Post job

Security Architect jobs at Comcast - 162 jobs

  • Aircraft Services Architect

    Global Connect Technologies 4.4company rating

    Portland, OR jobs

    Job Title: Aircraft Services Architect Duration: Long Term The Aircraft Services Architect will provide technical leadership and architectural expertise for complex aviation software systems. This role is responsible for defining, designing, and governing secure, scalable, and standards-compliant architectures for aircraft and in-flight systems. The position ensures compliance with aviation regulations such as DO-178C, DAL-D/E, and Security Assurance Levels (SAL) while enabling integration across multiple aircraft domains and platforms. Key Responsibilities Define system-level and product-level requirements, including both functional and non-functional requirements, for aviation software systems. Translate requirements into technical specifications, architecture designs, and implementation artifacts. Design and govern system and software architectures that meet DAL-D/E and SAL 1-3 assurance requirements, including domain and data segregation. Lead architecture design for hosting platforms leveraging cloud-native virtualization technologies. Ensure compliance with DO-178C and other applicable aviation safety and regulatory standards. Collaborate with engineering teams, aircraft OEMs, and manufacturers for system integration, validation, and certification activities. Design and implement secure system architectures, including secure boot, secure firmware updates, encryption, authentication, and secure communication protocols. Support Agile development teams, including participation in PI planning, sprint reviews, and architecture/design reviews. Develop and maintain architecture diagrams, design documentation, and test strategy reviews. Act as a technical leader and mentor, guiding teams on best practices, resolving design challenges, and improving engineering processes. Required Skills & Expertise Aviation Software Architecture Extensive experience designing and implementing large-scale, complex aviation software systems. Compliance & Standards Strong knowledge of DO-178C, DAL-D/E, SAL levels, and aviation security standards. Security Hands-on expertise in encryption, authentication, access control, threat modeling, secure boot, and secure firmware updates. Virtualization & Hosting Experience with cloud-native virtualization technologies for hosting and platform architectures. Programming & Platforms Proficiency in C++, GoLang, Java, and Python. Experience with Linux kernel programming and embedded/Linux-based systems. Databases Working knowledge of MySQL, MariaDB, and SQLite. Quality & Process Strong understanding of aviation software QA processes, including verification, validation, and SQA. Experience working within SAFe or SCRUM Agile frameworks. Nice-to-Have Skills Experience with AWS Cloud and cloud-native architectures. Familiarity with CI/CD pipelines and DevOps practices. Exposure to architecture and collaboration tools such as Confluence, Visio, Draw.io. Qualifications Bachelor's or Master's degree in Computer Science, Aerospace Engineering, or a related field. 8+ years of experience in aviation software architecture and design. Prior experience working with aircraft OEMs or aviation systems is highly desirable. Strong analytical, problem-solving, communication, and leadership skills. Proven ability to collaborate with global, cross-functional teams.
    $84k-135k yearly est. 2d ago
  • Job icon imageJob icon image 2

    Looking for a job?

    Let Zippia find it for you.

  • Platform Services Architect

    L&T Technology Services 3.6company rating

    Hillsboro, OR jobs

    The Platform Services Architect is responsible for designing and developing architecture for embedded infrastructure services within the platform. This includes bootup, commissioning, storage management, thermal management, and integration with embedded hardware and software systems. The role requires expertise in Linux/Android OS, virtualization, and hardware-software alignment. Roles & Responsibilities: Design and develop architecture for platform services such as bootup, commissioning, storage management, and thermal management. Drive architecture for embedded software, collaborating with engineers in system software, virtualization, trusted OS, graphics, compute, device drivers, storage, networking, and security. Act as a technical leader, providing insight and direction to resolve issues and improve processes. Collaborate with hardware engineering teams to ensure hardware-software integration. Architect solutions using Linux, Android, and microcontroller RTOSs, including storage/persistence layers and device management. Break down architecture into development tasks, review deliverables, and resolve design issues or blockers. Document architecture using C4 and model-based frameworks and maintain version-controlled design artifacts. Participate in Agile development processes, PI planning, and architecture reviews. Required Skills & Expertise: Operating Systems: Deep knowledge of Linux and Android OS internals, kernel modules, and integration with embedded hardware. Embedded Systems: Experience designing and developing software for embedded systems, including hardware abstraction and device drivers. Storage Systems: Expertise in file systems, RAID, distributed storage, and data replication. Networking: Familiarity with Layer 2/3 networking concepts and protocols (VLAN, STP, LLDP, OSPF, IGMP, BGP). Virtualization: Containers, hypervisors, orchestration (Linux and Android environments). Hardware Bring-Up: Provisioning and commissioning experience. OTA Architecture: Over-the-air update strategies, edge computing, CDN integration. Programming: Proficiency in C++, Java, Python, and Linux kernel programming. Agile Practices: Experience in SAFe or SCRUM methodologies. Qualifications: Bachelor's or Master's degree in Computer Science, Electrical Engineering, or related field. 8+ years of experience in embedded systems architecture and platform services design. Strong analytical and problem-solving skills with ability to lead technical discussions. Excellent communication and collaboration skills for global team environments. Nice-to-Have: Experience with AWS Cloud and cloud-native architectures. Familiarity with CI/CD pipelines (GitLab CI, Jenkins) and DevOps practices. Exposure to architecture documentation tools (Confluence, Visio, Draw.io). Qualification: Bachelors/Masters
    $74k-100k yearly est. 2d ago
  • Senior Lead Cloud Security Architect

    Cox Communications 4.8company rating

    Atlanta, GA jobs

    Company Cox Automotive - USA Job Family Group Information Technology Job Profile Cybersecurity Sr Lead Architect Management Level Sr Manager - Non People Leader Flexible Work Option Hybrid - Ability to work remotely part of the week Travel % Yes, 15% of the time Work Shift Day Compensation Compensation includes a base salary of $148,500.00 - $247,500.00. The base salary may vary within the anticipated base pay range based on factors such as the ultimate location of the position and the selected candidate's knowledge, skills, and abilities. Position may be eligible for additional compensation that may include an incentive program. Job Description The Senior Lead Cybersecurity Architect is responsible for defining the principles, standards, and design patterns to build secure products and enterprise tools for all of Cox Automotive's multi-cloud and on-premises environments. This position's architecture focus is on securing multi-cloud infrastructure and services and on-premises infrastructure. Peer cybersecurity architects will be focused on application security, software as a service (SaaS), and network security.This role will use their deep cybersecurity knowledge in the designing and building of secure infrastructure and services in both multi-cloud and on-premises environments. They must be able to collaborate with cross-functional teams throughout the organization and propose well-defined cybersecurity architectural guidelines to be adopted by product and enterprise engineering teams. This role will directly report to the Senior Director of Cybersecurity Architecture at Cox Automotive. Primary Responsibilities Identify and recommend relevant cybersecurity policies, standards, procedures, and guardrails. Drive the definition of cybersecurity guidelines across the product and enterprise architecture group by leading working groups focused on cybersecurity. Develop secure design patterns in conjunction with the product and enterprise architecture group based on standards that can be adopted and implemented by engineering teams. Contribute to the development of non-cyber architecture-related governance patterns, policies, and standards. Provides complex analysis of potential risks to information systems' security and recommends innovative solutions. Work with cross-functional technical, development and delivery teams to ensure the application of smooth, efficient and scalable release processes. Engage with business teams and engineering teams to define cybersecurity guardrails that promote efficient and seamless adoption of secure design patterns. Participate in security events and incident response to identify gaps in current design and propose solutions to prevent threats from reoccurring. Research and evaluate emerging security trends, threats, and technologies, and recommend appropriate solutions and enhancements. Collaborate with data users, software and other technical stakeholders to ensure security considerations are factored into and underpin development and operational decision making. Collaborate with cybersecurity peers to incorporate vulnerability management, governance, risk and compliance, cyber defense, continuous controls monitoring, and identity governance into cybersecurity standards as a cohesive cybersecurity organization. Minimum Qualifications Bachelor's degree in a related discipline and 8 years of experience in a related field. The right candidate could also have a different combination, such as a master's degree and 6 years of experience; a Ph.D. and 3 years of experience in a related field; or 12 years' experience in a related field. At least 4 years focused on cybersecurity. Must have practical expertise in AWS cloud infrastructure and services and on-premises infrastructure. Clearly articulate the objective of specific cybersecurity policies and procedures to technical and non-technical stakeholders. Excellent customer service skills, writing, and executive presentation skills. Develop a strong and productive working environment with key stakeholders and collaborate closely with other Cox entities' cybersecurity teams to implement cybersecurity best practices. Consultative nature to work through controversial or complex topics to employees, leaders, and/or senior leadership. Evaluate risks and recommend actions based on impact and likelihood of the risk to the business. Knowledge of current cybersecurity and technology architectures such as zero trust, IaaS, PaaS, SaaS, virtualization, and containerization. Creatively solving complex cybersecurity challenges while exhibiting solid, pragmatic business acumen. Experience utilizing Agile methodologies. Initiating change and deploying solutions in Fortune 1000 companies. Knowledge of cybersecurity frameworks (e.g., ISO 27000, NIST, FFIEC) and industry relevant regulations that will guide architectural requirements (e.g., GDPR, FFIEC, GLBA). Collaborate with AI agents to create, validate, and assess architectural artifacts Lead cross-functional teams in designing AI-enhanced solutions, establish standards for AI integration, and assess AI technologies within solution architectures. Implement AI-driven architectural governance and compliance by defining robust AI governance frameworks and reference architectures. Improve vendor tool assessments using AI to speed evaluations and minimize mistakes and unknowns. Preferred Qualifications Experience in the development and design of cybersecurity standard methodologies to all layers of the hosting and application stack in both cloud and on-premises environments. Relevant experience with application security, SaaS, network security, DevSecOps, and software-defined networking across a variety of environments and deployments. Knowledge of Identity and Access Management (IAM), cryptography / key management, secrets management, access controls and security protocols (e.g., multi-factor, SAML, OAuth, OIDC). Experience with application security implementations and standard methodologies. Extensive technology knowledge and recognized expertise in several areas including Python, .NET, Java, Spring frameworks, Oracle, serverless, cloud patterns, cloud service and user authentication or similar. Experience with firewall, web application firewalls, and other edge services as well as deep understanding of DMZ and other network architectures. AWS Well-Architected Framework. Experience establishing a strategy for and implementing cloud enterprise solutions in AWS, GCP, or Azure. A strong understanding of cloud containers and/or serverless platforms (e.g., EKS, ECS, Lambda, Fargate). Big four consulting or Fortune 500 company experience. Relevant industry certification (e.g., CISSP, CEH, OSCP, Azure, AWS, CISM, CISA). Drug Testing To be employed in this role, you'll need to clear a pre-employment drug test. Cox Automotive does not currently administer a pre-employment drug test for marijuana for this position. However, we are a drug-free workplace, so the possession, use or being under the influence of drugs illegal under federal or state law during work hours, on company property and/or in company vehicles is prohibited. Benefits The Company offers eligible employees the flexibility to take as much vacation with pay as they deem consistent with their duties, the company's needs, and its obligations; seven paid holidays throughout the calendar year; and up to 160 hours of paid wellness annually for their own wellness or that of family members. Employees are also eligible for additional paid time off in the form of bereavement leave, time off to vote, jury duty leave, volunteer time off, military leave, and parental leave. About Us Through groundbreaking technology and a commitment to stellar experiences for drivers and dealers alike, Cox Automotive employees are transforming the way the world buys, owns, sells - or simply uses - cars. Cox Automotive employees get to work on iconic consumer brands like Autotrader and Kelley Blue Book and industry-leading dealer-facing companies like vAuto and Manheim, all while enjoying the people-centered atmosphere that is central to our life at Cox. Benefits of working at Cox may include health care insurance (medical, dental, vision), retirement planning (401(k)), and paid days off (sick leave, parental leave, flexible vacation/wellness days, and/or PTO). For more details on what benefits you may be offered, visit our benefits page. Cox is an Equal Employment Opportunity employer - All qualified applicants/employees will receive consideration for employment without regard to that individual's age, race, color, religion or creed, national origin or ancestry, sex (including pregnancy), sexual orientation, gender, gender identity, physical or mental disability, veteran status, genetic information, ethnicity, citizenship, or any other characteristic protected by law. Cox provides reasonable accommodations when requested by a qualified applicant or employee with disability, unless such accommodations would cause an undue hardship.Applicants must currently be authorized to work in the United States for any employer without current or future sponsorship. No OPT, CPT, STEM/OPT or visa sponsorship now or in future.
    $148.5k-247.5k yearly Auto-Apply 19d ago
  • Associate, Security Engineer (Vulnerability Management)

