Security Engineer, WWPS Solutions Architecture
Cyber Security Analyst Job 364 miles from Victorville
requires that the selected candidate has U.S. citizenship. Amazon Web Services is looking for a security focused Engineer for the Controlled Working Environment (CWE) program. We are seeking an experienced and motivated Security Engineer (SE) to expand our Security Operating Center (SOC) and maintain security compliance in this working environment. The right candidate must thrive in high-pressure situations, think like both an attacker and defender, and drive relevant teams to take the right actions in the right time frames to mitigate risks.
We are looking for an individual with a deep understanding on how to balance business and technical risk that can effect the program. The candidate should be able to identify IT risks, define a mitigation plan to remediate, and consistently drive for the right results. They must have a passion for engineering novel solutions to complex security challenges, and recognize and fill gaps in capabilities. The ability to quickly design and build internal-facing tools that enable scaled programmatic automation is a plus.
The successful candidate will have a good mix of broad technical knowledge and a demonstrated background in information security. We value broad and deep technical knowledge, specifically in the fields of Windows forensics, Cloud security, security operations, incident response, network security, and emergent security intelligence.
An ideal candidate should be able to accomplish most of the following:
* Confidently and intelligently respond to security incidents, and proactively consider how to prevent the same type of incidents from occurring in the future.
* Design and coordinate cohesive responses to security events that involve multiple teams across the organization.
* Build security utilities and tools that enable the team to operate at high speed and wide scale.
* Evaluate the impact of current security threats, advisories, publications, and academic research to the organization. Identify plans of action and coordinate as necessary across teams to mitigate risk.
* Ability to communicate effectively at different levels of sensitivity, knowledge, and audiences.
* Recognize, adopt, and instill the best practices of security engineering throughout the organization
* Fulfill regular on-call responsibilities.
Amazon has a fast-paced environment where we “Work Hard, Have Fun, Make History.” On a “typical” day engineers might deep dive to root cause a customer issue, investigate why a metric is trending the wrong way, consult with the top engineers at Amazon, or discuss radical new approaches to automate operational issues.
About the team
Diverse Experiences
Amazon values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn't followed a traditional path, or includes alternative experiences, don't let it stop you from applying.
Why AWS
Amazon Web Services (AWS) is the world's most comprehensive and broadly adopted cloud platform. We pioneered cloud computing and never stopped innovating - that's why customers from the most successful startups to Global 500 companies trust our robust suite of products and services to power their businesses.
Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there's nothing we can't achieve in the cloud.
Inclusive Team Culture
Here at AWS, it's in our nature to learn and be curious. Our employee-led affinity groups foster a culture of inclusion that empower us to be proud of our differences. Ongoing events and learning experiences, including our Conversations on Race and Ethnicity (CORE) and AmazeCon (gender diversity) conferences, inspire us to never stop embracing our uniqueness.
Mentorship and Career Growth
We're continuously raising our performance bar as we strive to become Earth's Best Employer. That's why you'll find endless knowledge-sharing, mentorship and other career-advancing resources here to help you develop into a better-rounded professional.
AWS Sales, Marketing, and Global Services (SMGS) is responsible for driving revenue, adoption, and growth from the largest and fastest growing small- and mid-market accounts to enterprise-level customers including public sector. The AWS Global Support team interacts with leading companies and believes that world-class support is critical to customer success. AWS Support also partners with a global list of customers that are building mission-critical applications on top of AWS services.
BASIC QUALIFICATIONS- BS degree in Computer Science, MIS, Computer Engineering, or other technical degree or 3+ year's equivalent technology experience.
- Minimum of 3 years' experience in three or more of the following: incident response, application security, network security, security operations, or network engineering, with at least two years of experience on a Security Operations team, especially coordinating responses to security incidents.
- Experience using industry-standard SIEMs, especially ElasticSearch.
- Experience with security operations of Window and Linux operating system (OS) environments, (e.g. Windows system, security, application event logs)
- Experience working with AWS security services (e.g. AWS Security hub, Amazon GuardDuty, AWS Config, etc)
- This position requires that the candidate selected be a U.S. citizen.
PREFERRED QUALIFICATIONS- Security related certifications such as OSCP, CISSP, CCSP, RHCSA, CompTIA Security+ Linux+, GIAC, GCIH, GCFA, GCIA, GPEN, GNFA, GCUX, CE
- Effective written and oral communication with multiple levels of leadership involving both business and technical teams.
- Experience in scripting or programming (Ruby, Python, Shell/BASH, Java, etc.) and automation of security tasks through scripting/programming.
- Experience in compliance requirements (e.g. NIST, ISO, HIPAA, FedRAMP, etc.).
- Extensive knowledge of internet security issues, cloud architectures, threat landscape, and experience with virtualization technologies like AWS services.
Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.
Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company's reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit ********************************************************* for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $136,000/year in our lowest geographic market up to $212,800/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit ******************************************************** This position will remain posted until filled. Applicants should apply via our internal or external career site.
Cyber Security Analyst
Cyber Security Analyst Job 117 miles from Victorville
🚨 We're Hiring: Cyber Security Analyst (or Sr. Cyber Security Analyst)
📍
On-site role | San Diego, CA
💸
Salary: $115,000 - $145,000 (DOE)
We're currently partnering with an innovative tech-driven company in the healthcare sector that's scaling its internal cyber security team. They're looking for a skilled and proactive Cyber Security Analyst who's passionate about protecting digital environments, loves solving problems, and thrives in a collaborative, fast-paced setting.
This role involves a balance of blue team and red team activities - perfect for someone who enjoys both defense and offense in the cyber space 🧠⚔️
🔍 What You'll Be Doing:
🛠️ Investigating escalated security incidents across Windows and Linux environments
🔍 Conducting threat hunts and assessments across enterprise IT infrastructure
⚙️ Using offensive security tools (BAS platforms) to improve detection capabilities
📊 Analyzing and tuning SIEM logs and alerts for better signal-to-noise
📚 Developing and maintaining runbooks and incident response playbooks
🧱 Contributing to system hardening and CIS Benchmark implementation
🔬 Staying current with threats, vulnerabilities, and attack techniques
🧠 What We're Looking For:
4+ years' experience working in SIEM, incident response, or threat detection
Strong knowledge of Windows & Linux security
Comfortable working across both offensive and defensive cyber domains
Excellent verbal and written communication skills
Familiarity with forensic practices a plus
Preferred (but not required) certifications: GCFE, GCIH, GCIA, GCED, GCWN, GMON, GCUX, GCDA
Degree in Computer Science, Engineering, or equivalent experience
💼 What's In It For You?
