAML, SCIM.
Familiarity with endpoint engineering for mac OS and Windows
Software Engineering and DevOps experience with proficiency in python and/or golang as well as familiarity with Terraform and/or Pulumi
Experience with Okta, Salesforce, NetSuite, Workday, Microsoft Entra/Azure/InTune, JAMF, and/or ConductorOne is a plus
Experience with generative AI or the legal field is not required.
4+ years of experience in security-focused software engineering, corporate engineering, IT, and/or program management.
Compensation
$201,000 - $264,000 USD
Please find our CA applicant privacy notice here.
#LI-KV1
Harvey is an equal opportunity employer and does not discriminate on the basis of race, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law.
We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made by emailing accommodations@harvey.ai
$201k-264k yearly Auto-Apply 4d ago
Infrastructure Security Engineer
Harvey 4.5
San Francisco, CA jobs
Why Harvey
At Harvey, we're transforming how legal and professional services operate - not incrementally, but end-to-end. By combining frontier agentic AI, an enterprise-grade platform, and deep domain expertise, we're reshaping how critical knowledge work gets done for decades to come.
This is a rare chance to help build a generational company at a true inflection point. With 1000+ customers in 58+ countries, strong product-market fit, and world-class investor support, we're scaling fast and defining a new category in real time. The work is ambitious, the bar is high, and the opportunity for growth - personal, professional, and financial - is unmatched.
Our team is sharp, motivated, and deeply committed to the mission. We move fast, operate with intensity, and take real ownership of the problems we tackle - from early thinking to long-term outcomes. We stay close to our customers - from leadership to engineers - and work together to solve real problems with urgency and care. If you thrive in ambiguity, push for excellence, and want to help shape the future of work alongside others who raise the bar, we invite you to build with us.
At Harvey, the future of professional services is being written today - and we're just getting started.
Role Overview
Some of the world's largest companies and their law firms use Harvey's AI capabilities to deliver world-class client services at unprecedented scale and efficiency. Harvey allows high-performing professionals to gain deep domain knowledge faster, understand the big picture, and tackle more complex challenges in less time.
Security is at the heart of what we do. Our customers trust us with their most sensitive data, and we take that responsibility seriously. As part of our team, you'll help us maintain a secure, trustworthy, and compliant platform-an essential foundation for everything we build.
As an Infrastructure Security Engineer, you'll design and build secure-by-default infrastructure that product teams can rely on. This includes designing and implementing processes and technologies for least privilege, isolating different components, managing attack surface, and implementing layers of tenant isolation on our multi-tenant SaaS offering. You'll also create frameworks and repeatable patterns that enable our research and engineering teams to move quickly and independently-without sacrificing security.
Our security program at Harvey is driven by our collective offensive security experience: breaking into systems at other companies (in white-hat capacities), responding to real security incidents, and learning from other companies' data breaches. We regularly conduct penetration tests and red team exercises. At the same time, we are all software engineers - contributing code daily and approaching security with an engineering-first mindset.
What You'll Do
Incorporate secure design principles into our cloud architecture.
Develop isolation mechanisms (e.g. sandboxing) in collaboration with our product engineering team
Review security-critical configuration changes and act as Codeowner for security-critical parts of our cloud configurations (everything is IaC)
Audit our existing cloud environment for vulnerabilities
Develop policies and procedures for the secure creation and operation of our cloud environments
What You Have
5+ years experience in Security Engineering, Software Engineering, or Site Reliability Engineering roles
Demonstrated experience writing high-quality software and building production-grade infrastructure and raising the quality bar of engineering teams
Strong fundamentals in networking, operating systems, and cryptographic protocols
In-depth knowledge of Kubernetes, common misconfigurations, and privilege escalation vectors
Demonstrated ability to find weaknesses (e.g. privilege escalation) in real-world cloud environments
Experience applying security best practices in cloud environments (AWS, Azure, or Google Cloud)
(No experience with generative AI or legal required)
Bonus
Familiarity with large-scale Infrastructure as Code (IaC) deployments
Familiarity with Kubernetes Admission Controllers and policy enforcement
Exposure to multi-cloud environments
Compensation Range
$201,000 - $260,000 USD
Please find our CA applicant privacy notice here.
#LI-KV1
Harvey is an equal opportunity employer and does not discriminate on the basis of race, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law.
We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made by emailing accommodations@harvey.ai
$201k-260k yearly Auto-Apply 60d+ ago
Information Security Officer
PEC 3.9
Syracuse, NY jobs
About Us: Progressive Expert Consulting: Reimagining Virtual Learning Progressive Expert Consulting (PEC) is a forward-thinking technology company leading the charge in reimagining virtual learning. We believe that education shouldn't be confined to physical classrooms, and we're dedicated to developing innovative solutions that make immersive, engaging, and effective learning experiences accessible to anyone, anywhere.
Your Responsibilities Will Include:
Completing and maintaining compliance paperwork and certifications
Developing and implementing a comprehensive plan to secure our computing network.
Identifying vulnerabilities in our current network.
Monitoring network usage to ensure compliance with security policies.
Keeping up to date with developments in IT security standards and threats.
Documenting any security breaches and assessing their damage.
Educating colleagues about security software and best practices for information security.
You'll Thrive If You Have:
Effective verbal and written communication skills.
Professional information security certification.
Experience in an information security role.
Solid knowledge of various information security frameworks.
Ability to educate a nontechnical audience about various security measures.
Bonus Points For:
Creating, submitting, and maintaining a FedRAMP certification
Creating, submitting, and maintaining a CMMC certification
Please submit your resume and cover letter outlining why you're the perfect triple-threat creative we've been searching for. Portfolios are encouraged. We can't wait to hear from you!
Location:
Syracuse, NY
Salary Range:
Based on experience
Compensation: $50,000.00 - $80,000.00 per year
$50k-80k yearly Auto-Apply 60d+ ago
Security Analyst
Maintainx 3.4
Raleigh, NC jobs
MaintainX is the world's leading Asset and Work Intelligence platform for industrial and frontline environments. We are a modern IoT-enabled cloud-based tool for reliability, safety, and operations on physical equipment and facilities. MaintainX powers operational excellence for 12,000+ businesses including Duracell, Univar Solutions Inc., Titan America, McDonald's, Brenntag, Cintas, Xylem, and Shell.
We recently completed a $150 million Series D round, bringing our total funding to $254 million and valuing the company at $2.5 billion.
We're looking for a Security Analyst to support our security program across both regulated (FedRAMP) and non-regulated environments. This role focuses on security operations, vulnerability management, and compliance support. You will work with tools like Datadog, Wiz, and AWS to protect our infrastructure and data across multiple environments.
This role is hybrid out of our Raleigh or Montreal office.
What you'll do:
* Monitor and triage security alerts using tools like Datadog, SIEM platforms, and other security monitoring solutions.
* Manage vulnerability assessment programs, tracking remediation efforts across cloud and on-premise infrastructure.
* Conduct security control assessments and prepare technical documentation and evidence for audits.
* Support penetration testing initiatives and security assessments on internal products and infrastructure.
* Investigate security incidents, document findings, and support incident response activities.
* Collaborate with DevOps, IT, Product, and other teams to implement and verify security controls.
* Develop tooling for the security team
* Participate in internal and external audits across multiple compliance frameworks (FedRAMP, SOC 2, ISO 27001, etc.).
* Contribute to security policy development, documentation, and awareness training initiatives.
* Stay current with emerging threats, security best practices, and compliance requirements.
About you:
* Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience).
* 2-4 years of experience in information security, security operations, or related roles.
* Hands-on experience with cloud security (mainly AWS) and cloud-native security tools.
* Familiarity with security frameworks such as NIST 800-53, SOC 2, ISO 27001, or FedRAMP.
* Experience with vulnerability management tools and processes.
* Understanding of security monitoring, log analysis, and incident response.
* Strong analytical and problem-solving skills with attention to detail.
* Excellent written and verbal communication skills.
* Ability to work independently and collaboratively in a fast-paced environment.