    Galaxy Group 3.4company rating

    Remote

    Who We Are: Galaxy is a global leader in digital assets and data center infrastructure, delivering solutions that accelerate progress in finance and artificial intelligence. We believe that blockchain and digital asset innovation will transform how value moves through the world - and we're building the products and services to make that future a reality. Our institutional digital assets platform spans trading, investment banking, asset management, staking, self-custody, and tokenization technology. We also invest in and operate cutting-edge data center infrastructure to power AI and high-performance computing, addressing the growing demand for scalable energy and compute in the U.S. We work at the intersection of finance and technology, helping institutions, startups, and developers navigate a digitally native economy. Led by CEO and Founder Michael Novogratz, our team blends deep crypto expertise with institutional experience and a shared commitment to shaping the future of Web3 and AI. Galaxy is headquartered in New York City, with offices across North America, Europe, the Middle East, and Asia. To learn more about our businesses and products, visit *************** What We Value: We are a diverse team of free thinkers, and fast movers united to help investors and creators energize the global economy. We are looking for individuals who thrive in a culture of builders and overachievers and embrace high performance, transparent feedback, and a mission-first approach. Our culture shapes our way of working and gets us where we want to be. Seek Excellence. Be Selective To Be Effective. Be Highly Aligned, Loosely Coupled. Disagree Transparently. Encourage Independent Decision-Making. Build Dream Teams. Who You Are: Galaxy is seeking an Associate Security Engineer (Vulnerability Management) to administer application security tooling and help drive the vulnerability management program. You'll join a collaborative team of product and offensive security engineers who tackle complex technical challenges and align closely with Galaxy's business objectives. This role reports directly to the Director of Product Security and interfaces closely with Engineering, DevOps, and Infrastructure teams. What You'll Do: Administer application security tooling: manage and configure to reduce false positives and enhance accuracy. Provide comprehensive support and documentation of security tooling to encourage adoption among engineering teams. Develop dashboards and KPIs to clearly visualize security activities, vulnerabilities, and cybersecurity risks for individual departments or teams. Aggregate and analyze data from vulnerability management and asset inventory systems. Support the vulnerability management program by ensuring technology teams adhere to SLAs for vulnerability triage and remediation. Track and report on vulnerability remediation progress across infrastructure and application environments. Coordinate with engineering teams to validate, assign, and prioritize vulnerabilities based on risk and asset criticality. Leverage AI-driven tools for efficient data analysis and qualitative risk assessment. Assist in security assessments and proactively suggest improvements related to tooling and risk insights. What We're Looking For: Bachelor or post-graduate diploma in cybersecurity or technology 4+ years of work experience in cybersecurity, software development, or security operations Proficiency in scripting or object programming languages Familiarity with application security and vulnerability management practices Strong analytical skills, detail-oriented, proactive, and capable of independent problem-solving Very good verbal and written communication skills, collaborative and solution-driven Security or cloud certifications What We Offer: Competitive base salary and discretionary bonus Flexible Time Off (i.e. unlimited paid vacation days) Company paid Holidays (11) Company paid sick leave Company-paid health and protective benefits for employees, partners, and other dependents 3% 401(k) company contribution Generous paid Parental Leave Free virtual coaching and counseling sessions through Headspace Opportunities to learn about the Crypto industry Free daily snacks in-office Smart, entrepreneurial, and fun colleagues Employee Resource Groups Apply now and join us on our mission to engineer a new economic paradigm. Galaxy respects diversity and seeks to provide equal employment opportunities to all employees and job applicants for employment without regard to actual or perceived age, race, color, creed, religion, sex or gender (including pregnancy, childbirth, lactation and related medical conditions), gender identity or gender expression (including transgender status), sexual orientation, marital or partnership or caregiver status, ancestry, national origin, citizenship status, disability, military or veteran status, protected medical condition as defined by applicable state or local law, genetic information or predisposing genetic characteristic, or other characteristic protected by applicable federal, state, or local laws and ordinances. We will endeavor to make a reasonable accommodation to the known limitations of a qualified applicant with a disability unless the accommodation would impose an undue hardship on the operation of our business. If you believe you require such assistance to complete the application process or to participate in an interview, please contact ******************.
    $91k-131k yearly est. Auto-Apply 60d+ ago
  • SAP S\/4 HANA Security BASIS Lead Consultant \

    Simple Solutions 3.9company rating

    Jacksonville, FL jobs

    SAP S\/4 HANA SECURITY BASIS LEAD CONSULATANT \- Remote with some travel SAP S\/4 HANA BASIS Consultant Who has done an Assessment of "As Is to Be" for an ECC to S\/4 HANA Migration and Implementation. Starting the Assessment in December and then kicking off the 1\-2 year project in early January. SAP BASIS Security consultant is a "Hands On" role focused on ensuring the security of SAP systems, including their technical infrastructure (BASIS) and applications. This involves designing, implementing, and maintaining security policies, roles, and authorizations, as well as troubleshooting and resolving security issues. They work with various SAP modules and technologies, including S\/4HANA, Solution Manager, and cloud environments, and often collaborate with functional teams and other IT security professionals. Key Responsibilities: Security Strategy & Roadmap: Developing and maintaining the overall SAP security strategy and roadmap, aligning it with business needs and regulatory requirements. Security Design & Implementation: Designing, configuring, and implementing security solutions for SAP systems, including access controls, authorization objects, and security roles. Security Monitoring & Auditing: Monitoring SAP systems for security breaches and conducting regular security audits to ensure compliance with policies and regulations. Troubleshooting & Issue Resolution: Investigating and resolving security incidents, vulnerabilities, and other security\-related issues. Collaboration & Communication: Working with functional teams, business stakeholders, and other IT security professionals to ensure a cohesive and secure SAP environment. Staying Up\-to\-Date: Keeping abreast of the latest SAP security threats, vulnerabilities, and best practices. Skills and Qualifications: Technical Expertise: . Opens in new tab Strong knowledge of SAP BASIS, including NetWeaver, S\/4HANA, Solution Manager, and other relevant technologies. Security Knowledge: . Opens in new tab Deep understanding of SAP security concepts, including roles, authorizations, and access controls. Experience with Security Tools: . Opens in new tab Familiarity with SAP security tools like GRC (Governance, Risk, and Compliance) and other relevant security solutions. Cloud Security: . Opens in new tab Experience with cloud environments (e.g., AWS, Azure) and their security implications for SAP systems. Communication & Collaboration: . Opens in new tab Excellent communication and interpersonal skills to effectively collaborate with various stakeholders. Problem\-Solving: . Opens in new tab Strong analytical and problem\-solving skills to troubleshoot and resolve security issues. Certifications: . Opens in new tab SAP BASIS and Security certifications are often required or preferred. In essence, an SAP BASIS Security Architect is a critical role for organizations that rely on SAP systems to protect their sensitive data and ensure the integrity of their business operations. "}}],"is Mobile":false,"iframe":"true","job Type":"C","apply Name":"Apply Now","zsoid":"662490260","FontFamily":"PuviRegular","job OtherDetails":[{"field Label":"Industry","uitype":2,"value":"Airline \- Aviation"},{"field Label":"Job Opening ID","uitype":111,"value":"ZR_2693_JOB"},{"field Label":"Work Experience","uitype":2,"value":"10+ Years"},{"field Label":"City","uitype":1,"value":"Jacksonville"},{"field Label":"State\/Province","uitype":1,"value":"Florida"},{"field Label":"Zip\/Postal Code","uitype":1,"value":"32086"}],"header Name":"SAP S\/4 HANA Security BASIS Lead Consultant \- Remote","widget Id":"**********00072311","is JobBoard":"false","user Id":"**********00194003","attach Arr":[],"custom Template":"3","is CandidateLoginEnabled":true,"job Id":"**********02757013","FontSize":"15","google IndexUrl":"https:\/\/simplesolutions.zohorecruit.com\/recruit\/ViewJob.na?digest=y7aAKF2qOzvLOXeqB8tAB8jaWnY8Hrl6KYyDTM.0Bjo\-&embedsource=Google","location":"Jacksonville","embedsource":"CareerSite","indeed CallBackUrl":"https:\/\/recruit.zoho.com\/recruit\/JBApplyAuth.do","logo Id":"60ly0a8d0c6dd592942c4b0bb6d05adacee99"}
    $76k-104k yearly est. 60d+ ago
  • SAP S\/4 HANA Security BASIS Consultant \

