Post job

Cyber Security Engineer jobs at Fidelity Investments

- 665 jobs
  • Vice President, Application Cyber Security Specialist

    CLS Group 4.8company rating

    Iselin, NJ jobs

    Job information: Functional title - Application Security Specialist Department - IT Security Corporate level - Vice President Report to - Director, Application Security Expected full-time salary range between $ 140,000- $180,000 + variable compensation + 401(k) match + benefits. What you will be doing: Perform Application Security scans (e.g. DAST and SCA) on applications and APIs to identify security vulnerabilities and weaknesses, Triage security findings and collaborate with development teams to prioritize and remediate identified vulnerabilities. Drive threat modelling as a standard part of the SDLC, and develop and maintain threat models for critical applications, identifying potential security risks and proposing mitigations. Drive the Security Champions program, and define and promote secure coding practices, patterns, and standards across development teams. Conduct security reviews and provide guidance on security requirements for new features and projects. Assist in the analysis, selection and rollout of new application security tools, processes, and standards. Stay up to date with the latest security threats, vulnerabilities, and industry best practices. What we're looking for: Proven experience in application security with a focus on application security testing and vulnerability management. Hands-on experience with Application Security tools. Strong understanding of common application vulnerabilities (e.g., OWASP Top 10) and mitigation techniques. Experience with threat modelling methodologies and tools. Proficiency in at least one programming language (e.g., Java, Python, JavaScript). Excellent communication and collaboration skills, with the ability to work effectively in cross functional teams. Strong understanding of risk management. Professional qualifications / certifications Degree in a technology discipline (Computer Science, Information Management, Computer Engineering, Cybersecurity or equivalent). Relevant security certifications (e.g. CISSP, CEH, CSSLP) or equivalent is preferred.
    $140k-180k yearly 2d ago
  • Information Security Analyst

    Deutsche Bank 4.9company rating

    Jacksonville, FL jobs

    Job Title Information Security Analyst Corporate Title Associate Deutsche Bank Chief Security Office (CSO) is looking for an Information Security Analyst to support the Bank's Information Security Threat Operations (ISTO) - Data Leakage Monitoring (DLM) capabilities. The DLM Analyst is responsible for timely acting on data leakage events and incidents, taking decisions to ensure the corresponding course of action for rapid containment and mitigation, as well as ensuring all applicable steps in the Bank's DLM process get timely implemented (e.g. impact assessment. consequence management) and accurately documented. Besides operations tasks, he/she will be supporting to evaluate and adjust processes, tools, and reporting, as well as wider ISTO initiatives or projects. What We Offer You A diverse and inclusive environment that embraces change, innovation, and collaboration A hybrid working model, allowing for in-office / work from home flexibility, generous vacation, personal and volunteer days Employee Resource Groups support an inclusive workplace for everyone and promote community engagement Competitive compensation packages including health and wellbeing benefits, retirement savings plans, parental leave, and family building benefits Educational resources, matching gift and volunteer programs What You'll Do Monitor and analyze data activities to detect and prevent unauthorized data transfers and leaks Utilize metadata logged by DLP solutions to support incident management and forensic investigations Ensure timely response and containment of data leakage incidents Ensure proper information security incident documentation and hand over to other colleagues within ISTO as needed Provide accurate information and reporting with regards to DLM incidents to the relevant stakeholders and timely escalate to other relevant teams/roles as needed, Support the assessment of financial, reputational, client, market or regulatory impact associated with data leakage security incidents Contribute to data leakage monitoring process improvements as well as detection rules tuning Skills You'll Need Bachelor's degree or equivalent required Previous experience in a similar position, or background on incident management, or SOC related roles Familiar with the MITTRE ATT&CK framework as well as CISSP, CISM, GCIH or other relevant certifications in the field Knowledge of industry standards and best practices for data protection Reasonable understanding/background with Security Incident and Event Management (SIEM) systems, and detection tools, ideally on Splunk, McAfee, Symantec, Microsoft Sentinel & Purview Skills That Will Help You Excel Fluent in English, very good communication skills and confident assuming timely decisions Independent way of working with strong decision making and problem-solving ability Appetite for continuous learning Comfortable with working in international & multicultural teams Expectations It is the Bank's expectation that employees hired into this role will work in the Jacksonville office in accordance with the Bank's hybrid working model. Deutsche Bank provides reasonable accommodations to candidates and employees with a substantiated need based on disability and/or religion. The salary range for this position in Jacksonville, FL is $60,000 to $86,000. Actual salaries may be based on a number of factors including, but not limited to, a candidate's skill set, experience, education, work location and other qualifications. Posted salary ranges do not include incentive compensation or any other type of remuneration. Deutsche Bank Benefits At Deutsche Bank, we recognize that our benefit programs have a profound impact on our colleagues. That's why we are focused on providing benefits and perks that enable our colleagues to live authenti cally and be their whole selves, at every stage of life. We provide access to physical, emotional, and financial wellness benefits that allow our colleagues to stay financially secure and strike balance between work and home. Click here to learn more! Learn more about your life at Deutsche Bank through the eyes of our current employees *************************** The California Consumer Privacy Act outlines how companies can use personal information. If you are interested in receiving a copy of Deutsche Bank's California Privacy Notice please email ****************.
    $60k-86k yearly 3d ago
  • Application Security Analyst

