Information Security Analyst and Engineer
Cyber security analyst job in Boston, MA
ABOUT OUR CLIENT
Our Client is a leader in energy management and power trading, leveraging cutting-edge platforms to deliver secure and resilient operations. With a strong focus on protecting systems, data, and intellectual property, they are committed to building a world-class information security program that supports business growth while staying ahead of emerging cyber threats.
ABOUT THE ROLE
The Information Security Analyst and Engineer will play a key role in safeguarding mission-critical systems, ensuring compliance, and advancing the organization's security maturity. This hybrid role blends hands-on security engineering with proactive monitoring, incident response, and program improvement. The position will collaborate with consultants, managed service providers (MSPs), and internal stakeholders to realize a highly effective security strategy. Reporting directly to the Director of Information Security, the role also provides occasional support to the Infrastructure team with basic system administration and help desk duties.
RESPONSIBILITIES
Develop and implement processes and technologies to enhance the security program and protect business platforms
Monitor security systems and analyze alerts, logs, and reports
Analyze vulnerability reports and track remediation across teams and systems
Provide metrics to evaluate security program effectiveness
Support security training and awareness programs, including phishing campaigns and in-person sessions
Research emerging IT security trends, attack techniques, and defensive measures
Assist in designing secure architectures across applications and infrastructure
Support internal and external risk assessments, vendor reviews, and security audits
Analyze penetration test results and drive remediation
Contribute to security roadmaps and maturity assessments
Safeguard IT assets and intellectual property by recommending best practices and solutions
Participate in incident response planning, investigations, and compliance reviews
Enhance data loss prevention technologies and processes
Respond rapidly to incidents, conduct root cause analysis, and recommend mitigations
Support business continuity and disaster recovery planning and testing
Validate MSP-delivered security solutions to ensure alignment with standards
Use automation to improve efficiency and effectiveness of security processes
Maintain and improve information security policies and ensure compliance
QUALIFICATIONS
Bachelor's degree in Computer Science, Information Security, or a related technical field
3-5 years of IT security experience, with hands-on implementation and analysis
Proficiency with EDR or SIEM solutions for configuration and investigations
Competency with firewalls, email gateways, internet filters, and VPNs
Strong background in network security, protocols, and best practices
Understanding of operating system, network, and application security concepts
Familiarity with the NIST Cybersecurity Framework
Working knowledge of network and data center operations
Experience with hybrid, public cloud (Azure preferred), and SaaS environments
Strong analytical, troubleshooting, and problem-solving skills
Excellent communication skills and attention to detail
Adaptability and eagerness to learn new technologies in a collaborative environment
PREFERRED QUALIFICATIONS
Experience in the energy or financial services industries
Familiarity with regulatory compliance frameworks such as NERC CIP or SOX
Relevant certifications such as CISSP, CompTIA, or GIAC
Experience in Agile and DevSecOps environments
Scripting knowledge in PowerShell and/or Python
Senior Security Engineer
Cyber security analyst job in Boston, MA
Senior Security Engineer (US)
New York & Boston candidates: Office-based
Other listed states: Remote employees considered
Contract: Full-time, Hybrid / Flexible | 35-hour week
Salary: $175,000 base + 15% bonus
Overview
We are seeking a hands-on, senior security engineer to proactively strengthen our security posture across cloud-native and hybrid environments. This highly technical, strategic role will lead security platform integration, governance, threat detection, and mentoring, while influencing security-first practices across the organisation.
Key Responsibilities
Security Architecture & Engineering
Lead integration and optimisation of Zscaler, Wiz (EDR/CSPM/CNAPP), and endpoint protection (EDR/XDR) to maximise prevention, detection, and response.
Develop detection rules and manage analytics in Microsoft Sentinel and Wiz.
Conduct proactive threat hunting, posture management, and remediation validation.
Administer Zscaler Internet Access (ZIA), including policy tuning, SSL inspection, forwarding profiles, and authentication flows.
Troubleshoot traffic flows and collaborate with DevOps, IT, and R&D to integrate security into CI/CD pipelines and infrastructure-as-code.
Compliance, Audit & Governance
Ensure compliance with NIST SP 800-53, NIST SP 800-171, SOC 2, ISO/IEC 27001:2022, and client-specific requirements.
Lead audits, penetration testing, and maintain continuous audit readiness.
Security Operations & Incident Response
Develop, tune, and manage detection rules and playbooks across Wiz, Zscaler, and other platforms aligned with MITRE ATT&CK.
Hunt threats, triage alerts, and lead incident investigations.
Manage advanced email security with Microsoft Defender for Office 365.
Drive automation and orchestration initiatives to improve operational efficiency.
Stakeholder Engagement & Leadership
Act as a technical advisor on Zero Trust, cloud security, and operations.
Mentor junior staff and foster a security-first culture.
Communicate complex security concepts clearly to technical and non-technical stakeholders, including senior leadership.
Mandatory Platform Expertise
GitGuardian
CyberHaven
Wiz Advanced & Defend
Zscaler
Email Security (various platforms)
Education & Preferred Certifications
Master's degree in Information Security, Computer Science, or related field.
GIAC certifications: GCIA, GCED, GCIH, GDAT, GDSA, GMON
Microsoft Cloud Security certifications: AZ-500, AZ-305, SC-300
Cloud Security Engineer
Cyber security analyst job in Merrimack, NH
Immediate need for a talented Cloud Security Engineer. This is a 12 months contract opportunity with long-term potential and is located in Westlake, TX/ Merrimack, NH(Onsite). Please review the job description below and contact me ASAP if you are interested.
Job Diva ID: 25-95092
Pay Range: $70 - $75 /hour. Employee benefits include, but are not limited to, health insurance (medical, dental, vision), 401(k) plan, and paid sick leave (depending on work location).
Key Responsibilities:
Designing, scaling, and deploying various cloud security controls and services
Building processes and workflows along with a consolidated and collaborative integration of IaaS, SaaS, and PaaS cloud services
Ensuring seamless user experience with advanced security and compliance of our cloud infrastructure
Maintaining and containing business risk as it pertains to the Azure cloud infrastructure
Working across teams and Business Units to define requirements and deliver solutions
Building comprehensive security controls to enforce policy
Supporting business unit technologists deploying to the public cloud
Key Requirements and Technology Experience:
Key skills; Azure Policy Exp
Azure Security Services - Security Center, Key Vault, Log Analytics
Identity and Access Management Exp
Prior Software Engineering background, any language is fine but someone coming from a Sys Admin/Devops background won't be the right fit here.
6-9 years of experience in IT infrastructure, security, compliance
A strong understanding of Azure services and security capabilities
Solid hands-on experience with at least two of the following:
Engineering/operational support of cloud account configuration in AWS or Azure
Software Development, Linux Systems Administration, Data Networking
Hands-on configuration of CI/CD pipelines for cloud-native deployments
Very strong with scripting languages, including integration with CSP APIs; python preferred
Azure Networking
Identity and Access Management - RBAC
Azure Policies
Azure Security Services - Security Center, Key Vault, Log Analytics
Azure ARM/PowerShell
Ability to work with application and security teams to promote a secure posture in the cloud
You can mentor and train other team members to work effectively in the cloud
You are a self-starter who can independently by reading technical documentation
Advanced Azure Certifications
Our client is a leading financial Industry, and we are currently interviewing to fill this and other similar contract positions. If you are interested in this position, please apply online for immediate consideration
Pyramid Consulting, Inc. provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, colour, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.
By applying to our jobs, you agree to receive calls, AI-generated calls, text messages, or emails from Pyramid Consulting, Inc. and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy here.
Global Cyber Wordings Analyst
Cyber security analyst job in Boston, MA
Join our global Cyber team as a Wordings Analyst supporting the Global Cyber Wordings Manager in the strategic development and governance of our Cyber and Tech policy suite, including Liberty Cyber Resolution and Liberty Tech Resolution. This role is a hands-on business enabler: you will help translate complex legal and regulatory requirements into clear, market-ready wordings, maintain our global clause library, support manuscript negotiations, and produce practical tools that empower underwriters and strengthen broker confidence. It's an excellent opportunity for an early-career insurance wordings or legal professional to build expertise in a fast-moving, global specialty line and make a visible impact on growth, innovation, and client experience.
Key responsibilities:
Wording library and drafting support
Maintain and expand the global wording library centered on Liberty Cyber Resolution and Liberty Tech Resolution, including endorsements, exclusions, and guidance notes.
Redline and prepare first drafts of standard clauses and endorsements; ensure consistency with definitions, coverage intent, and plain-language standards.
Track version control, change logs, approvals, and archiving;
Assist with localization for different jurisdictions, coordinating translations and filing documentation with Legal/Compliance.
Commercial enablement
Build practical tools (playbooks, FAQs, objection-handling guides, coverage summaries) to help regional teams position our products and close deals efficiently.
Prepare broker/client comparison decks and battlecards; support pitches, RFP/RFI responses, and manuscript negotiations with clause comparisons and recommended alternatives.
Triage wording queries from regions; track SLAs and referral approvals per the global governance framework.
Partner closely with Underwriting, Product, Global Cyber Engagement, Claims, Legal/Compliance, and regional leaders to deliver accurate, timely support and uphold governance standards.
Regulatory and legal stewardship
Monitor and synthesize global regulatory and market developments (e.g., Lloyd's cyber war/systemic guidance, GDPR, DORA, NIS2, sanctions) into succinct briefs and recommended wording actions.
Maintain audit-ready documentation; assist with regulatory filings or attestations where required.
Claims partnership and feedback loop
Collaborate with Claims to capture lessons from disputes and litigation trends; draft guidance notes and propose clarifications to improve coverage certainty.
Support coverage position letters and documentation packs with research, citations, and clause histories.
Innovation and product development support
Help draft prototype wordings for new propositions
Check alignment between underlying policy wordings and reinsurance treaty/facultative clauses.
Administer wording management tools, ensuring robust version control, approval workflows, and usage analytics.
Build dashboards and trackers for adoption of standard forms, deviation rates, SLA performance, disputes, and audit findings; provide monthly reporting to stakeholders.
Qualifications
Bachelor's degree in business, economics, or other quantitative field. Minimum 3 years, typically 4 years or more of relevant work experience.
2 - 5 years of experience in insurance wordings, legal/paralegal support, underwriting support, or product documentation; cyber specialty experience preferred.
Strong drafting, redlining, and proofreading skills with a plain-language mindset and exceptional attention to detail.
Working knowledge of insurance policy structures, endorsements, exclusions, and coverage interpretation; familiarity with cyber war/systemic language, sanctions, and privacy regulations is advantageous.