🩺 Full medical, dental, and vision coverage (with telehealth options)
💊 Convenient 90-day prescription mail-order service
💸 Health Savings Account (HSA) with quarterly company contributions
🎓 Tuition assistance for ongoing professional development
🧘 ♂️ A wellness program supporting mental, physical, and financial wellbeing
🏦 401k retirement plan with company match
🌐 About the Company:
This forward-thinking tech company supports organizations in the healthcare space by providing intelligent platforms that enhance operational efficiency and improve user experiences. Their solutions touch areas like revenue operations, digital workflows, and data-driven decision-making - helping healthcare providers focus more on patient care and less on complexity 💡
📲 Interested? Let's Talk!
We're managing applications on behalf of this client - get in touch today for a confidential conversation about the role.
***************************** / ************
Cyber Security Engineer
Cyber Security Analyst Job 117 miles from Victorville
DirectViz Solutions (DVS) is a dynamic and rapidly growing government contractor committed to delivering innovative IT solutions that address the mission-critical needs of our government clients. Through the expertise and dedication of our talented team, we provide cutting-edge technology services designed to achieve success and exceed expectations.
At DVS, we prioritize our employees as our greatest asset. We offer competitive compensation, comprehensive medical benefits, a 401(k) match, generous PTO accrual, professional development reimbursement, corporate-funded technology certifications, and robust employee recognition and appreciation programs.
We are seeking a skilled and experienced Cybersecurity Engineer to provide critical Cybersecurity (CS) engineering support across various systems, ensuring the security, integrity, and compliance of complex Department of Defense systems. This role will involve working within the full system Life-Cycle, from analysis and secure design to testing, evaluation, and life-cycle management.
THIS POSITION REQUIRES AN ACTIVE SECRET CLEARANCE OR HIGHER.
Key Responsibilities:
Provide Cybersecurity (CS) engineering services including analysis, secure design, testing and evaluation (T&E), systems analysis and assessment, and life-cycle management.
Support the implementation of cybersecurity and Information Assurance (IA) boundary defense techniques across various platforms and systems.
Implement and manage Risk Management Framework (RMF) processes for system accreditation and cybersecurity compliance.
Conduct vulnerability assessments using tools such as the Assured Compliance Assessment Solution (ACAS).
Perform Security Technical Implementation Guide (STIG) implementations and remediations.
Apply Cybersecurity best practices for various IA-enabled appliances including Firewalls, Intrusion Detection Systems (IDS), Intrusion Prevention Systems (IPS), Switches/Routers, Cross Domain Solutions (CDS), EMASS, and Endpoint Security Solutions (ESS).
Remediate cybersecurity vulnerabilities, including the application of vendor patches on both Linux and Windows operating systems.
Provide support for Cybersecurity engineering activities related to total ship computing environments and other defense systems.
Required Education:
Bachelor of Science in Information Systems, Information Technology, Computer Science, or Computer Engineering.
Required Certification:
DoD 8570.01-M certification (minimum IAT Level III) in accordance with DFARS ************ Baseline Certification.
Experience:
Minimum of 10 years of full-time professional experience in the following functional areas:
Computer security, military system specifications, and DoD cybersecurity policies.
National Cyber Range Complex (NCRC) Total Ship Computing Environment (TSCE) Program requirements, mission, ship install requirements, and protocols.
Implementation and management of Risk Management Framework (RMF), including cybersecurity and IA boundary defense techniques.
Experience with IA-enabled appliances such as Firewalls, IDS, IPS, Switch/Routers, CDS, EMASS, and ESS.
Performing STIG implementation and vulnerability assessments.
Remediating vulnerability findings, including the implementation of vendor patches for both Linux and Windows operating systems.
Clearance Requirements: Active Secret clearance or Higher
Skills and Abilities:
Strong understanding of DoD cybersecurity policies and guidelines.
Extensive experience with cybersecurity tools, vulnerability assessment tools, and remediation strategies.
Ability to work across all stages of the system Life-Cycle within the Systems Engineering V Model.
Proficiency in applying cybersecurity measures to complex defense systems.
If you thrive on solving complex problems and building meaningful connections, we'd love to hear from you. Join our team and make an impact today!
Physical and Mental Qualifications:
Maintain focus and awareness throughout scheduled working hours.
Perform tasks requiring prolonged periods of sitting or standing at a desk, utilizing a computer, mouse, and keyboard.
Lift and move objects weighing up to 15 pounds as needed.
Exhibit excellent verbal and written communication skills, with a strong command of the English language.
Demonstrate the ability to work independently while also collaborating effectively as part of a team.
Quickly learn and retain routine tasks and processes.
Possess strong organizational skills, attention to detail, business correspondence proficiency, and self-management capabilities.
Perform the essential functions of the role satisfactorily; reasonable accommodation will be provided for employees with disabilities upon request.
Accept and adapt to additional responsibilities or changes to assigned duties as determined by DirectViz Solutions (DVS).
DirectViz Solutions, LLC (DVS) is an equal opportunity employer who prohibits discrimination and harassment against any employee or applicant for employment based on race, , sex (including pregnancy), age, gender identity, creed, religion, national origin, sexual orientation, marital status, genetic information, disability, political affiliation, protected veteran status, or any other status protected by federal, state or local law.
DVS has a zero-tolerance policy for harassment, threats, coercion, discrimination, and intimidation. Employees may file a complaint or exercise any right protected by Executive Order 11246, Section 503 of the Rehabilitation Act of 1973, as amended, Section 4212 of the Vietnam Era Veterans Readjustment Assistance Act of 1974, or the Veterans Employment Opportunities Act of 1998.
Information Security Engineer (Health Information Systems)
Cyber Security Analyst Job 117 miles from Victorville
The information security engineer designs, implements, monitors and evaluates network security, host-based security, application security and other forms of technical security systems, mechanisms, configurations and procedures. This position encompasses activities which directly support the confidentiality, integrity and availability of computing systems (servers, network, and workstations) including, design, certification, management, monitoring, auditing and use of such systems. The primary responsibility of this job is to provide expertise in project implementation and production support of the System Development Life Cycle (SDLC) that includes information security, design, implementation, assessment, and management of IT systems and compliance with all IT defined processes.
MINIMUM QUALIFICATIONS:
Bachelor's Degree in Information Security, Computer Science, Information Systems, Business, or 3 years of experience in Information Security in lieu of degree
Ability to work actively and collaboratively within a team
Strong project management, time management and communication (both technical and non-technical) skills
Strong analytical problem solving and troubleshooting skills
Ability to write reports and plans
Ability to analyze, troubleshoot, and investigate security related information system anomalies
Ability to conduct security vulnerability assessments against multiple types of information systems
PREFERRED QUALIFICATIONS:
Five years of experience
Experience with network and system security audits and with application security audits
Solid understanding of Federal and State laws pertaining to safeguarding electronic protected health information, personally identified information, and other sensitive data types
Experience with disaster recovery planning and certification and accreditation process
Security certification such as CISSP or GIAC
Systems or network administration or performed ability to acquire required skills
Previous experience working with Healthcare Information Systems
Previous experience as a help desk administrator, systems engineer, or other IT related functions
Device Security Engineer
Cyber Security Analyst Job 364 miles from Victorville
Code Red is Partnered with one of the most innovative companies in the world. They have raised $100M+ funding and are backed by leading investors like a16z. The team is ready to make the first core security team hires, with great impact and scope. We are hiring an Embedded Security Engineer for the Device Security team.
