Cyber Security Analyst
Cyber security analyst job in Irvine, CA
Required Skills & Experience:
Bachelor's degree in a related field preferred but not required.
5+ years of experience in a SOC or similar security environment.
Expertise with SIEM, EDR, CSPM tools; strong skills in SQL/KQL/Cypher for data analysis.
Proven ability to lead complex investigations and coordinate across technical and business stakeholders.
Solid understanding of cybersecurity frameworks (MITRE ATT&CK, NIST CSF, NIST SP800-61r3).
Experience with log aggregation technologies and SIEM tuning processes.
Job Description:
A large financial services customer based in Irvine, CA is seeking a Cyber Security Operations Analyst, focused on Incident Response. This individual will lead Incident Response, and act as a technical expert within the SOC. This team protects the organization from cyber threats. This role requires strong analytical skills, leadership in high-severity incidents, and deep knowledge of security tools and frameworks.
Pay:
50-65/hr
Lead AI Security Engineer
Cyber security analyst job in Irvine, CA
"I can be myself at work." You are more than a job title. We want you to feel comfortable doing great work and bringing your best, authentic self to everything you do. We value your talents, traditions, and uniqueness-and we're committed to fostering a strong sense of belonging in a respectful workplace.
We intentionally seek diverse perspectives, experiences, and backgrounds, investing in a culture designed to celebrate differences. We believe that belonging leads to better outcomes and a stronger community of associates united by our mission. At Capital, we live our core values every day: Integrity, Client Focus, Diverse Perspectives, Long-Term Thinking, and Community.
"I can influence my income."
You want to feel recognized at work. Your performance will be reviewed annually, and your compensation will be designed to motivate and reward the value that you provide. You'll receive a competitive salary, bonuses and benefits. Your company-funded retirement contribution will factor in salary and variable pay, including bonuses.
"I can lead a full life."
You bring unique goals and interests to your job and your life. Whether you're raising a family, you're passionate about where you volunteer, or you want to explore different career paths, we'll give you the resources that can set you up for success.
* Enjoy generous time-away and health benefits from day one, with the opportunity for flexible work options
* Receive 2-for-1 matching gifts for your charitable contributions and the opportunity to secure annual grants for the organizations you love
* Access on-demand professional development resources that allow you to hone existing skills and learn new ones
"I can succeed as a Lead AI Security Engineer at Capital Group"
As a Lead AI Security Engineer, you will be responsible for securing Capital Group's enterprise AI Platforms. You will help enable Capital Group's AI strategy by building and/or procuring solutions to protect a diverse set of enterprise AI platforms being built and deployed at Capital Group. You'll collaborate with platform engineering, security engineering, and risk teams to ensure their solutions support scalable, secure adoption of AI.
Additionally, you'll be expected to provide mentoring, advising diverse teams across the organization, and promoting AI Security principles across Capital Group.
* AI Security Procurement Managements: You will procure and/or build technical solutions to reduce the risk of misconfiguration, exploitation, and other security issues for multiple enterprise AI platforms.
* Embedding Security in the AI Platform Ecosystem: Working closely with platform teams to integrate security into every component of the AI Platform.
* Implementing Security Controls & "Guardrails" for GenAI: Designing, deploying, and operating technical controls to prevent misuse of AI systems. Guardrails design includes content filtering systems, usage policies, and safety checks that mitigate issues like prompt injection attacks, unauthorized data extraction, model bias or hallucinations, and other misuse of generative AI platforms.
* AI Runtime Security: Engineer continually tests and updates to the guardrails, replacing weaker controls with more robust solutions as threats evolve.
* AI Governance: You will work cross functionally with architecture and platform teams to monitor alignment of solutions to AI Governance processes
* Contribute to Standards and Policies: You will provide thought leadership for Information Security policies and standards for AI in collaboration with technology risk
* AI/Agent SME: You will provide AI/Agent subject matter expertise for AI Incidents and Security Reviews, and help develop incident response playbooks for AI-related security incidents
"I am the person Capital Group is looking for."
* You have 8+ years of experience in information security, application security, platform security, or penetration testing, DevSecOps, network security and other security disciplines.
* You have experience securing AI platforms, whether internal AI platforms or offerings such as CoPilot Studio, Amazon Bedrock, and/or Azure AI Gateway
* Proficient in Programming & ML Tool. Strong Python skills required, with experience in AI/ML frameworks. Ability to review and write ML code to implement security measures (e.g., model validation, adversarial testing) is desired.
* You have 5+ years of relevant professional experience or demonstrated an equivalent level of expertise in security engineering, such as cloud, API, or platform security.
* You have 3+ years of experience embedded identity, network, and encryption controls into enterprise platforms
* You can effectively partner and collaborate with stakeholder teams.
* You have effective communication skills and the ability to outline security risks to leadership.
* You are familiar with cloud and API security vendors and managed services providers.
Preferred Qualifications:
* You have knowledge and experience with technologies including Kubernetes, Containers, CI/CD, and Cloud Service Providers
* You are familiar with function and purpose of key AI platform components such as AI gateways (Kong, Databricks Mosaic AI Gateway, custom API orchestration), Model Orchestration (Examples LangChain, LlamaIndex, etc.)
* You are familiar with key AI regulatory frameworks such as NIST AI RMF, MITRE ATLAS, GDPR, EU AI Act, etc
* You have information Security certifications (CISSP, SANS GIAC, CISA, etc.)
"I can apply in less than 4 minutes."
You've reviewed this job posting and you're ready to start the candidate journey with us. Apply now to move to the next step in our recruiting process. If this role isn't what you're looking for, check out our other opportunities and join our talent community.
"I can learn more about Capital Group."
At Capital Group, the success of the people who invest with us depends on the people in whom we invest. That's why we offer a culture, compensation and opportunities that empower our associates to build successful and prosperous careers. Through nine decades, our goal has been to improve people's lives through successful investing. We know that our history is a testament to the strength of the people we hire. More than 9,000 associates in 30+ offices around the world help our clients and each other grow and thrive every day. Find us on LinkedIn, Instagram, YouTube and Glassdoor.
Southern California Base Salary Range: $179,273-$286,837
San Antonio Base Salary Range: $147,378-$235,805
New York Base Salary Range: $190,040-$304,064
In addition to a highly competitive base salary, per plan guidelines, restrictions and vesting requirements, you also will be eligible for an individual annual performance bonus, plus Capital's annual profitability bonus plus a retirement plan where Capital contributes 15% of your eligible earnings.
You can learn more about our compensation and benefits here.
* Temporary positions in the United States are excluded from the above mentioned compensation and benefit plans.
We are an equal opportunity employer, which means we comply with all federal, state and local laws that prohibit discrimination when making all decisions about employment. As equal opportunity employers, our policies prohibit unlawful discrimination on the basis of race, religion, color, national origin, ancestry, sex (including gender and gender identity), pregnancy, childbirth and related medical conditions, age, physical or mental disability, medical condition, genetic information, marital status, sexual orientation, citizenship status, AIDS/HIV status, political activities or affiliations, military or veteran status, status as a victim of domestic violence, assault or stalking or any other characteristic protected by federal, state or local law.
Auto-ApplySoftware Security Analyst
Cyber security analyst job in Irvine, CA
Job Description
About Us:
Headquartered in the United States, TP-Link Systems Inc. is a global provider of reliable networking devices and smart home products, consistently ranked as the world's top provider of Wi-Fi devices. The company is committed to delivering innovative products that enhance people's lives through faster, more reliable connectivity. With a commitment to excellence, TP-Link Systems serves customers in over 170 countries and continues to grow its global footprint.
We believe technology changes the world for the better! At TP-Link Systems Inc, we are committed to crafting dependable, high-performance products to connect users worldwide with the wonders of technology.
Embracing professionalism, innovation, excellence, and simplicity, we aim to assist our clients in achieving remarkable global performance and enable consumers to enjoy a seamless, effortless lifestyle.
Overview:
We are seeking many highly skilled and experienced Software Security Analyst (aka Source Code Auditor) to join our cybersecurity team. In this role, you will be responsible for reviewing and analyzing source code to identify potential security vulnerabilities, ensure compliance with coding standards, and enhance the overall security posture of our applications. You will work closely with development teams, security professionals, and stakeholders to provide actionable insights and recommendations for improving code quality and security.
Key Responsibilities
Conduct thorough audits of source code to identify vulnerabilities, security weaknesses, and coding inefficiencies.
Review and analyze code across a variety of programming languages and frameworks, including but not limited to Python, Java, C++, JavaScript, Swift and Kotlin.
Develop and maintain code auditing standards, processes, and tools to ensure consistent and high-quality reviews.
Collaborate with development teams to provide feedback and guidance on secure coding practices and remediation strategies.
Prepare detailed audit reports that outline findings, risks, and recommendations for improving code security and quality.
Stay up to date with the latest security threats, coding standards, and best practices to continuously improve audit processes.
Mentor junior auditors and provide guidance on auditing techniques, tools, and best practices.
Work with cross-functional teams to integrate security practices into the software development lifecycle (SDLC).
Assist in developing and conducting security training and awareness programs for development teams.
Requirements
Qualifications:
Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent experience.
5+ years of experience in source code auditing, software development, or application security.
Strong understanding of secure coding principles, software vulnerabilities, and common attack vectors (e.g., SQL injection, cross-site scripting, buffer overflow).
Proficiency in multiple programming languages and familiarity with a variety of development frameworks and environments.
Experience with automated code review tools (e.g., SonarQube, Coverity, Checkmarx, Veracode) and manual code review techniques.
Excellent analytical and problem-solving skills with a keen eye for detail.
Strong communication skills, with the ability to explain complex technical concepts to non-technical stakeholders.
Relevant certifications such as Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), or Certified Information Systems Security Professional (CISSP) are a plus.