Research and synthesis skills to translate complex regulatory/legal topics into practical guidance and actionable updates.
Proficiency with MS Word (advanced track changes/redlining), Excel (trackers and dashboards), PowerPoint (training/pitch materials), and document/enablement tools.
Collaborative, service-oriented approach; comfortable operating in a global matrix and meeting defined SLAs.
Curiosity about cybersecurity risks and the incident response ecosystem; willingness to learn common threat scenarios to inform practical drafting.
About Us
Pay Philosophy: The typical starting salary range for this role is determined by a number of factors including skills, experience, education, certifications and location. The full salary range for this role reflects the competitive labor market value for all employees in these positions across the national market and provides an opportunity to progress as employees grow and develop within the role. Some roles at Liberty Mutual have a corresponding compensation plan which may include commission and/or bonus earnings at rates that vary based on multiple factors set forth in the compensation plan for the role.
At Liberty Mutual, our goal is to create a workplace where everyone feels valued, supported, and can thrive. We build an environment that welcomes a wide range of perspectives and experiences, with inclusion embedded in every aspect of our culture and reflected in everyday interactions. This comes to life through comprehensive benefits, workplace flexibility, professional development opportunities, and a host of opportunities provided through our Employee Resource Groups. Each employee plays a role in creating our inclusive culture, which supports every individual to do their best work. Together, we cultivate a community where everyone can make a meaningful impact for our business, our customers, and the communities we serve.
We value your hard work, integrity and commitment to make things better, and we put people first by offering you benefits that support your life and well-being. To learn more about our benefit offerings please visit: ***********************
Liberty Mutual is an equal opportunity employer. We will not tolerate discrimination on the basis of race, color, national origin, sex, sexual orientation, gender identity, religion, age, disability, veteran's status, pregnancy, genetic information or on any basis prohibited by federal, state or local law.
Fair Chance Notices
California
Los Angeles Incorporated
Los Angeles Unincorporated
Philadelphia
San Francisco
We can recommend jobs specifically for you! Click here to get started.
Auto-ApplyCyber Security Privileged Access Management (PAM) Analyst
Cyber security analyst job in Boston, MA
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates' physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Position Summary:
Global Information Security (GIS) is responsible for protecting bank information systems, confidential and proprietary data, and customer information. GIS develops the bank's Information Security strategy and policy, manages the Information Security program, identifies and addresses vulnerabilities and operates a global security operations center that monitors, detects and responds to cybersecurity incidents. Within GIS, Identity and Access Management (IAM) is a security discipline that enables the right individuals to access the right resources at the right times and in the right context. IAM addresses the mission-critical need to ensure appropriate access to the resources across increasingly heterogeneous technology environments, and to meet increasingly rigorous compliance requirements.
Role Description:
This role is primarily responsible for ensuring that relevant Privileged Access Controls are adequately enforced across platforms and applications to comply with IAM Standard.
Partner with PAM Governance leads to ensure that Privileged Access Controls are appropriately measured, reported and governed.
Apply industry PAM best practices, templates, and documentation while also proposing improvements based on practical knowledge.
Document and convey PAM related requirements to technology partners to build/implement enhanced PAM solutions that are efficient, effective, and modern and able to result in material risk reduction in sustainable manner.
Collaborate with stakeholders to develop PAM requirements that iteratively support long term PAM modernization and transformation (covers Process, Data and Technology aspects).
Provide education to team members and technology partners regarding the proposed changes to PAM controls.
Partners with the policy governance team for socialization and publication of proposed changes to the PAM Standard
Takes accountability for addressing PAM risks. Proactively identify risk and ways to continuously enhance and improve BAC's PAM controls. Implement and take decisive actions in finding solutions. Drives towards intended outcomes.
Engage senior management to provide factual, transparent, and timely reporting on existing and emerging PAM or information security risks.
Active participation in GIS IAM/PAM forums including but not limited to Monthly IAM Stakeholder Forum and Control Owner Forum for standard and Single Process Inventory (SPI) enhancements.
Supports audit issues for closure and sustainability
Required Qualifications:
7 years relevant hands-on experience in PAM in complex and heterogenous technology environment.
Deep experience with Linux, Windows, Cloud scale Identity, Access Management (Single Sign-On, Multi Factor Authentication), Authorization services or design and architecture of PAM services
Deep knowledge of bank financial practices and policies and ability to adapt to fast changing environment
Working level experience with IAM platforms such as Ping Identity, Active Directory OpenLDAP, OpenDJ
Experience in consumption of Web Service APIs such as JSON / XML
Hands on experience and involvement in large and complex projects.
Expert level knowledge of privileged access management methodologies and techniques for on-prem and Cloud implementation.
Expert level knowledge of authentication platforms such as Active Directory, LDAP, Kerberos, LDAP, Radius.
Expert knowledge of PAM related tools which support session proxy, vaulting, just-in-time provision, integration with service management tool would be an advantage.
Deep security knowledge which covers core technology infrastructure (network, storage, servers, databases, etc.) identity management and application security practice.
Deep knowledge on Federation platforms or protocols such as Oauth, OpenID, SAML, WS-Fed, etc.
Good knowledge and understanding of PAM-specific laws, rules, and regulations within the financial services sector.
Proficient in Microsoft Office suite of products with ability to quickly analyze and synthesize large volumes of data.
Familiarity with security standards such as NIST, ISO/EC, FFIEC.
Understanding and interpreting BAC's established information security Policy, Standards, Procedure and Guides, and applying this knowledge to related PAM decisions and response.
Possession of CISSP certification would be an advantage.
Knowledge of Compliance Certifications such as SOX, SOC, SOC2.
Serve as the Subject Matter Experts in advising BAC business and technology counterparts on effective ways to achieve or exceed compliance with applicable Policy, Standards, Procedures and Guides.
Proficient in articulating facts and data-driven plans and to partner with stakeholders to implement intended solutions to drive risk reductions and adherence to PAM standards.
Strong attention to detail and advanced analytical skills.
Excellent communication and presentation skills. Able to effectively prioritize multiple tasks.
Proven track record in delivering outcomes that result in sustainable risk reductions in PAM.
Ability to work independently on initiatives with little oversight. Motivated and willing to learn.
Confident and effective in delivering messages across a wide spectrum of individuals with varying degrees of technical and business understanding
This job will be open and accepting applications for a minimum of seven days from the date it was posted
Shift:
1st shift (United States of America)
Hours Per Week:
40
Pay Transparency details
US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842), US - MA - Boston - 100 Federal St - 100 Federal St Lp (MA5100) Pay and benefits information Pay range$78,200.00 - $137,700.00 annualized salary, offers to be determined based on experience, education and skill set.Discretionary incentive eligible This role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.BenefitsThis role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.
Auto-ApplyCyber Security Solutions Engineer - GES
Cyber security analyst job in Boston, MA
States: MA, NH, RI, ME, CT, VT, NJ, NY is home office based. Meet the Team You will provide guidance and assist Security Sellers and Account teams within the territory in a pre-sales technical role, showcasing Cisco security product solutions, setting up demonstrations, explaining features and benefits to customers, and designing and configuring products to address specific customer security needs. You will form relationships with our customer's key decision-makers, positioning Cisco security solutions aligned accurately to their requirements.
You will be a part of an outstanding technical pre-sales team in our Global Security Sales Organization (GSSO), responsible for driving the success of Cisco's Security Portfolio and focusing on protecting Customer Application Environments no matter where they live (on-prem / any cloud).
Our mission is simple: democratize security by making it easy and effective for everyone. We're transforming security from the ground up by solving the world's most pressing geopolitical challenge - safe, secure information access. We engineer our business to enable our customers to easily address their ever-evolving security challenges.
We believe that impactful work is rewarding work and that our team is at its best when everyone feels empowered to bring their whole self to work. We learn together by hiring for cultural contribution, not cultural fit, and recognize that diversity in background and thought are essential to building high-impact teams.
We invest in growth and learning opportunities and encourage our people to never stop learning. We foster collaboration and believe in being recognized (and rewarded!) for hard work. We champion a healthy work-life balance. We're kinder than necessary.
Together we build for the future by designing simple solutions for complex problems. And that's why we're the most loved and trusted name in security.
Your Impact
As an advisor to the customer, you'll be working with technology experts to craft architectures and configure products to meet customer-specific needs, are prepared to lead all technical aspects of pre-sales activities, and position security solutions effectively against competing offerings. You are an aggressive starter, self-starter with the ability to build executive relationships, develop and execute sales strategies and tactics that improve Cisco's opportunity with a customer environment, position and promote the partner and customer value proposition for Cisco security architecture, articulate Cisco's product and business strategies, and create the demand that makes deals happen! You will:
* Serve as the subject matter expert in Cisco security solutions
* Provide guidance and assist account teams within the territory in building solutions to address specific customer security needs
* Understand business requirements for a customer base and be able to translate them into technical requirements
* Understand and articulate Cisco's architecture and services within security technologies
* Create, present, and document technical solutions
* Perform in-depth and high-level technical presentations for customers partners and prospects
* Drive identified major account opportunities (i.e. technical consulting, upper-level management presentations, and Cisco technology solutions) while allowing local account teams to maintain long-term ownership
Who You Are
You are passionate about the customer experience and excited about new technology. You are a true teammate and love to learn. Being a self-starter, our SEs act as an industry domain authority, and strive to help Cisco make customers for life.
Minimum Qualifications
* Minimum of 4 years of pre-sales experience
* Hands on experience with one or more of these Cisco Security Products (or their competitive equivalent):
********************************************************************
* Experience with whiteboard discussions that transform customer requirements into security solutions
Preferred Qualifications
* History of successful quota achievement.
* Ability to demo / POV any of these Cisco Security products (the more the better): ********************************************************************
* Knowledge of public clouds AWS, Azure, GCP, and OCI.
* Experience with incident response a plus
* Experience with administering security for a company (e.g. purchased and deployed Cisco security products as a customer) is a plus.
* Solid presentation and interpersonal skills.
* Highly motivated self-starter who does not need day-to-day management
* Experience with APIs and scripting languages
Why Cisco?
At Cisco, we're revolutionizing how data and infrastructure connect and protect organizations in the AI era - and beyond. We've been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds. These solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint.
Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions. Add to that our worldwide network of doers and experts, and you'll see that the opportunities to grow and build are limitless. We work as a team, collaborating with empathy to make really big things happen on a global scale. Because our solutions are everywhere, our impact is everywhere.
We are Cisco, and our power starts with you.