What you'll do:
secure embedded devices by innovating + applying state-of-the-art security tech
drive the development of new hardware or software security features + deploy them to a global fleet of devices in the wild
engage with external resources to continuously improve the security of the device
Does this sound like you?
4+ years' exp. designing + delivering security-critical systems for embedded devices
experience incorporating hardware-based security techniques (TPM, TEEs, secure boot, etc.) into a robust hardware/software system design
Knowledge of cryptographic primitives and public key infrastructure
Experience taking products end-to-end, from conception to product launch
[leveling L4-L7 FAANG equivalent - high impact individual contributor, Senior-Principal]
*Direct-Hire/Permanent - hybrid 3 days/week onsite San Francisco (in the city)*
Cannot wait to hear more about this position?
Click apply below or reach out to Erin Barry (************************) today, and they will share more information and details about the role.
Code Red Partners are extremely committed to working with equal opportunity employers helping build a diverse and inclusive workforce within Cyber Security. We put the people we work with at the heart of everything we do and dedicate all we do to playing a part in developing an industry that represents a variety of backgrounds, perspectives, and skills.
Sr. Security Operations Engineer for HOT Data Start-up in Mountain View, CA
Cyber Security Analyst Job 332 miles from Victorville
Join a rapidly growing data start-up specializing in data value engineering as a Sr. Security Operations Engineer and play a key role in securing our cloud-hosted applications while ensuring compliance with industry standards. Our innovative platform offers a comprehensive approach to data management, covering collection, analysis, packaging, visualization, and exchange. Designed for flexibility and integration, our system empowers organizations and individuals to take control of their data, recognize its ownership, and maximize its value.
Responsibilities:
Hands on engagement in security review, implication and compliance issues with Developers, DevOps, customers.
Drive security audit reviews and certification process
Configure, integrate and implement various security controls using tools and technologies (IAM, MFA, SSO, Firewall/IDS/IPS systems, Network/application vulnerability scanners etc) in cloud environment
Understanding of Security Industry Standards and Compliance Frameworks and Requirements (PCI-DSS, SOC2, CIS configuration Benchmarks, NIST, GDPR, LGPD, etc.)
Build dashboards of various security controls implemented for reviews by compliance team
Develop and augment security process automation through scripting or programming
Work collaboratively with developers, staff and business partners
Document tasks, procedures, environments in configuration
Requirements:3+ years of experience in security operations
2+ years of experience designing, building, implementing, integrating and/or maintaining code
Deep understanding of security controls for data security in cloud hosted applications based on PCI-DSS & SOC2 standards
Experience in vulnerability assessment using tools like GitHub Advanced Security, SonarQube, Qualys etc
Experience working in AWS cloud environments (Azure or GCP a nice to have).
Ability to develop automation scripts and perform design reviews
Strong experience implementing security controls and integration in cloud hosted environments using tools and technologies (IAM, MFA, SSO, DLP systems, Firewall/IDS/IPS systems, Secure Configurations, network/application vulnerability scanners)
Understanding of the security industry standards and compliance frameworks, controls and requirements (PCI-DSS, SOC2, CIS configuration Benchmarks, NIST, GDPR, LGPD, etc.)
Understanding of OWASP vulnerabilities and common network/application/API attacks
Some experience in task automation with Python/Shell Scripting
At least one of the security certifications, like CISA, CISM, GSEC, CASP+
Education:
Bachelor of science degree (or equivalent) in computer science, engineering, or similar experience
Type: Fulltime and Hybrid work schedule
Location: Mountain View, CA
Salary Range: $155K-$175K/Year, plus benefits
Submit resume to ***********************
Cloud Security Engineer
Cyber Security Analyst Job 63 miles from Victorville
Pay: $125,000 - $165,000
Fulltime/Onsite
We are seeking a skilled Cloud Security Engineer with experience in AWS, Kubernetes, and containerized applications to join our engineering team. The ideal candidate will be responsible for planning, implementing, and maintaining the security of our cloud environments and for maintaining compliance with NIST SP 800-171 standards.
Essential Job Functions and Desired Accomplishments
Design and implement security architectures for AWS infrastructure, ensuring best practices in cloud security and containerized application.
In compliance with NIST SP 800-171, conduct security risk assessments and vulnerability assessments on cloud resources, applications, and services
Collaborate with Corporate Cybersecurity Lead on developing and maintaining security policies, training, and procedures related to cloud environments
Lead the development of automated monitoring of cloud infrastructure for security incidents using tools such as AWS CloudTrail, CloudWatch, and GuardDuty
Collaborate with cross-functional teams to integrate security into new feature(s)/software releases to ensure on-going compliance
Respond to security incidents, performing root cause analysis and remediation
Provide security guidance and support during architecture reviews and system deployments and maintain cloud security risk register
Stay updated with the latest security trends, threats, and technology solutions related to cloud security
Participate in DevOps sprints by implementing (not just designing) security measures and contribute routine DevOps sprints (as a lower priority).
Education/Qualifications/Certifications
Required:
Bachelor's degree in Computer Science, Information Technology, or a related field.
Proven experience in cloud security engineering, with a strong focus on AWS, Kubernetes, and containerized applications.
Experience with cloud security frameworks such as CSA STAR, NIST, or ISO 27001.
Proficiency in scripting or programming languages (e.g., Python, Bash) for automation of security tasks.
Knowledge of IAM, VPC, security groups, EC2 instances, and other AWS services.
Experience with security tools such as AWS Security Hub, WAF, and third-party solutions (e.g., SIEM).
Problem-solving skills and the ability to work independently as well as in a team.
Desired:
Relevant security certifications (e.g., AWS Certified Security, CISSP, CISM, CKS) are a plus.
Embedded Security Engineer, Device
Cyber Security Analyst Job 364 miles from Victorville
Join the Device Security Team - Pioneering the Future of Secure Technology
Are you ready to redefine the boundaries of device security? The Device Security Team at TFH is a tight-knit group of industry-leading security experts and hackers, united by a shared passion for innovation and our bold mission. This team is at the forefront of safeguarding every aspect of device security across its entire lifecycle-from manufacturing to decommissioning-and across all layers, from hardware and firmware to the software stack.
Our work goes beyond traditional assessments; we invent. From crafting groundbreaking security solutions for provisioning devices in hostile factory environments to developing advanced attestation mechanisms, we set new standards in transparency, decentralization, and innovation. Each feature we build reflects our commitment to creating industry-first technologies with meaningful global impact.