Bonus if you have:
* Experience with security tools such as Wiz, Datadog, Jira, vulnerability scanners, password managers, EDRs and SIEM platforms.
* Previous experience supporting compliance programs (FedRAMP, SOC 2, ISO 27001, etc.).
* Security certifications such as Security+, GSEC, OSCP, CISSP, or equivalent.
* Experience with penetration testing methodologies and tools.
* Knowledge of DevSecOps practices and security automation.
* Scripting or programming experience (typescript, dot net) for security automation.
What's in it for you:
* Competitive salary and meaningful equity opportunities.
* Healthcare, dental, and vision coverage.
* 401(k) / RRSP enrolment program.
* Take what you need PTO.
* A Work Culture where:
* You'll work alongside folks across the globe that reflect the MaintainX values, Smart Humble Optimist.
* We believe in meritocracy, where ideas and effort are publicly celebrated.
About us:
Our mission is to make the life of blue-collar workers easier worldwide by creating software that meets their needs and realities. Our product is truly life-changing for 80% of the workforce that doesn't work behind a desk and needs enterprise-grade software at their fingertips.
MaintainX is committed to creating a diverse environment. All qualified applicants will receive consideration for employment without regard to race, colour, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.
$70k-103k yearly est. Auto-Apply 14d ago
Security Analyst
D.R. Horton 4.6
Arlington, TX jobs
Security Analyst - 2600425 Description D. R. Horton, Inc. , the largest homebuilder in the U. S. , was founded in 1978 and is a publicly traded company on the New York Stock Exchange. It is engaged in the construction and sale of high quality homes designed principally for the entry-level and first time move-up markets.
The Company also provides mortgage financing and title services for homebuyers through its mortgage and title subsidiaries.
Please visit our website at www.
drhorton.
com for more information.
D.
R.
Horton, Inc.
is currently looking for a Security Analyst.
The right candidate will address daily tasks and routine processes for IT security.
This position will be responsible for assessing IT security incidents and applying the necessary technical troubleshooting steps to resolve the issue.
The Security Analyst will also be responsible for monitoring suspicious or malicious activity in the company IT infrastructure and addressing security risk and incidents.
Essential Duties and ResponsibilitiesNetwork Security OperationsMonitor network traffic and alerts for indicators of compromise, malicious behavior, lateral movement, or anomalous activity.
Respond to and investigate network‑based security incidents across firewalls, routers, switches, wireless environments, and cloud interconnectivity.
Support DDoS detection, mitigation coordination, and response.
Maintain and improve network security configurations such as ACLs, VLAN segmentation, VPN policies, and IPS/IDS signatures.
Assist in managing and reviewing logs from security tools (SIEM, IDS/IPS, NetFlow analyzers, EDR/XDR platforms).
Manage and monitor email security and email flow.
Detect phishing scams and analyze email headers.
Understanding of DEMARC/DKIM/SPF security a plus.
Maintain content filtering platform and determine risk with websites or URLs.
Knowledge of domain registration and reputation scoring is optimal.
Network Infrastructure SupportPartner with the Networking and IT Operations teams to troubleshoot connectivity, authentication, or routing issues affecting system security.
Maintain DNS security hygiene, including DNS records, name resolution integrity, and DNS‑related attack protections.
Work with F5 or other load‑balancing/DNS traffic‑management technologies to ensure secure traffic distribution.
Directory & Identity SecuritySupport Active Directory and ADFS from a security perspective, including authentication flows, privileged access, and hardening standards.
Assist with identity‑related investigations or authentication anomalies.
Patching & Vulnerability ManagementAnalyze security advisories, CVEs, and vendor bulletins specifically for network and infrastructure components.
Validate successful patch deployment across network appliances, security tools, and infrastructure systems.
Coordinate with SCCM and infrastructure teams to ensure patching is aligned with risk priorities and security controls.
Forensic & Incident ResponsePerform network‑centric forensic investigations, including packet captures, log correlation, and threat‑hunting activities.
Identify root causes of network compromise and recommend containment or mitigation strategies.
Document incident findings and collaborate with teams to close security gaps.
Project & Operational SupportContribute to network‑security projects, deployments, and upgrades.
Provide subject‑matter input on firewall changes, secure architecture designs, and network segmentation initiatives.
Work with cross‑functional teams to ensure secure rollouts of new applications or services.
Additional ResponsibilitiesParticipate in the weekly on‑call rotation and respond to after‑hours incidents.
Mentor Security Administrators and junior team members.
Support IT operational emergencies when they impact business‑critical systems.
Travel overnight as required.
Qualifications Education and/or ExperienceHigh school diploma or GED.
1-4 years of experience in IT or network security.
Understanding of network architectures, network protocols, and traffic analysis.
Experience with security operations, incident response, or forensic analysis.
Knowledge of DNS, Active Directory, network routing/switching, or authentication services.
Experience with security or monitoring platforms (SIEM, IDS/IPS, EDR, NetFlow, packet capture tools).
Strong communication, documentation, collaboration, and customer service skills.
Ability to work independently or within a team.
Ability to interpret technical research and apply it to real‑world security problems.
Proficiency with Microsoft Office and email.
Preferred QualificationsBachelor's Degree in Cybersecurity, Information Security, or related discipline.
Experience with enterprise firewalls, VPNs, or secure access solutions.
Familiarity with DDoS concepts, threat‑hunting methodologies, or network‑security frameworks.
Strong attention to detail and the ability to manage multiple tasks simultaneously.
Come join a winning team with a Fortune 500 company! We are growing fast and are looking for enthusiastic attitudes and team players to join our success.
We offer an excellent benefits package including:· Medical, Dental and Vision· 401(K)· Employee Stock Purchase Plan· Flex Spending Accounts· Life & Disability Insurance· Vacation, Sick, Personal Time and Company Holidays· Multiple Voluntary and Company provided BenefitsBuild YOUR future with D.
R.
Horton, America's Builder.
#WeBuildPeopleToo Job: Information Technology Primary Location: TX-Arlington Organization: Corporate Schedule: Full-time Job Posting: Jan 22, 2026, 11:02:38 PM
$78k-108k yearly est. Auto-Apply 20h ago
Security Analyst
D.R. Horton, Inc. 4.6
Arlington, TX jobs
D.R. Horton, Inc., the largest homebuilder in the U.S., was founded in 1978 and is a publicly traded company on the New York Stock Exchange. It is engaged in the construction and sale of high quality homes designed principally for the entry-level and first time move-up markets. The Company also provides mortgage financing and title services for homebuyers through its mortgage and title subsidiaries. Please visit our website at **************** for more information.
D.R. Horton, Inc. is currently looking for a Security Analyst. The right candidate will address daily tasks and routine processes for IT security. This position will be responsible for assessing IT security incidents and applying the necessary technical troubleshooting steps to resolve the issue. The Security Analyst will also be responsible for monitoring suspicious or malicious activity in the company IT infrastructure and addressing security risk and incidents.
Essential Duties and Responsibilities
Network Security Operations
* Monitor network traffic and alerts for indicators of compromise, malicious behavior, lateral movement, or anomalous activity.
* Respond to and investigate network‑based security incidents across firewalls, routers, switches, wireless environments, and cloud interconnectivity.
* Support DDoS detection, mitigation coordination, and response.
* Maintain and improve network security configurations such as ACLs, VLAN segmentation, VPN policies, and IPS/IDS signatures.
* Assist in managing and reviewing logs from security tools (SIEM, IDS/IPS, NetFlow analyzers, EDR/XDR platforms).
* Manage and monitor email security and email flow. Detect phishing scams and analyze email headers. Understanding of DEMARC/DKIM/SPF security a plus.
* Maintain content filtering platform and determine risk with websites or URLs. Knowledge of domain registration and reputation scoring is optimal.
Network Infrastructure Support
* Partner with the Networking and IT Operations teams to troubleshoot connectivity, authentication, or routing issues affecting system security.