Message to applicants applying to work in the U.S. and/or Canada:
The starting salary range posted for this position is $217,200.00 to $274,100.00 and reflects the projected salary range for new hires in this position in U.S. and/or Canada locations, not including incentive compensation*, equity, or benefits.
Individual pay is determined by the candidate's hiring location, market conditions, job-related skillset, experience, qualifications, education, certifications, and/or training. The full salary range for certain locations is listed below. For locations not listed below, the recruiter can share more details about compensation for the role in your location during the hiring process.
U.S. employees are offered benefits, subject to Cisco's plan eligibility rules, which include medical, dental and vision insurance, a 401(k) plan with a Cisco matching contribution, paid parental leave, short and long-term disability coverage, and basic life insurance. Please see the Cisco careers site to discover more benefits and perks. Employees may be eligible to receive grants of Cisco restricted stock units, which vest following continued employment with Cisco for defined periods of time.
U.S. employees are eligible for paid time away as described below, subject to Cisco's policies:
* 10 paid holidays per full calendar year, plus 1 floating holiday for non-exempt employees
* 1 paid day off for employee's birthday, paid year-end holiday shutdown, and 4 paid days off for personal wellness determined by Cisco
* Non-exempt employees receive 16 days of paid vacation time per full calendar year, accrued at rate of 4.92 hours per pay period for full-time employees
* Exempt employees participate in Cisco's flexible vacation time off program, which has no defined limit on how much vacation time eligible employees may use (subject to availability and some business limitations)
* 80 hours of sick time off provided on hire date and each January 1st thereafter, and up to 80 hours of unused sick time carried forward from one calendar year to the next
* Additional paid time away may be requested to deal with critical or emergency issues for family members
* Optional 10 paid days per full calendar year to volunteer
For non-sales roles, employees are also eligible to earn annual bonuses subject to Cisco's policies.
Employees on sales plans earn performance-based incentive pay on top of their base salary, which is split between quota and non-quota components, subject to the applicable Cisco plan. For quota-based incentive pay, Cisco typically pays as follows:
* .75% of incentive target for each 1% of revenue attainment up to 50% of quota;
* 1.5% of incentive target for each 1% of attainment between 50% and 75%;
* 1% of incentive target for each 1% of attainment between 75% and 100%; and
* Once performance exceeds 100% attainment, incentive rates are at or above 1% for each 1% of attainment with no cap on incentive compensation.
For non-quota-based sales performance elements such as strategic sales objectives, Cisco may pay 0% up to 125% of target. Cisco sales plans do not have a minimum threshold of performance for sales incentive compensation to be paid.
The applicable full salary ranges for this position, by specific state, are listed below:
New York City Metro Area:
$223,000.00 - $330,300.00
Non-Metro New York state & Washington state:
$217,200.00 - $315,300.00
* For quota-based sales roles on Cisco's sales plan, the ranges provided in this posting include base pay and sales target incentive compensation combined.
Employees in Illinois, whether exempt or non-exempt, will participate in a unique time off program to meet local requirements.
Cyber Security Engineer
Cyber security analyst job in Norway, ME
We are seeking a detail-oriented and analytical Security Engineer to join a growing Information Security team. The ideal candidate will be responsible for designing, implementing, and managing a variety of security technologies and controls in accordance with the Information Security Program. This role plays a critical part in protecting the organization from cyber threats and ensuring compliance with security policies and regulations.
Responsibilities:
+ Monitor security systems, SIEM tools, and threat intelligence feeds for anomalies and potential threats.
+ Investigate and respond to security incidents, including malware infections, phishing attempts, and unauthorized access.
+ Conduct vulnerability assessments and assist in remediation efforts.
+ Maintain and update security policies, procedures, and documentation.
+ Collaborate with IT and other departments to implement security best practices.
+ Assist in security audits, risk assessments, and compliance initiatives (e.g., ISO 27001, NIST, SOC 2).
+ Stay current with emerging threats, vulnerabilities, and regulatory requirements.
+ Support security awareness training and phishing simulations for employees.
Requirements
+ Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field.
+ 2+ years of experience in a security or similar role.
+ Familiarity with security tools such as firewalls, IDS/IPS, antivirus, and SIEM platforms.
+ Understanding of networking protocols, operating systems, and common attack vectors.
+ Familiarity with cloud infrastructure; Azure, AWS, Entra ID O365/M365.
+ Understanding of Microsoft Server, Windows 10/11, Active Directory, AD CS, IDS/IPS, NGFW, DLP, EDR, SIEM, MDM, PAM, MFA, Netwrix.
+ Experience with cloud security (AWS, Azure, or GCP).
+ Knowledge of scripting or automation (Python, PowerShell, etc.).
Technology Doesn't Change the World, People Do.
Robert Half is the world's first and largest specialized talent solutions firm that connects highly qualified job seekers to opportunities at great companies. We offer contract, temporary and permanent placement solutions for finance and accounting, technology, marketing and creative, legal, and administrative and customer support roles.
Robert Half works to put you in the best position to succeed. We provide access to top jobs, competitive compensation and benefits, and free online training. Stay on top of every opportunity - whenever you choose - even on the go. Download the Robert Half app (https://www.roberthalf.com/us/en/mobile-app) and get 1-tap apply, notifications of AI-matched jobs, and much more.
All applicants applying for U.S. job openings must be legally authorized to work in the United States. Benefits are available to contract/temporary professionals, including medical, vision, dental, and life and disability insurance. Hired contract/temporary professionals are also eligible to enroll in our company 401(k) plan. Visit roberthalf.gobenefits.net for more information.
© 2025 Robert Half. An Equal Opportunity Employer. M/F/Disability/Veterans. By clicking "Apply Now," you're agreeing to Robert Half's Terms of Use (https://www.roberthalf.com/us/en/terms) .
Systems Security Engineer
Cyber security analyst job in Dedham, MA
Basic Qualifications
CLEARANCE REQUIREMENTS: Department of Defense Secret security clearance is required at time of hire. Applicants selected will be subject to a U.S. Government security investigation and must meet eligibility requirements for access to classified information. Due to the nature of work performed within our facilities, U.S. citizenship is required.
Responsibilities for this Position
We are seeking a Systems Security Engineer who has experience in the design and development of NSA-certified Cybersecurity devices.
Key Responsibilities:
Design and develop specifications for mission-critical NSA-certified Cybersecurity devices
Collaborate with software and validation engineering teams to deliver high-speed data solutions
Develop real-time multi-threaded Embedded System architecture using Model-based Systems Engineering (MBSE) tools and techniques
Analyze and maintain system security requirements throughout product development lifecycle
Conduct trade studies, perform functional analysis, and design system security.
Preferred Skills and Experiences:
NSA approved Cryptography/Encryption
Security requirements analysis
Real-Time multi-threaded Embedded System architecture and development
Model-based Systems Engineering (MBSE)
CISSP certification or similar
INCOSE ASEP, CSEP, or ESEP certification
We value candidates who possess:
Drive to expand knowledge and experience in designing complex systems
Ability to define project scope, schedule, and expected results
Initiative to complete assignments and ability to engage in technical direction and leadership
Our Commitment to You:
An exciting career path with opportunities for continuous learning and development
Research-oriented work with award-winning teams
Competitive benefits package
Salary Note This estimate represents the typical salary range for this position based on experience and other factors (geographic location, etc.). Actual pay may vary. This job posting will remain open until the position is filled. Combined Salary Range USD $107,529.00 - USD $114,000.00 /Yr. Company Overview
General Dynamics Mission Systems (GDMS) engineers a diverse portfolio of high technology solutions, products and services that enable customers to successfully execute missions across all domains of operation. With a global team of 12,000+ top professionals, we partner with the best in industry to expand the bounds of innovation in the defense and scientific arenas. Given the nature of our work and who we are, we value trust, honesty, alignment and transparency. We offer highly competitive benefits and pride ourselves in being a great place to work with a shared sense of purpose. You will also enjoy a flexible work environment where contributions are recognized and rewarded. If who we are and what we do resonates with you, we invite you to join our high-performance team!
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
Auto-ApplyInformation System Security Officer
Cyber security analyst job in Woods Hole, MA
Woods Hole Oceanographic Institution is searching for a highly skilled and cleared Information System Security Officer (ISSO) / Classified Systems Information Assurance Analyst to join our team, focusing exclusively on the security of classified information systems and networks. This critical role is responsible for ensuring the confidentiality, integrity, and availability of sensitive government information in accordance with stringent U.S. government (USG) security directives.
The ISSO will be instrumental in the authorization and accreditation(A&A) process, continuous monitoring, incident response, and the implementation of robust security controls for classified environments. The ideal candidate will possess a deep understanding of relevant security frameworks, policies, and a proven track record of maintaining secure classified systems. This is a regular, full-time, exempt position, and is eligible for full benefits.
ESSENTIAL FUNCTIONS
Authorization & Accreditation (A&A) / Risk Management Framework (RMF):
Lead or support the development, review, and submission of comprehensive security authorization packages (e.g., System Security Plans (SSPs), Risk Assessment Reports, Contingency Plans, Plan of Action and Milestones (POA&Ms)) for classified systems.
Ensure all classified systems maintain an Authority to Operate (ATO), Interim Authority to Test (IATT), or Authority to Connect (ATC) in accordance with RMF or legacy A&A processes (e.g., DIACAP).
Interpret and apply USG security policies, regulations, and guidelines, including but not limited to: NISPOM, DoD Instruction 8500.01, NIST SP 800-53, DCID 6/3, ICD 503, JSIG, and DISA STIGs.
Security Control Implementation & Enforcement:
Design, implement, and maintain security controls specific to classified systems, including secure configurations, access controls, auditing, media control, and classified spillage prevention/response.
Configure and manage specialized security tools relevant to classified environments (e.g., Assured Compliance Assessment Solution (ACAS), Host Based Security System (HBSS), Data Loss Prevention (DLP) solutions).
Perform rigorous hardening of operating systems (Windows, Linux), applications, and network devices based on DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs).
Vulnerability Management & Continuous Monitoring:
Conduct vulnerability scans, analyze results, and work with system administrators to remediate security weaknesses on classified systems.
Oversee and perform continuous monitoring activities, including reviewing audit logs, security events, and system alerts for anomalous behavior.
Track and ensure compliance with Information Assurance Vulnerability Management (IAVM) directives.
Incident Response & Classified Spillage:
Act as a primary point of contact and lead for security incidents and classified spillage events on assigned systems.
Execute incident response procedures, including containment, eradication, recovery, and detailed reporting to relevant government authorities.