    CTC 4.6company rating

    Plano, TX jobs

    Bachelor's degree in Computer Science, Cybersecurity, or related field. 3+ years of experience in DevOps, Security Engineering, or related roles. 2-3 years of security experience. Overall, 6 years Strong understanding of CI/CD tools (e.g., Jenkins, Harness). Development knowledge on Java, Python, .Net, etc Experience with security tools (e.g., Veracode, GHAS, Orca). Proficiency in scripting languages (e.g., Python, Bash). Familiarity with containerization and orchestration (Docker, Kubernetes). Knowledge of cloud platforms (AWS, Azure, GCP) and their security features. Understanding of secure coding practices and application security principles. Knowledge of Infrastructure as Code (Terraform, Ansible).
    $84k-132k yearly est. 5d ago
  • Cyber Security Identity & Access Management Engineer

    Tata Consulting Services 4.3company rating

    Elmwood Park, NJ jobs

    Job Title : Cyber Security Identity & Access Management Engineer Experience Required - 7+ Years Must Have Technical/Functional Skills * Deep understanding of Access Management - Authentication & Single Sign-On, authentication protocols like OAuth2.0, OpenID Connect and SAML2.0 * Experience with development of Transmit Security Journeys, WebSDK & scripting (AuthScript) * Hands on experience in implementation of user authentication and authorization using Transmit Security * Hands on with development and deployment of custom developed applications using Java/J2EE technologies. * Hand on with development of REST API using Java Spring Framework * Full understanding of HTTP Request/Response tracing, Session Handling * Good understanding of Secure HTTP communication - client to server and server to server secure communication * Good understanding of Java Spring Boot application development, deployment * Good understanding of NoSQL databases like MongoDB, Casandra, etc. * Good understanding of DevOps tools like Git, Eclipse/IntelliJ, Jenkins, Docker, Puppet, Kubernetes, Ansible, etc. Non-Technical: * Scheduling & Planning - should be able to plan and execute the deliverables as per the proposed design. * Communication - Ability to communicate Up, Down, and Across All Levels of the Organization and Technical Backgrounds * Detail Oriented - Good Understanding of IAM concepts * Analytical, Self-motivated - Critical thinker who can analyze issues and is able to troubleshoot, along with the developers, to find root cause of the problem. * Interpersonal skills and Professional demeanor - Respond to customer inquiries in a timely manner, guiding and advising customers on security best practices in a friendly customer facing manner. * Team Player - Ability to work in a team & collaborate with other application team and infrastructure teams * Problem-Solver - Processes tactical mitigations based on results of analysis and determination of issues found in the incident and issues found in inherited legacy systems. Provide recommendation for improvements on the existing set up Roles & Responsibilities * Incident Triaging - Performing incident resolution through analysis and technology support * Daily Health checks and Monitoring * Operation status reports and metrics: Incident management, Service request management * SLA Management for respond, restore and resolve, Troubleshooting and resolution of issues, Configuration Management, Enhancements, Product Vendor Connect, Platform Support * Knowledge management - SOP creation and updates. Knowledge transition. Provide complete knowledge of system flow and interdependence between various internal and external systems. * Auditing & Reporting - Support Health Equity in audits and provide Out-of-the-box reports Project Management Salary Range - $100,000 to $160,000 per year TCS Employee Benefits Summary: Discretionary Annual Incentive. Comprehensive Medical Coverage: Medical & Health, Dental & Vision, Disability Planning & Insurance, Pet Insurance Plans. Family Support: Maternal & Parental Leaves. Insurance Options: Auto & Home Insurance, Identity Theft Protection. Convenience & Professional Growth: Commuter Benefits & Certification & Training Reimbursement. Time Off: Vacation, Time Off, Sick Leave & Holidays. Legal & Financial Assistance: Legal Assistance, 401K Plan, Performance Bonus, College Fund, Student Loan Refinancing. #LI-JS2
    $100k-160k yearly 13d ago
  • Vice President, Cyber Security Engineer