    Simple Solutions 3.9company rating

    Jacksonville, FL jobs

    SAP S\/4 HANA SECURITY BASIS CONSULATANT \- Remote with some travel SAP S\/4 HANA BASIS Consultant Who has done Assessments of "As Is to Be" of ECC migration and upgrade to S\/4 HANA Implementations Anticipating starting in December start on Assessment and then kick\-of 1\-2 year project in January. They work with various SAP modules and technologies, including S\/4HANA, Solution Manager, and cloud environments, and often collaborate with functional teams and other IT security professionals. ​ SAP BASIS Security consultant is a "Hands On" role focused on ensuring the security of SAP systems, including their technical infrastructure (BASIS) and applications. This involves designing, implementing, and maintaining security policies, roles, and authorizations, as well as troubleshooting and resolving security issues. Previous work and knowledge of ITAR is a BIG PLUS And security clearance too. Key Responsibilities: Security Strategy & Roadmap: Developing and maintaining the overall SAP security strategy and roadmap during the assessment, aligning it with business needs and regulatory requirements. Security Design & Implementation: Designing, configuring, and implementing security solutions for SAP systems, including access controls, authorization objects, and security roles. Security Monitoring & Auditing: Monitoring SAP systems for security breaches and conducting regular security audits to ensure compliance with policies and regulations. Troubleshooting & Issue Resolution: Investigating and resolving security incidents, vulnerabilities, and other security\-related issues. Collaboration & Communication: Working with functional teams, business stakeholders, and other IT security professionals to ensure a cohesive and secure SAP environment. Staying Up\-to\-Date: Keeping abreast of the latest SAP security threats, vulnerabilities, and best practices. Skills and Qualifications: Technical Expertise: . Opens in new tab Strong knowledge of SAP BASIS, including NetWeaver, S\/4HANA, Solution Manager, and other relevant technologies. Security Knowledge: . Opens in new tab Deep understanding of SAP security concepts, including roles, authorizations, and access controls. Experience with Security Tools: . Opens in new tab Familiarity with SAP security tools like GRC (Governance, Risk, and Compliance) and other relevant security solutions. Cloud Security: . Opens in new tab Experience with cloud environments (e.g., AWS, Azure) and their security implications for SAP systems. Communication & Collaboration: . Opens in new tab Excellent communication and interpersonal skills to effectively collaborate with various stakeholders. Problem\-Solving: . Opens in new tab Strong analytical and problem\-solving skills to troubleshoot and resolve security issues. Certifications: . Opens in new tab SAP BASIS and Security certifications are often required or preferred. In essence, an SAP BASIS Security Architect is a critical role for organizations that rely on SAP systems to protect their sensitive data and ensure the integrity of their business operations. "}}],"is Mobile":false,"iframe":"true","job Type":"C","apply Name":"Apply Now","zsoid":"662490260","FontFamily":"PuviRegular","job OtherDetails":[{"field Label":"Industry","uitype":2,"value":"Airline \- Aviation"},{"field Label":"Job Opening ID","uitype":111,"value":"ZR_2758_JOB"},{"field Label":"Work Experience","uitype":2,"value":"8\-10 Years"},{"field Label":"Salary","uitype":1,"value":"$80\-$100\/hr"},{"field Label":"City","uitype":1,"value":"Jacksonville"},{"field Label":"State\/Province","uitype":1,"value":"Florida"},{"field Label":"Zip\/Postal Code","uitype":1,"value":"32086"}],"header Name":"SAP S\/4 HANA Security BASIS Consultant \- Remote","widget Id":"**********00072311","is JobBoard":"false","user Id":"**********00194003","attach Arr":[],"custom Template":"3","is CandidateLoginEnabled":true,"job Id":"**********03539202","FontSize":"15","google IndexUrl":"https:\/\/simplesolutions.zohorecruit.com\/recruit\/ViewJob.na?digest=y7aAKF2qOzvLOXeqB8tABxFPsY2FTixi6Xo9Ej@2XhE\-&embedsource=Google","location":"Jacksonville","embedsource":"CareerSite","indeed CallBackUrl":"https:\/\/recruit.zoho.com\/recruit\/JBApplyAuth.do","logo Id":"60ly0a8d0c6dd592942c4b0bb6d05adacee99"}
    $76k-104k yearly est. 60d+ ago
  • Information System Security Officer (ISSO) - (TS/SCI Required)

    Viasat Inc. 4.5company rating

    Carlsbad, CA jobs

    About us One team. Global challenges. Infinite opportunities. At Viasat, we're on a mission to deliver connections with the capacity to change the world. For more than 35 years, Viasat has helped shape how consumers, businesses, governments and militaries around the globe communicate. We're looking for people who think big, act fearlessly, and create an inclusive environment that drives positive impact to join our team. What you'll do Keeping our systems, technology, and employees safe is a key priority for Viasat. As a member of the Information Assurance team, you will focus on the day-to-day information system security requirements, serve as a Subject Matter Expert (SME) in the Information Assurance realm, and provide innovative solutions to complex problems. The day-to-day * Work independently as well as with a team of Information Assurance Professionals. * Responsible for ensuring Information System Compliance with the potential to span multiple business areas or programs. * Assess, document, and recommend controls based on a thorough understanding of RMF, NISPOM and other NISP regulatory requirements, and determine which controls are applicable to the application, as well as document implementation in Security Controls Tractability Matrix (SCTM). * Document compliance actions within the approved automated compliance tracking system or develop a Plan of Actions and Milestones (POA&M) to address non-compliance. * Participate in internal/external security audits/inspections; performs risk assessments and continuous monitoring. * Ensure systems are operated, maintained, and disposed of in accordance with the governing authority approved authorization package and customer directives * Develop procedures and documentation to ensure compliance with Configuration Management (CM) for security relevant IS software, hardware, and firmware. * Ensure proper protection and / or corrective measures have been taken when an incident or vulnerability has been discovered. Follows-up to ensure completion and quality resolution. * Assesses and revises policies and procedures as needed to improve quality, timeliness, and efficiency of work. What you'll need * Bachelor's degree or equivalent experience * 3+ years as an Information System Security Officer (ISSO) in a DoD, IC, or other industrial security program and in-depth understanding of DoD 8500 series, NIST 800 series, and ICD 503, Joint Special Access Program Implementation Guide (JSIG) and overall understanding of DoD Risk Manage Framework (RMF) process. * Experience working with vulnerability and compliance scanning tools. (Nessus, SCAP, ACAS) * Familiarity with network technologies (LAN & WAN) and best practices within a classified environment to include crypto and key management * Working knowledge with Microsoft Windows operating systems (workstation & server), Linux, and system virtualization in a secure network environment. * Strong written communication and organizational skills * Interpersonal skills to deal courteously and effectively with a diverse group of individuals * Ability to work well under pressure, and possess advanced problem-solving skills * Possess a current DoD 8570.1/DoD 8140.01 Certification - Security+ CE a minimum * Active Top Secret Security Clearance with SCI eligibility * Ability to travel up to 10% What will help you on the job * 5+ years as an Information System Security Officer (ISSO) Salary range $93,500.00 - $148,000.00 / annually. For specific work locations within San Jose, the San Francisco Bay area and New York City metropolitan area, the base pay range for this role is $112,000.00- $168,000.00/ annually At Viasat, we consider many factors when it comes to compensation, including the scope of the position as well as your background and experience. Base pay may vary depending on job-related knowledge, skills, and experience. Additional cash or stock incentives may be provided as part of the compensation package, in addition to a range of medical, financial, and/or other benefits, dependent on the position offered. Learn more about Viasat's comprehensive benefit offerings that are focused on your holistic health and wellness at ************************************ EEO Statement Viasat is proud to be an equal opportunity employer, seeking to create a welcoming and diverse environment. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, ancestry, physical or mental disability, medical condition, marital status, genetics, age, or veteran status or any other applicable legally protected status or characteristic. If you would like to request an accommodation on the basis of disability for completing this on-line application, please click here. * Bachelor's degree or equivalent experience * 3+ years as an Information System Security Officer (ISSO) in a DoD, IC, or other industrial security program and in-depth understanding of DoD 8500 series, NIST 800 series, and ICD 503, Joint Special Access Program Implementation Guide (JSIG) and overall understanding of DoD Risk Manage Framework (RMF) process. * Experience working with vulnerability and compliance scanning tools. (Nessus, SCAP, ACAS) * Familiarity with network technologies (LAN & WAN) and best practices within a classified environment to include crypto and key management * Working knowledge with Microsoft Windows operating systems (workstation & server), Linux, and system virtualization in a secure network environment. * Strong written communication and organizational skills * Interpersonal skills to deal courteously and effectively with a diverse group of individuals * Ability to work well under pressure, and possess advanced problem-solving skills * Possess a current DoD 8570.1/DoD 8140.01 Certification - Security+ CE a minimum * Active Top Secret Security Clearance with SCI eligibility * Ability to travel up to 10% * Work independently as well as with a team of Information Assurance Professionals. * Responsible for ensuring Information System Compliance with the potential to span multiple business areas or programs. * Assess, document, and recommend controls based on a thorough understanding of RMF, NISPOM and other NISP regulatory requirements, and determine which controls are applicable to the application, as well as document implementation in Security Controls Tractability Matrix (SCTM). * Document compliance actions within the approved automated compliance tracking system or develop a Plan of Actions and Milestones (POA&M) to address non-compliance. * Participate in internal/external security audits/inspections; performs risk assessments and continuous monitoring. * Ensure systems are operated, maintained, and disposed of in accordance with the governing authority approved authorization package and customer directives * Develop procedures and documentation to ensure compliance with Configuration Management (CM) for security relevant IS software, hardware, and firmware. * Ensure proper protection and / or corrective measures have been taken when an incident or vulnerability has been discovered. Follows-up to ensure completion and quality resolution. * Assesses and revises policies and procedures as needed to improve quality, timeliness, and efficiency of work.
    $112k-168k yearly 7d ago
  • Network Security Architect - Herndon, Virginia ( Only GC or Citizens )

    Info. Services Inc. 4.2company rating

    Herndon, VA jobs

    Role: Network Security Architect Duration: 6+ Months BGV will be done for the selected candidates. Job Functions (Network & Security Architect) Performs analysis of network security needs and contributes to design, integration, and installation of hardware and software. Analyzes, troubleshoots, and corrects network problems remotely and on-site. Maintains and administers perimeter security systems such as firewalls and intrusion detection systems. Modifies and maintains network security policy. Installs and maintains Cisco routers and Cisco switches Hands on experience on Cisco Nexus switches, Cisco ASR series routers, Cisco Fabric switches.\ Implements and administers IP load balancing with Citrix NetScaler, F5 load balancers and Big/IP, hardware SSL accelerators, and other software/hardware as necessary. Designs and implements remote connectivity solutions including IPsec VPN, PPTP, and SSLVPN Design, configure, and implements Citrix Presentation Server solutions Troubleshoots Windows 2012/2008/2003 permission and other related issues Builds and integrates new application servers including file and print, database, web, mail, and servers to support call center applications. Monitors security system logs (i.e. intrusion detection system, firewall system logs, etc.) and reports on discovered anomalies or problems (i.e. insufficient disk space, inappropriate access patterns) on a weekly basis. Meet with Business and Engineering teams to develop understanding of network & security requirements. Based on these requirements design the overall changes to the network solution across both Public and Private cloud including VPC & VLAN configuration, ports to be opened, ACLs, firewall rule changes. Tests new computer/router/switch hardware and software solutions prior to implementation. Administers and configures Windows 2008, Windows 2003, and Unix-based systems, as needed. Uses sniffers and other tools to troubleshoot and isolate network problems. Assists with network security assessments for potential business partners. Keeps fully abreast of trends and changing technologies as they relate to IT and Network Engineering and Information Security fields. Engages in continuous process improvement. Performs other related duties as may be required. Prior hands-on professional experience must include Windows 2008, Windows 2003, Windows XP, Juniper Firewalls, and Checkpoint Firewalls. Cisco ASA and/or Linux experience would be a plus. Working knowledge of operating systems including Windows 2008, Windows 2003, Windows 2000, Windows XP, and UNIX. Expertise on network security, Juniper firewalls, Checkpoint firewalls, intrusion detection systems, authentication mechanisms, encryption technologies, and networking protocols including SMTP, HTTP, DNS, TCP/IP, and SNMP Strong analytical, reasoning, and organizational skills are essential. Excellent verbal and written communications skills are essential. Ability to establish and maintain effective work relationships with all levels of personnel both internally and externally; e.g. leadership, executives, clients, vendors, and agencies. Ability to work in and constructively contribute to team work environment and meet stringent deadlines. Ability to prioritize and handle multiple tasks simultaneously. Attention to detail and follow through including the ability to document work. Ability to maintain the confidentiality of information is essential. Minimum of 10-12 years directly related work experience in network, security administration\ engineering. Acquire a complete understanding of a company's technology and information systems to be able to advice on overall security and network challenges. Review and address all vulnerabilities and security incidents, recommending strategies and solutions for risk mitigation. Develop and build security posture with respect to: user administration, privileged identity management, intrusion detection, firewall configuration, DDOS, WAF and other security related components; continuously update Somos on new vulnerabilities; assess risks and solutions and engage with third parties and OEMs as needed. Develop concrete plans. Reviewing results of monthly Vulnerability Scans, engaging infrastructure and application teams as needed to address vulnerabilities. Support for ISO27002 security audit and updates to security policy, security training program and vendor security requirements as required. Manage Antivirus policies on servers and Endpoints. Update server and antivirus clients. Plan, research and design robust security architectures for any IT project. Manage Network Firewalls, Web Application Firewalls and IDS/IPS. Research security standards, security systems and authentication protocols Infrastructure and Operations Services Statement of Work. Develop requirements for local area networks (LANs), wide area networks (WANs), virtual private Networks (VPNs), routers, firewalls, and related network devices. Review and approve installation of firewall, VPN, routers, IDS and servers. Test final security structures to ensure they behave as expected Provide technical supervision for (and guidance to) a security team. Define, implement and maintain security policies and procedures. Oversee security awareness programs and educational efforts. Please respond with your word resume and requested details: Full Name : Work Authorization: Contact Number : Email ID : Skype ID: Current location: Willing to relocate : Rate/hr : Additional Information All your information will be kept confidential according to EEO guidelines.
    $106k-144k yearly est. 1d ago
  • Checkpoint Security Engineer