Participate in forensic investigations as required for classified incidents.
Compliance & Audit Support:
Maintain meticulous documentation of all security artifacts, configurations, policies, and procedures for classified systems.
Support internal and external security inspections, audits, and assessments by government agencies (e.g., DCSA, DSS, NSA).
Develop and implement standard operating procedures (SOPs) for the secure operation of classified systems.
User Training & Guidance:
Provide guidance and training to users on proper handling, marking, and safeguarding of classified information and operation of classified systems.
Ensure all personnel accessing classified systems meet training requirements (e.g., security awareness, insider threat).
Configuration Management:
Manage and control changes to the hardware, software, and firmware of classified systems to maintain their security posture and accreditation.
MINIMUM QUALIFICATIONS
Security Clearance:
Active U.S. Government Security Clearance required at the SECRET level or above.
Education:
Bachelor's degree in Computer Science, Information Security, Cybersecurity, or equivalent experience.
Experience:
5 years of dedicated experience in Information Assurance/Cybersecurity within classified government or defense environments.
Demonstrable expertise in the Risk Management Framework (RMF) or equivalent A&A processes (e.g., DIACAP).
Hands-on experience with security tools and technologies used in classified environments (e.g., ACAS, HBSS, SIEM, dedicated firewalls).
Proven experience with DISA STIGs and their application to various operating systems and applications.
Technical Skills:
Strong understanding of network protocols, operating systems (Windows, Linux/Unix), and virtualized environments in a classified context.
Experience with encryption technologies and COMSEC devices.
Knowledge of scripting languages (e.g., PowerShell, Python, Bash) for automation and auditing is a plus.
Desired Certifications:
CISSP (Certified Information Systems Security Professional)
DoD 8570.01-M IAT Level II (e.g., CompTIA Security+, CySA+, CCNA Security, SSCP) or higher (IAM Level I, II, or III).
GIAC Certifications relevant to incident handling, forensics, or security auditing (e.g., GCIH, GCFA, GCCC, GSNA)
Additional Job Requirements
Salary Range: $114,000 to $148,000 USD
The salary range provided for this position reflects the expected minimum and maximum base pay for new hires. Actual compensation will be determined based on factors such as relevant skills, experience, and qualifications, as well as internal equity and market conditions. In addition to base salary, eligible employees also receive a comprehensive benefits package.
WHOI accepts applications on a rolling basis - applications will be reviewed as they are received, and we encourage you to submit your application as soon as possible to ensure full consideration. While we will continue to review applications until the position is filled, and early applicants may have an advantage in the selection process.
EEO Statement
Woods Hole Oceanographic Institution (WHOI) provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Auto-ApplyInformation Security Analyst
Cyber security analyst job in Westbrook, ME
INFORMATION SECURITY ANALYST SUMMARY: The Information Security Analyst is responsible for contributing, implementing, and maintaining the credit union's cyber security program. Leveraging the required skills and experience, the Information Security Analyst will investigate and respond to security incidents, work closely with internal departments and/or third parties, and provide status updates to management. ESSENTIAL DUTIES AND RESPONSIBILITIES include the following:
Review daily log reports generated from information security systems and investigate anomalous behavior.
Process reported social engineering attempts to determine if a threat exists and communicate outcomes to involved parties.
Monitor, investigate, remediate, and report security incidents as they arise. Work with other members of the Incident Response Team, as needed.
Conduct social engineering exercises across the organization and assist with training remediation efforts.
Administer the organizations vulnerability management program to identify and prioritize vulnerabilities. Will also work closely with the Information Technology team and product owners to remediate discovered vulnerabilities.
Administer the credit union's information security systems and tools.
Contribute to the organizations security policies, procedures, and processes.
Implements the information security strategy and objectives, as approved by the Chief Information Officer, including strategies to monitor and address current and emerging risks.
Participates on the Change Control Board ensuring systems changes are made with appropriate Confidentiality, Availability, Integrity and Cyber Security design and controls
Participates in industry collaborative efforts to monitor, share, and discuss emerging security threats. Maintains up-to-date knowledge of the security industry including awareness of new or revised security solutions, improved security processes and the development of new attacks and threat vectors.
Contributes to the deployment, integration, and initial configuration of all new security solutions and of any enhancements to existing security solutions in accordance with standard best operating procedures generically and the enterprise's security documents specifically.
Champions security awareness and training programs.
Participate in security NIST based incident response process including event handling, process reviews and tabletop exercises. Supervise all investigations into problematic activity and provide on-going communication and reports significant security events to the board, supervisory committee, and management as appropriate.
Responds to and complies with audit, regulatory, and credit union policies and procedures.
Monitor and respond to security related alerts during non-business hours.
QUALIFICATION REQUIREMENTS:
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
KEYS TO SUCCESS: Knowledge Of:
Experience in enterprise security document creation.
Experience in enterprise security architecture design.
Experience in NIST based Incident Handling
Working technical knowledge of Firewalls, Intrusion Detection, Networking technologies ( LAN / WAN ), Data Loss Prevention (DLP), Network Access Controls (NAC), Security Incident and Event Management Systems (SIEM), Email Security.
Vulnerability Management Tools (Nessus, Nexpose, Etc)
Command Line Utilities such as Nmap, netcat, etc.
Experience with security in cloud environments (Azure preferred) required.
Microsoft Windows Server, Active Directory, DNS and DHCP, etc.
Microsoft Windows 10 and later
Microsoft Office and Visio 2016 and later
Ability To:
Create and maintain detailed technical documentation
Proven analytical and problem-solving abilities.
Good written, oral, and interpersonal communication skills.
Ability to conduct research into IT security issues and products as required.
Ability to present ideas in business-friendly and user-friendly language.
Highly self-motivated and directed.
Team-oriented and skilled in working within a collaborative environment.
EDUCATION, EXPERIENCE, & TRAINING GUIDELINES: Any equivalent combination of education and experience that provides the applicant with the knowledge, skills, and abilities, required to perform the job is acceptable. A typical way to obtain the knowledge and abilities would be: Education/Experience:
Bachelor's degree preferably in Information Systems or Computer Science
3-5 years of relevant Information Technology or Information Security experience.
License or Certification:
Security certifications such as Security+, CySA+, SSCP, etc.
Bondable
Acceptable Credit History
Compensation & Benefits:
Salary Range: $62,200 - $93,300
Health, Dental & Vision Benefits
Bonus opportunity
401(k) with match and profit sharing
Flexible Time Off
Senior Security Compliance Analyst
Cyber security analyst job in Boston, MA
Job Description
At OneStudyTeam (a Reify Health company), we specialize in speeding up clinical trials and increasing the chance of new therapies being approved with the ultimate goal of improving patient outcomes. Our cloud-based platform, StudyTeam, brings research site workflows online and enables sites, sponsors, and other key stakeholders to work together more effectively. StudyTeam is trusted by the largest global biopharmaceutical companies, used in over 6,000 research sites, and is available in over 100 countries. Join us in our mission to advance clinical research and improve patient care.
One mission. One team. That's OneStudyTeam.
We are seeking a Senior Security Compliance Analyst with expertise in Governance, Risk, and Compliance (GRC) to support and enhance our security and compliance programs within the healthcare industry. This role is critical in ensuring adherence to industry regulations, responding to customer audits, and maintaining compliance with ISO 27001, HIPAA, and other security frameworks.
The ideal candidate will be a detail-oriented compliance expert who can navigate complex regulatory environments, assist with internal/external audits, and drive continuous improvement in security governance. The ideal candidate must be able to operate independently while delivering on the following duties.
What You'll Be Working On:
Lead and support customer security audits, responding to security questionnaires and demonstrating compliance with security frameworks.
Prepare, coordinate, and manage ISO 27001 audits, including evidence collection, control implementation, and auditor engagement.
Ensure ongoing compliance with HIPAA, NIST CSF, and other regulatory requirements applicable to healthcare data security.
Develop and maintain policies, procedures, and security documentation to meet regulatory and contractual obligations.
Perform gap analyses and risk assessments to identify and remediate compliance risks.
Manage and improve security governance frameworks, ensuring alignment with industry best practices and business objectives.
Conduct third-party vendor risk assessments, ensuring compliance with security policies and contractual obligations.
Monitor security controls, ensuring effectiveness and continuous improvement in alignment with security frameworks.
Support security awareness training initiatives, ensuring employees understand compliance responsibilities.
Stay current on ISO 27001, HIPAA, NIST 800-53, and other relevant standards, translating them into actionable security controls.
Assist in defining security metrics and reporting on compliance status and risk posture to leadership.
Work closely with legal, security, IT, and business teams to align compliance requirements with security operations.
What You'll Bring to OneStudyTeam:
Bachelor's degree in Information Security, Computer Science, Risk Management, or related field (or equivalent experience).
8+ years of progressive experience in GRC, compliance, or security audit roles.
Experience in healthcare or regulated industries strongly preferred.
Certifications strongly preferred: ISO 27001 Lead Auditor/Implementer, CISSP, CISM, CISA, HITRUST CCSFP, CRISC.
Experience leading ISO 27001, SOC2, or HITRUST audits, including ISMS implementation and external audit coordination.
Strong understanding of NIST CSF, SOC 2, GDPR, and other security frameworks.
Hands-on experience with customer security audits, including responding to security questionnaires and managing security assessments.
Ability to perform risk assessments, policy reviews, and compliance gap analyses.
Strong written and verbal communication skills, with the ability to explain technical concepts to non-technical stakeholders.
Detail-oriented with excellent organizational and project management skills.
Ability to work independently and collaboratively in a remote environment.
Familiarity with GRC tools (e.g., OneTrust, LogicGate, Archer, Vanta, Drata) is a plus.
We value diversity and believe the unique contributions each of us brings drives our success. We do not discriminate on the basis of race, sex, religion, color, national origin, gender identity, age, marital status, veteran status, or disability status.
Note: OneStudyTeam is unable to sponsor work visas at this time. If you are a non-U.S. resident applicant, please note that OneStudyTeam works with a Professional Employer Organization.
As a condition of employment, you will abide by all organizational security and privacy policies.
This organization participates in E-Verify (E-Verify's Right to Work guidance can be found here).
Senior Security Analyst
Cyber security analyst job in Boston, MA
We are seeking a detail-oriented and highly skilled Security Analyst to join our team in Boston and shape the future of Cybersecurity. As a Security Analyst at 7AI, you will leverage your expertise of the security landscape to review and analyze AI Agent investigations, ensuring accuracy and completeness, ultimately helping to build our multi-agent platform. You will be integral in building and maintaining the reliability of our AI Agents, working in tandem with Engineering and Product to inform our roadmap as we build. If you want to build the next generation of Cybersecurity and put AI in the hands of defenders, please apply below.