    CLS 4.8company rating

    New York, NY jobs

    CLS is the trusted party at the centre of the global FX ecosystem. Utilized by thousands of counterparties, CLS makes FX safer, smoother and more cost effective. Trillions of dollars' worth of currency flows through our systems each day. Created by the market for the market, our unrivalled global settlement infrastructure reduces systemic risk and provides standardization for participants in many of the world's most actively traded currencies. We deliver huge efficiencies and savings for our clients: in fact, our approach to multilateral netting shrinks funding requirements by over 96% on average, so clients can put their capital and resources to better use. CLS products are designed to enable clients to manage risk most effectively across the full FX lifecycle - whether through more efficient processing tools or market intelligence derived from the largest single source of FX executed data available to the market. Our ambition to make a positive difference starts with our people. Our values underpin everything that we do at CLS and define our working environment: Pivotal purpose Trusted guardian Targeted innovation Facilitate connections Delivering excellence Inclusive culture Job information: Functional title - Cyber Security Engineer Department - Security Engineering Corporate level - Vice President Report to - Director, Information Security Engineering Location - London, onsite 2 days per week. Expected full-time salary range between $140,000 - $180,000 + variable compensation + 401(k) match + benefits. Note: Disclosure as required by NY Pay Transparency Law of the expected salary compensation range for this role. Job Purpose The Cyber Security Engineering role is responsible for the delivery of security related activities and maintenance and enhancements of security solutions to improve the security posture of the CLS estate. This individual will interact with the IT Security Architecture Team, IT Security Operations Team, Project Management Teams, global IT Teams, and outsourcing partners to deliver solutions that enhance the security program for CLS. Essential Function / Major Duties and Job Responsibilities Strategic As part of the CLS Security Engineering team, develop and implement CLS security strategy in consultation with the CLS IT teams, ensuring that all initiatives are mirrored in respective strategies including the overall CLS Strategy. Provide security advice and support for information technology projects. Research new security related products and services to ensure that CLS is equipped with appropriate industry best of breed tools and solutions. Operational Operate and maintain CLS Security controls related to SIEM, DLP, Vulnerability Management, Cyber Threat Intelligence, Endpoint Protection, Network Protection, etc. Review and help refine CLS Security procedures to ensure compliance with cyber resilience requirements. Be responsible when assigned ownership of CLS Security related Regulatory and Internal Audit finding(s), and provide effective / timely resolution. Design and integrate consistent security solutions across CLS on-premise and cloud environments for domains like Vulnerability Management, Endpoint Security, Data Security, Network Security, Identity and Access management, etc. Facilitate monitoring and enforcement of configurations, as well as manage and monitor security on systems deployed in the cloud in a similar fashion as is done on-premises at CLS. Oversee design principles and controls relating to third party solution providers. Leadership Work as a team member and individual contributor being able to work independently and confidently without direct supervision. Through example and behaviour, strive to provide peer leadership to other team members with the goal of being excellent service providers and enablers to other constituencies (both internal and external). Strong communication (verbal and written) skills to engage with technical and non-technical audiences. Ability to clarify technical detail and confidently communicate business risks to senior management. Execute CLS Security Engineering team's vision and mission in alignment with the overall CLS Security vision and mission, as well as with CLS's strategic direction as it pertains to cyber resilience. Experience / Essential and