Benefits
Salary range: $100,000-$140,000
Free snacks and drinks, and provided lunch on Fridays
Fully paid medical, dental, and vision insurance (partial coverage for dependents)
Contributions to 401k funds
Bi-annual reviews, and annual pay increases
Health and wellness benefits, including free gym membership
Quarterly team-building events
At TP-Link Systems Inc., we are continually searching for ambitious individuals who are passionate about their work. We believe that diversity fuels innovation, collaboration, and drives our entrepreneurial spirit. As a global company, we highly value diverse perspectives and are committed to cultivating an environment where all voices are heard, respected, and valued. We are dedicated to providing equal employment opportunities to all employees and applicants, and we prohibit discrimination and harassment of any kind based on race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws. Beyond compliance, we strive to create a supportive and growth-oriented workplace for everyone. If you share our passion and connection to this mission, we welcome you to apply and join us in building a vibrant and inclusive team at TP-Link Systems Inc.
Please, no third-party agency inquiries, and we are unable to offer visa sponsorships at this time.
Information Systems Security Officer
Cyber security analyst job in Camp Pendleton South, CA
General information Requisition # R64222 Posting Date 11/14/2025 Security Clearance Required TS/SCI Remote Type Onsite Time Type Full time Description & Requirements Shape the future of defense with MANTECH! Join a team dedicated to safeguarding our nation through advanced tech and innovative solutions. Since 1968, we've been a trusted partner to the Department of Defense, delivering cutting-edge projects that make a real impact. Dive into exciting opportunities in Cybersecurity, IT, Data Analytics and more. Propel your career forward and be part of something extraordinary. Your journey starts now-protect and innovate with MANTECH!
MANTECH seeks a motivated, career and customer-oriented Information Systems Security Officer with strengths in Information Systems Security to join our team at Marine Corps Base Camp Pendleton California.
This position will assist Marine Corps Warfighting Laboratory (MCWL) prepare for and maintain the IT infrastructure, IT capabilities and Audio-Visual capabilities to support emerging ICD 705 Sensitive Compartmentalized Information Facilities (SCIFs) and Special Access Control Facilities (SAPFs) through planning, activation and operations.
Responsibilities include but are not limited to:
* Experience in network design, network monitoring, systems development, and knowledge of Information Assurance (IA) policies, directives, and best practices across DoD and Marine Corps.
* Knowledge and experience with organizations within the Marine Corps responsible for facilitating network approvals and connections.
* Work with various Marine Corps, Navy, Joint, and other services to coordinate installs supporting Initial Operating Capability (IOC) and Final Operating Capability (FOC).
* Ability to communicate and provide effective staff coordination across government, Marine Corps, and contractor organizations.
* Support the facility Site Security Manager (SSM)/Special Security Representative (SSR) and Information Systems Security Manager (ISSM) to oversee the secure installations and operations of systems across multiple security domains and in accordance with policies, directives, and best practices.
* Establishes and satisfies complex system-wide information security requirements based upon the analysis of user, policy, regulatory, and resource demands. Supports Marine Corps and other customers at the highest levels in the development and implementation of doctrine and policies.
Minimum Qualifications:
* Bachelor's degree and at least 10 years' experience planning and/or operating IT infrastructure within ICD 705 facilities.
* Experience with network security aspects of installations and operations.
Preferred Qualifications:
* Experience with MS Word, MS Power Point
Clearance Requirements:
* Candidate must have a current/active Top Secret clearance with the ability to obtain and maintain a TS/SCI clearance prior to starting this position.
Physical Requirements:
* Ability to maintain construction security oversight in outdoor environment; walk (with personal protective equipment) to inspect and document delivery of components and assembly/construction of structure.
The projected compensation range for this position is $112,400.00-$186,500.00. There are differentiating factors that can impact a final salary/hourly rate, including, but not limited to, Contract Wage Determination, relevant work experience, skills and competencies that align to the specified role, geographic location (For Remote Opportunities), education and certifications as well as Federal Government Contract Labor categories. In addition, MANTECH invests in its employees beyond just compensation. MANTECH's benefits offerings include, dependent upon position, Health Insurance, Life Insurance, Paid Time Off, Holiday Pay, short-term and long-term Disability, Retirement and Savings, Learning and Development opportunities, wellness programs as well as other optional benefit elections.
MANTECH International Corporation considers all qualified applicants for employment without regard to disability or veteran status or any other status protected under any federal, state, or local law or regulation.
If you need a reasonable accommodation to apply for a position with MANTECH, please email us at ******************* and provide your name and contact information.
Auto-ApplyInformation System Security Officer (ISSO)
Cyber security analyst job in Camp Pendleton South, CA
Auria is looking to hire an Information System Security Officer (ISSO). This role is ONSITE in Camp Pendleton, CA. This position is currently contingent. The Marine Corps Tactical Systems Support Activity (MCTSSA) provides 24/7 global technical support for Command, Control, Communications, Computers, Cyber, and Intelligence, Surveillance, and Reconnaissance (C5ISR) systems; and conducts engineering, testing and evaluation, and supports experimentation on C5I systems and amphibious platforms to inform acquisition decisions and make the Fleet Marine Force (FMF) more capable.
This contract will provide Data Management and Cybersecurity services to support the command's mission of Testing, Engineering, Integration, and Sustainment of the Marine Corps C5ISR Programs of Record.
WHAT YOU CAN EXPECT TO DO:
* Determine client security control requirements.
* Implement security controls in Marine Corps Compliance and Authorization Support Tool (MCCAST).
* Conduct annual review of each MCCAST record's security controls (via testing, examining, or interviewing).
* Prepare, distribute, and maintain plans, instructions, guidance, and SOP's concerning the security of network system(s) operations.
* Approve/disapprove System Authorization Access Requests (SAARs), verify training requirements are met, and perform retention of records.
* Participate in Removable Media Whitelisting Program (required to obtain and maintain Remedy account).
* Monitor and evaluate the effectiveness of the enterprise's cybersecurity safeguards to ensure that they provide the intended level of protection.
* Participate in the information security training and awareness program.
* Participate in an information security risk assessment during the Security Assessment and Authorization process.
* Identify security requirements specific to an information technology (IT) system in all phases of the system life cycle.
WHAT THE TEAM REQUIRES:
* Completion of a CNSSI 4014 - Information Systems Security Officers (ISSO) qualified course or equivalent
* CompTIA Security+ Certification
* Experience with Marine Corps Information Security programs, authorization procedures and requirements as well as interacting with higher military headquarter elements.
* Active Security Clearance - Secret
WHAT THE TEAM PREFERS:
* Certified Authorization Professional (CAP) Certification
* GIAC Security Leadership Certification (GSLC)
* Completion of CID M09BNJ1 Cybersecurity Technician course
* Completion of CID N23CUW1 Joint Cyber Analysis course
* Bachelor's Degree in Information Technology or Cybersecurity related field
* Completion of CNSSI 4012-Senior Systems Managers qualified course
* Completion of CNSSI 4013-System Administrators qualified course
* Completion of CNSSI 4015-Systems Certifiers qualified course
* Completion of CNSSI 4016-Risk Analysts qualified course
* NDU CISO certificate - Chief Information Security Officer (CISO).
PAY TRANSPARENCY: The salary offered will be based on the selected candidate's qualifications - skills, education & experience - and the position level. $130,000 - $150,000
APPLICATION DEADLINE: The deadline to apply to this role is November 27, 2025.
THE AURIA TEAM:
Auria is a provider of solutions and software in support of complex Space, National Security, and Cyber missions of federal, international, and commercial customers. Headquartered in Colorado Springs, CO our success is built on the excellence of diverse teams advancing innovative systems and operational software to strengthen our customers' missions. With a distinguished track record and a spirit of relentless pursuit, and R&D, we set the pace for progress and execute every mission with the utmost precision.
As a full-time Auria employee, here are some of the many benefits to enjoy:
* Generous PTO package with yearly tenure increases
* Flex time provides you with the flexibility needed
* 11 Company-Paid Holidays & Float days per year
* Up to 4% match on 401(k) employee contributions, employer and employee contributions immediately vested
* Up to $5,250 per year on Education and Training Assistance
* Low-cost medical plans that include company-sponsored HSA
* No-cost life insurance
* Employee Assistance Program (EAP)
* And much more!
Auria is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action-Employer, making decisions without regard to race, color, religion, sex, sexual orientation, gender identity, genetic information, marital status, national origin, age, veteran status, disability, or any other protected class.
Pay Range: $130,000 - $150,000 per year
Sr Information Security Compliance and Audit Analyst
Cyber security analyst job in Irvine, CA
Accelerate your career. Join the organization that's driving the world's technology and shape the future.
Ingram Micro is a leading technology company for the global information technology ecosystem. With the ability to reach nearly 90% of the global population, we play a vital role in the worldwide IT sales channel, bringing products and services from technology manufacturers and cloud providers to business-to-business technology experts. Our market reach, diverse solutions and services portfolio, and digital platform Ingram Micro Xvantage™ set us apart. Learn more at *******************
Come join our team where you'll make technology happen in surprising ways. Let's shape tomorrow - it'll be a fun journey!
We have the flexibility of hiring this role in 3 markets: Irvine-CA, Dallas/Fort Worth-TX and Carol Stream, IL. The role has the opportunity to work up to two days remote per week.
The Sr Information Security Compliance & Audit Analyst will report to our Sr Manager of Quality and will be part of the OpEx compliance team. The Analyst will support global activities as they relate to ISO27001, ISO9001 and ISO14001. You will be responsible for providing subject matter expertise in ISO27001 Information Security regarding compliance requirements. In addition, implementing, maintaining and improving the Information Security Management System at a corporate level for Ingram Micro facilities across North and Central America.
The Information Security Compliance & Audit Analyst will perform and lead complex compliance reviews, within the IT audits including network, internet, applications, telecommunications, security administration, and contingency planning. Assess risks, develops detail audit/compliance programs, execute audit/compliance programs steps, analyses result and effectively communicates results to senior management.