    Info. Services Inc. 4.2company rating

    Frisco, TX jobs

    Candidates MUST HAVE: Firewall, checkpoint, juniper, McAfee Web Gateway proxies experience is mandate • Level III operational support. • Rule base modifications to the proxies. • CLI access and mid/expert for troubleshooting of the hardware. • Reporter expertise to be able to generate reports and investigations to client. • Architecture and design expertise to recommend to the customer. • Expert level to whitelist URL sites for restoration of blocked traffic. • SSL 3.0 and TLS1.0 expertise and authentication methods to the proxies. • Explicit proxy PAC file modifications. • Hardware load balancing mechanism expertise through F5 troubleshooting. • Application control using third party APIs. • WCCP expertise for future implementation with core Cisco Nexus VDC McAfee IPS. • Level III operational support. • Expert level of CLI and GUI support to intrusion protection and reporting. • Troubleshooting techniques for protection and vulnerability assessment. Please respond with your word resume and requested details: Full Name : Work Authorization: Contact Number : Email ID : Skype ID: Current location: Willing to relocate : Salary : Additional Information All your information will be kept confidential according to EEO guidelines.
    $88k-122k yearly est. 1d ago
  • Senior Security Operations Center Analyst

    Ringcentral, Inc. 4.6company rating

    Belmont, CA jobs

    Say hello to opportunities. It's not everyday that you consider starting a new career. We're RingCentral, and we're happy that someone as talented as you is considering this role. First, a little about us, we're a $2 Billion annual revenue company with double digit Annual Recurring Revenue (ARR) and a $93 Billion market opportunity in UCaaS, Contact Center and AI-powered adjacencies. We invest more than $250 million annually to ensure our AI-enabled technology and platforms meet or exceed the needs of our customers. RingSense AI is our proprietary AI solution. It's designed to fit the business needs of our customers, orchestrated to be accurate and precise, and built on the same open platform principles we apply to our core software solutions. This is where you and your skills come in. We're currently looking for: Security Operations Center Analyst Job Type: Full-Time, 2 days on (08.00 PDT AM - 08.00 PDT PM) 2 days off Location: Belmont, CA Department: Security This is a great opportunity to work at a rapidly growing, market leading Unified Communications as-a-service company. RingCentral provides Voice-over-IP (VoIP), hosted PBX, voicemail, SMS, e-fax, and HD video meeting solutions for business. About this role: As a SOC Analyst at RingCentral, your primary responsibilities are to implement a comprehensive security monitoring, incident response and threat intelligence program for RingCentral's global cloud service, corporate and development environments. You will also be collaboratively providing feedback to improve security operations processes, generating actionable analysis and threat intelligence from tools, logs, and other data sources, ensuring strong documentation is in place to support ongoing SOC activities, and reporting your observations to other Security, Operations and IT personnel. Job Description: * Have proven skills in application security, security monitoring, incident response and intrusion analysis * Have strong knowledge of the diverse methods and technologies used to attack web/mobile/desktop applications, SaaS infrastructure, and data * Think critically, work well under pressure, and possess strong analytical, written, verbal, and interpersonal skills * Demonstrated track record of quality processes in candidate's work history * Be strongly self-motivated with an aptitude for both individual and team-oriented work * Have experience following and refining standard operating procedures and playbooks Responsibilities: * Monitor security events, analyze and investigate alarms, and maintain day-to-day operational activities of a secure cloud environment * Engage teams within and outside of RingCentral to mitigate and resolve cases * Maintain relevant documentation and audit artifacts * Identify and track suspicious system activity * Identify trends and patterns, and present them to Security Engineers to enhance our processes and systems * This role participates in on-call rotations Qualifications / Requirements: * 2+ years in a security engineering, SRE, or SOC roles in a cloud services environment * Experience with SIEM * Experience investigating security incidents * Basic knowledge AWS or GCP * Experience with IDS, case management, and related tools and practices * Experience with Linux, RedHat preferred * Basic knowledge of broad security topics such as encryption, application security, malware, ransomware, etc. * Knowledge of network, VoIP and web related protocols (e.g., TCP/IP, UDP, IPSEC, HTTP, HTTPS, SIP, RTP) Preferred Skills/Experience: * Experience using Crowdstrike, Cloudflare, FirePower, Splunk, ELK, Imperva, Syslog, packet capture, and Windows Event Log tools and similar tools * Knowledge of current hacking techniques, malicious code trends, botnets, exploits, malware, DDoS, and data breach events * Strong knowledge of Microsoft Windows * Experience automating security tasks, including scripting, programming and/or SecDevOps * Experience working with global teams Any combination of the following certifications: * GCIA (GIAC Certified Intrusion Analyst) * GCIH (GIAC Certified Incident Handler) * GCIA (GIAC Certified Intrusion Analyst) * GCFA (GIAC Certified Forensic Analyst) * GNFA (GIAC Certified Network Forensic Analyst) * GCFE (GIAC Forensic Examiner) * GASF (GIAC Advanced Smartphone Forensics) * GICA GCTI (GIAC Certified Cyber Threat Intelligence) * GPEN (GIAC Certified Pentester) * GWAPT (GIAC Certified Web Application Pentester) * GPYC (GIAC Certified Python Coder) * OSCP (Offensive Security Certified Pentester) What we offer: * Comprehensive medical, dental, vision, disability, life insurance * Health Savings Account (HSA), Flexible Spending Account (FSAs) and Commuter benefits * Voluntary supplemental health coverage and life insurance * 401K match and ESPP * Paid time off and paid sick leave * Paid parental and pregnancy leave * Family-forming benefits (IVF, Preservation, Adoption etc.) * Emergency backup care (Child/Adult/Pets) * Employee Assistance Program (EAP) with counseling sessions available 24/7 * Free legal services that provide legal advice, document creation and estate planning * Employee bonus referral program * Student loan refinancing assistance * Employee 1:1 coaching, perks and discounts program RingCentral's IT team ensures company data is accessible, secure, and optimized in ways that provide maximum competitive advantage. We are constantly discovering, developing and deploying innovations that power productivity and drive better decisions for our customers. Our IT professionals are talented, ambitious, out-of-the-box thinkers who love to learn on the job-planning, deploying and maintaining state-of-the-art technology to deliver flawless performance 24/7/365. RingCentral's work culture is the backbone of our success. And don't just take our word for it: we are recognized as a Best Place to Work by Glassdoor, the Top Work Culture by Comparably and hold local BPTW awards in every major location. Bottom line: We are committed to hiring and retaining great people because we know you power our success. About RingCentral RingCentral, Inc. (NYSE: RNG) is a leading provider of business cloud communications and contact center solutions based on its powerful Message Video Phone (MVP) global platform. More flexible and cost effective than legacy on-premises PBX and video conferencing systems that it replaces, RingCentral empowers modern mobile and distributed workforces to communicate, collaborate, and connect via any mode, any device, and any location. RingCentral is headquartered in Belmont, California, and has offices around the world. RingCentral is an equal opportunity employer that truly values diversity. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. If you are hired in Belmont, CA the compensation range for this position is between $86,100 and $123,000 for full-time employees, in addition to eligibility for variable pay, equity, and benefits. Benefits may include, but are not limited to, health and wellness, 401k, ESPP, vacation, parental leave, and more! The salary may vary depending on your location, skills, and experience. #LI-IG1
    $86.1k-123k yearly Auto-Apply 13d ago
  • Senior Security Operations Center Analyst