* Maintain DNS security hygiene, including DNS records, name resolution integrity, and DNS‑related attack protections.
* Work with F5 or other load‑balancing/DNS traffic‑management technologies to ensure secure traffic distribution.
Directory & Identity Security
* Support Active Directory and ADFS from a security perspective, including authentication flows, privileged access, and hardening standards.
* Assist with identity‑related investigations or authentication anomalies.
Patching & Vulnerability Management
* Analyze security advisories, CVEs, and vendor bulletins specifically for network and infrastructure components.
* Validate successful patch deployment across network appliances, security tools, and infrastructure systems.
* Coordinate with SCCM and infrastructure teams to ensure patching is aligned with risk priorities and security controls.
Forensic & Incident Response
* Perform network‑centric forensic investigations, including packet captures, log correlation, and threat‑hunting activities.
* Identify root causes of network compromise and recommend containment or mitigation strategies.
* Document incident findings and collaborate with teams to close security gaps.
Project & Operational Support
* Contribute to network‑security projects, deployments, and upgrades.
* Provide subject‑matter input on firewall changes, secure architecture designs, and network segmentation initiatives.
* Work with cross‑functional teams to ensure secure rollouts of new applications or services.
Additional Responsibilities
* Participate in the weekly on‑call rotation and respond to after‑hours incidents.
* Mentor Security Administrators and junior team members.
* Support IT operational emergencies when they impact business‑critical systems.
* Travel overnight as required.
Education and/or Experience
* High school diploma or GED.
* 1-4 years of experience in IT or network security.
* Understanding of network architectures, network protocols, and traffic analysis.
* Experience with security operations, incident response, or forensic analysis.
* Knowledge of DNS, Active Directory, network routing/switching, or authentication services.
* Experience with security or monitoring platforms (SIEM, IDS/IPS, EDR, NetFlow, packet capture tools).
* Strong communication, documentation, collaboration, and customer service skills.
* Ability to work independently or within a team.
* Ability to interpret technical research and apply it to real‑world security problems.
* Proficiency with Microsoft Office and email.
Preferred Qualifications
* Bachelor's Degree in Cybersecurity, Information Security, or related discipline.
* Experience with enterprise firewalls, VPNs, or secure access solutions.
* Familiarity with DDoS concepts, threat‑hunting methodologies, or network‑security frameworks.
* Strong attention to detail and the ability to manage multiple tasks simultaneously.
Come join a winning team with a Fortune 500 company! We are growing fast and are looking for enthusiastic attitudes and team players to join our success. We offer an excellent benefits package including:
* Medical, Dental and Vision
* 401(K)
* Employee Stock Purchase Plan
* Flex Spending Accounts
* Life & Disability Insurance
* Vacation, Sick, Personal Time and Company Holidays
* Multiple Voluntary and Company provided Benefits
Build YOUR future with D.R. Horton, America's Builder. #WeBuildPeopleToo
$78k-108k yearly est. 5d ago
Computer Security Analyst
Haynes 4.5
Charleston, SC jobs
, Inc. Haynes Inc, continues to partner with Department of State (DoS) in Charleston, SC. Our 80+ employees. support the DoS Comptroller and Global Financial Services (CGFS) Center in the areas of: Global Compensation, Information Systems Security (ISSO), and Global Financial Operations. We serve the U.S. Foreign Service, Department of State Civil Service, Foreign Service Retirees, Embassies, and Overseas U.S. Agencies reaching 180 countries and 140 currencies. Haynes, Inc. provides services in: Accounting, Administration, Budget, Travel, Vouchering, Accounts Receivables, Reconciliation, Systems Analysis, Information Systems, Computer Security, Payroll and Compensation, Treasury, Payroll Customer Service, Training, Audits, and Paralegal Analysis.
Haynes, Inc. provides our employee family a robust benefits package including: 11 paid Federal holidays, generous Employer Match on your 401k, Paid Time Off, Medical/Dental/Vision Insurance, Flexible Spending Accounts, Life Insurance, Disability, Tuition Reimbursement, free Professional Development & Training Program with 9000+ courses, and more! We thrive on providing a good work/life balance and in creating an inclusive culture where employees feel valued, appreciated, and are rewarded for top performance!
Department Overview
The U.S. Department of State (DoS), the Comptroller Global Financial Services (CGFS) Charleston office of the Information Systems Security Officer (ISSO) has responsibility for the development and implementation of the Department's information systems security program and the overall confidentiality, integrity, and availability of all DoS networks at CGFS.
Minimum Requirements
Four-year degree from an accredited university or college in computer science or a related field.
Two-four years of experience in intrusion detection, vulnerability assessments, and network diagnostics.
CompTIA Security+ Certification.
Experience or certifications may be substituted for education or degree type.
Skills
o Assessing new or modified technical capabilities for information technology operations
o Implementing controls, processes, and software
o Resolve systems and production issues
o Ability to communicate technical and non-technical information clearly (orally and written)
Technology
o Knowledge of and experience using Windows 11 in a Windows Network environment
o Experience with PC workstation operations including word processing, spreadsheets, electronic mail.
Preferred Skills
Certifications: other certifications in information security or computer systems such as CompTIA Cybersecurity Analyst (CySA+) and Certified Information Systems Security Professional (CISSP)
Experience with implementing financial accounting controls
Our most Successful Employees in this Position Demonstrate:
Initiative
Attention to detail
Analytical
Collaborative
Job Responsibilities
CGFS Charleston ISSO Information Assurance, Quality Control, and Network Security
User creation and conditional email assignment of user and administrative accounts on CGFS General Support Systems.
Active role in network and systems design to ensure that appropriate systems security policies and procedures are contemplated and introduced into designs at the outset.
Assess breaches of security to determine their impact on system operations and the confidentiality, integrity, and reliability of the information stored and manipulated within the system. Applies findings to the development of corrective measures and user awareness.
Customer service - walk-ins, telephonic, Teams, email.
User account and email creation (active directory): access permissions.
Creation and maintenance of users for CGFS Financial Applications.
Creation and maintenance of network drive folder file permissions.
Support internal and external access management audits.
Create and maintain ISO 9001 documentation for engineering and access management efforts.
Create, modify, and delete user accounts on automated information systems.
Software Systems Utilized
Windows 11
Microsoft Office (Word, Excel, PowerPoint)
Security Clearance Requirement
All contractors supporting this Department must be able to either possess or obtain a security clearance of Top Secret.
Work Schedule
To be hired, the candidate must reside in the state of South Carolina. This position supports a government contract and is subject to the government agency rules and managemen The employee will work an 8-hour shift, Monday - Friday, between the hours of 7:00 a.m. to 4:00 p.m. with a non-compensated 45-minute lunch (See your Assistant Project Manager for work schedule and department policies). Additional hours may be required and must be authorized by your Project Manager and DoS Leadership. This is a 100% on-site position.
Additional Information
Typically, one year of service in the current job is desired prior to moving into a different job on this contract.
Haynes, Inc is an Equal Opportunity Employer. We do not discriminate against any employee
or applicant for employment because of race, color, religion, gender, national origin, age, marital status, disability, veteran status, sexual orientation, or other protected status in any of the terms or conditions of employment.
$64k-81k yearly est. 38d ago
Controls Security & Fire System Engineer III
Johnson Controls Holding Company, Inc. 4.4
Huntington Beach, CA jobs
What you do
Be responsible for Pre Sales Support & End User Support for, but not limited to the design, configuration, and operation of complete building low voltage systems, including fire, security, and other low voltage control sub-systems (i.e. lighting, nurse call, data networks, etc.) to meet the intent of the project requirements.
Accountable to field teams for quality, timeliness and efficiency of designs.
Develops complex software programs, commissions and troubleshooting to ensure proper operations of the building control system.
Provides detailed information and submittals to communicate design and operation to customers, consultants, Johnson Controls field installation team and subcontractors.
How will you do it - Sales Support and End User Support
· Possible job walks with the Sales Team on the initial design phase
· Designs and configures are technically complex building control systems as defined by the contract documents.