Your role:
Manage and Support IT compliance activities for regional information security support of ISO27001 auditing, reporting and remediation where appropriate.
Coordinate and communicate IT compliance activities to align with Global Information Security leadership in support and improvement of ISO27001 management system.
Ensure regional Information Security compliance to Information security standards (ISO27001) requirements
Plan and conduct complex IS and integrated audit/compliance projects, including preparation of an objective risk-based assessment and an effective audit/compliance approach.
Leads and/or participates on audit/compliance activities of various locations and departments for compliance with plans, policies and procedures.
Execute operational activities to support IS audit and compliance activities including technical validation processes.
Execute collection of evidence to support compliance status
Provide and present reporting including monthly metric delivery
Manage escalation and enforcement for unresolved noncompliance issues
Manage and Support External Audit activities and reporting
Work with Information Security staff to ensure tools and reporting mechanisms are satisfactorily meeting statutory objectives
Support compliance and security validation of all 3rd party IT providers
Maintain strong working relationships with internal and external support teams including Global, Regional and Country Information Security associates
Work on special projects as required by management
Stay abreast of changes within the Information Security compliance areas including business change requirements and regulatory changes from an international perspective
Support and enforce Information Security Policy, Standards, and Guidelines for business operations and technology implementations
Work as the Subject Matter Expert (SME) on assigned projects and offers council regarding the intent of Compliance requirements
What you bring to the role:
Bachelor's degree in computer science, engineering, or related science and math discipline with an information security or business emphasis is required.
A minimum of 5 years of experience with IS compliance projects (specifically ISO27001)
Understands key security concepts such as access management, vulnerability and patch management, security information event management, and encryption
Strong understanding of TCP/ IP and other network protocols
Understanding of the basic audit best practices, standards and methodologies
Ability to formulate detailed technical documentation preferred
ASQ Certified Engineer, Auditor or OE Managers preferred
Experience using SharePoint, MS Excel, Word, PowerPoint and Visio
Must possess a valid passport and be legally allowed to leave and return to originating country.
Attributes we look for:
The ability to work independently and in cross functional teams
Actively looks for opportunities to develop new ideas to positively impact existing methods, services, or products.
Understands, analyzes, and documents cost/benefit analysis where appropriate.
Actively accepts individual and team responsibilities and meet commitments. Takes responsibility for own performance and actions and demonstrates responsibility and teamwork towards overall team/department goals.
Ability to multi-task and work on projects concurrently and under tight deadlines
Must be detail oriented and customer focused with excellent time management skills
Takes and exhibits initiative to further develop technical and professional skills, by attending training and/or willingness to learn new systems or technologies in use by the Information Systems department.
Possesses understanding of Ingram Micro's business including knowledge of department names and business processes conducted by each, company global organization, and key customer and vendor segments.
Behavorial Competencies:
Communication
Excellent verbal, written and inter-personal communication skills
Strong communication skills; capable of explaining technical issues simply both verbally and in writing
Keeps his/her manager informed of any problems, challenges, or unanticipated events affecting his/her work.
Listens respectfully and avoids interrupting.
Expresses ideas and suggestions in an organized and concise manner both orally and in written form.
Solicits and readily accepts constructive feedback.
Maintains composure when addressing an adversarial or hostile audience.
Decision Making
Researches and collects appropriate data points for effective decision making.
Readily makes recommendations and includes necessary documentation and material to support conclusions.
Develops Innovative Practices
Identify, develop and manage innovative ideas and solutions to problems.
Identify opportunities to reduce inefficiencies in work processes.
Recognizes when it is appropriate to challenge the status quo and when it is not.
Works as a Team Member
Supports team decisions to implement changes, suggestions, improvements, and solutions.
Encourages and supports the exploration and application of best practices.
Offers assistance to others and shares information regardless of personal likes or dislikes.
Acts with Integrity & Respect
Prevents personal conflicts from interfering with his/her objectivity.
Consistently arrives on time for meetings and appointments.
Accepts responsibility for the results of his/her decisions and actions.
Behaves in a way that is consistent with Ingram Micro's values.
#LI-Hybrid
#LI-AH1
The typical base pay range for this role across the U.S. is USD $93,000.00 - $158,100.00 per year.
The ranges above reflect the potential annual base pay across the U.S. for all roles; the applicable base pay range will depend on the candidate's primary work location, pay grade, and variable compensation plan. Individual base pay within each range depends on various factors, in addition to primary work location, such as complexity and responsibility of role, job duties/requirements, and relevant experience and skills. Base pay ranges are reviewed and typically updated each year. Offers are made within the base pay range applicable at the time of hire. New hires starting base pay generally falls in the bottom half (between the minimum and midpoint) of a pay range.
At Ingram Micro certain roles are eligible for additional rewards, including merit increases, annual bonus or sales incentives and long-term incentives. These awards are allocated based on position level and individual performance. U.S.-based employees have access to healthcare benefits, paid time off, parental leave, a 401(k) plan and company match, short-term and long-term disability coverage, basic life insurance, and wellbeing benefits, among others.
This is not a complete listing of the job duties. It's a representation of the things you will be doing, and you may not perform all these duties.
Please be prepared to pass a drug test and successfully pass a pre-employment (post offer) background check.
Ingram Micro Inc. is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, veteran status, or any other protected category under applicable law.
Auto-ApplyInformation Security Analyst 1 (On-site Rancho Cucamonga, CA)
Cyber security analyst job in Rancho Cucamonga, CA
Are you passionate about administrating and enforcing solutions that safeguard data? Are your interested in serving your fellow team and the community? If so, we want to talk to you - we are currently looking for Service Superstars to join our Team!
An Information Security Analyst 1 takes a lead role in the research, design, and implementation of all information security related hardware or software; including operating systems and communications products, coordinating implementations with third party vendors and supporting representatives as needed. This role also serves as a liaison between vendors and other departments on information security related projects.
Duties and Essential Functions:
Service
Personally, provides exceptional member service; uses Service Standards in every work-related interaction.
Ensures that
exceptional
member service is being provided to members and team members, at all times.
Serves as a strong example of leadership in work ethic, professionalism, and conduct.
Promotes a harmonious work environment that motivates others towards team participation, goal setting/accomplishment, and personal development.
Daily Operations
Assists in the management of multiple information security systems, ensuring proper integration of the components with computer systems, network equipment and other devices.
Assists in research of data security needs and requirements for current and future systems.
Performs regular vulnerability analysis for intentional and unintentional systems misuse and identifies appropriate counter measures.
Takes a supporting role in the management of the Credit Union's information security program including establishing, implementing and monitoring of information security, incident response procedures and policies, system configuration standards and ongoing risk assessments.
Assists the credit union management team with the creation, modification, and implementation of Information Security policies and standards.
Performs routine audits of security databases including Active Directory, Anti-Virus, Data Loss Prevention (DLP), Group Policy, Remote Authentication Dial-In User Service (RADIUS), and regularly reviews other security logging systems. Designs and/or implements changes to these systems in response to any discovered vulnerabilities.
Performs regular audits of credit union procedures including new hire/transfer/separation process, configuration checklists, firewall changes, Uniform Resource Locator (URL)/Spam filter changes, DLP changes, file permission changes, inventory changes, equipment changes, and system health checks.
Takes a supporting role in the management of Credit Union patch management, anti-virus, Spam filtering, DLP, URL filtering, and intrusion prevention systems.
Assists with the development and implementation of active directory group policy objects with an emphasis on enhancing computer systems security.
Manages the creation, deletion, or alteration of systems access for Credit Union team members. Makes key decisions on whether to honor system access requests and responds appropriately.
Takes a supporting role in the research, design, and implementation of all information security related hardware or software including operating systems and communications products; assists with coordination of implementations with third party vendors and supports representatives as needed; serves as a liaison between vendors and other departments on information security related projects.
Conducts various training and instruction programs for credit union team members on the secure use of e-mail and the internet as well as operating systems, networking, computer applications and databases.
Assists in the evaluation of new projects and proposes systems for security risks and makes recommendations for implementation to management.
Takes supporting role in analyzing, planning and implementing projects including software, in-house development, hardware, and networks to provide new products and services to members of the credit union and to improve the effectiveness of member data security. Performs capacity planning and tuning of information security systems to assure maximum availability and optimal utilization; directs/assists with hardware and software upgrades as needed.
Develops project scope and timeline documents for individual projects per Information Systems (IS) Department standards.
Stays current with evolving trends in information security related hardware, applications, development, and the internet.
Provides guidance and assistance on technical skills to other IS staff.
Provides regular documentation and reports on the progress of information security initiatives as well as provides suggestions or plans to further improve the credit union's security efforts.
Other duties as deemed necessary and assigned by Supervisor to achieve the goals of the department and the Credit Union.
Benefits Include:
(not a complete list)
Wellbeing
Weekly pay
401K Retirement Savings Plan with company match
Paid time off accrual begins upon hire, 15 paid vacation days, 11 paid holidays
Paid sick leave
Company-provided life insurance at twice your annual salary
Financial Education Programs
DoorDash DashPass
Health
Medical, Dental, and Vision Insurance for part-time and full-time employees
Modern Health
Care.com subscription
Teladoc
Career Development
Career development opportunities
Team members are eligible to apply for assistance with educational expenses through ArrowHeart's scholarship program.
To learn more about Arrowhead Credit Union and our service culture, visit our Career page, and our ArrowHeart Foundation.
The pay range for this position is listed below.
Starting pay for successful applicants is
generally within the minimum to midpoint of the pay range. Our consideration for pay is designed to support career growth and development over time. Offers extended depend on a variety of job-related factors, including but not limited to individual experience, knowledge, training, education, geographic location, market demands, and internal equity.