Here, you'll tackle extraordinary challenges you won't find anywhere else, working on projects that push the limits of what's possible in device security. If you're driven by curiosity, motivated by impact, and excited to collaborate with some of the brightest minds in the field, this is the team for you. Be part of a journey that's as ambitious as it is rewarding. Let's build the future of secure technology together.
About the Role:
In this role, you'll collaborate with industry-leading security experts and hackers to design and develop groundbreaking security technologies that set new standards for device protection. You will have the opportunities to work on a variety of exciting and impactful areas, for example:
Reinventing and implementing secure boot mechanisms to address practical challenges, such as anti-rollback, device demotion or decommissioning, personalized configuration files, while maintaining robust security.
Hardening device software by adopting sophisticated protection mechanisms, such as mandatory access control, system integrity protection, virtualization, and so on.
Redefining the standard of peripheral security and firmware security, to protect peripheral and firmware against the most sophisticated attacks in both hardware and software.
Developing advanced tamper detection and response mechanisms to ensure devices remain resilient and secure, even in the most hostile environments.
Redesigning platform software architecture with a security-first perspective by applying advanced technologies, such as a formally verification kernel, virtualization, and implementing it in products.
This role offers the chance to work on challenges that are not only technically demanding but also uniquely meaningful, with opportunities to leave a lasting impact on the industry.
About You:
5 to 10+ years of experience designing and delivering security-critical systems for internet-connected embedded devices. This may include hardware oracles, robotic systems, IoT devices, or automotive systems.
In-depth knowledge of TEE, secure boot, Linux security, Android or iOS security, or TPM,
In-depth knowledge of peripheral security, firmware security, or hardware security
Strong critical thinking, communication, and leadership abilities, with a proven track record of driving initiatives forward effectively.
Thrives in fast-paced, collaborative environments and is motivated to tackle challenges with a team-first attitude.
We know that no one checks every box, so if you're excited about this role but don't meet all the criteria below, we encourage you to apply. We're looking for passionate individuals eager to contribute and grow with our team. If you're energized by working at the intersection of innovation and security, we'd love to hear from you!
Nice-to-Have Skills:
Experience with se L4, formal verification, transparency technologies, smart contract
What we offer:
An open and collaborative office space in downtown SF
Unlimited PTO
Monthly Phone Reimbursement or a company device
Daily DoorDash credit for in-office meals
Top-tier medical, dental, vision insurance
401k + employer match program
The reasonably estimated salary for this role at TFH in San Francisco ranges from$280,000 - $320,000, plus a competitive long term incentive package, and may include variable compensation. Actual compensation is based on factors such as the candidate's skills, qualifications, and experience. In addition, TFH offers a wide range of best in class, comprehensive and inclusive employee benefits for this role including healthcare, dental, vision andmental health benefits, a 401(k) plan and match, life insurance, flexible time off, commuter benefits, professional development stipend and much more!
#J-18808-Ljbffr
Security Analyst
Cyber Security Analyst Job 136 miles from Victorville
Security Analyst
Compensation: $95,062 - $137,840
Reports To: Information Security Manager
Our client, a mission-driven health plan provider, is seeking a Security Analyst to help safeguard their systems, networks, and data. This role supports the Security Office and plays a critical part in protecting against cyber threats, monitoring security events, implementing solutions, and ensuring policy compliance.
Key Responsibilities:
Monitor network traffic and security alerts for suspicious activity; escalate as needed.
Partner with a third-party Security Operations Center to triage and investigate incidents.
Support incident response efforts, root cause analysis, and preventative strategies.
Assist in vulnerability management, access reviews, and patching workflows.
Contribute to annual security risk assessments and penetration testing efforts.
Develop and maintain security policies, training materials, and awareness campaigns.
Stay current with evolving threats and recommend proactive defense strategies.
Ideal Background:
1-3 years of experience in cybersecurity or a related field.
Bachelor's degree in Computer Science, IT, Cybersecurity, or similar.
Familiarity with tools such as DarkTrace, Microsoft Defender, Windows, Linux, and EDR platforms.
Working knowledge of security frameworks like NIST, CIS Controls, PCI-DSS, or GDPR.
Certifications such as CompTIA Security+, CISSP, or CEH are a plus.
What Sets You Apart:
Excellent problem-solving and analytical skills.
Strong attention to detail and ability to manage multiple tasks and deadlines.
Confident communicator with a collaborative mindset.
Discreet, trustworthy, and passionate about protecting sensitive information.
Senior Security Engineer
Cyber Security Analyst Job 364 miles from Victorville
At Pave, our vision is simple--unlock a labor market built on trust.
How are we going to get there? By building a compensation platform powered by the largest real-time compensation dataset on earth, giving you confidence in every compensation decision.
We partner with our customers to help them build and retain world-class teams through planning, communicating and benchmarking their team's compensation in real time. And you don't have to just hear it from us - you can hear it from our customers: Allbirds, Hover, Credit Karma, Grammarly, and more.
We're growing fast, building an incredible team and product, and having plenty of fun as we do it in our San Francisco and New York City offices.
If playing to win, building with intellectual honesty and focusing on the Pave platinum standard sounds like fun - we highly encourage you to reach out. We'd love to partner on our journey to change the world of compensation!
Security @ Pave
Security is part of everything we do at Pave. With amazing growth comes amazing engineering and security challenges. This is an opportunity to have a huge impact and run programs at a company that doesn't need to be convinced why security is important. Our customers count on us to secure some of their most sensitive data, and that trust is central to Pave.
What You'll Bring
5+ years of application security experience as part of a blue team
Expert knowledge of OWASP Top 10 and application security
Security design review experience
Experience in running bug bounty programs and pentesting
Outstanding communication and partnership skills with software engineers
Ideally, experience in Google Cloud Security best practices
Compensation
This salary range may include multiple levels. Your level is based on our assessment of your interview performance and experience. Salary is just one component of Pave's total compensation package for employees. Your total rewards package at Pave will include equity, top-notch medical, dental and vision coverage, commuter benefits, catered lunch, an unlimited PTO policy, and many other region-specific benefits.
Pave's salary range for this position: $205,700 - $278,300 USD
Our Compensation Philosophy
Pave's compensation philosophy is to target the 75th percentile of the market for both cash and equity at your job level. This means that the “mid point” of every band at Pave is the 75th percentile of the broader market.
Pave also has a merit-based philosophy when it comes to compensation increases. We run a performance cycle twice per year to evaluate employees' performance. Higher than average performance ratings result in compensation increases to the upper end of the individual's compensation range for their role. The result is that high performers at Pave are paid above the 75th percentile of the market at large.