· Creates flow diagrams, sequence of operations, bill of material, network layouts and electrical schematics as required.
· Develop and tests software programs necessary to operate the system per the project requirements' intent.
· Coordinates the creation of necessary drawings and equipment schedules for submittals and installation.
· Assists in the loading and commissioning of all system and network-level controllers as required.
· Assists in validation of complete system functionality and troubleshoots problems with subcontractors and other trades to ensure proper operation.
· Provides field change information to the project team for the creation of as-built drawings and software.
· Keeps management and JCI contractor or customer informed of job progress and issues.
· Assists in performing site-specific training for owner/operator on the total building control system.
· Participates in release meeting with the project field team.
· Performs value engineering to provide cost effective results while maintaining customer satisfaction.
· Adheres to safety standards.
· High degree of employee and subcontractor safety.
What we look for
Required Qualifications
· Minimum of seven years of experience, or an associate degree in a related technical field with seven years of relevant work experience required.
· Demonstrated knowledge of the construction, mechanical, electrical, or HVAC service industry.
· Demonstrated knowledge of mechanical drawings, electrical wiring diagrams, control theory, automatic temperature controls, building automation systems and other building subsystems.
· Demonstrated experience in the integration of low voltage building sub-systems using various industry protocols (i.e. LON, BACnet, etc.).
· Ability to relate technical knowledge to a non-technical audience.
· Demonstrated advanced computer skills required, particularly computer-related drafting tools, such as Visio.
Preferred Qualifications
· Bachelor's degree in engineering with a minimum of five years of experience, or an associate degree in a related technical field with seven years of relevant work experience required.
· Understanding of IP networking for building automation systems.
· Understanding of Tridium/Niagara Framework
HIRING SALARY RANGE: $100K to $125K (Salary to be determined by the education, experience, knowledge, skills, and abilities of the applicant, internal equity, location and alignment with market data.) This role offers a competitive Bonus plan that will take into account individual, group, and corporate performance. This position includes a competitive benefits package. For details, please visit the About Us tab on the Johnson Controls Careers site at *****************************************
Johnson Controls International plc. is an equal employment opportunity and affirmative action employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, protected veteran status, genetic information, sexual orientation, gender identity, status as a qualified individual with a disability or any other characteristic protected by law. To view more information about your equal opportunity and non-discrimination rights as a candidate, visit EEO is the Law. If you are an individual with a disability and you require an accommodation during the application process, please visit here.
$100k-125k yearly Auto-Apply 60d+ ago
Security Systems Field Laborer
Laforce Careers 4.2
Tampa, FL jobs
At LaForce, we specialize in delivering access control, video surveillance, and intercom solutions that keep people and businesses secure. We're looking for a dedicated and skilled Security Integration Field Laborer in our Tampa, FL location to join our team. This role assists with installing and maintaining access control systems, video surveillance, and other electro-mechanical security products for commercial businesses.
What You'll Do:
As a Field Laborer, you will help with ensuring secure and functional installations for our customers. Every day will bring new challenges, from problem solving complex technical issues to learning new technologies in the security industry. Your day-to-day will include:
Helping with installing and programming access control systems, CCTV, intercoms, security systems, and electrical hardware with precision and efficiency.
Troubleshooting and adjusting new or existing systems to meet customer needs.
Safely handling disassembly and removal of electrical products and door hardware.
Training customers on new and existing systems and software.
Producing quality results on time and within budget, representing the company professionally, and fostering strong customer relationships.
Helping with accurate wiring diagrams upon project completion for future reference.
Maintaining clear, professional communication with customers, sales staff, and supervisors.
Operating a company vehicle safely and respectfully in accordance with company policy.
What You'll Bring:
We welcome applicants with technical certificates, equivalent professional experience, or relevant military experience in electrical or mechanical fields. The ideal candidate has knowledge of low-voltage electrical wiring, the ability to read wiring diagrams and blueprints, strong problem-solving skills, and a valid driver's license with a clean record.
Physical Requirements
This role demands physical stamina and precision, including:
Frequently standing, walking, climbing ladders, and lifting up to 40 pounds.
Occasionally carrying loads up to 75 pounds
Performing tasks requiring elevated activity.
Why Join LaForce?
At LaForce, you're part of a team dedicated to growth, innovation, and excellence. From competitive pay to a supportive culture that values your ideas, we're here to help you thrive. You'll receive a cell phone stipend, company-provided tools, and comprehensive hands-on training.
How to Apply
Screening includes a drug test, background check, and driver's license verification. If you're passionate about security systems and looking to make a difference in the field, apply today! We look forward to meeting you!
$70k-101k yearly est. 60d+ ago
Security Systems Field Laborer
Laforce Inc. 4.2
Tampa, FL jobs
At LaForce, we specialize in delivering access control, video surveillance, and intercom solutions that keep people and businesses secure. We're looking for a dedicated and skilled Security Integration Field Laborer in our Tampa, FL location to join our team. This role assists with installing and maintaining access control systems, video surveillance, and other electro-mechanical security products for commercial businesses.
What You'll Do:
As a Field Laborer, you will help with ensuring secure and functional installations for our customers. Every day will bring new challenges, from problem solving complex technical issues to learning new technologies in the security industry. Your day-to-day will include:
* Helping with installing and programming access control systems, CCTV, intercoms, security systems, and electrical hardware with precision and efficiency.
* Troubleshooting and adjusting new or existing systems to meet customer needs.
* Safely handling disassembly and removal of electrical products and door hardware.
* Training customers on new and existing systems and software.
* Producing quality results on time and within budget, representing the company professionally, and fostering strong customer relationships.
* Helping with accurate wiring diagrams upon project completion for future reference.
* Maintaining clear, professional communication with customers, sales staff, and supervisors.
* Operating a company vehicle safely and respectfully in accordance with company policy.
What You'll Bring:
We welcome applicants with technical certificates, equivalent professional experience, or relevant military experience in electrical or mechanical fields. The ideal candidate has knowledge of low-voltage electrical wiring, the ability to read wiring diagrams and blueprints, strong problem-solving skills, and a valid driver's license with a clean record.
Physical Requirements
This role demands physical stamina and precision, including:
* Frequently standing, walking, climbing ladders, and lifting up to 40 pounds.
* Occasionally carrying loads up to 75 pounds
* Performing tasks requiring elevated activity.
Why Join LaForce?
At LaForce, you're part of a team dedicated to growth, innovation, and excellence. From competitive pay to a supportive culture that values your ideas, we're here to help you thrive. You'll receive a cell phone stipend, company-provided tools, and comprehensive hands-on training.
How to Apply
Screening includes a drug test, background check, and driver's license verification. If you're passionate about security systems and looking to make a difference in the field, apply today! We look forward to meeting you!
$70k-101k yearly est. 60d+ ago
Principal Security Engineer - IAM
Lennar 4.5
Waterford, MI jobs
We are Lennar
Lennar is one of the nation's leading homebuilders, dedicated to making an impact and creating an extraordinary experience for their Homeowners, Communities, and Associates by building quality homes and providing exceptional customer service, giving back to the communities in which we work and live in, and fostering a culture of opportunity and growth for our Associates throughout their career. Lennar has been recognized as a Fortune 500 company and consistently ranked among the top homebuilders in the United States.
Join a Company that Empowers you to Build your Future
The Principal Security Engineer is the highest technical position within the security engineering team, responsible for driving the overall security strategy of the organization. This role is focused on designing cutting-edge security solutions, with a strong emphasis on cloud security, and leading the organization's response to the most complex security challenges.
A career with purpose.
A career built on making dreams come true.
A career built on building zero defect homes, cost management, and adherence to schedules.
Your Responsibilities on the Team
Define and lead the implementation of the organization's security strategy, with a focus on Cloud Security, Identity Access Management, and all other aspects of Cybersecurity
Architect and oversee the deployment of IAM solutions across both on-premise and cloud environments, ensuring they meet the highest standards of security.
Lead the most complex security assessments, including threat modeling, red teaming, and cloud security reviews.