Pay range:
Minimum: $35.11/hourly
| Midpoint: $43.89/hourly | Maximum: $52.67/hourly
Senior Security Engineer
Cyber security analyst job in Irvine, CA
GoodLeap is a technology company delivering best-in-class financing and software products for sustainable solutions, from solar panels and batteries to energy-efficient HVAC, heat pumps, roofing, windows, and more. Over 1 million homeowners have benefited from our simple, fast, and frictionless technology that makes the adoption of these products more affordable, accessible, and easier to understand. Thousands of professionals deploying home efficiency and solar solutions rely on GoodLeap's proprietary, AI-powered applications and developer tools to drive more transparent customer communication, deeper business intelligence, and streamlined payment and operations. Our platform has led to more than $30 billion in financing for sustainable solutions since 2018.
GoodLeap is also proud to support our award-winning nonprofit, GivePower, which is building and deploying life-saving water and clean electricity systems, changing the lives of more than 1.6 million people across Africa, Asia, and South America.
Position Summary
The GoodLeap security team is responsible for both business enablement and safeguarding the organization's information assets; it is involved in virtually all aspects of the business, from product safety and resilience, to building security paved roads, customer, partner, and regulatory trust, managing technology governance and compliance, and ensuring the privacy, and safety of GoodLeap's customers, partners, and employees information.
The senior security engineer role provides a unique opportunity to shape the security and resilience of GoodLeap corporate systems, services, and operational processes. In this role, you will work closely with product, engineering, IT, and business teams within GoodLeap, acting as the key individual with both the authority and responsibility to ensure the safety and resilience of enterprise systems, products, and services.
Your oversight will encompass:
* Enterprise systems:Identifying potential misuse and abuse cases, proposing solutions to address these scenarios, and identifying product features, configuration settings, and/or mitigating or compensating controls to meet resilience requirements.
* Build-time controls: Managing applications/products security controls and activities during development.
* Runtime controls: Overseeing security measures at runtime, from prevention to detection and response.
Additionally, you will be involved with aspects of internally built products and represent all areas of security, spanning governance, risk, and compliance (GRC) to security monitoring, for a number of departments/teams. You will also have the authority and ability to involve other security team members as needed.
While you will take on multiple responsibilities-from advisor to builder and beyond-your primary focus will be designing and building security patterns and practices for services and processes, and fostering strong relationships with product, business, and engineering.
Essential Job Duties & Responsibilities
* Lead, participate in, and contribute to partnerships between security, IT, General & Administrative teams, engineering, product, and operations teams to build, orchestrate, and automate security controls and services in GoodLeap enterprise systems, products, services, and operational processes.
* Identify potential misuse and abuse cases in enterprise systems, propose solutions to address these scenarios, and identify product features, configuration settings, and/or mitigating or compensating controls to meet resilience requirements.
* Support or develop components of the security analytics platform.
* Contribute to investigations, threat hunting, and incident response activities in a supporting role.
* Collaborate with the monitoring and response team to create playbooks for specific incident response scenarios related to the products and services you oversee. These investigations, incidents, and playbooks may address security, fraud, privacy, resilience, and related concerns.
* Support the security operations team with the vulnerability management lifecycle for products and services under your purview.
* Ensure technical alignment for the products and services you oversee with team initiatives, including GRC, security operations, and monitoring and response activities.
Required Skills, Knowledge & Abilities
* Strong communicator with the ability to lead technical architecture discussions, drive technical decisions, and effectively communicate with non-technical audiences.
* Expertise in agile product lifecycles. Ideally, you have experience in a product manager or engineering manager role and understand how SaaS products (B2B, B2B2C, and B2C) are built, including roadmap planning and feature and defect prioritization.
* Experience with threat modeling methodologies, with the ability to create efficient and scalable approaches to conducting such assessments.
* Familiarity with AWS services, including KMS, SST, Container Registry, ELBs, Lambda, API Gateway, CloudTrail, and IAM (knowledge of GCP and/or Azure is a plus).
* Proven ability to establish credibility and build trust with business, engineers, and operational staff; confident yet humble.
* Hands-on experience with managing security for core enterprise systems, e.g., ERP, HCM, Salesforce, etc.
* Strong understanding of both human and non-human identity management and common enterprise and consumer authentication standards and use cases.
* Practical experience with CI/CD pipelines and DevOps tools, including Infrastructure-as-Code (IaC) tools like Terraform, Pulumi, or CDK; GitHub and GitHub Actions; artifact management; and secrets management tools like Doppler and HashiCorp Vault.
* Passionate about learning new technologies. While you're not expected to know everything, you should demonstrate a willingness and ability to learn as needed.
* Prior experience interfacing and supporting with G&A teams, internal product teams, and other cross-functional areas.
* Proficiency in writing automation scripts in multiple languages, with prior experience automating security processes in cloud or SaaS environments.
* Experience engaging with vendors in design partnerships.
* Experience overseeing vulnerability and threat management at the platform and application levels.
* Familiarity with penetration testing and red team exercises, including manual verification, exploitation, and lateral movement.
* Ability to balance a high-level view of security strategy with attention to detail, ensuring thorough and effective execution.
$146,000 - $170,000 a year
In addition to the above salary, this role may be eligible for a bonus.
Additional Information Regarding Job Duties and s:
Job duties include additional responsibilities as assigned by one's supervisor or other managers related to the position/department. This job description is meant to describe the general nature and level of work being performed; it is not intended to be construed as an exhaustive list of all responsibilities, duties and other skills required for the position. The Company reserves the right at any time with or without notice to alter or change job responsibilities, reassign or transfer job position or assign additional job responsibilities, subject to applicable law. The Company shall provide reasonable accommodations of known disabilities to enable a qualified applicant or employee to apply for employment, perform the essential functions of the job, or enjoy the benefits and privileges of employment as required by the law.
If you are an extraordinary professional who thrives in a collaborative work culture and values a rewarding career, then we want to work with you! Apply today!
We are committed to protecting your privacy. To learn more about how we collect, use, and safeguard your personal information during the application process, please review our Employment Privacy Policy and Recruiting Policy on AI.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Senior Security Firmware Engineer
Cyber security analyst job in Irvine, CA
Sandisk understands how people and businesses consume data and we relentlessly innovate to deliver solutions that enable today's needs and tomorrow's next big ideas. With a rich history of groundbreaking innovations in Flash and advanced memory technologies, our solutions have become the beating heart of the digital world we're living in and that we have the power to shape.
Sandisk meets people and businesses at the intersection of their aspirations and the moment, enabling them to keep moving and pushing possibility forward. We do this through the balance of our powerhouse manufacturing capabilities and our industry-leading portfolio of products that are recognized globally for innovation, performance and quality.
Sandisk has two facilities recognized by the World Economic Forum as part of the Global Lighthouse Network for advanced 4IR innovations. These facilities were also recognized as Sustainability Lighthouses for breakthroughs in efficient operations. With our global reach, we ensure the global supply chain has access to the Flash memory it needs to keep our world moving forward.
Job Description
ESSENTIAL DUTIES AND RESPONSIBILITIES:
Development of various cryptography-based security features such as data encryption, Secure Boot, and Device Attestation.
Integrate these security protocols and features into the SSD data and control flows to ensure a robust and secure system. Additionally, investigate and resolve any security protocol compatibility issues that may arise.
Investigating failures, documenting bug reports, and providing valuable assistance to product teams in identifying and resolving issues.
Debugging, optimizing, and validating the Firmware on SoC platforms, as well as bringing up of FPGA and ASIC.
Contribute to the Security Development Lifecycle of the Firmware by supporting its development at different stages, including design, threat analysis, implementation, validation, vulnerability testing, certification, and audit.
Qualifications
REQUIRED:
To qualify for this position, an ideal candidate would have/be.
A degree in Computer Science, Electrical/Computer Engineering, Software Engineering, or a related field.
3+ years of experience in embedded programming, with proficiency in C/C++ and one or more of the following: Python, Rust, Go.
Strong understanding of microcontroller architectures and debugging of hardware/firmware issues.
Experience in firmware code review, CI/CD test and validation methodology, as well as static and dynamic code analysis. Familiarity with the Agile software development process life cycle is also desired.
Proficiency in failure analysis in debugging an embedded firmware application, using JTAG/debuggers such as Lauterbach.
An engineer who can take ownership of given features and manage them from start to finish. Being self-motivated and driven is essential for this role.
Good communication skills and be able to work effectively with cross-functional teams.
What Sets You Apart
Detailed knowledge of RISC-V Instruction Set Architectures (ISA)
Technical expertise in applied cryptography and firmware/hardware security, including knowledge of data encryption, trusted execution environment, secure boot, and device attestation.
Knowledge of storage controller architectures and security protocols, such as TCG Opal/Ruby/Pyrite, IEEE 1667, SPDM, and IDE.
Develop firmware on SoC platforms, run simulation or bringing up FPGA and ASIC.
Familiarity with writing code in Github repository and it's CI/CD testing framework.
Additional Information
Sandisk is committed to providing equal opportunities to all applicants and employees and will not discriminate against any applicant or employee based on their race, color, ancestry, religion (including religious dress and grooming standards), sex (including pregnancy, childbirth or related medical conditions, breastfeeding or related medical conditions), gender (including a person's gender identity, gender expression, and gender-related appearance and behavior, whether or not stereotypically associated with the person's assigned sex at birth), age, national origin, sexual orientation, medical condition, marital status (including domestic partnership status), physical disability, mental disability, medical condition, genetic information, protected medical and family care leave, Civil Air Patrol status, military and veteran status, or other legally protected characteristics. We also prohibit harassment of any individual on any of the characteristics listed above. Our non-discrimination policy applies to all aspects of employment. We comply with the laws and regulations set forth in the "Know Your Rights: Workplace Discrimination is Illegal” poster. Our pay transparency policy is available here.
Sandisk thrives on the power and potential of diversity. As a global company, we believe the most effective way to embrace the diversity of our customers and communities is to mirror it from within. We believe the fusion of various perspectives results in the best outcomes for our employees, our company, our customers, and the world around us. We are committed to an inclusive environment where every individual can thrive through a sense of belonging, respect and contribution.