Key Responsibilities:
Review and validate alerts and investigations completed by the AI Agents for accuracy and completeness.
Collaborate with the Engineering and Product teams to provide feedback and assist in optimizing the AI platform.
Develop internal playbooks, standard operating procedures and tools that will guide the AI Agents to perform quality investigations.
Stay current with emerging cybersecurity trends, vulnerabilities, and new attack techniques, especially the field of AI-driven attacks.
Investigate flagged security incidents, analyzing potential threats and confirming the findings generated by AI.
Recommend mitigation strategies and remediation steps to train the AI to reduce the threat surface.
Correlate findings from multiple sources, including network logs, endpoint data, and threat intelligence, to validate AI-generated reports.
Assist with ongoing threat monitoring, triage, and prioritization of security incidents.
Required Qualifications:
4+ years of experience in a Security Analyst or similar role within the cybersecurity field.
Hands-on experience with incident response for Cloud and Identity alerts, and at least two of Email, EDR, Threat Intel and Networking alerts.
Strong understanding of security monitoring tools and techniques (SIEM, IDS/IPS, IDP, etc.).
Experience analyzing and investigating security alerts from multiple sources, including intrusion detection systems, network monitoring tools, and endpoint protection platforms.
Familiarity with the latest cybersecurity threats, attack vectors, and vulnerabilities.
Strong analytical and problem-solving skills, with the ability to verify AI-driven analysis and make independent security decisions.
Scripting experience with languages such as Python
Data querying experience with SIEM technologies (SPL, KQL, FQL, SQL, etc).
Auto-ApplyEngineer, Information Security and Risk
Cyber security analyst job in Boston, MA
Cardinal Health, Inc. (NYSE: CAH) is a global healthcare services and products company. We provide customized solutions for hospitals, healthcare systems, pharmacies, ambulatory surgery centers, clinical laboratories, physician offices and patients in the home. We are a distributor of pharmaceuticals and specialty products; a global manufacturer and distributor of medical and laboratory products; an operator of nuclear pharmacies and manufacturing facilities; and a provider of performance and data solutions. Working to be healthcare's most trusted partner, our customer-centric focus drives continuous improvement and leads to innovative solutions that improve the lives of people every day. With approximately 50,000 employees worldwide, Cardinal Health ranks among the top fifteen in the Fortune 500.
**_Department Overview:_**
**Information Technology** oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value.
**Information Security and Risk** develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure, or destruction. This job family develops system back-up and disaster recovery plans, conducts incident responses, threat management, vulnerability scanning, virus management and intrusion detection as well as completes risk assessments.
**Responsibilities:**
+ **M&A Integration Execution:** Collaborate and engage with IAM Lead and other business partners on planning, design, and execution of IAM integration strategies for M&A activities, ensuring alignment with overall business and security objectives. This includes assessing the IAM landscapes of merging entities to identify challenges and solutions.
+ **Design and Implement Sailpoint IIQ Solutions:** Configure and customize Sailpoint IIQ components (Lifecycel Manager, Compliance Manager etc). Also develop workflows, rules, and connectors for identity governance.
+ **Application integration with Sailpoint IIQ:** Integrate Sailpoint IIQ with enterprise applications, directories and cloud platforms in addition to developing and maintaining connectros for provisioning and de-provisioning.
+ **Sailpoint IIQ Development and Scripting:** Write and maintain BeanShell scripts, Java code and XML configurations, develop customer Sailpoint tasks and workflows.
+ **Identity System Merging & Consolidation:** Manage the complex process of merging disparate identity providers, user directories (e.g., Active Directory, Azure AD, LDAP), and access management systems from acquired companies into the existing infrastructure.
+ **User Lifecycle Management:** Streamline and automate user provisioning, de-provisioning, and periodic access reviews for employees, contractors, and partners across all integrated systems, ensuring smooth onboarding and offboarding during M&A transitions.
+ **Security & Compliance:** Ensure IAM systems and processes comply with regulatory requirements (e.g., GDPR, HIPAA, SOX) and internal security policies, providing auditable records of access activities. Protect against data breaches by ensuring only authorized personnel can access sensitive information.
+ **Technical Troubleshooting & Support:** Troubleshoot, identify, and resolve technical identity and access management-related issues, providing expert support to internal teams and end-users during and after integration.
+ **Collaboration & Communication:** Coordinate cross-functional teams, including Information Security, IT Operations, HR, and Application Development, to ensure effective IAM implementation and seamless integration with business processes. Communicate complex security concepts to technical and non-technical stakeholders.
+ **Documentation & Best Practices:** Develop, review, and maintain comprehensive technical documentation, including architecture diagrams, configuration guides, and operational procedures. Stay up-to-date with IAM best practices, regulatory requirements, and security trends.
**Qualifications**
+ Experience with SailPoint IdentityIQ (IIQ) is a must
+ Experience with SailPoint IIQ Integrations (Workday, Active Directory/LDAP, Webservices, SCIM, JDBC, SAP)
+ Experience implementing Life Cycle Manager (LCM) Configuration workflow tasks that model business functions, including Lifecycle Requests (Role or Entitlement), Lifecycle Events (Joiner, Mover, or Leaver), and LCM Workflow Details (Workflows and Subprocesses)
+ Solid understanding of the SailPoint object model, rules, and policies
+ Experience with both lifecycle manager (LCM) and compliance manager (CM) modules
+ Knowledge of Active Directory, LDAP, Workday, and cloud platforms (GCP, MS Entra ID) is required
+ Proven track record of successful IAM implementations including large scale enterprise deployments.
+ Experience working within regulatory standards and requirements such as, SOX, HIPAA, GDPR etc. is desired.
**Anticipated salary range:** $94,900 - $135,600
**Bonus eligible:** No
**Benefits:** Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
+ Medical, dental and vision coverage
+ Paid time off plan
+ Health savings account (HSA)
+ 401k savings plan
+ Access to wages before pay day with my FlexPay
+ Flexible spending accounts (FSAs)
+ Short- and long-term disability coverage
+ Work-Life resources
+ Paid parental leave
+ Healthy lifestyle programs
**Application window anticipated to close:** 12/20/2025 *if interested in opportunity, please submit application as soon as possible.
The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.
_Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply._
_Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal_ _Opportunity/Affirmative_ _Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law._
_To read and review this privacy notice click_ here (***************************************************************************************************************************
Information Security Specialist
Cyber security analyst job in Biddeford, ME
Fiber Materials Inc. | solutions for the most extreme places in the universe
FMI's manufacturing facility has been a leading solutions provider of high temperature materials and composites for more than 50 years, serving the Department of Defense and NASA. The focus in Maine is on multidirectional reinforced Carbon/Carbon (C/C) and Ceramic Matrix Composites (CMCs) that enable high-temperature components such as: thermal protection systems, re-entry vehicle nose tips as well as rocket motor throats and nozzles.
Our materials are being used on ground-breaking space initiatives such as the Orion Multi-Purpose Crew Vehicle and the heat shield for NASA's Mars 2020 mission, important missile programs, airfoils in commercial and military jet engines, and as lightweight armor for U.S. military ground vehicles.
Your role: FMI is seeking an Information Security Specialist to support a small, stand-alone classified information system(s) in support of a U.S. Government contract(s). As the Information Security Specialist, you will encompass the responsibilities of an Information System Security Officer (ISSO) and Information System Security Engineer (ISSE). To be successful, you will be responsible for compliance, operations, and technical security engineering of the classified environment. Please keep in mind this role is NOT remote.
Job Responsibilities:
Operational Security (ISSO Duties):
Perform continuous monitoring and day-to-day security administration of the system.
Manage user access, account creation, and audit log reviews.
Conduct security training and briefings for system users.
Document and report security incidents, vulnerabilities, and mitigation actions.
Engineering & Technical Security (ISSE Duties):
Design, implement, and maintain technical security controls for the system.
Evaluate, recommend, and integrate security solutions for classified IT environments.
What we need from you:
Associate's degree in Cybersecurity, Information Technology, or related field; equivalent experience considered
1-3 years of experience in information system security
Active or ability to obtain and maintain an U.S. Government security clearance (Secret or above)
Effective time management
Technical proficiency
Detail oriented
Strong listening skills
Customer focus
Self-motivated
Strong interpersonal skills
Ability to work independently and as part of a team in a fast-paced environment
Knowledge of NIST and or CMMC cybersecurity frameworks and standards
Understanding in cyber security assessment tools and methodologies
Understanding network and system security, intrusion detection and prevention, and incident response
Excellent analytical and problem-solving skills
Commitment to continuous learning and staying current with industry developments
Excellent communication and documentation skills
What you'll get from us:
16 ETO days
12 paid holidays (including Winter Closure!)
Medical / Dental / Vision
401k Company Match
Tuition Reimbursement
$1000 Sign-On Bonus
Senior Security Engineer
Cyber security analyst job in Portland, ME
Our Fortune 500 company is driving a digital transformation and looking for forward-thinking innovators to disrupt how our industry thinks about and uses technology. As one of the world's leading employee benefits providers, we help millions of people gain affordable access to benefits that help them protect their families, their finances and their futures.
Are you an asker of questions, a solver of problems, and a challenger of the status quo? Our mission is to provide a differentiated customer experience and exceed the expectations people have of technology at any company - not just insurers.
We are seeking individuals to join our team of talented IT professionals who share never-ending passion and an unwavering focus on our customer experience. Team members comfortable working in an agile, fast-paced, and delivery-focused environment thrive in our environment where we value an entrepreneurial spirit and those who challenge the status-quo.
Unum is changing, and we're excited about what's next. Join us.
General Summary:
Senior Security Engineer
Join a team where your expertise shapes enterprise-wide security strategy. We're seeking a Senior Security Engineer to lead the design and execution of cutting-edge security architecture and defense frameworks that protect critical assets across our global organization.
In this role, you'll:
Influence corporate-level security decisions
Architect and operate a depth-in-defense security framework
Drive Identity & Access Management and privileged access solutions
Collaborate with IT and business leaders to integrate secure technologies
Partner with internal and external audit teams to ensure compliance
You'll be solving complex security challenges, building scalable solutions, and helping shape the future of cybersecurity at Unum.
Job Specifications
* Bachelor's or advanced degree in computer science or related discipline preferred or comparable work experience.
* 6+ years of related work experience in information technology engineering, support or consulting experience. Preferred if two of those years was spent in networking, application development, system security or IT Audit related positions.