Collaborate with executive leadership to ensure that security initiatives align with the organization's strategic goals and risk appetite.
Act as the technical lead for large-scale security projects, coordinating cross-functional teams to ensure successful delivery.
Architect and implement solutions across workforce IAM, PAM, and customer IAM ecosystems.
Provide thought leadership in adopting passwordless authentication, passkeys, adaptive MFA, and AI-driven access orchestration strategies
Engineer integrations with Agentic AI tools for intelligent decisioning, policy enforcement, and autonomous identity lifecycle operations.
Develop and implement automated provisioning/deprovisioning workflows
Ensure integration of IAM with cloud platforms (Azure, AWS, GCP) and SaaS applications.
Mentor and develop the skills of seniorsecurity engineers, fostering a culture of continuous improvement and innovation.
Requirements
Education: Bachelor's degree in Computer Science, Cybersecurity, or a related discipline; Master's degree is highly preferred.
Professional Experience: Minimum of 10 years in security engineering, with significant expertise in Identity and Access Management (IAM).
Project Leadership: Demonstrated success in leading large-scale IAM initiatives and formulating security strategies for complex organizations.
IAM Solutions: Design and hands-on engineering across IAM:
Identity Providers (such as Microsoft Entra ID, Okta, Ping, ForgeRock),
Identity Governance & Administration (SailPoint, Saviynt),
Privileged Access Management (CyberArk, Delinea, HashiCorp Vault), and
Customer IAM (Auth0, PingOne-preferred).
Protocols & APIs: Deep understanding of federation protocols (SAML, OAuth2.0, OIDC), SCIM, and RESTful APIs.
Directory Services & Cloud IAM: Hands-on experience with Active Directory, LDAP, and cloud IAM solutions (Azure, AWS, GCP).
Security Frameworks: Solid foundation in Zero Trust architecture and contemporary security standards.
Automation: Proficient in scripting and automation using PowerShell, Python, Java, or RESTful APIs.
Recognized industry certifications such as CISSP, CCSP, AWS Certified Security - Specialty, or equivalent credentials.
Exceptional leadership and communication abilities, capable of influencing executive decision-makers and directing cross-functional teams.
Physical & Office/Site Presence Requirements
This is primarily a sedentary office position which requires the incumbent to have the ability to operate computer equipment, speak, hear, bend, stoop, reach, lift, and move and carry up to 25 lbs. Finger dexterity is necessary.
This description outlines the basic responsibilities and requirements for the position noted. This is not a comprehensive listing of all job duties of the Associates. Duties, responsibilities and activities may change at any time with or without notice.
Life at Lennar
At Lennar, we are committed to fostering a supportive and enriching environment for our Associates, offering a comprehensive array of benefits designed to enhance their well-being and professional growth. Our Associates have access to robust health insurance plans, including Medical, Dental, and Vision coverage, ensuring their health needs are well taken care of. Our 401(k) Retirement Plan, complete with a $1 for $1 Company Match up to 5%, helps secure their financial future, while Paid Parental Leave and an Associate Assistance Plan provide essential support during life's critical moments. To further support our Associates, we provide an Education Assistance Program and up to $30,000 in Adoption Assistance, underscoring our commitment to their diverse needs and aspirations. From the moment of hire, they can enjoy up to three weeks of vacation annually, alongside generous Holiday, Sick Leave, and Personal Day policies. Additionally, we offer a New Hire Referral Bonus Program, significant Home Purchase Discounts, and unique opportunities such as the Everyone's Included Day. At Lennar, we believe in investing in our Associates, empowering them to thrive both personally and professionally. Lennar Associates will have access to these benefits as outlined by Lennar's policies and applicable plan terms. Visit Lennartotalrewards.com to view our suite of benefits.
Join the fun and follow us on social media to see what's happening at our company, and don't forget to connect with us on Lennar: Overview | LinkedIn for the latest job opportunities.
Lennar is an equal opportunity employer and complies with all applicable federal, state, and local fair employment practices laws.
$94k-122k yearly est. Auto-Apply 60d+ ago
Security Engineer
E.T. Gresham 3.1
Woodlawn, MD jobs
•5+ years in Security Architecture •Must have Public Trust Clearance (required prior to start) •2+ years of experience with OpenStack based private cloud suite •4+ years with preparing Cloud Security Assessments and Documentation •3+ years creating technical security architecture design documentation and standard operating procedure
•3+ years of experience with security hardening in RHEL, vulnerability scanning using Nessus and penetration testing.
•3+ years of experience analyzing malware, advanced persistent threats, security breaches.
•3+ years of experience with Red Hat Linux Enterprise 6/7
•3+ years of experience performing vulnerability scanning risk analysis and coordinated technical remediation activities
Regards
Avinash
**************************
************
Additional Information
All your information will be kept confidential according to EEO guidelines.
$82k-112k yearly est. Easy Apply 1d ago
AI Security Engineer
The Aspen Group 4.0
Chicago, IL jobs
The Aspen Group (TAG) is one of the largest and most trusted retail healthcare business support organizations in the U.S. and has supported over 20,000 healthcare professionals and team members with close to 1,500 health and wellness offices across 48 states in four distinct categories: dental care, urgent care, medical aesthetics, and animal health. Working in partnership with independent practice owners and clinicians, the team is united with a single purpose: to prove that healthcare can be better and smarter for everyone. TAG provides a comprehensive suite of centralized business support services that power the impact of five consumer-facing businesses: Aspen Dental, ClearChoice Dental Implant Centers, WellNow Urgent Care, Chapter Aesthetic Studio, and Lovet. Each brand has access to a deep community of experts, tools and resources to grow their practices, and an unwavering commitment to delivering high-quality consumer healthcare experiences at scale.
As a reflection of our current needs and planned growth we are very pleased to offer a new opportunity to join our dedicated team as a AI Security Engineer.
Job Overview:
An AI security engineer designs and implements security controls for AI systems, protecting models, data, and infrastructure from threats like adversarial attacks and prompt injection. Key responsibilities include performing technical security assessments, developing AI-specific defenses, integrating security into the AI/ML lifecycle, and creating automated security tools for tasks like threat detection and compliance. This role requires a combination of cybersecurity fundamentals and AI-specific knowledge, including secure coding for AI and understanding AI-related vulnerabilities.
Essential Job Duties
Collaboratively develop agent RBAC (role-based access control) to ensure AI agents operate under permissions aligned to firm roles, enforcing least-privilege access
Design integrations for AI systems with corporate IAM/SSO (Entra, Okta, etc.) to manage persona- and role-based access across the enterprise
Design Data Loss Prevention (DLP) and redaction pipelines to prevent confidential, regulated, or proprietary data from being sent to external LLM endpoints
Provide technical advice, direction, and hands-on support to design and develop safe, compliant, and resilient AI workflows
Evaluate existing and proposed AI/ML architectures for bias, fairness, drift, hallucination, and security risks; recommend controls aligned with NIST AI RMF, EU AI Act, ISO/IEC 42001, CIS
Collaborate with Information Security, Cloud, Governance, and Engineering teams to implement standardized AI safety and compliance practices
Actively contribute to the development of AI security standards, playbooks, and architectural patterns
Automate guardrails, compliance checks, and AI gateway protections for scale and efficiency
Build and maintain initiative-level artifacts, including AI policy-as-code configs (YAML), architectural diagrams, and risk assessments
Monitor, log, and audit AI activity for policy violations, compliance tracking, and security event correlation. YAML-based guardrails, architectural diagrams, and AI risk assessments
Design and build systems to detect and prevent AI abuse, such as anti-abuse agents.
Perform technical security assessments, code reviews, and penetration testing on AI products and systems.
Integrate security controls throughout the AI/ML lifecycle, from data handling and model training to deployment and monitoring.
Develop and implement AI-driven automation for tasks like real-time alert enrichment, log analysis, and incident triage using tools like Security Copilot and other AI-assisted platforms.