Sandisk is committed to offering opportunities to applicants with disabilities and ensuring all candidates can successfully navigate our careers website and our hiring process. Please contact us at jobs.accommodations@sandisk.com to advise us of your accommodation request. In your email, please include a description of the specific accommodation you are requesting as well as the job title and requisition number of the position for which you are applying.
Based on our experience, we anticipate that the application deadline will be 03/15/2026 (3 months from posting), although we reserve the right to close the application process sooner if we hire an applicant for this position before the application deadline. If we are not able to hire someone from this role before the application deadline, we will update this posting with a new anticipated application deadline.
#LI-RT1
Compensation & Benefits Details
An employee's pay position within the salary range may be based on several factors including but not limited to (1) relevant education; qualifications; certifications; and experience; (2) skills, ability, knowledge of the job; (3) performance, contribution and results; (4) geographic location; (5) shift; (6) internal and external equity; and (7) business and organizational needs.
The salary range is what we believe to be the range of possible compensation for this role at the time of this posting. We may ultimately pay more or less than the posted range and this range is only applicable for jobs to be performed in California, Colorado, New York or remote jobs that can be performed in California, Colorado and New York. This range may be modified in the future.
You will be eligible to participate in Sandisk's Short-Term Incentive (STI) Plan, which provides incentive awards based on Company and individual performance. Depending on your role and your performance, you may be eligible to participate in our annual Long-Term Incentive (LTI) program, which consists of restricted stock units (RSUs) or cash equivalents, pursuant to the terms of the LTI plan. Please note that not all roles are eligible to participate in the LTI program, and not all roles are eligible for equity under the LTI plan. RSU awards are also available to eligible new hires, subject to Sandisk's Standard Terms and Conditions for Restricted Stock Unit Awards.
We offer a comprehensive package of benefits including paid vacation time; paid sick leave; medical/dental/vision insurance; life, accident and disability insurance; tax-advantaged flexible spending and health savings accounts; employee assistance program; other voluntary benefit programs such as supplemental life and AD&D, legal plan, pet insurance, critical illness, accident and hospital indemnity; tuition reimbursement; transit; the Applause Program, employee stock purchase plan, and the Sandisk's Savings 401(k) Plan.
Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, benefits, or any other form of compensation and benefits that are allocable to a particular employee remains in the Company's sole discretion unless and until paid and may be modified at the Company's sole discretion, consistent with the law.
Information Security Engineer
Cyber security analyst job in Temecula, CA
It's fun to work in a company where people truly BELIEVE in what they're doing!
We're committed to bringing passion and customer focus to the business.
The Information Security Engineer is responsible for contributing to the corporate Information Security program by assisting in the identification, recommendation and implementation of industry leading application security tools and techniques. The incumbent will also maintain and update application security processes and procedures and train team members on any relevant updates.
This position is remote, but local to the Temecula, CA office.
Essential Functions
Assist with the development, implementation, and administration of information security policies, standards, and procedures, adhering to industry best practices
Assist in integrating regulatory compliance requirements (e.g., PCI, GLBA) into the organizational security roadmap
Assist in ensuring that the corporate IT environment is secure and complies with all external audit requirements and federal standards
Coordinate with IT Operations to ensure endpoints and network devices conform to security standards, and that security devices and controls are working as designed
Assist in the identification, evaluation and implementation of industry leading application security tools and techniques
Plan, coordinate, and implement security measures to regulate access to computer data files and prevent unauthorized modification, destruction, or disclosure of information
Perform risk assessments and execute system tests to ensure proper functioning of data processing activities and security measures
Identify potential security risks, and define and document remediation options or mitigating controls
Perform security incident investigations including: chain of custody, containment measures, root cause analysis, and identification of preventive measures
Define and assist in the management of an Incident Response Team that addresses potential or in-progress security events, establishing and adhering to escalation procedures and response times
Perform information systems evidence gathering, to support e-discovery requests and messaging searches
Perform security reviews on requests for new commercial software or material configuration changes to existing software
Perform periodic internal IT security audit functions on IT operational controls, to include system access controls, firewall rule reviews, etc.
Participate in on-call rotation
Perform related duties as requested
Essential Knowledge, Skills, & Abilities
Excellent written and verbal communication skills required
Solid presentation skills
Significant knowledge of security-oriented regulatory requirements and compliance
Excellent familiarity with IT security principles and practices including firewalling, hardening, data loss prevention, threat prevention, and identity management.
Ability to provide technical guidance to less experienced team members
Knowledge of the mortgage industry is helpful, but not required
Commitment and ability to cultivate a diverse and inclusive work environment.
Education
Bachelor's degree in computer science, Engineering, Information Systems Security or a related field is required.
Security class certifications strongly preferred
Azure certifications preferred
CISSP license preferred
Experience
5+ years of related IT experience required
2+ years in an Information Security engineering role
3+ years of experience in a regulated IT environment including some combination of SOX, HIPAA, GLBA, PCI preferred
Compensation and Benefits
Covius offers an extensive benefits package for all employees, including medical, dental, vision and 401(k)!
Compensation: $96,000 to $120,000 annually with a 10% AIP opportunity
Application Guidelines:
For best consideration, please submit your resume and application materials as soon as possible. Review of applications will begin immediately.
Working Conditions
Work is performed in a climate controlled indoor administrative office setting. The noise level in the work environment is usually quiet to moderate, depending upon the office or meeting location.
Physical Demands and Activities
While performing the duties of this job, the employee is frequently required to communicate. The employee frequently is required to remain stationary. The employee is frequently required to move about the office, operate a computer and other office machinery, such as calculator, copy machine, and computer printer; rarely position self to maintain files; rarely moves boxes weighing up to 10 lbs. Close and distance observation required with the ability to observe objects at close range in presence of glare or bright lighting (e.g., computer screen). Must possess the ability to communicate information and ideas so others will understand and have the ability to interact with external and internal stakeholders.
Covius is committed to equal opportunity in all employment practices to all qualified applicants and employees without regard to race, color, religion, gender, gender identity, age, national origin, pregnancy, disability, genetics, marital status, military or veteran status or any other protected category as established by local, state, and federal law. This policy applies to all aspects of the employment relationship including recruitment and hiring, placement, promotion, transfer, compensation, disciplinary action, layoff, leaves of absence, training, and termination. All such employment decisions will be made without unlawful discrimination based on any prohibited basis.
The essential functions, working conditions and physical demands described above are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of this position.
Please note that all s are not intended to be all-inclusive. This job description is not designed to cover all activities, duties or responsibilities that are required of the employee for this job. Employees may be required to perform other duties at any time with or without notice to meet the ongoing needs of the organization.
If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us!
Auto-ApplySecurity Engineer
Cyber security analyst job in Irvine, CA
Momenti is a dynamic and immersive content company that revolutionizestraditional media by bringing visceral experiences to all forms of content. Wespecialize in interactive video that breaks the 4th wall, creating deeperconnections and emotions with our audience. Join us in transforming the waypeople engage with content and bring moments to life. Momenti is at theforefront of the content revolution, and we want you to be part of it.
Job Summary:We are seeking a talented and experienced Security Engineer to join Momentias our first security hire and report directly to our Engineering Director. In thisrole, you will be responsible for ensuring the security and integrity of oursystems, applications, and data. You will work closely with cross-functionalteams to identify potential vulnerabilities, develop and implement securitymeasures, and provide ongoing support to maintain a secure environment. Thisis a unique opportunity to make a significant impact and shape the securitylandscape at Momenti.
Key Responsibilities:• Develop and implement effective security strategies, policies, and proceduresto protect Momenti's systems, applications, and data.• Conduct regular security assessments, vulnerability testing, and risk analysisto identify and address potential security weaknesses.• Collaborate with software engineers and other stakeholders to design andimplement secure coding practices and ensure secure applicationdevelopment.• Monitor and respond to security incidents, including investigating andresolving security breaches, intrusions, and unauthorized access attempts.• Stay up-to-date with the latest security technologies, trends, and bestpractices, and provide recommendations for enhancements to our securityposture.• Educate and train employees on security awareness and best practices topromote a culture of security throughout the organization.Preferred Qualifications:• Solid experience in a security engineering or related role, with a focus onapplication and system security.• Strong understanding of web application security, network security principles,and secure coding practices.• Familiarity with security frameworks such as OWASP, NIST, and CISbenchmarks.• Knowledge of cloud security principles and experience securing cloud-basedenvironments (e.g., GCP, AWS, Azure).• Experience with security assessment tools and techniques, such asvulnerability scanners, penetration testing, and log analysis.Basic Qualifications:• Proven experience in implementing and managing security controls in aproduction environment.• Familiarity with compliance standards and regulations (e.g., GDPR, HIPAA,PCI DSS).• Strong problem-solving and analytical skills, with the ability to assess risksand develop effective mitigation strategies.• Excellent communication and collaboration skills, with the ability to workeffectively in cross-functional teams.
Auto-ApplyIT Security Engineer -Bilingual (Korean/English)
Cyber security analyst job in Irvine, CA
For More Open Positions Visit us at:
**********************************
Our Mission WOONGJIN, Inc. is a rapidly growing team who provides a range of unique, exceptional, and enhanced services to our clients. We have a strong moral code that includes the service of goodness without expectations of reward. We are motivated by the sense of responsibility and servant leadership.
Benefits
Medical Insurance
Vision Insurance
Dental Insurance
401(k)
Paid Sick hours
Job Description
The IT Security Engineer is responsible for supporting the planning, implementation, and management of the organization's IT security infrastructure and policies. This role assists in identifying security risks, responding to incidents, and ensuring compliance with internal standards and external regulations.