Demonstrated ability and success in:
* Working effectively in an ambiguous environment, functioning independently, and effectively working across geographical locations.
* Detecting and analyzing hostile and other improper actions in such an environment.
* Investigating and responding to security alerts, or new security threats with a sense of urgency.
* Strong oral and written communications skills
* Strong analytical and problem-solving skills and proactive thinking skills
* Strong Knowledge of (at least one) UNIX, Windows, Mainframe, and/or Apple Operating System vulnerabilities and secure configuration settings
* Strong Knowledge of threats and vulnerabilities associated with application and network security.
* Strong Knowledge of the principles of implementation and operation and experience with security technology such as firewalls, multi-level security implementation, security assessment, monitoring and profiles tools (e.g. IDS/IPS, SEIM, AV, Qualys, etc.), and password crackers.
* Mentor and support junior level security staff
* Develops strong partnerships with client management, business clients, application developers, software vendors and other technical resources which includes, but not limited to, legal, compliance, and privacy
* Maintain close relationships with the business to understand strategy, processes, plans and needs to help influence planning by advising on best practices, innovation/technology enablement opportunities
* Communicates effectively with business partners, customers, brokers, third party suppliers/partners, and systems resources at all levels.
* Delivers effective, high-quality solutions in a timely manner while balancing shifting priorities and, at times, accelerated timelines.
* Facilitate matching business needs and services options by leveraging knowledge of business strategy, processes, and market offerings to assist in evaluating the most appropriate products and services to meet its requirements
* Provide an overall perspective or point of clarification to partner on operational aspects of a service. Has a good overall understanding of infrastructure and application portfolios to provide guidance to service partner provider.
Technical Skills for Identity & Access Management
* Experience in implementing and supporting global Identity and Access Management solutions (Identi-ty Management, Access Management, Virtual Directory, SSO)
* Knowledge and experience on Oracle OAM ,ForgeRock OpenAM and/or other Web Access Manage-ment systems (like CA SiteMinder), and API integration
* Experience on ForgeRock OpenIDM, Oracle OIM and/or other Identity management systems
* Experience on SSO (Single-Sign-On) technologies including Cloud, SAML and federation of identities (IdP initiated and SP initiated), multi-factor authentication
* Experience on CyberArk, Enterprise Certificate Management and Enterprise Token Services technol-ogies.
* Experience with LDAP/Directory Services including Active Directory and Radiant Logic
* Experience with RACF, DB2, SQL
* Experience with Azure, O365 and AWS
* Familiar with Regulations, including, GLPA, HIPAA, GDPR, CCPA, and other Cyber Security Regulatory compliance requirements and related programs
* ISO 27001/27002 the NIST Cyber Security Framework
* CISSP, CISM, SANS, and other security related certifications a plus
Technical Skills for Cyber Security
Excellent working knowledge of one or more of the following security areas desired:
* Operating System Security (Windows, Apple, AIX, Linux, zOS)
* Internet Technologies (NNTP, Proxy, HTTP, HTTPS, HTLM, SSL, X.509)
* TCP/IP and networking (LAN/WAN/Wireless)
* Intrusion Detection and Prevention products
* Incident Response Management
* Public Key Infrastructure technologies including encryption, Kerberos, certification authorities
* Application and Network Security Assessments methodologies and tools
* General Access Control Security (Active Directory, Linux, and Mainframe security)
* IPSEC and remote access technologies
* End Point Security products (i.e. Anti-virus, Malware, Hard Drive encryption)
* Ethical Hacking, Incident Response and case management.
* Forensic tools such as Oxygen, encase, Atola Forensic equipment
* Experience in implementing and operating security technology such as firewalls, multi-level security implementation, security assessment scanners, and security monitoring tools (e.g. IDS/IPS, SEIM, AV, Qualys, etc.)
* Experience in application and network security assessment methodologies, tools, and techniques
* Experience in implementing and operating global end-point security products (anti-virus, anti-malware, hard drive encryption, DLP, etc.)
* Security Coding Standards (e.g. OWASP) and Secure Software Development Lifecycles.SOX and HIPPA compliance requirements and related programs
Familiar with Regulations, including, GLPA, HIPAA, GDPR, CCPA, and other Cyber Security Regulatory compliance requirements and related programs
* ISO 27001/27002 the NIST Cyber Security Framework
* CISSP, CISM, SANS, and other security related certifications a plus
Principal Duties and Responsibilities
Performing cyber security monitoring and security incident response, including:
* Monitors for external threats and indicators of compromise
* Responds to and leads incident response for threat alerts
* Monitors for inappropriate utilization of computer resources
* Assesses reported security threats and weaknesses.
* Provides level II support for Operations
* Participates in 24/7 on-call rotation.
* Participates in ethical hacking red team/blue team exercises.
* Performs day-to-day operations and technical support, including system upgrades, on the Unum security technology portfolio.
* Consults on the security framework to IT/Business project teams, and in day-to-day business operations.
* Consults with development and business partners on integration and security configuration for new or existing software or solutions
* Participates in the evaluation of vendor's product strategies, technology roadmaps and software enhancements, and consults on the inclusion and rollout these recommendations in the corporate security roadmap.
* Develops and consults on sound security policies and procedures.
* Assists with application and network security assessments, as assigned.
* Maintains expertise to function as subject matter expert in one or more security disciplines.
* Develops strong partnerships with business clients, application developers, software vendors and other technical resources.
* Performs other duties as assigned.
#LI-AD1
#LI-MULTI
~IN1
Our company is built on helping individuals and families, and this starts with our employees. We want employees to maintain a positive balance, which is why we provide access to the benefits and resources they need to invest in themselves. From our onsite fitness facilities and generous paid time off to employee professional development programs, we are committed to helping employees live and work their best - both inside and outside the office.
Unum is an equal opportunity employer, considering all qualified applicants and employees for hiring, placement, and advancement, without regard to a person's race, color, religion, national origin, age, genetic information, military status, gender, sexual orientation, gender identity or expression, disability, or protected veteran status.
The base salary range for applicants for this position is listed below. Unless actual salary is indicated above in the job description, actual pay will be based on skill, geographical location and experience.
$98,340.00-$201,900.00
Additionally, Unum offers a portfolio of benefits and rewards that are competitive and comprehensive including healthcare benefits (health, vision, dental), insurance benefits (short & long-term disability), performance-based incentive plans, paid time off, and a 401(k) retirement plan with an employer match up to 5% and an additional 4.5% contribution whether you contribute to the plan or not. All benefits are subject to the terms and conditions of individual Plans.
Company:
Unum
Auto-ApplyPhysical Security Systems Engineer
Cyber security analyst job in Wilmington, MA
Overview
Join Allied Universal Technology Services, a global leader in transforming the security industry. We integrate advanced technology - video surveillance, electronic access control, alarm monitoring and augmented solutions with physical security to help people feel safe. Whether you're an installation technician, service technician, engineer, or project manager, you'll discover rewarding opportunities to grow your career as part of a valued team.
Apply today and be phenomenal-build a meaningful career while protecting what matters most through innovative security technology.
Job Description
Allied Universal is looking to hire a Solution Engineer. The Solution Engineer creates all post-sale security systems design, engineering, value engineering, and documentation. The position is part of the Solutions Engineering department, which is responsible for translating, expanding, finalizing, and documenting pre-sales proposals and technical designs produced by Sales and Solutions Architecture in pre-sale systems architecting and quoting. This position works closely with Sales, Solutions Architecture, Operations, and external customers as required.
The primary work products for the Solution Engineer are security system and construction technical drawings, including custom installation drawings and instructions, network design diagrams, riser diagrams, typical installation diagrams, point-to-point system schedules, door hardware schedules, document redlining, functional narratives describing systems operations, and as-built documentation.
RESPONSIBILITIES:
Creates and updates comprehensive post-sale engineering packages illustrating device locations, IDF/MDF room layouts, SOC/GSOC layouts, console designs, installation diagrams, riser diagrams, network designs, etc.
Creates and updates performance-based and product-based specifications
Creates and updates pre-fabrication submittal packages as specified by architects and engineers for their approval prior to installation
Develops and maintains as-built record documentation over the life cycle of various projects and follow-on MAC work
Utilizes and contributes to a comprehensive library of standard post-sale engineering documents, templates, and standards, as well as project-specific and customer-specific submittals
Ensures effective value engineering by assuring technical compliance while at the same time reducing Allied Universal Technology Services costs whenever possible
Reviews AUTS proposals both pre-sale and post-sale to scrutinize selected products for applicability and specification compliance
Collaborates with AUTS's product suppliers to ensure the desired functionality of selected products.
Consistently applies AUTS's standards for installation
Contributes to AUTS internal guidelines for Solutions Engineering engagement and post-sale systems engineering
QUALIFICATIONS (MUST HAVES):
A minimum of five (5) years of experience in electronic security systems design / engineering
In-depth knowledge of security system design best practices and product applicability, including products like:
Video surveillance and related technologies (Analog, IP, Codecs, VMS)
Access control and related technologies (card access, biometrics, PIV, FIPS-201, HSPD-12, various processor panels, electric locking hardware, etc.)
Physical intrusion detection (Bosch, DMP, etc.)
Software House, Lenel, Amag, Brivo, Genetec, and Avigilon systems architectures
Computer software skills to include: AutoCAD and associated rendering applications, MS Office, Acrobat Writer, and Visio
Ability to read and understand complex architectural and engineering drawings
Working knowledge of AC and DC circuitry, voltage drop calculations, and wire sizing
Ability to collaborate with diverse teams of technical designers and engineers
Ability to simultaneously work on multiple large, complex projects
Good written and verbal communication skills
Strong analytical decision-making capabilities
Self-motivated with the ability to influence others
PREFERRED QUALIFICATION (NICE TO HAVES):
Manufacture certifications
PMP/PSP certifications
A bachelor's or associate's degree in electrical engineering or equivalent is considered a plus
Ability to plan, size, and design enterprise-class IT network and storage solutions, including products like:
Virtualization technologies such as VMware vSphere and View
Data-center networking technologies such as Cisco Nexus
Storage Area Network technologies such as NetApp or EMC
Load balancing / firewalling technologies such as Cisco ACE or Cisco ASA
Data-center protocols such as Fibre Channel, NFS, IP, iSCSI, DCE
Physical Security Information Management (PSIM)
BENEFITS:
Salary: $80,000 - 115,000 / annually
Medical, dental, vision, basic life, AD&D, and disability insurance
Enrollment in our company's 401 (k) or Supplemental Income Plan, subject to eligibility requirements
Eight paid holidays annually, five sick days, and four personal days
Vacation time offered at an accrual rate of 3.08 hours biweekly. Unused vacation is only paid out where required by law.