Research and reproduce vulnerabilities in AI systems, develop mitigation strategies, and work with engineering teams to improve security.
Contribute to creating and implementing governance policies, security standards, and privacy frameworks for AI systems.
Develop AI-specific incident response plans and playbooks.
Stay up-to-date on emerging AI security threats, such as adversarial attacks, prompt injection, and data leakage.
Skills and Experience
At least 5+ years' experience in cybersecurity, including compliance and risk management with a system and network security engineering background.
Strong background in traditional cybersecurity, including networking, web-based protocols, and security systems.
Experience in secure software development, including secure coding for AI-powered applications.
Familiarity with AI concepts, machine learning, and the AI/ML lifecycle.
Experience with implementing security controls like encryption, access controls, and authentication for AI systems.
Experience with security tools and platforms like Chronicle & Orca/Wiz, and familiarity with concepts like SAST/DAST.
Excellent problem-solving, communication, and leadership skills.
Experience with dynamic and static analysis tools.
Track record of acting with integrity, taking pride in work, seeking to excel, being curious and adaptable, and communicating effectively.
Additional Qualifications
Experience with applications hosted in Google Cloud Platform (GCP), Amazon Web Services (AWS) or Microsoft Azure.
Experience with cryptography controls and measures to secure applications and data. Proficiency with scripting in Python, JavaScript, PowerShell, PHP or Ruby.
Proficiency with Terraform, Python, and cloud automation
Prior experience in cloud security, data protection, and SIEM/logging for AI traffic
Experience with one or more of the following: ISO 27001, NIST, PCI Data Security Standard (PCI DSS), HIPAA, Health Information Technology for Economic and Clinical Health (HITECH) Act, SOX, the General Data Protection Regulation (GDPR), Center for Internet Security (CIS) standards or Service Organization Controls (SOC) 2.
Working knowledge of Windows, Linux and Unix.
Familiarity with state privacy laws.
Highly trustworthy; leads by example.
Education Requirements
Bachelor's degree in computer science, information assurance, MIS or related field, or equivalent.
Experience Requirements
5-7+ years of related experience required
Certification Requirements
SANS certifications (GWAPT) and others; CISSP (preferred, or CSSLP), OSCP (and related)
Annual Salary Range: $130,000-$150,000/year, with a generous benefits package that includes paid time off, health, dental, vision, and 401(k) savings plan with match.
If you are an applicant residing in California, please view our privacy policy here: *********************************************************************************
$130k-150k yearly Auto-Apply 50d ago
Security Engineer II
Procore Technologies, Inc. 4.5
Austin, TX jobs
We're looking for a Security Engineer II to join Procore's Security Engineering team. In this role, you'll be a key contributor, focused on building, implementing, and operating the foundational security controls that protect our platform, data, and users. Your primary goal is to help build and maintain a secure, scalable, and resilient cloud product and infrastructure.
As a Security Engineer II, you'll work with Engineering, IT, Security Operations, and GRC to apply security principles to our systems. Use your experience in cloud security, automation, and core security principles to implement and operate automated security controls across our SaaS ecosystem. This is a fantastic opportunity to grow your skills and make a real impact on protecting the data of millions of users-Apply today.
This position reports into the Senior Director, Security Engineering and will be based in our Austin, TX office. We're looking for someone to join us immediately.
What you'll do:
* Configure and support IAM guardrails for cloud (AWS/GCP/Azure) and corporate (Okta) environments.
* Implement and support automated pipelines for asset inventory and Software Bill of Materials (SBOM) generation.
* Support the implementation of data protection tools and processes, including key management and encryption.
* Implement secure configurations for our containerized (Kubernetes, EKS) and IaC (Terraform) workflows under the guidance of senior engineers.
* Collaborate with Product & Technology teams to test and document resilience patterns.
* Assist GRC and Internal Audit teams by gathering data and providing context on security controls.
* Operate and triage alerts from security tools and platforms, and help drive remediation.
* Participate in the evaluation of new security technologies and tools.
* Provide on-call support on a rotational basis.
What we're looking for:
* Bachelor's degree in Computer Science or equivalent practical experience.
* 2+ years of experience in a hands-on technical security or IT/ops role with a security focus.
* Solid understanding of core security domains such as IAM, network security, and infrastructure security.
* Hands-on experience with at least one major cloud provider (AWS preferred).
* Hands-on experience identifying and exploiting common web/API vulnerabilities (e.g., Burp Suite usage) and secure API design.
* Proficiency in scripting to automate simple security tasks or checks.
* Familiarity with identity and access management platforms platforms (IdP, IGA, PAM), joiner-mover-leaver (JML) mechanisms, and concepts (SAML, OAuth 2.0, OIDC, SCIM).
* Experience with, or a strong desire to learn, IaC (Terraform) and container orchestration (Kubernetes).
* Understanding of data protection principles, including encryption and key management.
* A passion for automation and experience with scripting languages (Python, Go, or similar).
* Good communication skills and a collaborative, team-oriented attitude.
Additional Information
Base Pay Range:
113,040.00 - 155,430.00 USD Annual
This role may also eligible for Equity Compensation. Procore is committed to offering competitive, fair, and commensurate compensation, and has provided an estimated pay range for this role. Actual compensation will be based on a candidate's job-related skills, experience, education or training, and location.
This position requires access to technology, software, and data that is controlled or restricted under U.S. law, regulation, executive order, or government contract.
For Los Angeles County (unincorporated) Candidates:
Procore will consider for employment all qualified applicants, including those with arrest or conviction records, in accordance with the requirements of applicable federal, state, and local laws, including the City of Los Angeles' Fair Chance Initiative for Hiring Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act.
A criminal history may have a direct, adverse, and negative relationship on the following job duties, potentially resulting in the withdrawal of the conditional offer of employment: 1. appropriately managing, accessing, and handling confidential information including proprietary and trade secret information, as well as accessing Procore's information technology systems and platforms; 2. interacting with and occasionally having unsupervised contact with internal/external customers, stakeholders, and/or colleagues; and 3. exercising sound judgment.
$89k-113k yearly est. 41d ago
Principal Security Engineer - IAM
Lennar 4.5
Irving, TX jobs
THIS ROLE WILL BE ONSITE IN OUR IRVING, TX. OFFICE
We are Lennar
Lennar is one of the nation's leading homebuilders, dedicated to making an impact and creating an extraordinary experience for their Homeowners, Communities, and Associates by building quality homes and providing exceptional customer service, giving back to the communities in which we work and live in, and fostering a culture of opportunity and growth for our Associates throughout their career. Lennar has been recognized as a Fortune 500 company and consistently ranked among the top homebuilders in the United States.
Join a Company that Empowers you to Build your Future
The Principal Security Engineer is the highest technical position within the security engineering team, responsible for driving the overall security strategy of the organization. This role is focused on designing cutting-edge security solutions, with a strong emphasis on cloud security, and leading the organization's response to the most complex security challenges.
A career with purpose.
A career built on making dreams come true.
A career built on building zero defect homes, cost management, and adherence to schedules.
Your Responsibilities on the Team
Define and lead the implementation of the organization's security strategy, with a focus on Cloud Security, Identity Access Management, and all other aspects of Cybersecurity
Architect and oversee the deployment of IAM solutions across both on-premise and cloud environments, ensuring they meet the highest standards of security.
Lead the most complex security assessments, including threat modeling, red teaming, and cloud security reviews.
Collaborate with executive leadership to ensure that security initiatives align with the organization's strategic goals and risk appetite.
Act as the technical lead for large-scale security projects, coordinating cross-functional teams to ensure successful delivery.
Architect and implement solutions across workforce IAM, PAM, and customer IAM ecosystems.
Provide thought leadership in adopting passwordless authentication, passkeys, adaptive MFA, and AI-driven access orchestration strategies
Engineer integrations with Agentic AI tools for intelligent decisioning, policy enforcement, and autonomous identity lifecycle operations.
Develop and implement automated provisioning/deprovisioning workflows
Ensure integration of IAM with cloud platforms (Azure, AWS, GCP) and SaaS applications.