Responsibilities
Assist in developing, implementing, and maintaining IT security policies, standards, and procedures
Monitor and analyze security events, logs, and alerts using tools like Splunk of Sentinel to detect and respond to threats
Collaborate with internal IT teams and external vendors to improve overall security posture
Manage user access controls and identity management systems
Monitor and audit for potential security breaches, abnormal behavior, and unauthorized access
Verify that applied security policies are properly configured and effectively enforced
Monitor network, system, and application security to detect and respond to potential threats and vulnerabilities
Participate in incident response processes, including investigation, containment, recovery, and documentation
Assist in audits and ensure compliance with regulatory requirements
Support security awareness training and compliance initiatives for employees and third parties
Maintain up-to-date knowledge of cybersecurity trends, threats, and best practices
Document security configurations, procedures, and technical findings
Conduct vulnerability assessments
Salary: $80,000 - $95,000 per year (D.O.E)
Qualifications
Skills
3 - 5 years of experience in IT security or related IT roles required
Knowledge of security technologies such as firewalls, IDS/IPS, antivirus, SIEM, and endpoint protection required
Security certifications preferred (e.g., CISSP, CISM, CompTIA Security+, CEH) preferred
Strong problem-solving, analytical, and communication skills required
Education & Experience
Bachelors Degree Required
Computer Science, Information Security, or a related field required
6 - 9 Years of Direct Experience Required
7 - 11 Years of Direct Experience Required
1 - 3 Years of Supervisory Experience Required
3-5 years of experience in IT Security or related IT roles required
Physical Requirements
Ability to sit in front of a desk and/or in front of the computer for long periods
Repetitive use of hand/grasping product, writing, and typing
Lift up to 10lbs
Carry up to 10lbs
Stand/walk
Additional Information
All your information will be kept confidential according to EEO guidelines.
*** NO C2C ***
IT Security Engineer -Bilingual (Korean/English)
Cyber security analyst job in Irvine, CA
For More Open Positions Visit us at: ********************************** Our Mission WOONGJIN, Inc. is a rapidly growing team who provides a range of unique, exceptional, and enhanced services to our clients. We have a strong moral code that includes the service of goodness without expectations of reward. We are motivated by the sense of responsibility and servant leadership.
Benefits
Medical Insurance
Vision Insurance
Dental Insurance
401(k)
Paid Sick hours
Job Description
The IT Security Engineer is responsible for supporting the planning, implementation, and management of the organization's IT security infrastructure and policies. This role assists in identifying security risks, responding to incidents, and ensuring compliance with internal standards and external regulations.
Responsibilities
Assist in developing, implementing, and maintaining IT security policies, standards, and procedures
Monitor and analyze security events, logs, and alerts using tools like Splunk of Sentinel to detect and respond to threats
Collaborate with internal IT teams and external vendors to improve overall security posture
Manage user access controls and identity management systems
Monitor and audit for potential security breaches, abnormal behavior, and unauthorized access
Verify that applied security policies are properly configured and effectively enforced
Monitor network, system, and application security to detect and respond to potential threats and vulnerabilities
Participate in incident response processes, including investigation, containment, recovery, and documentation
Assist in audits and ensure compliance with regulatory requirements
Support security awareness training and compliance initiatives for employees and third parties
Maintain up-to-date knowledge of cybersecurity trends, threats, and best practices
Document security configurations, procedures, and technical findings
Conduct vulnerability assessments
Salary:
$80,000 - $95,000 per year (D.O.E)
Qualifications
Skills
3 - 5 years of experience in IT security or related IT roles required
Knowledge of security technologies such as firewalls, IDS/IPS, antivirus, SIEM, and endpoint protection required
Security certifications preferred (e.g., CISSP, CISM, CompTIA Security+, CEH) preferred
Strong problem-solving, analytical, and communication skills required
Education & Experience
Bachelors Degree Required
Computer Science, Information Security, or a related field required
6 - 9 Years of Direct Experience Required
7 - 11 Years of Direct Experience Required
1 - 3 Years of Supervisory Experience Required
3-5 years of experience in IT Security or related IT roles required
Physical Requirements
Ability to sit in front of a desk and/or in front of the computer for long periods
Repetitive use of hand/grasping product, writing, and typing
Lift up to 10lbs
Carry up to 10lbs
Stand/walk
Additional Information
All your information will be kept confidential according to EEO guidelines.
*** NO C2C ***
Sr. Security Engineer
Cyber security analyst job in Vista, CA
The Sr. Security Engineer is part of the Global IT, Security & Compliance (CISO) team, supporting security across IT, OT, and cloud environments. This role involves managing internal security platforms, partnering with our 24/7 MDR provider, responding to incidents, and integrating security into company-wide initiatives. The Senior SOC Engineer drives threat detection engineering, response automation, and security visibility across endpoints, networks, and cloud infrastructure. They are responsible for the technical leadership of SOC activities, mentoring junior engineers, optimizing integrations (Zscaler, Sentinel, Vulnerability management tools), and contributing to the global security roadmap and incident response program.
What you will do
* Lead and support internal incident management, including triage, containment, remediation, and post-incident reviews.
* Act as the primary interface with our external MDR team for alerts, investigations, and incident handling.
* Onboard and integrate new log/data sources into security monitoring.
* Monitor vulnerabilities and support patch management coordination.
* Design, manage, maintain, and optimize internal security applications such as EDR/XDR, SIEM, SOAR, IAM, PAM, vulnerability management, and DLP.
* Develop and automate operational processes, playbooks, and response workflows.
* Partner with IT, OT, and business teams to embed security into projects (cloud, infrastructure, workplace, OT).
* Support OT security initiatives, including securing industrial control systems, legacy systems, and production environments.
* Contribute to security architecture and roadmap initiatives.
* Act as a security advocate to promote best practices and raise awareness across teams.
* Design modern, user-friendly security solutions that balance usability, compliance, and risk reduction.
Qualifications
* Bachelor's degree in information security, computer science, or engineering
* Master's degree in information security, computer science, or engineering (preferred)
* 5 years' experience working in or with a SOC or MDR environment
* Strong understanding of incident response processes and digital forensics basics
* Knowledge of security frameworks and standards (ISO 27001, NIST, CIS, MITRE ATT&CK)
* Ability to design and implement modern, user-friendly security solutions that drive adoption across business and IT/OT stakeholders
* Excellent communication skills to collaborate with IT, OT, and business stakeholders
* Analytical mindset with problem-solving ability
* Relevant certifications are a plus (e.g., GCIA, GCIH, GCED, Azure Security Engineer, CISSP, Security+)
* EDR/XDR and endpoint security (Microsoft Defender)
* SIEM/SOAR administration and tuning (Microsoft Sentinel)
* Understanding of Identity and Access Management (IAM, PAM, MFA)
* Vulnerability management tools and remediation workflows
* Cloud security (Azure, AWS, GCP)
* Scripting/automation
* OT security (ICS/SCADA, IIoT, legacy systems) desirable
Base salary range: $112,640 - $154,880
Placement of new hires in this wage range is based on several factors including education, skill sets, experience, and training.
Total Rewards
We offer all Team Members a total rewards package including competitive pay, annual performance bonus, a generous benefit package with comprehensive Medical/Dental/Vision coverage, 401(k) plan with employer contribution, and paid vacation, personal and sick days.
Corporate Social Responsibility
Bachem takes responsibility for future generations by a careful handling of resources and avoiding environmental risks. We continually improve our ecological performance and develop and implement new approaches for enhancing employees' environmental awareness. EcoVadis has awarded Bachem Gold Medal status in their assessment of Bachem.
Bachem Americas is an Equal Opportunity Employer
As an equal opportunity employer, we celebrate the diversity of our team and are committed to building an inclusive workplace where individuals are hired and advanced based on merit, skills, and qualifications. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity or expression, sexual orientation, national origin, genetics, disability, age, veteran status, or other legally protected status.
Please note: unsolicited resumes from recruitment agencies will not be considered.
Share this job posting by email
Security Engineer
Cyber security analyst job in Irvine, CA
**Job Title:** Security Engineer **Duration:** 12 month W2 Contract **Pay Range:** $51.72 **Role Summary:** The Security Engineer is a hands-on technical expert responsible for implementing, maintaining, and optimizing MNAO's security tooling. This role works closely with platform and infrastructure teams to ensure all security controls are properly configured and operational.
**Key Responsibilities:**
+ Implements and maintains security tooling for MNAO, ensuring proper configurations, applying Security-by-Design principles.
+ Works directly with MNAO's infrastructure, Client Services team and MSSP to ensure all platforms are configured for visibility.
+ Applies data security principles to tool configurations and integrations.
+ Implements and maintains security tooling that supports MNAO's business continuity and disaster recovery.
+ Develops and implements security automation scripts and tools to streamline security operations and enforcement.
+ Conducts technical vulnerability remediation and coordinates patching efforts.
+ Provides advanced technical support and troubleshooting for security-related issues.
+ Develops and maintains technical documentation for security configurations, procedures, and hardening standards.
**Qualifications:**
+ Bachelor's degree in Computer Science, Information Technology, or a related field.
+ 5+ years of experience in security engineering or a similar technical role.
+ Hands-on experience with security technologies such as firewalls, EDR, cloud security controls, and SIEM.
+ Proficiency in scripting languages (e.g., Python, PowerShell).
+ Strong understanding of networking, cloud environments, and operating systems.
+ Relevant certifications such as Security+, CCNP Security, or relevant cloud certifications.
**Reports to:** Architecture, Cloud, and Engineering Lead
If this is a role that interests you and you'd like to learn more, click apply now and a recruiter will be in touch with you to discuss this great opportunity. We look forward to speaking with you!