Pave is committed to pay equity. If you get an offer from Pave, it will be based on your level as determined by your interview performance. And nothing else. We explicitly do not negotiate salary and equity to ensure that we aren't introducing bias that could lead to pay inequities within the team between candidates who have different negotiation tactics.
Apply for this job
First Name *
Last Name *
Email *
Phone *
Resume/CV *
Enter manually
Accepted file types: pdf, doc, docx, txt, rtf
LinkedIn Profile
Website
Pave believes in-person work is a key component in building a world-class culture and product. As such, we are seeking talent who can work in-office several times per week. Which office(s) are you applying for? *
New York City
Do you now, or will you in the future, require sponsorship for employment visa status (e.g., H-1B visa status, etc.) to work legally for our Company in the United States? *
#J-18808-Ljbffr
Offensive Security Engineer
Cyber Security Analyst Job 330 miles from Victorville
OSCP Certification
You are a highly skilled Offensive Security Engineer with deep expertise in application security, penetration testing, and exploit development
This role will focus on reviewing source code, identifying security flaws, and developing exploits to test internal systems
In this role, you'll be responsible for executing offensive security assessments and penetration testing strategies
You'll work closely with development and security teams to uncover vulnerabilities and improve security resilience
Reviewing source code to identify common application vulnerabilities
Writing functional exploits for newly discovered vulnerabilities
Leveraging existing tools and developing custom offensive security scripts
Performing penetration tests on internal systems.
Automating baseline red team activities based on the environment and code base
Staff Embedded Security Engineer
Cyber Security Analyst Job 336 miles from Victorville
Title: Staff Embedded Security Engineer
Duration: Contract
Notes: W2 only, NO CTC, NO work visa sponsorship
Responsibilities:
Contribute to Embedded Security requirements, design and test specifications
Implement production quality software components according to specifications
Work jointly with internal development teams to review application code and refine security posture
Communicate security-related concepts to technical and non-technical teams
Provide mentorship to junior team members
Qualifications:
Experience working in Embedded Security
Experience in ARM Trust Zone and Trusted Execution Environment
Experience in Secure Boot and Secure Storage
Excellent Embedded System programming in C
Experience in a fast-moving startup environment
Extensive work experience in design and development of Cyber Security methodologies and comply to Security standards
In-depth technical knowledge of cryptography hardware, key management and certificate management
Extensive integration/porting experience in Hardware Security Modules
Strong Linux fundamentals
Able to bring Security aspects in product development life cycle
Demonstrable proficiency with one or more programming languages (C/C++ etc)
Strong understanding of network concepts including TCP/IP protocol stack, HTTP and TLS, DDoS detection/prevention, Intrusion detection and prevention
Experience in Agile development environment
Advantageous:
Automotive Security
Android Security knowledge
Understanding of SELinux
Experience with Automotive communication protocols would be a plus
Experience with socket programming is desirable.
About Maxonic:
Since 2002 Maxonic has been at the forefront of connecting candidate strengths to client challenges. Our award winning, dedicated team of recruiting professionals are specialized by technology, are great listeners, and will seek to find a position that meets the long-term career needs of our candidates. We take pride in the over 10,000 candidates that we have placed, and the repeat business that we earn from our satisfied clients.
Interested in Applying?
Please apply with your most current resume. Feel free to contact Nina Schindler (**************** / ************* for more details.
Data Security Engineer
Cyber Security Analyst Job 332 miles from Victorville
The DBA/Data Security Engineer will have a strong background in securing and maintaining an enterprise cloud data environment. Preference will also be given to Cloud Security Engineers or Database Administrators (DBAs) with experience in Analytics Data Security.
Responsibilities: (this is not an all-inclusive list; duties may evolve over time as business needs change)
Strong communication and collaboration skills to work effectively with cross-functional teams
Implement and maintain cloud data and analytics security solutions
Implement access policies to secure databases, schemas, tables, and other database objects
Implement access policies to secure CCI and PII sensitive data using Row-Level Security (RLS), Column-Level Security (CLS), data masking, and data encryption features
Understand and abide by all Information Security policies and control standards
Conducts troubleshooting of data security issues, performs root cause analysis and optimize security incidents through lessons learned process
Adept understanding of the Cloud Security best practices in Azure
Proven experience with Microsoft technologies including Azure B2B and Application Security in Azure
Education / Experience
Bachelor's Degree in Computer Science, Information Technology, Information Security, Information Assurance, Information Management in related field or equivalent experience
Certifications in Cloud Cybersecurity (e.g., CCSP, CCSK, Microsoft Azure Security Engineer Associate (AZ-500), etc.) Strongly Preferred
Knowledge / Skills / Abilities
Excellent problem-solving skills and the ability to perform root cause analysis.
7+ years of experience working in Database Administration/Data security Engineering
2-3 years of experience in Azure data warehousing and analytics stack with a focus on data security set up
3+ years of experience in SQL DB/Warehouse security setup and implementing access policies to secure CCI and PII sensitive data using Row-Level Security (RLS), Column-Level Security (CLS), data masking, and data encryption features
Must have at least 3+ years' experience with SQL database development in creating complex queries, optimization and maintaining existing queries,
3+ years of experience in working with Microsoft Azure and strong knowledge about ADLS, Blob Storage, Data Factory, SQL WH etc.
Familiarity with common APIs: REST, SOAP preferred
Android Kernel Security Engineer
Cyber Security Analyst Job 332 miles from Victorville
Hourly Pay Rate Range - $70.00 - $82.00 /HR (Depending on working experience)
Note:- Experience with System Level Penetration and Kernel is must for this role
Certification:- Must have any one of these OSCE, OSCP, OSEE,
WHO we're looking for:
We are looking for an Offensive Android Kernel Security Specialist who will be responsible for joining our cutting-edge Pen Test Team. In this role, you will focus on identifying and mitigating security threats to our kernel and Android operating system.
Role and Responsibilities:
· Conduct in-depth research on kernel vendor modules to identify potential vulnerabilities in the Android system.
· Review, analyze secure OS architectures and perform reverse engineering, fuzzing to identify vulnerabilities.
· Perform penetration testing on Android OS components, including TEE, bootloader, and kernel.
· Research and test the latest exploit trends, developing POC attacks and advanced exploits (0-day, 1-day).
· Document and present findings, including reproducible steps, in a clear and concise manner.
Necessary Skills and Attributes:
· Self-motivated individual with the ability to thrive in a team-based or independent environment.
· Detail-oriented with strong organization skills.
· Ability to work in a fast-paced environment.
· Limited supervision and the exercise of discretion.
Required Experience and Education:
· 3+ years of experience in Android system-level penetration testing and vulnerability.
· Bachelor's degree in Computer Science, Cybersecurity, or a related field.
· Experience in publishing CVE in Android.
· Hands on experience of kernel-level programming and architecture.
· Proficiency in tools for kernel debugging, fuzzing, and penetration testing.