Desired for Successful Job Performance A minimum of 5 years of information security experience with at least 2 years in cloud security. Expert knowledge of one or more of the following: firewalls, TCP/IP, network IDS/IPS, host-based IDS/IPS, endpoint and network-based DLP, web proxies, email protection, endpoint protection software, SIEM Sound knowledge of enterprise security concepts/frameworks and products, secure design principles and patterns Monitor, tune and develop technical CLS Security controls and frameworks to ensure appropriate preparation, monitoring and response to threats Ability to collaborate effectively with others to drive forward key security objectives Strong documentation and report writing skills (to both technical and business audiences) Excellent time management and organizational skills combined with technical CLS Security acumen Financial and/or Banking industry experience preferred Qualifications / Certifications in a technology discipline (Computer Science, Information Management, Computer Engineering, Cybersecurity or equivalent) or Security Certifications such as CISSP, SANS GIAC GSEC, GCED, GCIA, GCIH, GREM Industry recognized cloud security qualifications (e.g. CCSK, CCSP, AWS Security Fundamentals, AWS Certified Security) Working knowledge of the following frameworks and regulations: ISO 27001/2, SANS Top 20 Critical Security Controls, NIST CSF, NIST 800-53 and FFIEC handbook Success Factors / Personal Characteristics Contributing to an Individual's Ability to Excel in the Position Possess a strong service-oriented mind set to consistently deliver balanced security solutions that include people, process and technology. Possess strong technical, analytical and problem-solving skills. Self-motivated to exceed management expectations and objectives. Ability to effectively communicate complex technical issues to both business and technical staff at all levels. Strong collaboration skills to tackle complex security challenges that may span across multiple internal and external departments and groups. Able to effectively cope with change and comfortably handle risk and ambiguity, not upset when things are up in the air. Tenacious resolve and positive attitude in challenging situations Our commitment to employees: At CLS, we celebrate inclusion and consider this to be one of our strongest assets. We are committed to fostering an environment in which everyone feels comfortable to be who they are, and inclusion is valued. All employees have access to our inclusive benefits, including: Holiday - UK/Asia: 25 holiday days and 3 ‘life days' (in addition to bank holidays). US: 23 holiday days. 2 paid volunteer days so that you can actively support causes within your community that are important to you. Generous parental leave policies to ensure you can enjoy valuable time with your family. Parental transition coaching programmes and support services. Wellbeing and mental health support resources to ensure you are looking after yourself, and able to support others. Employee Networks (including our Women's Forum, Black Employee Network and Pride Network) in support of our organisational commitment to embrace and always be learning more about inclusivity. Hybrid working to promote a healthy work/life balance, enabling employees to work collaboratively in the office when needed and work from home when they don't. Active support of flexible working for all employees where possible. Monthly ‘Heads Down Days' with no meetings across the whole company. Generous non-contributory pension provision for UK/Asia employees, and 401K match from CLS for US employees. Private medical insurance and dental coverage. Social events that give you opportunities to meet new people and broaden your network across the organisation. Annual flu vaccinations. Discounts and savings and cashback across a wide range of categories including health and retail for UK employees. Discounted Gym membership - Complete Body Gym Discount/Sweat equity program for US employees. All employees have access to Discover - our comprehensive learning platform with 1000+ courses from LinkedIn Learning. Access to frequent development sessions on a number of topics to help you be successful and develop your career at CLS.
    $140k-180k yearly Auto-Apply 6d ago
  • Senior Cyber Security Engineer -Threat Simulation