Mentor and develop the skills of seniorsecurity engineers, fostering a culture of continuous improvement and innovation.
Requirements
Education: Bachelor's degree in Computer Science, Cybersecurity, or a related discipline; Master's degree is highly preferred.
Professional Experience: Minimum of 10 years in security engineering, with significant expertise in Identity and Access Management (IAM).
Project Leadership: Demonstrated success in leading large-scale IAM initiatives and formulating security strategies for complex organizations.
IAM Solutions: Design and hands-on engineering across IAM:
Identity Providers (such as Microsoft Entra ID, Okta, Ping, ForgeRock),
Identity Governance & Administration (SailPoint, Saviynt),
Privileged Access Management (CyberArk, Delinea, HashiCorp Vault), and
Customer IAM (Auth0, PingOne-preferred).
Protocols & APIs: Deep understanding of federation protocols (SAML, OAuth2.0, OIDC), SCIM, and RESTful APIs.
Directory Services & Cloud IAM: Hands-on experience with Active Directory, LDAP, and cloud IAM solutions (Azure, AWS, GCP).
Security Frameworks: Solid foundation in Zero Trust architecture and contemporary security standards.
Automation: Proficient in scripting and automation using PowerShell, Python, Java, or RESTful APIs.
Recognized industry certifications such as CISSP, CCSP, AWS Certified Security - Specialty, or equivalent credentials.
Exceptional leadership and communication abilities, capable of influencing executive decision-makers and directing cross-functional teams.
Physical & Office/Site Presence Requirements
This is primarily a sedentary office position which requires the incumbent to have the ability to operate computer equipment, speak, hear, bend, stoop, reach, lift, and move and carry up to 25 lbs. Finger dexterity is necessary.
This description outlines the basic responsibilities and requirements for the position noted. This is not a comprehensive listing of all job duties of the Associates. Duties, responsibilities and activities may change at any time with or without notice.
Life at Lennar
At Lennar, we are committed to fostering a supportive and enriching environment for our Associates, offering a comprehensive array of benefits designed to enhance their well-being and professional growth. Our Associates have access to robust health insurance plans, including Medical, Dental, and Vision coverage, ensuring their health needs are well taken care of. Our 401(k) Retirement Plan, complete with a $1 for $1 Company Match up to 5%, helps secure their financial future, while Paid Parental Leave and an Associate Assistance Plan provide essential support during life's critical moments. To further support our Associates, we provide an Education Assistance Program and up to $30,000 in Adoption Assistance, underscoring our commitment to their diverse needs and aspirations. From the moment of hire, they can enjoy up to three weeks of vacation annually, alongside generous Holiday, Sick Leave, and Personal Day policies. Additionally, we offer a New Hire Referral Bonus Program, significant Home Purchase Discounts, and unique opportunities such as the Everyone's Included Day. At Lennar, we believe in investing in our Associates, empowering them to thrive both personally and professionally. Lennar Associates will have access to these benefits as outlined by Lennar's policies and applicable plan terms. Visit Lennartotalrewards.com to view our suite of benefits.
Join the fun and follow us on social media to see what's happening at our company, and don't forget to connect with us on Lennar: Overview | LinkedIn for the latest job opportunities.
Lennar is an equal opportunity employer and complies with all applicable federal, state, and local fair employment practices laws.
$95k-120k yearly est. Auto-Apply 4d ago
Security Engineer
The Sundt Companies 4.8
Tempe, AZ jobs
JobID: 9112 JobSchedule: Full time JobShift: : As a 100% employee-owned contractor, when you work at Sundt, you're not just hiring on at a company, you're joining a culture. Because everyone at Sundt is part owner, you'll join a team of people who are deeply invested in their work. From apprentices to managers, we're passionate about the details and deliberate in everything we do.
At Sundt we focus on building long-term prosperity for our clients, communities, and employee-owners. We offer competitive pay, industry-leading benefits including a 401k and employee stock ownership plan, incentive programs for craft and administrative employees as well as training that focuses on your personal and professional growth. We're driven by skill, grit and purpose. Join us as we strive to be the most skilled builder in America.
Job Summary
As a Security Engineer, you will play a crucial role in safeguarding our organization's digital assets and infrastructure. You will be responsible for implementing, managing, and maintaining security solutions and practices to protect against threats and vulnerabilities. Your role will involve close collaboration with various teams to ensure the security of our systems, applications, and data. This position is generally more focused on implementation and maintenance rather than strategy.
Key Responsibilities
1. Asset Security: Protect organizational assets, including data, hardware, and software, through the implementation of security policies and controls.
2. Communication and Network Security: Provide guidance on secure communication protocols and network infrastructure. Ensure the integrity and confidentiality of data transmitted across networks.
3. Identity and Access Management (IAM): Implement and manage IAM solutions to enforce access controls, authentication mechanisms, and user privileges. Ensure compliance with security policies and best practices.
4. Security Architecture and Engineering: Design and implement secure network and system architectures. Stay updated on emerging threats and technologies, and apply security measures accordingly.
5. Security Assessment and Testing: Perform regular vulnerability assessments, penetration testing, and security audits. Identify and remediate security weaknesses in systems and applications.
6. Security Operations: Monitor security alerts and incidents, analyze potential threats, and respond promptly to mitigate risks. Conduct root cause analysis and develop incident response plans.
7. Security and Risk Management: Evaluate and manage security risks. Develop and implement risk mitigation strategies and ensure compliance with relevant security standards and regulations.
8. Software Development Security: Collaborate with software development teams to integrate security practices into the software development lifecycle. Ensure secure coding practices and conduct security reviews.
Minimum Job Requirements
1. Ability to work independently and manage multiple tasks in a fast-paced environment.
2. Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent work experience.
3. Excellent problem-solving skills and attention to detail.
4. Experience with scripting and programming languages (e.g., Python, PowerShell) for automation and integration.
5. Minimum of 3-5 years of experience in cybersecurity or a related field.
6. Proficiency in security tools and technologies such as Office 365, Azure, Sentinel One EDR & XOR, Tenable Nessus, Microsoft Defender, and Proofpoint.
7. Relevant certifications such as CISSP, CISM, CEH, or equivalent preferred.
8. Strong communication and interpersonal skills for effective collaboration with cross-functional teams.
9. Strong knowledge of security frameworks and standards (e.g., CMMC, NIST, ISO 27001/27002).
Note: Job Description is subject to change at any time and may include other duties as assigned.
Physical Requirements
1. May stoop, kneel, or bend, on an occasional basis
2. Must be able to comply with all safety standards and procedures
3. Required to use hands to grasp, lift, handle, carry or feel objects on a frequent basis
4. Will interact with people and technology frequently during a shift/work day
5. Will lift, push or pull objects up to 50Ibs on an occasional basis.
6. Will sit, stand or walk short distances for up to the entire duration of a shift/work day.
7. Will use telephone, computer system, email, and other electronic devices on a frequent basis to communicate with internal and external customers or vendors
Safety Level
Non-Safety Sensitive
Note: Jobs with the Safety-Sensitive designation are those that include tasks or duties that the employer reasonably believes could affect the safety and health of the employee performing the task or others such as operating a vehicle, operating equipment, operating machinery or power tools, repairing/maintaining the operation of any vehicle/equipment, the handling/disposal/transport of hazardous materials, or the handling/treatment/disposal of potentially flammable/combustible materials.
Equal Opportunity Employer Statement: Sundt is committed to the equal treatment of all employees, and/or applicants for employment, and prohibits discrimination based on race, religion, sex (including pregnancy), sexual orientation, gender identity, color, age, disability, national origin, covered veteran status, genetic information; or any other classification protected by applicable Federal, state, or local laws.