· Experience with reverse engineering tools (g. IDA Pro & Ghidra), debugging tools.
· Understanding of the Android software stack, with deeper technical knowledge in Android framework security, access controls, and internals.
· (Preferred) Certifications: OSCE, OSCP, OSEE, or equivalent.
· (Preferred) Exploit development & Vulnerability discovery.
· (Preferred) Experience presenting findings at security conferences.
Employee Benefits:
At LanceSoft, full time regular employees who work a minimum of 30 hours a week or more are entitled to the following benefits:
Four options of medical
Insurance
Dental and Vision
Insurance
401k Contributions
Critical Illness
Insurance
Voluntary Permanent Life
Insurance
Accident Insurance
Other Employee Perks
About LanceSoft
LanceSoft is rated as one of the largest staffing
firms in the US by SIA. Our mission is to establish global cross-culture human connections that further the careers of our employees and strengthen the businesses of our clients. We are driven to use the power of our global network to connect businesses with the right people, and people with the right businesses without bias. We provide Global Workforce Solutions with a human touch.
EEO Employer
LanceSoft is a certified
Minority Business Enterprise (MBE) and an equal opportunity employer. We
prohibit discrimination and harassment of any kind based on race, color, sex, religion, sexual orientation, national origin, disability, genetic information, pregnancy, or any other protected characteristic as outlined by federal, state ,or local laws.
This policy applies to all employment practices within our organization, including hiring, recruiting, promotion, termination, layoff, recall, leave of absence, compensation, benefits, training, and apprenticeship. LanceSoft makes hiring decisions based solely on qualifications, merit, and business needs at the time.
Want to read more about LanceSoft?
Engineer III - Security Analyst
Cyber Security Analyst Job 32 miles from Victorville
JD:
Must have experience:
Must have Engineering experience; if they don't have engineering experience, they will not consider them.
Microsoft Defender: defender for server identity, cloud and endpoint. Someone that knows policy and can disable, onboard and offboard it.
Qualys: administrator, update tags and modify scans
Additional experience: security investigation, first response, read what the investigation flow should be; respond to cyber security threats.
Conditional access, intra (active directory functions).
Security Analyst - 5 days a week, onsite
Experience Requirement:
Eight (8) or more years IT experience with at least five (5) years in a cybersecurity role with a focus on protect, detect, and respond in addition to the following:
- Mitre ATT&CK and Cyber Kill Chain frameworks
- Establishing or participating in Blue Team exercises
- In-depth knowledge of computer operating systems such as Windows, MacOS and Linux.
- System development lifecycle.
- Deploying, managing, and using Security Operations tools such as SIEM, EPM, DLP, Vulnerability Management, Firewalls, WAFs, Antivirus Solutions, Email Protection Solutions, Incident Response and Threat hunting and management.
- Scripting experience such as PowerShell, JavaScript, or Python.
- Experience working with Identity and Access Control Management Tools.
MAJOR DUTIES AND RESPONSIBILITIES
1. Monitor firewalls, network and host intrusion prevention/detection systems, virtual private networks, threat intelligence platforms, endpoint protection, security training platforms, email security, forensic tools, public/private/hybrid cloud infrastructure, identity and access management systems, and physical security systems.
2. Monitor security operations center tools and dashboards.
3. Perform threat hunting activities using security operations center tools across the environment using internal or external threat intelligence sources.
4. Architect cybersecurity solutions for on premises and cloud computing environments.
5. Participate in and/or leads cybersecurity engineering projects.
6. Assist with risk analysis activities.
7. Assist with designing and implementing controls to mitigate risk.
8. Identify attack surface reduction opportunities through vulnerability data analysis and/or identify opportunities for process improvements and automation.
Senior Security Incident Response Engineer
Cyber Security Analyst Job 364 miles from Victorville
Rippling gives businesses one place to run HR, IT, and Finance. It brings together all of the workforce systems that are normally scattered across a company, like payroll, expenses, benefits, and computers. For the first time ever, you can manage and automate every part of the employee lifecycle in a single system.
Take onboarding, for example. With Rippling, you can hire a new employee anywhere in the world and set up their payroll, corporate card, computer, benefits, and even third-party apps like Slack and Microsoft 365-all within 90 seconds.
Based in San Francisco, CA, Rippling has raised $1.4B+ from the world's top investors-including Kleiner Perkins, Founders Fund, Sequoia, Greenoaks, and Bedrock-and was named one of America's best startup employers by Forbes.
We prioritize candidate safety. Please be aware that all official communication will only be sent from @ Rippling.com addresses.
About The Role
We are looking for a Senior Security Incident Response Engineer to join our Detection and Response Team (DART). In this role, you will be at the forefront of handling security incidents, working to investigate, contain, and mitigate threats across Rippling's environments. You will play a pivotal role in developing and optimizing our incident response function, ensuring that security incidents are managed efficiently and effectively, while continuously improving our processes and infrastructure.
You will work alongside cross-functional teams to respond to complex security incidents, drive improvements in detection and response capabilities, and create scalable solutions to manage and address emerging threats. This is an opportunity to build out Rippling's incident response function from the ground up, providing leadership and technical expertise to secure our production and corporate environments.
What You Will Do
Lead and coordinate the response to security incidents, including triage, investigation, analysis, and communication to internal and external stakeholders.
Develop and maintain incident response playbooks and runbooks for new and existing threat scenarios.
Automate and optimize workflows for detection, incident analysis, and response, improving the speed and effectiveness of incident handling.
Improve security detection capabilities through rule development, tuning, and proactive threat hunting to identify potential attack vectors.
Conduct root cause analysis of incidents and suggest improvements to processes and technologies to prevent future occurrences.
Collaborate with teams across Rippling to implement security measures and mitigation strategies that enhance detection and response capabilities.
Provide expert input on the design and implementation of security controls, processes, and automation tools.
What You Will Need
Strong communication skills, with the ability to communicate complex security findings to both technical and non-technical stakeholders.
7+ years of hands-on experience in security incident response, including detection, investigation, and containment of security incidents in cloud and on-premise environments.
Strong expertise in leading security incident investigations and managing complex incidents involving multiple stakeholders.
Advanced knowledge of cloud security, particularly AWS, including security controls and monitoring services.
Proficiency in using SIEM, SOAR, and other security tools to monitor, investigate, and respond to security incidents.
Strong knowledge of adversary tactics, techniques, and procedures (TTPs) and familiarity with frameworks such as MITRE ATT&CK.
Ability to analyze and correlate large sets of security data to identify anomalous activity and potential security incidents.
Expertise in malware analysis, endpoint forensics, and persistence mechanisms.
Experience in developing security automation using scripting and programming languages such as Python, Bash, or PowerShell.
Deep understanding of operating system internals and forensic analysis techniques for mac OS, Windows, and Linux environments.