#LI-EL1
Closing
Allied Universal is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race/ethnicity, age, color, religion, sex, sexual orientation, gender identity, national origin, genetic information, disability, protected veteran status or relationship/association with a protected veteran, or any other basis or characteristic protected by law. For more information: ***********
If you have difficulty using the online system and require an alternate method to apply or require an accommodation, please contact our local Human Resources department. To find an office near you, please visit: ***********/offices.
Requisition ID
2025-1495451
Physical Security Systems Engineer
Cyber security analyst job in Wilmington, MA
Join Allied Universal Technology Services, a global leader in transforming the security industry. We integrate advanced technology - video surveillance, electronic access control, alarm monitoring and augmented solutions with physical security to help people feel safe. Whether you're an installation technician, service technician, engineer, or project manager, you'll discover rewarding opportunities to grow your career as part of a valued team.
Apply today and be phenomenal-build a meaningful career while protecting what matters most through innovative security technology.
Job Description
Allied Universal is looking to hire a Solution Engineer. The Solution Engineer creates all post-sale security systems design, engineering, value engineering, and documentation. The position is part of the Solutions Engineering department, which is responsible for translating, expanding, finalizing, and documenting pre-sales proposals and technical designs produced by Sales and Solutions Architecture in pre-sale systems architecting and quoting. This position works closely with Sales, Solutions Architecture, Operations, and external customers as required.
The primary work products for the Solution Engineer are security system and construction technical drawings, including custom installation drawings and instructions, network design diagrams, riser diagrams, typical installation diagrams, point-to-point system schedules, door hardware schedules, document redlining, functional narratives describing systems operations, and as-built documentation.
RESPONSIBILITIES:
Creates and updates comprehensive post-sale engineering packages illustrating device locations, IDF/MDF room layouts, SOC/GSOC layouts, console designs, installation diagrams, riser diagrams, network designs, etc.
Creates and updates performance-based and product-based specifications
Creates and updates pre-fabrication submittal packages as specified by architects and engineers for their approval prior to installation
Develops and maintains as-built record documentation over the life cycle of various projects and follow-on MAC work
Utilizes and contributes to a comprehensive library of standard post-sale engineering documents, templates, and standards, as well as project-specific and customer-specific submittals
Ensures effective value engineering by assuring technical compliance while at the same time reducing Allied Universal Technology Services costs whenever possible
Reviews AUTS proposals both pre-sale and post-sale to scrutinize selected products for applicability and specification compliance
Collaborates with AUTS's product suppliers to ensure the desired functionality of selected products.
Consistently applies AUTS's standards for installation
Contributes to AUTS internal guidelines for Solutions Engineering engagement and post-sale systems engineering
QUALIFICATIONS (MUST HAVES):
A minimum of five (5) years of experience in electronic security systems design / engineering
In-depth knowledge of security system design best practices and product applicability, including products like:
Video surveillance and related technologies (Analog, IP, Codecs, VMS)
Access control and related technologies (card access, biometrics, PIV, FIPS-201, HSPD-12, various processor panels, electric locking hardware, etc.)
Physical intrusion detection (Bosch, DMP, etc.)
Software House, Lenel, Amag, Brivo, Genetec, and Avigilon systems architectures
Computer software skills to include: AutoCAD and associated rendering applications, MS Office, Acrobat Writer, and Visio
Ability to read and understand complex architectural and engineering drawings
Working knowledge of AC and DC circuitry, voltage drop calculations, and wire sizing
Ability to collaborate with diverse teams of technical designers and engineers
Ability to simultaneously work on multiple large, complex projects
Good written and verbal communication skills
Strong analytical decision-making capabilities
Self-motivated with the ability to influence others
PREFERRED QUALIFICATION (NICE TO HAVES):
Manufacture certifications
PMP/PSP certifications
A bachelor's or associate's degree in electrical engineering or equivalent is considered a plus
Ability to plan, size, and design enterprise-class IT network and storage solutions, including products like:
Virtualization technologies such as VMware vSphere and View
Data-center networking technologies such as Cisco Nexus
Storage Area Network technologies such as NetApp or EMC
Load balancing / firewalling technologies such as Cisco ACE or Cisco ASA
Data-center protocols such as Fibre Channel, NFS, IP, iSCSI, DCE
Physical Security Information Management (PSIM)
BENEFITS:
Salary: $80,000 - 115,000 / annually
Medical, dental, vision, retirement plan, basic life, AD&D, and disability insurance
Eight paid holidays annually, five sick days, and four personal days
Vacation time offered at an accrual rate of 3.08 hours biweekly. Unused vacation is only paid out where required by law
#LI-EL1
Closing
Allied Universal is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race/ethnicity, age, color, religion, sex, sexual orientation, gender identity, national origin, genetic information, disability, protected veteran status or relationship/association with a protected veteran, or any other basis or characteristic protected by law. For more information: ***********
If you have difficulty using the online system and require an alternate method to apply or require an accommodation, please contact our local Human Resources department. To find an office near you, please visit: ***********/offices.
Requisition ID 2025-1495451
Auto-ApplySecurity Technical Engineer
Cyber security analyst job in Auburn, ME
Connectivity Point is seeking a highly skilled Security Technical Engineer to serve as the critical link between our field technicians and design team. This role ensures that purchased systems are installed accurately, efficiently, and in alignment with customer expectations-delivering exceptional customer service while supporting project profitability.
JOB RESPONSIBILITIES:
Review project documentation to gain thorough understanding and check for accuracy.
Create and maintain system configuration software.
Work with design team to create and update project installation documents using Bluebeam, Visio, Excel, and/or CAD as needed.
Coordinate on-site implementation process for security installations and service requests.
Travel as necessary. This may include overnight travel out of state.
Work with the security design engineers both presale and post-sale.
Oversee implementation of security solutions to ensure that equipment is installed per industry standards and best practices. This may require working in the field along with security technicians to accomplish the installation objective, timeline, and goal of customer satisfaction.
Report any out of scope work required to allow for change order generation as needed.
Participate in customer construction status calls/meetings as required.
Provide detailed project field status updates to security PM and Division Manager.
Provide end user training on newly installed systems.
Strengthen customer relationships by being responsible, accurate, helpful, and trustworthy.
Proactively look for opportunities to provide more value-add services to customers.
Assist with maintaining customer profiles and standards documents to ensure accuracy.
Provide remote technical support for out-of-market technicians in the field as needed.
Assist with ensuring customer profile documents are maintained and updated.
Stay up to date on security technologies and installation practices.
Work with the rest of the security team to evaluate new products and services.
Support existing customers remotely or in person as needed.
Perform other assigned duties as requested.
SKILLS/EXPERIENCE/TRAINING:
High School Diploma or General Education Degree (GED)
and
four to five years minimum industry experience in security system sales, management, service, or installation;
or
the equivalent combination of education and experience
Solid security system industry experience including sales, service, project management and/or installation of security systems, access control, and CCTV.
Kantech, DSC, and Exacqvision software experience.
Ability to follow blueprints, notes and specifications to meets the job requirements.
Basic written and verbal communications skills.
Proven ability to follow instructions and focused attention to detail.
Experience with construction and adherence to large and small project scheduling.
Enjoys hands-on problem solving in a fast paced work environment.
Ability to work well both independently and as part of a professional team.
Excellent time management, planning and forward-thinking skills.
Self-motivated with a positive and professional attitude.
Excellent communication and listening skills.
Strong teambuilding, customer service, and interpersonal skills.
Must possess good decision-making skills, be very organized and detail oriented.
Strong computer skills using Microsoft Office suite (i.e., Word, Excel, Outlook) required.
T
his job description is not intended to be and should not be construed as an all-inclusive list of all the responsibilities, skills or working conditions associated with the position. While it is intended to accurately reflect the position activities and requirements, the Company reserves the right to modify, add or remove duties and assign other duties as necessary.
Facility Security Officer & Information Systems Security Officer (Onsite)
Cyber security analyst job in North Berwick, ME
Country: United States of America Onsite U.S. Citizen, U.S. Person, or Immigration Status Requirements: Active and transferable U.S. government issued security clearance is required prior to start date. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance
Security Clearance:
DoD Clearance: Secret
Pratt & Whitney is working to once again transform the future of flight-designing, building and servicing engines unlike any the world has ever seen. And because transformation begins from within, we're seeking the people to drive it. So, calling all curious.
Come ready to explore and you'll find a place where your talent takes flight-beyond the borders of title, a country or your comfort zone. Bring your passion and commitment and we'll welcome you into a tight-knit team that takes our mission personally. Channel your drive to make a difference into shaping an organization and an industry that's evolving fast to the future.
At Pratt & Whitney, the difference you make is on display every day. Just look up. Are you ready to go beyond?
What You Will Do:
Support Pratt & Whitney's Government Security Compliance team as the Facility Security Officer (FSO) / Information Systems Security Officer (ISSO) for the North Berwick, ME facility. This critical leadership role ensures compliance with the National Industrial Security Program (NISP), NISP Operating Manual (NISPOM), Defense Counterintelligence and Security Agency (DCSA) standards, and other applicable government regulations. The FSO/ISSO will oversee security operations for a cleared facility, ensuring the protection of classified information, systems, and personnel while fostering a culture of security excellence.
Key Responsibilities:
The FSO/ISSO will report directly to the Pratt & Whitney Associate Director, Corporate Facility Security Officer, and will be responsible for the following:
* Leadership and Compliance:
* Lead the formulation, establishment, and execution of local collateral security policies, procedures, and protocols to ensure compliance with NISP, DAAPM, ICDs, and other governing regulations.
* Serve as the primary interface with internal and external stakeholders, including government agencies, subcontractors, and P&W leadership.
* Security Program Oversight:
* Manage the facility's classified holdings, maintain CAGE code facility clearance, and process changes in conditions.
* Conduct and oversee security program reviews, including DCSA inspections, self-inspections, and formal audits.
* Investigate and report security incidents/violations in collaboration with the Corporate FSO and Cognizant Security Authority.
* Insider Threat Program:
* Serve as a key member of the Insider Threat Management Council and liaise with the Corporate Insider Threat Program Senior Official (ITPSO).
* Provide North Berwick leadership and guidance on Insider Threat Program activities and initiatives.
* Information Systems Security:
* Collaborate with the Information Systems Security Manager (ISSM) to ensure the operational security posture of information systems.