    Ringcentral 4.6company rating

    Belmont, CA jobs

    Say hello to opportunities. It's not everyday that you consider starting a new career. We're RingCentral, and we're happy that someone as talented as you is considering this role. First, a little about us, we're a $2 Billion annual revenue company with double digit Annual Recurring Revenue (ARR) and a $93 Billion market opportunity in UCaaS, Contact Center and AI-powered adjacencies. We invest more than $250 million annually to ensure our AI-enabled technology and platforms meet or exceed the needs of our customers. RingSense AI is our proprietary AI solution. It's designed to fit the business needs of our customers, orchestrated to be accurate and precise, and built on the same open platform principles we apply to our core software solutions. This is where you and your skills come in. We're currently looking for: Security Operations Center Analyst Job Type: Full-Time, 2 days on (08.00 PDT AM - 08.00 PDT PM) 2 days off Location: Belmont, CA Department: Security This is a great opportunity to work at a rapidly growing, market leading Unified Communications as-a-service company. RingCentral provides Voice-over-IP (VoIP), hosted PBX, voicemail, SMS, e-fax, and HD video meeting solutions for business. About this role: As a SOC Analyst at RingCentral, your primary responsibilities are to implement a comprehensive security monitoring, incident response and threat intelligence program for RingCentral's global cloud service, corporate and development environments. You will also be collaboratively providing feedback to improve security operations processes, generating actionable analysis and threat intelligence from tools, logs, and other data sources, ensuring strong documentation is in place to support ongoing SOC activities, and reporting your observations to other Security, Operations and IT personnel. Job Description: Have proven skills in application security, security monitoring, incident response and intrusion analysis Have strong knowledge of the diverse methods and technologies used to attack web/mobile/desktop applications, SaaS infrastructure, and data Think critically, work well under pressure, and possess strong analytical, written, verbal, and interpersonal skills Demonstrated track record of quality processes in candidate's work history Be strongly self-motivated with an aptitude for both individual and team-oriented work Have experience following and refining standard operating procedures and playbooks Responsibilities: Monitor security events, analyze and investigate alarms, and maintain day-to-day operational activities of a secure cloud environment Engage teams within and outside of RingCentral to mitigate and resolve cases Maintain relevant documentation and audit artifacts Identify and track suspicious system activity Identify trends and patterns, and present them to Security Engineers to enhance our processes and systems This role participates in on-call rotations Qualifications / Requirements: 2+ years in a security engineering, SRE, or SOC roles in a cloud services environment Experience with SIEM Experience investigating security incidents Basic knowledge AWS or GCP Experience with IDS, case management, and related tools and practices Experience with Linux, RedHat preferred Basic knowledge of broad security topics such as encryption, application security, malware, ransomware, etc. Knowledge of network, VoIP and web related protocols (e.g., TCP/IP, UDP, IPSEC, HTTP, HTTPS, SIP, RTP) Preferred Skills/Experience: Experience using Crowdstrike, Cloudflare, FirePower, Splunk, ELK, Imperva, Syslog, packet capture, and Windows Event Log tools and similar tools Knowledge of current hacking techniques, malicious code trends, botnets, exploits, malware, DDoS, and data breach events Strong knowledge of Microsoft Windows Experience automating security tasks, including scripting, programming and/or SecDevOps Experience working with global teams Any combination of the following certifications: GCIA (GIAC Certified Intrusion Analyst) GCIH (GIAC Certified Incident Handler) GCIA (GIAC Certified Intrusion Analyst) GCFA (GIAC Certified Forensic Analyst) GNFA (GIAC Certified Network Forensic Analyst) GCFE (GIAC Forensic Examiner) GASF (GIAC Advanced Smartphone Forensics) GICA GCTI (GIAC Certified Cyber Threat Intelligence) GPEN (GIAC Certified Pentester) GWAPT (GIAC Certified Web Application Pentester) GPYC (GIAC Certified Python Coder) OSCP (Offensive Security Certified Pentester) What we offer: Comprehensive medical, dental, vision, disability, life insurance Health Savings Account (HSA), Flexible Spending Account (FSAs) and Commuter benefits Voluntary supplemental health coverage and life insurance 401K match and ESPP Paid time off and paid sick leave Paid parental and pregnancy leave Family-forming benefits (IVF, Preservation, Adoption etc.) Emergency backup care (Child/Adult/Pets) Employee Assistance Program (EAP) with counseling sessions available 24/7 Free legal services that provide legal advice, document creation and estate planning Employee bonus referral program Student loan refinancing assistance Employee 1:1 coaching, perks and discounts program RingCentral's IT team ensures company data is accessible, secure, and optimized in ways that provide maximum competitive advantage. We are constantly discovering, developing and deploying innovations that power productivity and drive better decisions for our customers. Our IT professionals are talented, ambitious, out-of-the-box thinkers who love to learn on the job-planning, deploying and maintaining state-of-the-art technology to deliver flawless performance 24/7/365. RingCentral's work culture is the backbone of our success. And don't just take our word for it: we are recognized as a Best Place to Work by Glassdoor, the Top Work Culture by Comparably and hold local BPTW awards in every major location. Bottom line: We are committed to hiring and retaining great people because we know you power our success. About RingCentral RingCentral, Inc. (NYSE: RNG) is a leading provider of business cloud communications and contact center solutions based on its powerful Message Video Phoneâ„¢ (MVPâ„¢) global platform. More flexible and cost effective than legacy on-premises PBX and video conferencing systems that it replaces, RingCentral empowers modern mobile and distributed workforces to communicate, collaborate, and connect via any mode, any device, and any location. RingCentral is headquartered in Belmont, California, and has offices around the world. RingCentral is an equal opportunity employer that truly values diversity. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. If you are hired in Belmont, CA the compensation range for this position is between $86,100 and $123,000 for full-time employees, in addition to eligibility for variable pay, equity, and benefits. Benefits may include, but are not limited to, health and wellness, 401k, ESPP, vacation, parental leave, and more! The salary may vary depending on your location, skills, and experience. #LI-IG1
    $86.1k-123k yearly Auto-Apply 4d ago
  • Edge Security Engineer

    Costar Group 4.2company rating

    Arlington, TX jobs

    CoStar Group (NASDAQ: CSGP) is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index and the NASDAQ 100, CoStar Group is on a mission to digitize the world's real estate, empowering all people to discover properties, insights and connections that improve their businesses and lives. We have been living and breathing the world of real estate information and online marketplaces for over 35 years, giving us the perspective to create truly unique and valuable offerings to our customers. We've continually refined, transformed and perfected our approach to our business, creating a language that has become standard in our industry, for our customers, and even our competitors. We continue that effort today and are always working to improve and drive innovation. This is how we deliver for our customers, our employees, and investors. By equipping the brightest minds with the best resources available, we provide an invaluable edge in real estate. We are seeking a skilled Edge Security Engineer to join our Product Security team. This role focuses on maintaining and optimizing edge security controls across CoStar's public-facing websites. You will be responsible for managing Akamai Kona WAF configurations, bot mitigation strategies, scraping protections, and other perimeter defenses to ensure high availability and secure access to our platforms. This position is located in Arlington, VA and is in office Monday through Thursday and work from home on Friday. Responsibilities Configure, monitor, and fine-tune Akamai Kona WAF policies to minimize false positives and maximize protection against OWASP and DDOS threats Implement and maintain bot protection and scraping mitigation strategies across CoStar's web properties. Analyze edge traffic patterns to detect anomalies and respond to security incidents. Support secure deployment and scaling of edge security controls across cloud and CDN environments. Provide edge security across 50+ high traffic websites, spanning distinct web tech stacks and threat profiles. Basic Qualifications Bachelor's Degree required from an accredited, not for profit, in person university or college. A track record of commitment to prior employers 1-3 years of experience in edge security, web application security, or managing Akamai, Cloudflare, Imperva, DataDome, Fastly, AWS WAF or similar technologies for a major Internet site. Familiarity with OWASP Top 10, API security best practices, and traffic analysis. Ability to collaborate across Product, Security, DevOps, Legal, and development teams. Experience with dashboards and log analysis tools such as Akamai WSA, ELK, or Athena. Preferred Qualifications and Skills Hands-on experience with Akamai Control Center for WAF rule configuration and monitoring. Knowledge of advanced bot detection strategies including behavioral analysis and AI-based solutions. Scripting and Infrastructure as code proficiency (Python, Terraform, Ansible, etc) for automation and reporting. Understanding of SDLC, CI/CD, and cloud-native development (Docker, EC2, EKS, RDS). Familiarity with compliance frameworks (NIST, ISO 27001, PCI DSS). What's in it for You When you join CoStar Group, you'll experience a collaborative and innovative culture working alongside the best and brightest to empower our people and customers to succeed. We offer you generous compensation and performance-based incentives. CoStar Group also invests in your professional and academic growth with internal training, and tuition reimbursement. Our benefits package includes (but is not limited to): Comprehensive healthcare coverage: Medical / Vision / Dental / Prescription Drug Life, legal, and supplementary insurance Virtual and in person mental health counseling services for individuals and family Commuter and parking benefits 401(K) retirement plan with matching contributions Employee stock purchase plan Paid time off Tuition reimbursement On-site fitness center and/or reimbursed fitness center membership costs (location dependent), with yoga studio, Pelotons, personal training, group exercise classes Access to CoStar Group's Diversity, Equity, & Inclusion Employee Resource Groups Complimentary gourmet coffee, tea, hot chocolate, fresh fruit, and other healthy snacks We welcome all qualified candidates who are currently eligible to work full-time in the United States to apply. However, please note that CoStar Group is not able to provide visa sponsorship for this position. #LI-AR CoStar Group is an Equal Employment Opportunity Employer; we maintain a drug-free workplace and perform pre-employment substance abuse testing
    $89k-124k yearly est. Auto-Apply 40d ago
  • Lead Security Engineer

    Costar Group 4.2company rating

    Arlington, TX jobs

    CoStar Group (NASDAQ: CSGP) is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index and the NASDAQ 100, CoStar Group is on a mission to digitize the world's real estate, empowering all people to discover properties, insights and connections that improve their businesses and lives. We have been living and breathing the world of real estate information and online marketplaces for over 35 years, giving us the perspective to create truly unique and valuable offerings to our customers. We've continually refined, transformed and perfected our approach to our business, creating a language that has become standard in our industry, for our customers, and even our competitors. We continue that effort today and are always working to improve and drive innovation. This is how we deliver for our customers, our employees, and investors. By equipping the brightest minds with the best resources available, we provide an invaluable edge in real estate. In this role, you'll communicate and reinforce security concepts to technical and non-technical audiences within the CoStar Enterprise. The ideal candidate will have experience implementing, using and updating standard security software in the areas of vulnerability scanning/management, leading remediation efforts, end-node security, security tool integration and orchestration for incident response. As the security section grows, so will the tools and the Lead Security Engineer will be the person charged with implementing them. The successful candidate will be a self-starter motivated to learn new technologies and tools and assist in moving security forward as it is implemented within the CoStar Enterprise. This position can be located in Arlington or Richmond, VA and is in office Monday through Thursday and work from home on Friday. Responsibilities Incident handling - serve as the incident response coordinator to oversee all incident response activities and ensure timely and successful resolution of incidents across various business verticals Develop, mature and lead incident response functions and reporting of findings Lead technical security assessments (network, application, database) for existing and newly acquired businesses or services and collaborate with other teams to adjust security configurations and architecture Facilitate quarterly incident response tabletop exercises and updating of the Incident Response Plan Team expert on Mitre Att&ck, tools, techniques, and practices of cyber attackers which you use to drive the overall strategy of the incident response team. Ability to define and develop platform automations to increase efficiency in responding to observed threats. Familiarity and comfort with at least one scripting language and basic understanding of CI/CD practices. Coordinate, performance and derive work from the security review and monitoring of the production environment setup permissions of users, open ports/services and overall network setup Ability to examine network, server, and application logs with forensic depth to determine trends and identify security incidents, and train and mentor others to deepen their skills Use security tools to audit infrastructure, detect issues and coordinate remediation of any issues Develop and mature threat hunting practices in the CoStar enterprise Collaborate with other teams to remediate discovered deficiencies, and develop and improve network and endpoint security configuration procedures Participate in 24x7 on-call rotation Basic Qualifications Bachelor's Degree required from an accredited, not for profit university or college. A track record of commitment to prior employers One or more security certification such as SANS/GIAC, CISSP, CISM, GIAC Certified Incident Handler (GCIH), Certified Expert Incident Handler (CEIH) or equivalent 8+ years in Information Technology, with 5+ years of cyber security experience. Scripting/programming skills (Perl, Python, PowerShell) Experience with Windows Server 2012/2016 /2019 and Active Directory Preferred Qualifications and Skills Excellent oral and written communication skills to work effectively with others regardless of departmental or geographic boundaries Ability to work on a cultural diverse team that spans international time zones and foster an environment of inclusions and participation with all team members Experience with Microsoft Security tooling (Defender, Sentinel, EOP etc.) a plus Ability to produce detailed technical documentation Proficiency with PC software applications, E-Mail, and job associated applications/systems to expediently process work Requires good organization skills to produce quality work, within required specifications, and within scheduled timelines Excellent customer service skills What's in it for You When you join CoStar Group, you'll experience a collaborative and innovative culture working alongside the best and brightest to empower our people and customers to succeed. We offer you generous compensation and performance-based incentives. CoStar Group also invests in your professional and academic growth with internal training, and tuition reimbursement. Our benefits package includes (but is not limited to): Comprehensive healthcare coverage: Medical / Vision / Dental / Prescription Drug Life, legal, and supplementary insurance Virtual and in person mental health counseling services for individuals and family Commuter and parking benefits 401(K) retirement plan with matching contributions Employee stock purchase plan Paid time off Tuition reimbursement On-site fitness center and/or reimbursed fitness center membership costs (location dependent), with yoga studio, Pelotons, personal training, group exercise classes Access to CoStar Group's Diversity, Equity, & Inclusion Employee Resource Groups Complimentary gourmet coffee, tea, hot chocolate, fresh fruit, and other healthy snacks We welcome all qualified candidates who are currently eligible to work full-time in the United States to apply. However, please note that CoStar Group is not able to provide visa sponsorship for this position. #LI-AR CoStar Group is an Equal Employment Opportunity Employer; we maintain a drug-free workplace and perform pre-employment substance abuse testing
    $89k-124k yearly est. Auto-Apply 60d+ ago
  • Senior Security Operations Center Analyst