Experience with threat hunting and proactive detection of advanced persistent threats (APTs).
If you are a skilled and motivated Security Incident Response professional looking to join an innovative team dedicated to building world-class security defenses, we would love to hear from you!
Additional Information
Rippling is an equal opportunity employer. We are committed to building a diverse and inclusive workforce and do not discriminate based on race, religion, color, national origin, ancestry, physical disability, mental disability, medical condition, genetic information, marital status, sex, gender, gender identity, gender expression, age, sexual orientation, veteran or military status, or any other legally protected characteristics. Rippling is committed to providing reasonable accommodations for candidates with disabilities who need assistance during the hiring process. To request a reasonable accommodation, please email **************************.
Rippling highly values having employees working in-office to foster a collaborative work environment and company culture. For office-based employees (employees who live within a defined radius of a Rippling office), Rippling considers working in the office, at least three days a week under current policy, to be an essential function of the employee's role.
This role will receive a competitive salary + benefits + equity. The salary for US-based employees will be aligned with one of the ranges below based on location; see which tier applies to your location here.
A variety of factors are considered when determining someone's compensation-including a candidate's professional background, experience, and location. Final offer amounts may vary from the amounts listed below.
The pay range for this role is:
159,000 - 278,250 USD per year (US Tier 1)
143,100 - 250,425 USD per year (US Tier 2)
135,150 - 236,513 USD per year (US Tier 3)
#J-18808-Ljbffr
Senior Security Engineer
Cyber Security Analyst Job 364 miles from Victorville
About Us
EchoTwin AI is revolutionizing automated compliance monitoring for smart cities. Using advanced artificial intelligence and digital twin technologies, we collect real-time data from vehicles, robots, and drones to maintain service, regulatory, and safety compliance, empowering the creation of resilient and sustainable communities.
What The Job Involves
Our Engineering teams work at the cutting edge of technology, leveraging AWS and GCP cloud services and developing our own Linux-based edge devices. As a dynamic startup, we understand the critical importance of cybersecurity in protecting our innovative solutions and ensuring the safety of our digital environment and customer data.
We're seeking a passionate Security Engineer to lead our cybersecurity initiatives and safeguard our code and infrastructure against ever-evolving threats. You will manage security for our production and corporate systems, handle security alerts, implement policies, and collaborate with external customers on security needs.
Responsibilities
Develop and implement comprehensive security strategies for our cloud environments (AWS and GCP) and Linux-based systems.
Design and implement public/private key management and PKI (Private Key Infrastructure) for our edge devices.
Perform regular security audits, risk assessments, and penetration testing to identify vulnerabilities in our code and infrastructure. This includes conducting thorough code audits from a security perspective to ensure our applications are developed with the highest security standards.
Design and manage security protocols for our edge devices, ensuring robust protection against external threats.
Stay abreast of the latest cybersecurity trends and threats, applying this knowledge to fortify our defenses. This includes proactive monitoring and implementing fixes for zero-day vulnerabilities to prevent exploitation.
Develop and enforce security policies and procedures, conducting security awareness training across the company to cultivate a security-first culture.
Collaborate with development teams to integrate security measures into the software development lifecycle (SDLC), promoting security best practices for application development to mitigate risks from the outset.
Respond swiftly to security incidents, leading the investigation and remediation efforts to minimize impact. This includes resolving security breaches and ensuring that similar vulnerabilities are addressed across all projects.
Manage and maintain CIS-compliant OS images for our Cloud infrastructure and field devices.
Must possess demonstrable knowledge of application security, security testing methodologies, and application security testing automation.
Qualifications
Degree in Computer Science, Engineering, or related field.
6+ years of software engineering or equivalent experience.
Experience with one of the core (Golang, Python) programming languages, scripting, and automation.
Strong knowledge of encryption protocols, public/private key management, and PKI (Private Key Infrastructure).
Strong understanding of network security, encryption practices, and secure coding principles.
Proven experience in cloud security management (AWS, Azure, GCP).
Familiarity with security policies and controls for internal corporate applications (Google Workspace, GitHub, Jira).
Familiarity with security compliance standards relevant to our industry.
Strong skills in managing security tools and vendor relationships.
Excellent ability to develop and implement security policies and guidelines.
Understanding of blockchain principles is a plus.
Relevant certifications in security and cloud platforms are highly desirable.
Benefits and Perks
There are endless learning and development opportunities from a highly diverse and talented peer group, including experts in various fields, including Computer Vision, GenAI, Digital Twin, Government Contracting, Systems and Device Engineering, Operations, Communications, and more!
Options for medical, dental, and vision coverage for employees and dependents (for US employees)
Flexible Spending Account (FSA) and Dependent Care Flexible Spending Account (DCFSA)
401(k) with 3% company matching
Unlimited PTO
Profit sharing
#J-18808-Ljbffr
Hardware Security Engineer, Trusted Computing and Cryptography
Cyber Security Analyst Job 364 miles from Victorville
About the Team
Security is at the foundation of OpenAI's mission to ensure that artificial general intelligence benefits all of humanity.
The Security team protects OpenAI's technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.
About the Role
Trusted Computing and Cryptography is a core security team at OpenAI focused on deploying high-performance cryptography at scale, secure key management, and trusted hardware enclaves-from boot measurements to GPU confidential computation. As a Hardware Security Engineer, you'll own hardware security at OpenAI by co-designing secure chipsets and integrating cryptographic techniques into our production systems.
In this role, you will:
Co-Design Secure Hardware: Collaborate with hardware vendors and cross-functional teams (kernel, compiler, and ML engineers) to design future secure hardware that meets performance and cryptographic needs.
Develop Critical Software: Write performance-critical code in Rust, Python, and C/C++ to build cryptographic libraries and secure key management systems.
Integrate Security Primitives: Architect and deploy systems using TPM2, Secure Boot, Nitro Enclaves, Intel SGX, AMD-SEV, and other secure hardware technologies.
Drive Innovation: Engage with internal and external partners to align hardware innovations with OpenAI's trusted computing and cryptographic requirements.
You might thrive in this role if you have:
10+ years of industry experience in hardware security or hardware-software co-design.
Proven expertise in deploying cryptographic systems at scale and integrating secure hardware primitives.
Strong coding skills in Rust and/or C/C++, with proficiency in Python.
Proven ability to collaborate across teams, architect solutions, and debug complex production systems.
A proactive, ownership-driven mindset with a focus on end-to-end problem solving.
Nice to Have
Advanced degree in Computer Architecture, Electrical Engineering, or related fields.
Familiarity with HPC, low-precision computing, and SIMD architectures.
About OpenAI
OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.
We are an equal opportunity employer and do not discriminate on the basis of race, religion, national origin, gender, sexual orientation, age, veteran status, disability or any other legally protected status.