* Manage user account requests, monitor user activity, and analyze audit records to identify and address anomalies.
* Support incident response activities in the event of security violations or breaches.
* Stakeholder Engagement:
* Foster effective communication and collaboration with government customers, associated contractors, subcontractors, P&W teams, and North Berwick senior leadership.
* Represent the GSC team as a project manager on select core projects and initiatives.
* Training and Development:
* Attend technical and security training to maintain expertise in security management, operating systems, and networking.
* Provide guidance and training to facility staff on security responsibilities and best practices.
* Serve as the Government Security Compliance Data Transfer Agent program focal:
* Provide leadership and oversight for the Data Transfer Agent (DTA) program, ensuring compliance with regulatory and customer requirements.
* Serve as the primary point of contact for customers regarding DTA program compliance and functionality.
* Collaborate with internal stakeholders to maintain and enhance program effectiveness and security.
* Develop and implement best practices, policies, and procedures for secure and efficient data transfer.
* Monitor program performance and drive continuous improvement to meet evolving security and customer needs.
* Other Duties:
* Perform additional tasks as directed by the Corporate Facility Security Officer.
* Coordinate and support the North Berwick Security Staff as directed.
Qualifications You Must Have:
* Advanced degree and 5+ years of experience in industrial security, cybersecurity, government compliance, or government regulated industry; OR Bachelor's degree and 8+ years of relevant industry experience; OR an Associate's degree and 10+ years of relevant industry experience. We will also consider high school diploma, technical or military training, or recognized industry certifications in combination with 12+ years or relevant industry experience.
* 1+ Year of hands-on experience supporting administering and/or maintaining computing systems, networks and/or software
* Active U.S. government issued Secret level security clearance required plus ability to obtain and maintain a Top-Secret level security clearance. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance.
* Must be able to obtain industry recognized Cybersecurity certification within 12 months of hire (i.e. Security + CE)
Qualifications You Prefer:
* Strong understanding of the NISPOM, DAAPM, ICDs, and other security regulations.
* Experience with DISS, NISS, SIMS, and other DCSA related databases.
* Proficiency in managing classified information systems and working with DCSA inspections.
* Cybersecurity certification (i.e. Security + CE).
* Facility Security Officer (FSO) certification.
* Information Systems Security Officer (ISSO) certification.
* Proven leadership experience, preferably within a defense, aerospace, or government environment.
* Experience with Insider Threat Programs and related compliance activities.
* Strong project management skills and the ability to manage multiple priorities effectively.
What is my Role Type?
In addition to transforming the future of flight, we are also transforming how and where we work. We've introduced role types to help you understand how you will operate in our blended work environment. This role is:
* Onsite: Employees who are working in Onsite roles will work primarily onsite. This includes all production and maintenance workers, as they are essential to the development of our engines.
Candidates will learn more about role type and current site status throughout the recruiting process. For onsite and hybrid roles, commuting to and from the assigned site is the employee's personal responsibility.
Learn more & apply today!
As part of our commitment to maintaining a secure hiring process, candidates may be asked to attend select steps of the interview process in-person at one of our office locations, regardless of whether the role is designated as on-site, hybrid or remote.
The salary range for this role is 101,000 USD - 203,000 USD. The salary range provided is a good faith estimate representative of all experience levels. RTX considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate's work experience, location, education/training, and key skills.
Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement.
Hired applicants may be eligible for annual short-term and/or long-term incentive compensation programs depending on the level of the position and whether or not it is covered by a collective-bargaining agreement. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company's performance.
This role is a U.S.-based role. If the successful candidate resides in a U.S. territory, the appropriate pay structure and benefits will apply.
RTX anticipates the application window closing approximately 40 days from the date the notice was posted. However, factors such as candidate flow and business necessity may require RTX to shorten or extend the application window.
RTX is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or veteran status, or any other applicable state or federal protected class. RTX provides affirmative action in employment for qualified Individuals with a Disability and Protected Veterans in compliance with Section 503 of the Rehabilitation Act and the Vietnam Era Veterans' Readjustment Assistance Act.
Privacy Policy and Terms:
Click on this link to read the Policy and Terms
Auto-ApplyFacility Security Officer & Information Systems Security Officer (Onsite)
Cyber security analyst job in North Berwick, ME
Country:
United States of America Onsite
U.S. Citizen, U.S. Person, or Immigration Status Requirements:
Active and transferable U.S. government issued security clearance is required prior to start date. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance
Security Clearance:
DoD Clearance: Secret
Pratt & Whitney is working to once again transform the future of flight-designing, building and servicing engines unlike any the world has ever seen. And because transformation begins from within, we're seeking the people to drive it. So, calling all curious.
Come ready to explore and you'll find a place where your talent takes flight-beyond the borders of title, a country or your comfort zone. Bring your passion and commitment and we'll welcome you into a tight-knit team that takes our mission personally. Channel your drive to make a difference into shaping an organization and an industry that's evolving fast to the future.
At Pratt & Whitney, the difference you make is on display every day. Just look up. Are you ready to go beyond?
What You Will Do:
Support Pratt & Whitney's Government Security Compliance team as the Facility Security Officer (FSO) / Information Systems Security Officer (ISSO) for the North Berwick, ME facility. This critical leadership role ensures compliance with the National Industrial Security Program (NISP), NISP Operating Manual (NISPOM), Defense Counterintelligence and Security Agency (DCSA) standards, and other applicable government regulations. The FSO/ISSO will oversee security operations for a cleared facility, ensuring the protection of classified information, systems, and personnel while fostering a culture of security excellence.
Key Responsibilities:
The FSO/ISSO will report directly to the Pratt & Whitney Associate Director, Corporate Facility Security Officer, and will be responsible for the following:
Leadership and Compliance:
Lead the formulation, establishment, and execution of local collateral security policies, procedures, and protocols to ensure compliance with NISP, DAAPM, ICDs, and other governing regulations.
Serve as the primary interface with internal and external stakeholders, including government agencies, subcontractors, and P&W leadership.
Security Program Oversight:
Manage the facility's classified holdings, maintain CAGE code facility clearance, and process changes in conditions.
Conduct and oversee security program reviews, including DCSA inspections, self-inspections, and formal audits.
Investigate and report security incidents/violations in collaboration with the Corporate FSO and Cognizant Security Authority.
Insider Threat Program:
Serve as a key member of the Insider Threat Management Council and liaise with the Corporate Insider Threat Program Senior Official (ITPSO).
Provide North Berwick leadership and guidance on Insider Threat Program activities and initiatives.
Information Systems Security:
Collaborate with the Information Systems Security Manager (ISSM) to ensure the operational security posture of information systems.
Manage user account requests, monitor user activity, and analyze audit records to identify and address anomalies.
Support incident response activities in the event of security violations or breaches.
Stakeholder Engagement:
Foster effective communication and collaboration with government customers, associated contractors, subcontractors, P&W teams, and North Berwick senior leadership.
Represent the GSC team as a project manager on select core projects and initiatives.
Training and Development:
Attend technical and security training to maintain expertise in security management, operating systems, and networking.
Provide guidance and training to facility staff on security responsibilities and best practices.
Serve as the Government Security Compliance Data Transfer Agent program focal:
Provide leadership and oversight for the Data Transfer Agent (DTA) program, ensuring compliance with regulatory and customer requirements.
Serve as the primary point of contact for customers regarding DTA program compliance and functionality.
Collaborate with internal stakeholders to maintain and enhance program effectiveness and security.
Develop and implement best practices, policies, and procedures for secure and efficient data transfer.
Monitor program performance and drive continuous improvement to meet evolving security and customer needs.
Other Duties:
Perform additional tasks as directed by the Corporate Facility Security Officer.
Coordinate and support the North Berwick Security Staff as directed.
Qualifications You Must Have:
Advanced degree and 5+ years of experience in industrial security, cybersecurity, government compliance, or government regulated industry; OR Bachelor's degree and 8+ years of relevant industry experience; OR an Associate's degree and 10+ years of relevant industry experience. We will also consider high school diploma, technical or military training, or recognized industry certifications in combination with 12+ years or relevant industry experience.
1+ Year of hands-on experience supporting administering and/or maintaining computing systems, networks and/or software
Active U.S. government issued Secret level security clearance required plus ability to obtain and maintain a Top-Secret level security clearance. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance.
Must be able to obtain industry recognized Cybersecurity certification within 12 months of hire (i.e. Security + CE)
Qualifications You Prefer:
Strong understanding of the NISPOM, DAAPM, ICDs, and other security regulations.
Experience with DISS, NISS, SIMS, and other DCSA related databases.
Proficiency in managing classified information systems and working with DCSA inspections.
Cybersecurity certification (i.e. Security + CE).
Facility Security Officer (FSO) certification.
Information Systems Security Officer (ISSO) certification.
Proven leadership experience, preferably within a defense, aerospace, or government environment.
Experience with Insider Threat Programs and related compliance activities.
Strong project management skills and the ability to manage multiple priorities effectively.
What is my Role Type?
In addition to transforming the future of flight, we are also transforming how and where we work. We've introduced role types to help you understand how you will operate in our blended work environment. This role is:
Onsite: Employees who are working in Onsite roles will work primarily onsite. This includes all production and maintenance workers, as they are essential to the development of our engines.
Candidates will learn more about role type and current site status throughout the recruiting process. For onsite and hybrid roles, commuting to and from the assigned site is the employee's personal responsibility.
Learn more & apply today!
As part of our commitment to maintaining a secure hiring process, candidates may be asked to attend select steps of the interview process in-person at one of our office locations, regardless of whether the role is designated as on-site, hybrid or remote.
The salary range for this role is 101,000 USD - 203,000 USD. The salary range provided is a good faith estimate representative of all experience levels. RTX considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate's work experience, location, education/training, and key skills.Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement.Hired applicants may be eligible for annual short-term and/or long-term incentive compensation programs depending on the level of the position and whether or not it is covered by a collective-bargaining agreement. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company's performance.This role is a U.S.-based role. If the successful candidate resides in a U.S. territory, the appropriate pay structure and benefits will apply.RTX anticipates the application window closing approximately 40 days from the date the notice was posted. However, factors such as candidate flow and business necessity may require RTX to shorten or extend the application window.
RTX is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or veteran status, or any other applicable state or federal protected class. RTX provides affirmative action in employment for qualified Individuals with a Disability and Protected Veterans in compliance with Section 503 of the Rehabilitation Act and the Vietnam Era Veterans' Readjustment Assistance Act.
Privacy Policy and Terms:
Click on this link to read the Policy and Terms
Auto-Apply