    Ringcentral, Inc. 4.6company rating

    Denver, CO jobs

    Say hello to opportunities. It's not everyday that you consider starting a new career. We're RingCentral, and we're happy that someone as talented as you is considering this role. First, a little about us, we're a $2 Billion annual revenue company with double digit Annual Recurring Revenue (ARR) and a $93 Billion market opportunity in UCaaS, Contact Center and AI-powered adjacencies. We invest more than $250 million annually to ensure our AI-enabled technology and platforms meet or exceed the needs of our customers. RingSense AI is our proprietary AI solution. It's designed to fit the business needs of our customers, orchestrated to be accurate and precise, and built on the same open platform principles we apply to our core software solutions. This is where you and your skills come in. We're currently looking for: Security Operations Center Analyst Job Type: Full-Time, 2 days on (08.00 PDT AM - 08.00 PDT PM) 2 days off Location: Denver, CO Department: Security This is a great opportunity to work at a rapidly growing, market leading Unified Communications as-a-service company. RingCentral provides Voice-over-IP (VoIP), hosted PBX, voicemail, SMS, e-fax, and HD video meeting solutions for business. About this role: As a SOC Analyst at RingCentral, your primary responsibilities are to implement a comprehensive security monitoring, incident response and threat intelligence program for RingCentral's global cloud service, corporate and development environments. You will also be collaboratively providing feedback to improve security operations processes, generating actionable analysis and threat intelligence from tools, logs, and other data sources, ensuring strong documentation is in place to support ongoing SOC activities, and reporting your observations to other Security, Operations and IT personnel. Job Description: * Have proven skills in application security, security monitoring, incident response and intrusion analysis * Have strong knowledge of the diverse methods and technologies used to attack web/mobile/desktop applications, SaaS infrastructure, and data * Think critically, work well under pressure, and possess strong analytical, written, verbal, and interpersonal skills * Demonstrated track record of quality processes in candidate's work history * Be strongly self-motivated with an aptitude for both individual and team-oriented work * Have experience following and refining standard operating procedures and playbooks Responsibilities: * Monitor security events, analyze and investigate alarms, and maintain day-to-day operational activities of a secure cloud environment * Engage teams within and outside of RingCentral to mitigate and resolve cases * Maintain relevant documentation and audit artifacts * Identify and track suspicious system activity * Identify trends and patterns, and present them to Security Engineers to enhance our processes and systems * This role participates in on-call rotations Qualifications / Requirements: * 2+ years in a security engineering, SRE, or SOC roles in a cloud services environment * Experience with SIEM * Experience investigating security incidents * Basic knowledge AWS or GCP * Experience with IDS, case management, and related tools and practices * Experience with Linux, RedHat preferred * Basic knowledge of broad security topics such as encryption, application security, malware, ransomware, etc. * Knowledge of network, VoIP and web related protocols (e.g., TCP/IP, UDP, IPSEC, HTTP, HTTPS, SIP, RTP) Preferred Skills/Experience: * Experience using Crowdstrike, Cloudflare, FirePower, Splunk, ELK, Imperva, Syslog, packet capture, and Windows Event Log tools and similar tools * Knowledge of current hacking techniques, malicious code trends, botnets, exploits, malware, DDoS, and data breach events * Strong knowledge of Microsoft Windows * Experience automating security tasks, including scripting, programming and/or SecDevOps * Experience working with global teams Any combination of the following certifications: * GCIA (GIAC Certified Intrusion Analyst) * GCIH (GIAC Certified Incident Handler) * GCIA (GIAC Certified Intrusion Analyst) * GCFA (GIAC Certified Forensic Analyst) * GNFA (GIAC Certified Network Forensic Analyst) * GCFE (GIAC Forensic Examiner) * GASF (GIAC Advanced Smartphone Forensics) * GICA GCTI (GIAC Certified Cyber Threat Intelligence) * GPEN (GIAC Certified Pentester) * GWAPT (GIAC Certified Web Application Pentester) * GPYC (GIAC Certified Python Coder) * OSCP (Offensive Security Certified Pentester) What we offer: * Comprehensive medical, dental, vision, disability, life insurance * Health Savings Account (HSA), Flexible Spending Account (FSAs) and Commuter benefits * Voluntary supplemental health coverage and life insurance * 401K match and ESPP * Paid time off and paid sick leave * Paid parental and pregnancy leave * Family-forming benefits (IVF, Preservation, Adoption etc.) * Emergency backup care (Child/Adult/Pets) * Employee Assistance Program (EAP) with counseling sessions available 24/7 * Free legal services that provide legal advice, document creation and estate planning * Employee bonus referral program * Student loan refinancing assistance * Employee 1:1 coaching, perks and discounts program RingCentral's IT team ensures company data is accessible, secure, and optimized in ways that provide maximum competitive advantage. We are constantly discovering, developing and deploying innovations that power productivity and drive better decisions for our customers. Our IT professionals are talented, ambitious, out-of-the-box thinkers who love to learn on the job-planning, deploying and maintaining state-of-the-art technology to deliver flawless performance 24/7/365. RingCentral's work culture is the backbone of our success. And don't just take our word for it: we are recognized as a Best Place to Work by Glassdoor, the Top Work Culture by Comparably and hold local BPTW awards in every major location. Bottom line: We are committed to hiring and retaining great people because we know you power our success. About RingCentral RingCentral, Inc. (NYSE: RNG) is a leading provider of business cloud communications and contact center solutions based on its powerful Message Video Phone (MVP) global platform. More flexible and cost effective than legacy on-premises PBX and video conferencing systems that it replaces, RingCentral empowers modern mobile and distributed workforces to communicate, collaborate, and connect via any mode, any device, and any location. RingCentral is headquartered in Belmont, California, and has offices around the world. RingCentral is an equal opportunity employer that truly values diversity. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. If you are hired in Denver, CO the compensation range for this position is between $73,500 and $105,000 for full-time employees, in addition to eligibility for variable pay, equity, and benefits. Benefits may include, but are not limited to, health and wellness, 401k, ESPP, vacation, parental leave, and more! The salary may vary depending on your location, skills, and experience. #LI-IG1
    $73.5k-105k yearly Auto-Apply 13d ago
  • Senior Security Operations Center Analyst

    Ringcentral 4.6company rating

    Denver, CO jobs

    Say hello to opportunities. It's not everyday that you consider starting a new career. We're RingCentral, and we're happy that someone as talented as you is considering this role. First, a little about us, we're a $2 Billion annual revenue company with double digit Annual Recurring Revenue (ARR) and a $93 Billion market opportunity in UCaaS, Contact Center and AI-powered adjacencies. We invest more than $250 million annually to ensure our AI-enabled technology and platforms meet or exceed the needs of our customers. RingSense AI is our proprietary AI solution. It's designed to fit the business needs of our customers, orchestrated to be accurate and precise, and built on the same open platform principles we apply to our core software solutions. This is where you and your skills come in. We're currently looking for: Security Operations Center Analyst Job Type: Full-Time, 2 days on (08.00 PDT AM - 08.00 PDT PM) 2 days off Location: Denver, CO Department: Security This is a great opportunity to work at a rapidly growing, market leading Unified Communications as-a-service company. RingCentral provides Voice-over-IP (VoIP), hosted PBX, voicemail, SMS, e-fax, and HD video meeting solutions for business. About this role: As a SOC Analyst at RingCentral, your primary responsibilities are to implement a comprehensive security monitoring, incident response and threat intelligence program for RingCentral's global cloud service, corporate and development environments. You will also be collaboratively providing feedback to improve security operations processes, generating actionable analysis and threat intelligence from tools, logs, and other data sources, ensuring strong documentation is in place to support ongoing SOC activities, and reporting your observations to other Security, Operations and IT personnel. Job Description: Have proven skills in application security, security monitoring, incident response and intrusion analysis Have strong knowledge of the diverse methods and technologies used to attack web/mobile/desktop applications, SaaS infrastructure, and data Think critically, work well under pressure, and possess strong analytical, written, verbal, and interpersonal skills Demonstrated track record of quality processes in candidate's work history Be strongly self-motivated with an aptitude for both individual and team-oriented work Have experience following and refining standard operating procedures and playbooks Responsibilities: Monitor security events, analyze and investigate alarms, and maintain day-to-day operational activities of a secure cloud environment Engage teams within and outside of RingCentral to mitigate and resolve cases Maintain relevant documentation and audit artifacts Identify and track suspicious system activity Identify trends and patterns, and present them to Security Engineers to enhance our processes and systems This role participates in on-call rotations Qualifications / Requirements: 2+ years in a security engineering, SRE, or SOC roles in a cloud services environment Experience with SIEM Experience investigating security incidents Basic knowledge AWS or GCP Experience with IDS, case management, and related tools and practices Experience with Linux, RedHat preferred Basic knowledge of broad security topics such as encryption, application security, malware, ransomware, etc. Knowledge of network, VoIP and web related protocols (e.g., TCP/IP, UDP, IPSEC, HTTP, HTTPS, SIP, RTP) Preferred Skills/Experience: Experience using Crowdstrike, Cloudflare, FirePower, Splunk, ELK, Imperva, Syslog, packet capture, and Windows Event Log tools and similar tools Knowledge of current hacking techniques, malicious code trends, botnets, exploits, malware, DDoS, and data breach events Strong knowledge of Microsoft Windows Experience automating security tasks, including scripting, programming and/or SecDevOps Experience working with global teams Any combination of the following certifications: GCIA (GIAC Certified Intrusion Analyst) GCIH (GIAC Certified Incident Handler) GCIA (GIAC Certified Intrusion Analyst) GCFA (GIAC Certified Forensic Analyst) GNFA (GIAC Certified Network Forensic Analyst) GCFE (GIAC Forensic Examiner) GASF (GIAC Advanced Smartphone Forensics) GICA GCTI (GIAC Certified Cyber Threat Intelligence) GPEN (GIAC Certified Pentester) GWAPT (GIAC Certified Web Application Pentester) GPYC (GIAC Certified Python Coder) OSCP (Offensive Security Certified Pentester) What we offer: Comprehensive medical, dental, vision, disability, life insurance Health Savings Account (HSA), Flexible Spending Account (FSAs) and Commuter benefits Voluntary supplemental health coverage and life insurance 401K match and ESPP Paid time off and paid sick leave Paid parental and pregnancy leave Family-forming benefits (IVF, Preservation, Adoption etc.) Emergency backup care (Child/Adult/Pets) Employee Assistance Program (EAP) with counseling sessions available 24/7 Free legal services that provide legal advice, document creation and estate planning Employee bonus referral program Student loan refinancing assistance Employee 1:1 coaching, perks and discounts program RingCentral's IT team ensures company data is accessible, secure, and optimized in ways that provide maximum competitive advantage. We are constantly discovering, developing and deploying innovations that power productivity and drive better decisions for our customers. Our IT professionals are talented, ambitious, out-of-the-box thinkers who love to learn on the job-planning, deploying and maintaining state-of-the-art technology to deliver flawless performance 24/7/365. RingCentral's work culture is the backbone of our success. And don't just take our word for it: we are recognized as a Best Place to Work by Glassdoor, the Top Work Culture by Comparably and hold local BPTW awards in every major location. Bottom line: We are committed to hiring and retaining great people because we know you power our success. About RingCentral RingCentral, Inc. (NYSE: RNG) is a leading provider of business cloud communications and contact center solutions based on its powerful Message Video Phoneâ„¢ (MVPâ„¢) global platform. More flexible and cost effective than legacy on-premises PBX and video conferencing systems that it replaces, RingCentral empowers modern mobile and distributed workforces to communicate, collaborate, and connect via any mode, any device, and any location. RingCentral is headquartered in Belmont, California, and has offices around the world. RingCentral is an equal opportunity employer that truly values diversity. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. If you are hired in Denver, CO the compensation range for this position is between $73,500 and $105,000 for full-time employees, in addition to eligibility for variable pay, equity, and benefits. Benefits may include, but are not limited to, health and wellness, 401k, ESPP, vacation, parental leave, and more! The salary may vary depending on your location, skills, and experience. #LI-IG1
    $73.5k-105k yearly Auto-Apply 4d ago
  • Senior Information System Security Officer