**About ManpowerGroup, Parent Company of:** **Manpower, Experis, Talent Solutions, and Jefferson Wells**
_ManpowerGroup (NYSE: MAN), the leading global workforce solutions company, helps organizations transform in a fast-changing world of work by sourcing, assessing, developing, and managing the talent that enables them to win. We develop innovative solutions for hundreds of thousands of organizations every year, providing them with skilled talent while finding meaningful, sustainable employment for millions of people across a wide range of industries and skills. Our expert family of brands -_ **_Manpower, Experis, Talent Solutions, and Jefferson Wells_** _-_ creates substantial value for candidates and clients across more than 75 countries and territories and has done so for over 70 years. We are recognized consistently for our diversity - as a best place to work for Women, Inclusion, Equality and Disability and in 2022 ManpowerGroup was named one of the World's Most Ethical Companies for the 13th year - all confirming our position as the brand of choice for in-demand talent.
ManpowerGroup is committed to providing equal employment opportunities in a professional, high quality work environment. It is the policy of ManpowerGroup and all of its subsidiaries to recruit, train, promote, transfer, pay and take all employment actions without regard to an employee's race, color, national origin, ancestry, sex, sexual orientation, gender identity, genetic information, religion, age, disability, protected veteran status, or any other basis protected by applicable law.
Principal Security Engineer
Cyber security analyst job in Lake Forest, CA
AVEVA is a global leader in industrial software. Our cutting-edge solutions are used by thousands of enterprises to deliver the essentials of life - such as energy, infrastructure, chemicals and minerals - safely, efficiently and more sustainably. We're the first software business in the world to have our sustainability targets validated by the SBTi, and we've been recognized for the transparency and ambition of our commitment to diversity, equity, and inclusion. We've also recently been named as one of the world's most innovative companies.
If you're a curious and collaborative person who wants to make a big impact through technology, then we want to hear from you! Find out more at AVEVA Careers.
For more information about our privacy policy and how to manage cookies, visit our Privacy Policy.
Position: Principal Security Engineer - Application Security & Incident Response
Location: Calgary Canada/ Lake Forest, CA
Type: Full time- Hybrid
Path: Individual Contributor
Salary Range:
$123,500.00 - $205,900.00
About the Role:
We're looking for a Principal Security Engineer to lead our application security efforts and help protect our global technology environment. This is a hands-on, high-impact role for someone with deep expertise in application security, a strong development background, and real-world breach response experience.
You'll work across engineering and product teams to identify vulnerabilities, guide secure development, and respond to security incidents. As part of our global 24×7 security team, you'll help ensure continuous coverage and rapid response to emerging threats.
Key Responsibilities:
* Lead application security practices across development and deployment workflows.
* Identify and remediate vulnerabilities in collaboration with engineering teams.
* Monitor for threats and respond to security incidents across global environments.
* Apply breach response experience to strengthen threat modeling and security controls.
* Stay ahead of emerging threats and translate insights into actionable improvements.
* Develop secure coding standards and mentor teams on best practices.
* Work as part of a global 24×7 team to ensure consistent security coverage.
Required Qualifications:
* Strong development background with experience in secure coding and software engineering.
* Proven experience in application security and incident response.
* Proven experience securing cloud applications (e.g., Azure, AWS, GCP).
* At least two years operating at Principal level or in a senior technical leadership role.
* Strong understanding of secure development practices and threat modeling.
* Experience with cloud-native environments, CI/CD pipelines, and containerized applications.
* Excellent communication and stakeholder engagement skills.
Preferred Qualifications:
* Certifications like CSSLP, OSWE, or GWAPT.
* Experience with automated security tools and analysis platforms.
* Familiarity with compliance frameworks (e.g., GDPR, PCI-DSS, ISO 27001).
* Understanding of the NIS Directive and its impact on security operations.
R&D at AVEVA
Our global team of 2000+ developers work on an incredibly diverse portfolio of over 75 industrial automation and engineering products, which cover everything from data management to 3D design. AI and cloud are at the centre of our strategy, and we have over 150 patents to our name.
Our track record of innovation is no fluke - it's the result of a structured and deliberate focus on learning, collaboration and inclusivity. If you want to build applications that solve big problems, join us.
AVEVA requires all successful applicants to undergo and pass a comprehensive background check before they start employment. Background checks will be conducted in accordance with local laws and may, subject to those laws, include proof of educational attainment, employment history verification, proof of work authorization, criminal records, identity verification, credit check. Certain positions dealing with sensitive and/or third party personal data may involve additional background check criteria.
AVEVA is an Equal Opportunity Employer. We are committed to being an exemplary employer with an inclusive culture, developing a workplace environment where all our employees are treated with dignity and respect. We value diversity and the expertise that people from different backgrounds bring to our business.
Come and join AVEVA to create the transformative technology that enables our customers to engineer a better world.
Principal Security Engineer
Cyber security analyst job in Lake Forest, CA
**AVEVA is a global leader in industrial software. Our cutting-edge solutions are used by thousands of enterprises to deliver the essentials of life - such as energy, infrastructure, chemicals and minerals - safely, efficiently and more sustainably.**
**We're the first software business in the world to have our sustainability targets validated by the SBTi, and we've been recognized for the transparency and ambition of our commitment to diversity, equity, and inclusion. We've also recently been named as one of the world's most innovative companies.**
**If you're a curious and collaborative person who wants to make a big impact through technology, then we want to hear from you! Find out more at AVEVA Careers (**************************************** .**
**For more information about our privacy policy and how to manage cookies, visit our** **Privacy Policy (**************************************************************************************************************************** **.**
**Position:** Principal Security Engineer - Application Security & Incident Response
**Location:** Calgary Canada/ Lake Forest, CA
**Type:** Full time- Hybrid
**Path:** Individual Contributor
**Salary Range:**
$123,500.00 - $205,900.00
**About the Role:**
We're looking for a **Principal Security Engineer** to lead our application security efforts and help protect our global technology environment. This is a hands-on, high-impact role for someone with deep expertise in application security, a strong development background, and real-world breach response experience.
You'll work across engineering and product teams to identify vulnerabilities, guide secure development, and respond to security incidents. As part of our global 24×7 security team, you'll help ensure continuous coverage and rapid response to emerging threats.
**Key Responsibilities:**
+ Lead application security practices across development and deployment workflows.
+ Identify and remediate vulnerabilities in collaboration with engineering teams.
+ Monitor for threats and respond to security incidents across global environments.
+ Apply breach response experience to strengthen threat modeling and security controls.
+ Stay ahead of emerging threats and translate insights into actionable improvements.
+ Develop secure coding standards and mentor teams on best practices.
+ Work as part of a global 24×7 team to ensure consistent security coverage.
**Required Qualifications:**
+ Strong development background with experience in secure coding and software engineering.
+ Proven experience in application security and incident response.
+ Proven experience securing cloud applications (e.g., Azure, AWS, GCP).
+ At least **two years operating at Principal level** or in a senior technical leadership role.
+ Strong understanding of secure development practices and threat modeling.
+ Experience with cloud-native environments, CI/CD pipelines, and containerized applications.
+ Excellent communication and stakeholder engagement skills.
**Preferred Qualifications:**
+ Certifications like CSSLP, OSWE, or GWAPT.
+ Experience with automated security tools and analysis platforms.
+ Familiarity with compliance frameworks (e.g., GDPR, PCI-DSS, ISO 27001).
+ Understanding of the NIS Directive and its impact on security operations.
**R&D at AVEVA**
Our global team of 2000+ developers work on an incredibly diverse portfolio of over 75 industrial automation and engineering products, which cover everything from data management to 3D design. AI and cloud are at the centre of our strategy, and we have over 150 patents to our name.
Our track record of innovation is no fluke - it's the result of a structured and deliberate focus on learning, collaboration and inclusivity. If you want to build applications that solve big problems, join us.
**AVEVA requires all successful applicants to undergo and pass a comprehensive background check before they start employment. Background checks will be conducted in accordance with local laws and may, subject to those laws, include proof of educational attainment, employment history verification, proof of work authorization, criminal records, identity verification, credit check. Certain positions dealing with sensitive and/or third party personal data may involve additional background check criteria.**
**AVEVA is an Equal Opportunity Employer. We are committed to being an exemplary employer with an inclusive culture, developing a workplace environment where all our employees are treated with dignity and respect. We value diversity and the expertise that people from different backgrounds bring to our business.**
**Come and join AVEVA to create the transformative technology that enables our customers to engineer a better world.**
Empowering you with pioneering tech
AVEVA is a global leader in industrial software. Our cutting-edge solutions are used by thousands of enterprises to deliver the essentials of life - such as energy, infrastructure, chemicals and minerals - safely, efficiently and more sustainably.
We're the first software business in the world to have our sustainability targets validated by the SBTi, and we've been recognized for the transparency and ambition of our commitment to diversity, equity, and inclusion. We've also recently been named as one of the world's most innovative companies.
If you're a curious and collaborative person who wants to make a big impact through technology, then we want to hear from you! Find out more at AVEVA Careers (**************************************** .
For more information about our privacy policy and how to manage cookies, visit our Privacy Policy (*********************************************************************************************************************** .
Information Security Analyst
Cyber security analyst job in San Jacinto, CA
Job DescriptionSummary
The Information Security Analyst supports the organization's centralized information security program across both Tribal Administration and Soboba Casino operations. This role focuses on monitoring and analyzing security alerts, conducting vulnerability assessments, supporting incident response, and validating security controls. The Analyst collaborates with IT teams, business units, and vendors to identify security gaps, track remediation efforts, and support audit and compliance requirements. The role emphasizes analysis, investigation, validation, and reporting of security issues, rather than day-to-day system administration.
Duties/Responsibilities
Monitor, review, and analyze security alerts, logs, and reports across enterprise systems, including SIEM platforms (e.g., Splunk, QRadar, Sentinel).
Conduct vulnerability assessments and coordinate remediation tracking with IT teams, departments, and vendors.
Lead security incident investigations, including analysis, documentation, containment, and post-incident reviews, in coordination with the Information Security Manager and operational teams.
Coordinate and analyze penetration testing activities and vulnerability scans using tools such as Tenable, Nessus, or Qualys.
Design, perform, and report on security system and end-user activity audits.