Benefit list:
Market Competitive Salary (paid weekly)
Bonus Eligibility based on company, group, and individual performance
Employee Stock Ownership Plan & 401K
Industry Leading Health Coverage Starting Your First Day
Flexible Time Off (FTO)
Medical, Health Savings, and Wellness credits
Flexible Spending Accounts
Employee Assistance Program
Workplace Wellness Programs
Mental Health Program
Life and Disability Insurance
Employee-Owner Perks
Educational Assistance
Sundt Foundation - Charitable Employee-Owner's program
$87k-115k yearly est. Auto-Apply 47d ago
Security Engineer
Sundt Construction 4.8
Tempe, AZ jobs
As a 100% employee-owned contractor, when you work at Sundt, you're not just hiring on at a company, you're joining a culture. Because everyone at Sundt is part owner, you'll join a team of people who are deeply invested in their work. From apprentices to managers, we're passionate about the details and deliberate in everything we do.
At Sundt we focus on building long-term prosperity for our clients, communities, and employee-owners. We offer competitive pay, industry-leading benefits including a 401k and employee stock ownership plan, incentive programs for craft and administrative employees as well as training that focuses on your personal and professional growth. We're driven by skill, grit and purpose. Join us as we strive to be the most skilled builder in America.
Job Summary
As a Security Engineer, you will play a crucial role in safeguarding our organization's digital assets and infrastructure. You will be responsible for implementing, managing, and maintaining security solutions and practices to protect against threats and vulnerabilities. Your role will involve close collaboration with various teams to ensure the security of our systems, applications, and data. This position is generally more focused on implementation and maintenance rather than strategy.
Key Responsibilities
1. Asset Security: Protect organizational assets, including data, hardware, and software, through the implementation of security policies and controls.
2. Communication and Network Security: Provide guidance on secure communication protocols and network infrastructure. Ensure the integrity and confidentiality of data transmitted across networks.
3. Identity and Access Management (IAM): Implement and manage IAM solutions to enforce access controls, authentication mechanisms, and user privileges. Ensure compliance with security policies and best practices.
4. Security Architecture and Engineering: Design and implement secure network and system architectures. Stay updated on emerging threats and technologies, and apply security measures accordingly.
5. Security Assessment and Testing: Perform regular vulnerability assessments, penetration testing, and security audits. Identify and remediate security weaknesses in systems and applications.
6. Security Operations: Monitor security alerts and incidents, analyze potential threats, and respond promptly to mitigate risks. Conduct root cause analysis and develop incident response plans.
7. Security and Risk Management: Evaluate and manage security risks. Develop and implement risk mitigation strategies and ensure compliance with relevant security standards and regulations.
8. Software Development Security: Collaborate with software development teams to integrate security practices into the software development lifecycle. Ensure secure coding practices and conduct security reviews.
Minimum Job Requirements
1. Ability to work independently and manage multiple tasks in a fast-paced environment.
2. Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent work experience.
3. Excellent problem-solving skills and attention to detail.
4. Experience with scripting and programming languages (e.g., Python, PowerShell) for automation and integration.
5. Minimum of 3-5 years of experience in cybersecurity or a related field.
6. Proficiency in security tools and technologies such as Office 365, Azure, Sentinel One EDR & XOR, Tenable Nessus, Microsoft Defender, and Proofpoint.
7. Relevant certifications such as CISSP, CISM, CEH, or equivalent preferred.
8. Strong communication and interpersonal skills for effective collaboration with cross-functional teams.
9. Strong knowledge of security frameworks and standards (e.g., CMMC, NIST, ISO 27001/27002).
Note: Job Description is subject to change at any time and may include other duties as assigned.
Physical Requirements
1. May stoop, kneel, or bend, on an occasional basis
2. Must be able to comply with all safety standards and procedures
3. Required to use hands to grasp, lift, handle, carry or feel objects on a frequent basis
4. Will interact with people and technology frequently during a shift/work day
5. Will lift, push or pull objects up to 50Ibs on an occasional basis.
6. Will sit, stand or walk short distances for up to the entire duration of a shift/work day.
7. Will use telephone, computer system, email, and other electronic devices on a frequent basis to communicate with internal and external customers or vendors
Safety Level
Non-Safety Sensitive
Note: Jobs with the Safety-Sensitive designation are those that include tasks or duties that the employer reasonably believes could affect the safety and health of the employee performing the task or others such as operating a vehicle, operating equipment, operating machinery or power tools, repairing/maintaining the operation of any vehicle/equipment, the handling/disposal/transport of hazardous materials, or the handling/treatment/disposal of potentially flammable/combustible materials.
Equal Opportunity Employer Statement: Sundt is committed to the equal treatment of all employees, and/or applicants for employment, and prohibits discrimination based on race, religion, sex (including pregnancy), sexual orientation, gender identity, color, age, disability, national origin, covered veteran status, genetic information; or any other classification protected by applicable Federal, state, or local laws.
Benefit list:
Market Competitive Salary (paid weekly)
Bonus Eligibility based on company, group, and individual performance
Employee Stock Ownership Plan & 401K
Industry Leading Health Coverage Starting Your First Day
Flexible Time Off (FTO)
Medical, Health Savings, and Wellness credits
Flexible Spending Accounts
Employee Assistance Program
Workplace Wellness Programs
Mental Health Program
Life and Disability Insurance
Employee-Owner Perks
Educational Assistance
Sundt Foundation - Charitable Employee-Owner's program
$87k-115k yearly est. Auto-Apply 47d ago
Information Security Analyst
Deem 4.7
Arizona jobs
Our mission is simple. We make business travel less complicated for travelers, less costly for employers and more profitable for service providers. Using our industry-leading software solutions, employees book travel and car service and report those expenses faster and more easily than ever before. Corporations control costs more effectively. Travel management companies deliver more engaging customer experiences. Car service operators benefit from new efficiencies and widen their customer reach. In other words, everybody wins. We've helped thousands of forward-thinking companies modernize their systems, improve travel management and save money. Deem is backed by leading venture capital funds as well as corporate and private equity investors. The company is headquartered in San Francisco, CA and has an office in Bangalore, India.
We are seeking an experienced, talented, energetic, hands-on, and proactive Information Security Analyst to maintain and operate Deem's Information Security programs. You will be responsible for developing policies and driving processes based on a combination of threat intelligence and regulatory compliance.
Responsibilities
Advise senior management in the development, implementation and maintenance of a company-wide information security infrastructure, and ensure appropriate control objectives for system integrity, confidentiality, accountability and assurance within the context of the company's risk tolerance.
Ensure conformance with enterprise policy standards, which include monitoring metrics, response integration and escalation, and various risk analysis.
Maintain internal governance and recommend adjustments as threats and practices evolve.
Operate the information protection effort to comply with industry standard audits including (SSAE-18, SOC , PCI 3.2).
Determine security violations and inefficiencies by conducting periodic internal audits.
Develop a prioritized plan to close security gaps. Work with engineering teams (product & operations) to implement solutions.
Be hands-on where/when appropriate, in installing and evaluating security tools.
Install and maintain security management and monitoring tools in corporate and production environments, including vulnerability scanning, SEIM, IDS, etc.
Make sound, well-reasoned recommendations on vendor and tool selection.
Provide securityconsultation as needed for product development and industry marketing solutions.
Manage Internal Penetration Testing & Vulnerability Assessment Tools and Programs.
Investigate security incidents and recommend actions needed to resolve situations.
Work with product engineering to test for and fix vulnerabilities in the product code.
Develop content for and administer Employee Security Training Programs.
Qualifications
3+ years in the technology industry, 3+ in an information security role
Expert knowledge of identity management, IDS, SEM/SIEM, WAF
Industry-standard certifications: CISSP, or equivalent
Expertise in compliance standards, most notably PCI and SSAE16
Experience leading security and compliance audits
Thorough understanding and up-to-date knowledge of the web security threats (XSS, code injection, etc.)
Strong troubleshooting and forensic skills and ability to effectively work in cross functional teams as needed to resolve issues
Strong written, oral, and interpersonal communications skills
Capable of performing penetration tests and collaborating with Engineering on the static security analysis and remediation
Coding experience with Ruby, Java, Python, Javascript, Bash, or C# are nice to have