For US Based Candidates: Pursuant to the San Francisco Fair Chance Ordinance, we will consider qualified applicants with arrest and conviction records.
We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link.
At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.
#J-18808-Ljbffr
Palo Alto Networks Security Consultant
Cyber Security Analyst Job 364 miles from Victorville
The objective is to procure professional services and support for Palo Alto products, including Cortex XDR Pro and Prisma Cloud. The goal is to secure the organization's systems from zero-day attacks and malicious activities, focusing on incident response, threat hunting, and security investigations.
The primary concerns are maintaining secure infrastructure and responding to emerging cyber threats, including insider threats and ransomware.
- Palo Alto product support (Cortex XDR Pro, Prisma Cloud).
- Incident response services.
- Threat hunting and intelligence validation.
Senior Information Security, Risk & Compliance Specialist
Cyber Security Analyst Job 36 miles from Victorville
Who we are Geotab is a global leader in IoT and connected transportation and certified “Great Place to Work™.” We are a company of diverse and talented individuals who work together to help businesses grow and succeed, and increase the safety and sustainability of our communities. Geotab is advancing security, connecting commercial vehicles to the internet and providing web-based analytics to help customers better manage their fleets. Geotab's open platform and Geotab Marketplace , offering hundreds of third-party solution options, allows both small and large businesses to automate operations by integrating vehicle data with their other data assets. Processing billions of data points a day, Geotab leverages data analytics and machine learning to improve productivity, optimize fleets through the reduction of fuel consumption, enhance driver safety and achieve strong compliance to regulatory changes. Our team is growing and we're looking for people who follow their passion, think differently and want to make an impact. Ours is a fast paced, ever changing environment. Geotabbers accept that challenge and are willing to take on new tasks and activities - ones that may not always be described in the initial job description. Join us for a fulfilling career with opportunities to innovate, great benefits, and our fun and inclusive work culture. Reach your full potential with Geotab. To see what it's like to be a Geotabber, check out our blog and follow us @InsideGeotab on Instagram. Join our talent network to learn more about job opportunities and company news.Who you are:
We are always looking for amazing talent who can contribute to our growth and deliver results! We are seeking a Senior Information Security, Compliance & Risk Specialist, that will keep the legal and ethical integrity of Geotab through policy enforcement and program planning. The Senior Information Security, Compliance & Risk Specialist, will ensure all departments of our business are complying with the rules and regulations the company upholds. If you are a compliance guru, a team player, and are keen to join an industry leader - we would love to hear from you!
What you'll do:
As a Senior Information Security, Compliance & Risk Specialist, your key area of responsibility will be to support the development of information security policies to achieve the Geotab's security goals. In this role you will provide technical drafts for individual policies addressing Programs, Network Connectivity Security, Wireless Security, Incident Handling, and Password Utilization. You will also need to prepare gap analyses for management regarding policies that will advance Geotab's technology goals and objectives.
To be successful in this role you will be a need to be able to work independently and in a team when required, with strong written and verbal communication skills, and have the ability to quickly understand complex security concepts. In addition, the successful candidate will need to have excellent project management skills with an ability to identify needs, develop effective solutions, and manage projects and programs through to completion. The successful candidate will also be able to manage multiple timelines and contrasting priorities to ensure timely results.
How you'll make an impact:
Develop deep knowledge of Geotab's security programs as well as our internal systems and data infrastructure, in order to consult effectively on Security best practices.
Provide information assurance and subject matter expertise as required in support of panels, committees, and working groups.
Ensures security compliance with legal and regulatory standards.
Incorporate findings to develop, update, or revise policies and standards for customers.
Oversee and manage security audits against the systems, processes, and network infrastructure according to existing security policies and standards.
Collaborate with and advise internal departments to improve on security-related risks.
Act as a technical mentor/SME to other team members, and act as a point of escalation for more complex issues and initiatives.
Support Geotab global strategic initiatives.
What you'll bring to the role:
Post-Secondary Diploma/Degree specialization in Computer Science, Engineering or a related field.
5-8 years experience in security evaluation/analysis and/or risk assessments, within a technology-focused industry.
Working knowledge of system and network security engineering best practices.
Familiarity with basic information security documentation requirements, certification and accreditation processes, and abreast with general reporting requirements for industry security standards (e.g. ISO 27001, NIST SP 800-53).
Expertise in common security tool use.
High accuracy and meticulous attention to detail.
Able to work well under pressure and respond to fast changing priorities and deadlines.
Highly organized and able to manage multiple tasks and projects simultaneously.
Excellent verbal and written communication skills, including comfort with delivering presentations and training.
Strong interpersonal relationship building skills.
Strong analytical skills with the ability to problem solve with well-judged decisions.
Strategic mindset, has a keen sense of priorities, along with an ability to pivot as the landscape changes.
A strong team-player with the ability to engage with all levels of the organization.
Technical competence using software programs, including, but not limited to, Google Suite for business (Sheets, Docs, Slides).
Entrepreneurial mindset and comfortable in a flat organization.
If you got this far, we hope you're feeling excited about this role! Even if you don't feel you meet every single requirement, we still encourage you to apply. Please note: Geotab does not accept agency resumes and is not responsible for any fees related to unsolicited resumes. Please do not forward resumes to Geotab employees. Why job seekers choose Geotab
Flex working arrangements
Home office reimbursement program
Baby bonus & parental leave top up program
Online learning and networking opportunities
Electric vehicle purchase incentive program
Competitive medical and dental benefits
Retirement savings program
*The above are offered to full-time permanent employees only
How we work At Geotab, we have adopted a flexible hybrid working model in that we have systems, functions, programs and policies in place to support both in-person and virtual work. However, you are welcomed and encouraged to come into our beautiful, safe, clean offices as often as you like. When working from home, you are required to have a reliable internet connection with at least 50mb DL/10mb UL. Virtual work is supported with cloud-based applications, collaboration tools and asynchronous working. The health and safety of employees are a top priority. We encourage work-life balance and keep the Geotab culture going strong with online social events, chat rooms and gatherings. Join us and help reshape the future of technology! We believe that ensuring diversity is fundamental to our future growth and progress and is an integral part of our business. We believe that success happens where new ideas can flourish - in an environment that is rich in diversity and a place where people from various backgrounds can work together. Geotab encourages applications from all qualified individuals. We are committed to accommodating people with disabilities during the recruitment and assessment processes and when people are hired. We will ensure the accessibility needs of employees with disabilities are taken into account as part of performance management, career development, training and redeployment processes. If you require accommodation at any stage of the application process or want more information about our diversity and inclusion as well as accommodation policies and practices, please contact us at ******************. By submitting a job application to Geotab Inc. or its affiliates and subsidiaries (collectively, “Geotab”), you acknowledge Geotab's collection, use and disclosure of your personal data in accordance with our Privacy Policy. Click here to learn more about what happens with your personal data.