    Tyto Athene 4.2company rating

    Washington, DC jobs

    Tyto Athene is hiring a **Senior Information System Security Officer (ISSO)** to support one of our law enforcement customers in Washington, DC. The successful candidate will ensure information systems and high value assets (HVA) meet NIST security requirements, managing the entire Risk Management Framework (RMF) and Authorization to Operate (ATO) lifecycles. **Responsibilities:** + Develop and update security authorization packages in accordance with the client's requirement and compliant with FISMA. Core documents that the candidate will be responsible for are the System Security Plan, Risk Assessment Report, Security Assessment Plan and Report, Contingency Plan, Incident Response Plan, Standard Operating Procedure, Plan of Actions and Milestones, Remediation Plans, Configuration Management Plan, etc. + Develop and maintain the Plan of Action and Milestones and support remediation activities + Validate protective measures for physical security are in place to support the system security requirements + Maintain an inventory of hardware and software for the information system + Develop, coordinate, test, and train on Contingency Plans and Incident Response Plans + Perform risk analyses to determine cost-effective and essential safeguards + Support Incident Response and Contingency activities + Perform security control assessment in using NIST 800-53A + Conduct independent scans of the application, network, and database (where required) + Provide continuous monitoring to enforce client security policy and procedures and create processes that will provide oversight into the following activities for the system owner + Coordinate with multiple stakeholders to complete mandatory agency data calls in a timely manner + The ISSO should be intimately familiar with some aspects of the following: + Federal Government Information Assurance policies and regulations to include OMB requirements, FISMA, and NIST 800 series + OMB A-123 circular; OMB A-130 circular; FIPS 140, 199, 200, 201; NIST SP 800-18, 37 Revision 1, 39, 53 Revision 3 and 4, 53A Revision 1, 60 Volumes 1 and 2, 800-64 Revision 2, 137, 144, 147; CNSS 1253 and risk management methodologies + Network, network protocols, routers, and switches and how they interact with automated vulnerability assessment tools, open-source vulnerability assessment tools, and techniques used for evaluating security controls on Windows, Linux, and Unix operating systems, networking devices, databases, and web servers + Developing custom assessment scripts + Network Security Architecture **Qualifications** **Required:** + 8+ years of professional experience with at least 5 years supporting ISSO RMF activities. + Bachelor's Degree or 4 years of additional experience in lieu of a degree. + A demonstrated understanding of information privacy, including information access, the release of information, and implementation of control technologies as they apply to privacy information contained in electronic and non-electronic media. + Thorough understanding and knowledge of FISMA, NIST RMF and Security and Privacy Assessment and Authorization (SPA&A) processes. + Experience with NIST publications, OMB circulars and memoranda, and CNSS publications and their requirements and impact on system security. + Proficiency in writing technical analysis reports with strong written and oral communication skills + Ability to work quickly, efficiently, and accurately in a dynamic and fluid environment + Good relationship management, business acumen, judgment, and ability to think critically **Desired:** + Experience supporting the legislative branch + Preferred certifications: CISA, CAP or equivalent + Experience with FedRAMP and cloud service providers + Experience with CSAM and ServiceNow + Experience with vulnerability assessments tools such as Nessus and/or Qualys **Clearance:** US Citizen with Public Trust eligibility required **Location:** Hybrid-remote in Washington DC, with the expectation to be onsite 2 days/week. **About Tyto Athene** **Compensation:** + Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary for this role is $120-130K. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range. **Benefits:** + Highlights of our benefits include Health/Dental/Vision, 401(k) match, Flexible Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and maternity/paternity leave. Tyto Athene is a trusted leader in IT services and solutions, delivering mission-focused digital transformation that drives measurable success. Our expertise spans four core technology domains-Network Modernization, Hybrid Cloud, Cybersecurity, and Enterprise IT-empowering our clients with cutting-edge solutions tailored to their evolving needs. With over 50 years of experience, Tyto Athene proudly support Defense, Intelligence, Space, National Security, Civilian, Health, and Public Safety clients across the United States and worldwide. At Tyto Athene, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamTyto? Tyto Athene, LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law. Submit a Referral (*********************************************************************************************************************************************** **Location** _US-DC-Washington_ **ID** _2025-1630_ **Category** _Cybersecurity_ **Position Type** _Full-Time_
    $120k-130k yearly 32d ago
  • Senior Information System Security Officer

    Tyto Athene 4.2company rating

    Washington, DC jobs

    Tyto Athene is hiring a Senior Information System Security Officer (ISSO) to support one of our law enforcement customers in Washington, DC. The successful candidate will ensure information systems and high value assets (HVA) meet NIST security requirements, managing the entire Risk Management Framework (RMF) and Authorization to Operate (ATO) lifecycles. Responsibilities: Develop and update security authorization packages in accordance with the client's requirement and compliant with FISMA. Core documents that the candidate will be responsible for are the System Security Plan, Risk Assessment Report, Security Assessment Plan and Report, Contingency Plan, Incident Response Plan, Standard Operating Procedure, Plan of Actions and Milestones, Remediation Plans, Configuration Management Plan, etc. Develop and maintain the Plan of Action and Milestones and support remediation activities Validate protective measures for physical security are in place to support the system security requirements Maintain an inventory of hardware and software for the information system Develop, coordinate, test, and train on Contingency Plans and Incident Response Plans Perform risk analyses to determine cost-effective and essential safeguards Support Incident Response and Contingency activities Perform security control assessment in using NIST 800-53A Conduct independent scans of the application, network, and database (where required) Provide continuous monitoring to enforce client security policy and procedures and create processes that will provide oversight into the following activities for the system owner Coordinate with multiple stakeholders to complete mandatory agency data calls in a timely manner The ISSO should be intimately familiar with some aspects of the following: Federal Government Information Assurance policies and regulations to include OMB requirements, FISMA, and NIST 800 series OMB A-123 circular; OMB A-130 circular; FIPS 140, 199, 200, 201; NIST SP 800-18, 37 Revision 1, 39, 53 Revision 3 and 4, 53A Revision 1, 60 Volumes 1 and 2, 800-64 Revision 2, 137, 144, 147; CNSS 1253 and risk management methodologies Network, network protocols, routers, and switches and how they interact with automated vulnerability assessment tools, open-source vulnerability assessment tools, and techniques used for evaluating security controls on Windows, Linux, and Unix operating systems, networking devices, databases, and web servers Developing custom assessment scripts Network Security Architecture Qualifications Required: 8+ years of professional experience with at least 5 years supporting ISSO RMF activities. Bachelor's Degree or 4 years of additional experience in lieu of a degree. A demonstrated understanding of information privacy, including information access, the release of information, and implementation of control technologies as they apply to privacy information contained in electronic and non-electronic media. Thorough understanding and knowledge of FISMA, NIST RMF and Security and Privacy Assessment and Authorization (SPA&A) processes. Experience with NIST publications, OMB circulars and memoranda, and CNSS publications and their requirements and impact on system security. Proficiency in writing technical analysis reports with strong written and oral communication skills Ability to work quickly, efficiently, and accurately in a dynamic and fluid environment Good relationship management, business acumen, judgment, and ability to think critically Desired: Experience supporting the legislative branch Preferred certifications: CISA, CAP or equivalent Experience with FedRAMP and cloud service providers Experience with CSAM and ServiceNow Experience with vulnerability assessments tools such as Nessus and/or Qualys Clearance: US Citizen with Public Trust eligibility required Location: Hybrid-remote in Washington DC, with the expectation to be onsite 2 days/week. About Tyto Athene Compensation: Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary for this role is $120-130K. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range. Benefits: Highlights of our benefits include Health/Dental/Vision, 401(k) match, Flexible Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and maternity/paternity leave. Tyto Athene is a trusted leader in IT services and solutions, delivering mission-focused digital transformation that drives measurable success. Our expertise spans four core technology domains-Network Modernization, Hybrid Cloud, Cybersecurity, and Enterprise IT-empowering our clients with cutting-edge solutions tailored to their evolving needs. With over 50 years of experience, Tyto Athene proudly support Defense, Intelligence, Space, National Security, Civilian, Health, and Public Safety clients across the United States and worldwide. At Tyto Athene, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamTyto? Tyto Athene, LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.
    $120k-130k yearly Auto-Apply 30d ago
  • Cloud Security Engineer