Validate the effectiveness of security controls and recommend improvements based on risk analysis and threat intelligence.
Track and report on security findings, remediation progress, and risk trends.
Support internal and external audits, compliance reviews, and regulatory requirements (e.g., PCI-DSS, HIPAA, NIGC) through evidence collection and analysis.
Research emerging threats, vulnerabilities, and security trends to support continuous improvement of the security program.
Translate technical security findings into clear, risk-based recommendations for IT teams and executive leadership.
Collaborate with the Information Security Manager and CIO to support enterprise risk management initiatives.
Perform risk-based analysis of security events, vulnerabilities, and incidents to determine potential business impact.
Support third-party and vendor security assessments and risk reviews.
Assist with security awareness initiatives, including user education, phishing simulations, and training campaigns.
Develop and maintain security findings, investigation records, and remediation documentation.
Participate in continuous improvement of the information security program based on evolving threats, technologies, and organizational needs.
Engage in cross-functional collaboration with IT, compliance, legal, and operational teams to ensure alignment of security objectives.
Perform special projects and other responsibilities, tasks, or duties as requested.
Education / Qualifications
Must be at least 21 years of age.
High School Diploma or GED equivalent, required.
Bachelors in computer science or related field, or equivalent work experience, preferred.
Industry-recognized security certifications such as Security+, SSCP, or equivalent preferred; advanced certifications (e.g., CISSP, GIAC) are a plus.
Minimum of three (3) years of experience in systems, network, or security administration in enterprise environments with direct involvement in information security functions, such as security monitoring, vulnerability assessment, incident investigation, or control validation, preferred.
Any combination of education, experience, and training that provides the required knowledge, skills, and abilities.
Must have excellent verbal and written communication skills to promote a positive and professional image.
Broad hands-on knowledge of firewalls, intrusion detection systems, anti-virus software, data encryption, and other industry-standard techniques and practices, preferred.
In-depth technical knowledge of enterprise network, endpoint, and platform operating systems within heterogeneous environments, preferred.
Working technical knowledge of enterprise operating systems and platforms across Windows and Linux-based environments, preferred.
Strong knowledge of TCP/IP and network administration/protocols, preferred.
Hands-on experience with devices such as hubs, switches, and routers, preferred.
Knowledge of data privacy and data protection practices, along with familiarity with information security frameworks and best practices such as NIST, CIS, and ISO standards, preferred.
Must be able to provide evidence of eligibility to work in the United States of America.
Certificates, licenses, and registration
Ability to obtain and maintain a valid Soboba Tribal Gaming Commission license.
Required to submit to and obtain negative results on all drug and/or alcohol testing.
Soboba Casino Resort Benefits
Full-time team members are eligible to participate in a variety of group health and wellness benefits upon timely submission of appropriate enrollment forms. Coverage effective dates vary by plan and additional information will be provided to you during New Hire Orientation. Benefit offerings may change from time-to-time, but presently, Soboba Casino resort offers the following:
401k Plan
Basic Life Insurance (employer paid) with the option to purchase Supplemental Life Insurance
Medical available to employees at a significantly reduced cost. Dental & Vision paid for the employee.
Employee Assistance Program
Wellness Program (Annual Health Fair, Wellness Education, and Incentive Programs)
Paid Time Off
Soboba Casino Resort Team Member Recognition including, but not limited to:
Reward and Recognition Program (Quarterly, and Annually)
Team member Incentives
Discounted Team member meal
Senior Information Security Analyst
Cyber security analyst job in Tustin, CA
The Company: VeSync is a portfolio company with brands that cover different categories of health & wellness products. We wouldn't be surprised if you have one of our Levoit air purifiers in your living room or a COSORI air fryer whipping up healthy and delicious meals for you every night.
We're a young and energetic company, we've had tremendous success, and we are constantly growing our team. As we garner more industry attention - just check out our accomplishments and awards by CES Innovation, iF Design, IGA, and Red Dot - we also need driven and talented people to join our team.
That brings us to you, and what you'll be joining. Our teams are smart and diligent and take ownership of their work - they're confident in their work but know how to collaborate with open ears and a spirit of learning. If you're down-to-earth, approachable, and easy to strike up a conversation with, this may be a great fit for you.
Check out our brands:levoit.com | cosori.com | etekcity.com
The Opportunity:
Information Security Planning • Develop and implement comprehensive information security plans to safeguard the security of company data and assets, including on-premise and cloud environments. • Thoroughly analyze the company's business processes and data characteristics, and combine industry best practices and frameworks such as NIST Cybersecurity Framework (CSF)to create customized security plans, ensuring the confidentiality, integrity, and availability of information assets in various scenarios.
Policy Development and Compliance • Create security policies and ensure that the company's operations are in strict compliance with industry standards (e.g., ISO 27001, NIST, GDPR) and regulatory requirements. • Continuously monitor industry trends and regulatory changes, and adjust security policies in a timely manner to provide a solid security and compliance framework for the company's business operations. • Experience with OneTrust, Drata or similiar tools
System, Network and Cloud Security • Maintain and enhance security measures for systems, networks , and public cloud platforms (e.g., AWS, Azure, GCP) to prevent potential threats. • Utilize advanced technical means and tools to conduct real - time monitoring and risk early warning of systems, networks, and cloud environments, promptly detect and block various attack behaviors, and ensure the stable and secure operation of IT infrastructure. • Familiar with AWS security suites • Familiar with security scorecards, SIEM tools and dashboards (Splunk, QRadar, Rapid7, Wazhu)
Security Monitoring and Incident Response • Monitor security events in real - time, respond promptly to emergencies, and effectively mitigate risks. • Build an efficient security monitoring platform, use intelligent analysis technology to promptly capture abnormal behaviors, activate emergency response plans, and minimize the impact of security incidents. • Conduct re/blue team exercise
Security Awareness and Training • Develop and deliver security training programs to enhance employees' security awareness and encourage their adherence to best practices. • Design targeted training courses according to the needs of different positions and use diverse training methods to ensure that employees have a deep understanding of and implement security requirements.
Access Control and Identity Management • Oversee user access controls, regularly review permissions, and ensure secure identity management. • Implement a strict access control mechanism, Conduct regular audits of user permissions, and use reliable identity management systems to prevent unauthorized access and ensure the security of company resources.
Risk Assessment and Management • Conduct comprehensive risk assessments, identify vulnerabilities, and implement effective mitigation strategies. • Use scientific risk assessment methods and frameworks such as NIST CSF to evaluate potential threats and vulnerabilities, formulate corresponding mitigation measures based on the assessment results, and continuously improve the company's security defense capabilities. • Develop KPIs and metrics
Documentation and Mentorship • Document Cyber Security controls, detection rules and playbooks • Mentoring team members
What you bring to the role:
Bachelor's degree in Information Security, Computer Science, or a related field.
8+ years of experience in information security, with a strong background in security event analysis, incident response, vulnerability management, and risk assessment.
Hands-on experience with public cloud security (e.g., AWS, Azure, GCP), including cloud-native security tools and best practices.
Familiarity with security regulatory compliance standards and frameworks such as NIST CSF, ISO 27001, and CIS.
Knowledge of network security principles, intrusion detection/prevention systems (IDS/IPS), firewalls, and endpoint protection.
Understanding these aspects is essential for ensuring the company's security compliance and building a robust security defense system.
Strong analytical and problem - solving skills, with the ability to quickly identify and mitigate security threats.
Relevant security certifications such as CISSP, CISM, CEH are a plus.
Location:
This is an on-site, office-based role in Tustin, CA.
Salary:
Starting at $125K
Perks and Benefits:
100% covered Medical/Dental/Vision insurance for employee AND spouse + dependents!
401K with 4% employer match (eligible after 90 days of employment) and immediate 100% vesting
Generous PTO policy + paid holidays
Life Insurance
Voluntary Life Insurance
Disability Insurance
Critical Illness Coverage
Accident Insurance
Healthcare FSA
Dependent Care FSA
Travel Assistance Program
Employee Assistance Program (EAP)
Fully stocked kitchen
Auto-ApplyInformation Security Analyst
Cyber security analyst job in Rancho Cucamonga, CA
This position is responsible for ensuring that the Bank's Security operations and preventive controls are managed and maintained in accordance with established Information Security policies, standards and procedures, published regulations and industry best practices.
Primarily responsible for the constant review of vendor security controls in comparison with policies and industry frameworks, risk assessments, determination of control gaps and their remediation.
ESSENTIAL FUNCTIONS
Performs vendor security risk assessments to determine inherent risk on proposed projects and assesses vendor security controls to determine residual risk.
Evaluates the potential exposure to application security risks and threats based on industry security frameworks and recommends appropriate mitigation.
Assesses security practices including Information Security governance, Identity and access control, Incident monitoring and response, Vulnerability assessment and Penetration tests, Network Security and Endpoint Security, among others.
Acts as liaison with Third Party Risk Management, Information Technology and business department Relationship Managers related to vendor risk assessments.
Reports information security risks and follows-up remediations.
Remediates audit and regulatory findings and recommendations related to Information Security and Vendor Risk Management.
QUALIFICATIONS
Education:
College degree in Information Technology or Information Security or equivalent;
Security+, SSCP, CISSP, CISM or similar information security certifications preferred.
Experience:
Minimum two years of experience in Information Security Risk, Information Security Operations or Security Auditing.
Proven experience on third-party risk management and vendor security assessments.
Working knowledge of security practices such as Endpoint Security, Network Security, Security Operations and Security Governance required.
Experience working with Vendor Risk Management (VRM) applications preferred.
Skills/Ability:
Proven ability to initiate and manage projects.
Excellent communication and problem-solving skills.
Strong inter-personal communication and collaboration skills.
Self-starter, highly motivated, and able to work with general supervision.
OTHER DETAILS
$28.84 - $33.65 / hour
Pay determined based on job-related knowledge, skills, experience, and location.
This position may be eligible for a discretionary bonus.