    Iridium Communications 4.7company rating

    Chandler, AZ jobs

    Iridium is an award-winning and innovative satellite communications company with bragging rights to the only network that offers voice and data connectivity anywhere in the world. For over 20 years, Iridium's unique network and services have supported critical communications needs for individuals, businesses, and the evolving Internet of Things. At Iridium, we understand the importance of staying connected and the limitations of traditional communications networks. People across the globe, including first responders, humanitarians, global militaries, scientific researchers, and lone workers, as well as ships, aircraft and remote operations all rely on Iridium to stay connected. We take our responsibility for providing these essential communications very seriously and pride ourselves on offering a reliable lifeline when needed. Likewise, Iridium is committed to providing an exciting and innovative workplace, where employees are challenged to think outside the box and collaborate on new, bold ideas and solutions. Our talented teams are passionate about their work and the impact our company makes around the world. Iridium fosters an empowering and inclusive culture that allows employees to genuinely be their best selves. We are looking for others who want to join this truly unique company that celebrates our employees and provides the opportunity to truly make a difference in the world. What We're Looking For: If you enjoy learning about and working with breakthrough technologies and are enthusiastic about working in the space industry, then you will be excited about the Senior Software Engineer opening with Iridium for a Space Development Agency (SDA) project. As the Senior Software Engineer within the Ground Systems Development team, you will apply cutting edge technologies to rapidly develop and deploy ground system operations and user service capabilities within a satellite operations environment. Additionally, the Senior Software Engineer will identify and autonomously implement ideas/solutions within the larger development team to support cross-functional efforts across all areas of ground system software development. What You'll Do: Develop high performing/scalable App Cyber Security architecture and implementation to meet the requirements of the SDA project Engage in cross-team DevOps, Ground and Constellation development to support AWS PaaS deployment environment and automation. Develop Work within the Agile/Scrum framework for software development (Atlassian tool suite desired) Create or maintain build environments for software products Play a key role in planning and executing software releases per stakeholder/program schedules and budgets Update issue/feature data in Atlassian Project/Software tracking tools Follow existing Iridium processes for Change Control, Prioritization, Risk Management, Commercial off-the-shelf (COTS) Management, Build and Test software deployments and use advanced knowledge to assist in development of process/procedure documentation materials Edit, structure and present data, concepts and arguments clearly and succinctly through briefings and documentation Respond to questions within scope from stakeholders, as appropriate What You'll Need to Succeed: Bachelor of Science degree in Computer Science, or other engineering discipline 8+ years software programming experience Coding experience on Agile based teams Excellent communication skills, with the ability to clearly convey products, deliverables, analyses, and/or issues to groups outside of your team or those who are unfamiliar with the topic Have confidence and be able to easily build relationships with leadership and colleagues outside of your team Possess an analytical mindset, with the ability to understand a situation or problem and think critically to make decisions and come up with out-of-the-box solutions Be proactive in providing feedback and be enthusiastic in sharing your knowledge with others Capable of prioritizing your own tasks and potentially the tasks of others while making sure deadlines are met Proactivity in seeking out ways to continuously improve yourself and gain new knowledge, including the ability to learn the different software that make up the System Performance and Analysis software Ability to comprehend technical documentation Have a positive attitude to take on ever increasing software development tasks Passion for working in a team driven environment consisting of operators, software testers, senior developers, and system engineers Things That Would be Great if You Brought to the Table: Experience with the following technologies: Design and implementation of Role-based Access Control Keycloak / Vault / IPA / IAM mTLS / SSL or security protocol equivalent Cryptography and PKI/Certifications Authentication and Authorization architecture Design and implementation of Kubernetes auto-deployment to AWS (Helm Charts) Linux based environments and bash shell scripting Security Vulnerability Analysis and Procedures (CVE, TLS) Terraform Python / Java / C++ / Type Script / Perl RESTful / HTTP / ELK or similar / WebSockets XML / JSON / SQL SQL: (e.g., PostgreSQL) and NoSQL based DBs (e.g., Mongo) js / Apache Web Server Assist in software development response to security findings Atlassian management/software development tools: Jira / Git / Crucible / Confluence Micro services architecture Automated testing frameworks Gov and non-Gov Amazon Web Services (AWS) cloud environments We'll Also Need You To: This position directly performs under, supports, or is exposed to a U.S. government contract. To comply with the requirements of Iridium's U.S. government contracts, applicants for this position must be U.S. citizens. Work Environment: This position primarily works in an office setting and is largely sedentary with the majority of the position working with a computer. The role typically requires the use of basic office equipment such as a phone, video, computer, keyboard, mouse, and printer. Iridium is an Equal Opportunity Employer, including individuals with disabilities and protected veterans.
    $87k-120k yearly est. Auto-Apply 19d ago
  • Security Systems Engineer

    Dagostino Electronic Services 4.1company rating

    Pittsburgh, PA jobs

    The Systems Engineer position is responsible for providing full cycle implementation and support of customer systems, while working across multiple company departments to ensure full client satisfaction. Under the direction of a manager or dispatcher, coordinates the design and maintenance of all access control, intrusion, and video surveillance systems. Incumbent receives and evaluates work orders and requests, investigates requests and troubleshoots problems where appropriate, establishes priorities and coordinates with contractors, when required. Requirements Essential functions and responsibilities: Assists with security systems integration, mapping and software updates and helps train personnel in the use of these systems. Assists on new projects in both existing areas and new construction helping with security assessments, vendor selection, technology upgrades, product selections, testing, field verification of systems and inspection of work in progress for compliance with standards Assess work sites, conditions, and logistics for each project; Develop Method of Procedure based on pre-project assessment. Design, develop and provide documentation of systems, configurations, and other pertinent information for the customer. Communicate with clients to resolve issues in a professional and confidential manner; Develop and execute client specific solutions. Manage the allocation of project resources, including software, hardware, tools, and related items specific to each customer and/or project. Direct the work responsibilities of union labor personnel based on specific project needs. Design and oversee training programs for new and existing customers; Determine which customers receive training. Collaborate with Customer Relationship Managers on demonstrations for new and potential clients. Perform installation, configuration, programming, and final commissioning of customer systems. Work collaboratively with installation, project management and engineering teams. Perform infrastructure services, including pulling cables, installing wall, and ceiling cabling, and installing surface mounted devices, as required. Perform system wiring and terminations services, as required. Deliver on-going remote and on-site technical support for existing customers and systems. Additional responsibilities may be required as necessary, including but not limited to: Provide internal support for basic trouble shooting. Organizes and manage parts stock and tools. Perform other duties as needed. Success factors/job competencies: Effectively communicate both in writing and verbally Work independently and prioritize multiple tasks and adapt to needed change Analysis Mechanical aptitude Comprehend technical language and read and interpret blueprints, wiring diagrams, and schematics Safety orientation Customer Focus Attention to Detail Teamwork/Collaboration Stay abreast of changes in security technology Physical demands and work environment: The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. Individual will be required to travel to customer sites as needed. While performing the duties of this job, the employee is occasionally exposed to moving mechanical parts. The employee is occasionally exposed to outside weather conditions and risk of electrical shock. Individual will regularly be required to lift, push, pull, and carry up to 50 pounds, and occasionally up to 75 pounds. Incumbent will be required to use a computer with keyboard, telephone, or handheld mobile device for extended periods of time, and office machinery as needed. Incumbent must be able to read, see, hear, and speak. Workdays and Shifts: Position works Monday-Friday, daylight hours, and additional time as needed to complete work. Education/Certification(s)/License(s) required: Bachelor's Degree in Electronics, Information Technology or related field, or equivalent experience. May be required to participate in safety trainings and/or certifications provided by the Company or customers. Valid driver's license, as employee will be required to travel to local and overnight client sites as needed. Manufacturer specific certifications, as required. Responsible to maintain active certifications and obtain new and updated certifications as required by the Company. Experience/Other required: Position requires two (2) to three (3) years of relevant experience in the electronic services. Strong knowledge of Microsoft Office. Strong computer skills with advanced software aptitude. Security systems to include, service and maintenance across a broad spectrum of access control, intrusion and video surveillance systems such as, Genetec, Milestone, Bosch, and DMP. Applicants must be currently authorized to work in the United States on a full-time basis. Visa sponsorship is not available for this position. This is a full-time, in-person position, and candidates must be able to work from our office located in Pittsburgh, Pennsylvania.
    $90k-127k yearly est. 60d+ ago
  • Cybersecurity Engineer/Azure Sr Security Engg

    Nextgen Solutions Corp 3.6company rating

    Richmond, VA jobs

    Number of positions: 1 Length: 12Months + Work Address: Richmond, VA 23219 Immediate interviews Web Cam Interview Elect - Cybersecurity Engineer Is Remote. Seeking an Azure Senior Security Engineer (Cybersecurity Engineer 3) with minimum 5 years experience to work with an existing software development team. You will be working with our more established contractors and staff to focus on several web and Windows applications used both by internal staff and constituents of the Commonwealth of Virginia. The candidate will need expertise in all aspects of IT security and cloud security and experience working in an Agile/Scrum development environment interacting with technical and non-technical stakeholders. Candidate will need to have extensive knowledge of cybersecurity practices, industry security standards, and regulatory standards. A bachelors degree and/or applicable recognized industry certifications are strongly desired and will help you stand out in this position. using mobile and responsive design practices, so a familiarity with these methodologies would be a plus. Required/Desired Skills Candidates must have ALL the Required skills in order to be considered for the position. Desired or Highly Desired skills are a PLUS but may NOT be required. Skill Matrix (Please fill the last two columns of this matrix) Experience with Business workflow processes Required / Desired Amount of Experience Years of Experience Last Used 5+ years in IT security or cloud security roles required. Required 5 Years 3+ years of hands-on experience securing Azure environments Required 3 Years Bachelors degree in Computer Science, Cybersecurity, or related field or equivalent work experience required. Required 5 Years Relevant certifications (MS Certified Cybersecurity Architect Expert, Azure Security Engineer Associate (SC-300), CompTIA Security+, CISSP, CISM Highly desired 5 Years Experience with Azure Security Services (Azure Defender, MS Sentinel, Azure Key Vault, Azure Policy and Blueprints, Azure Security Center) required. Required 5 Years Experience with Azure Active Directory (AAD), including conditional access, MFA, and identity protection required. Required 5 Years Extensive knowledge of PIM and RBAC required Required 5 Years Experience with NSGs, ASGs, VPN, ExpressRoute, and hybrid connectivity security required Required 5 Years Ability to implement and moitor compliance with regulatory standards such as NIST, ISO 27001, GDPR, etc. is required Required 5 Years Extensive knowledge of threat modeling and vulnerability management, SIEM/SOAR tuning and response workflows, and security alert triage and forensics Required 5 Years Ability to perform scripting and automation using PowerShell, Bicep, ARM templates, or Terraform Required 5 Years Ability to perform perform integration with CI/CD pipelines for secure deployments (GitHub Actions, Azure DevOps) Required 5 Years Ability to create and deliver security architecture reports and documentation Required 5 Years Experience in risk assessment and mitigation strategies Required 5 Years
    $81k-114k yearly est. 12d ago

Learn more about Comcast jobs

View all jobs