    CME Group 4.4company rating

    Chicago, IL jobs

    Join the Global Information Security (GIS) department at CME Group as a Sr. Cyber Security Engineer - Threat Simulation. You will be an integral part of our Offensive Security organization, directly contributing to improving CME Group's security posture. This high-impact role is responsible for the execution of Red Team adversary emulations against our complex hybrid environment, proactively testing and strengthening our internal and internet-facing systems. You'll also be a key participant in Purple Team activities to continuously improve the organization's cyber detection and response capabilities. This is a perfect opportunity for a sharp, action-oriented engineer to become a key part of a team of highly skilled cybersecurity professionals who execute a pivotal role in protecting and defending national critical infrastructure. What You'll Get * Elevate your expertise in a supportive environment fostering continuous learning, rapid career progression, and an inclusive, global team culture. * Gain broad exposure to CME Group's diverse products, asset classes, and cross-functional teams, expanding your impact across critical financial infrastructure. * Receive a competitive salary and comprehensive benefits package. What You'll Do As a key member of our offensive security team, you will: * Execute high-impact Red Team exercises against our complex hybrid cloud environments, driven by real-world threat intelligence and the MITRE ATT&CK Framework. * Engineer and maintain robust Red and Purple Team infrastructure, continuously automating processes for efficiency and scale. * Co-design and lead joint Purple Team exercises, directly partnering with cyber defense to improve detection and response capabilities. * Innovate through continuous research into new offensive security TTPs (Tactics, Techniques, and Procedures) and drive knowledge transfer across the security organization. * Conduct specialized, ad-hoc offensive security tests utilizing industry-leading and internally developed tooling to uncover subtle security gaps. * Author comprehensive post-exercise reports, including detailed technical findings, compromise narratives, and strategic, risk-rated recommendations for remediation. * Mentor cyber defense teams during incident investigations, providing critical subject matter expertise on attacker tradecraft and mindset. * Champion security awareness and technical knowledge-sharing by collaborating with information security, technology, and business stakeholders. What You'll Bring We're looking for an engineer with a robust offensive mindset and a proven track record of breaking and building in complex enterprise environments. Technical Mastery * 5+ years' experience wielding industry-standard penetration testing and adversary emulation tools (e.g., Cobalt Strike, Sliver, Mythic, Bloodhound, Burp Suite). * Expert understanding of the MITRE ATT&CK Framework and advanced evasion techniques used to bypass modern security controls. * Strong comprehension of the cyber kill chain and the full lifecycle of an Advanced Persistent Threat (APT) targeting financial institutions. * Proficiency in at least one scripting language (e.g., Python, PowerShell) and experience with a compiled language (e.g., Go, C#) for tool development. * Deep experience attacking and securing complex cloud, on-prem, and hybrid environments, from initial access through actions on objective. * Solid knowledge of Windows and Linux system hardening concepts, Purple Team automation strategies, and vulnerability rating methodologies. * Proven experience with security within at least one major cloud provider (e.g., AWS, Azure, GCP). Nice to Haves: * Previous hands-on experience performing sophisticated adversary emulations/simulations specifically within the financial services sector. * A recognized offensive security industry certification (e.g., OSCP, GPEN, GXPN, OSWE, eCPTX) demonstrating specialized, high-impact skills. * Familiarity with modern enterprise security standards and frameworks (e.g., TIBER-EU, CBEST, NIST CSF). * Experience conducting offensive security exercises against emerging technologies, such as AI/ML systems or mac OS. #LI-DD1 #LI-Hybrid CME Group is committed to offering a competitive total rewards package for our employees that recognizes their contributions to the business and reflects our long-term investment in their future. The pay range for this role is $116,600-$194,300. Actual salary offered will be dependent on a wide array of factors including but not limited to: relevant experience, skills, education and comparison to internal employees (where relevant). Our compensation program also includes an annual target bonus opportunity for all employees, as well as the opportunity to become an owner in the company through our broad-based equity program. Through our benefits program, we strive to offer flexibility, value and choice. From comprehensive health coverage, to a retirement package that includes both a 401(k) and an active pension plan, to highly competitive education reimbursement provisions, paid time off and a mental health benefit, CME Group offers a holistic benefits package for our team and their dependents. CME Group: Where Futures are Made CME Group is the world's leading derivatives marketplace. But who we are goes deeper than that. Here, you can impact markets worldwide. Transform industries. And build a career by shaping tomorrow. We invest in your success and you own it - all while working alongside a team of leading experts who inspire you in ways big and small. Problem solvers, difference makers, trailblazers. Those are our people. And we're looking for more. At CME Group, we embrace our employees' unique experiences and skills to ensure that everyone's perspectives are acknowledged and valued. As an equal-opportunity employer, we consider all potential employees without regard to any protected characteristic. Important Notice: Recruitment fraud is on the rise, with scammers using misleading promises of job offers and interviews to solicit money and personal information from job seekers. CME Group adheres to established procedures designed to maintain trust, confidence and security throughout our recruitment process. Learn more here.
    $116.6k-194.3k yearly 60d+ ago
  • Cyber Security Engineer - Expert

    Janus Soft 4.8company rating

    Chantilly, VA jobs

    REQUIRED SKILLS • Demonstrated experience in cyber security, InfoSec, security engineering, or network engineering. • Demonstrated experience with vulnerability scanning tools. • Demonstrated experience analyzing and documenting test results. • Demonstrated experience assessing systems against information assurance policies and regulations. • Demonstrated experience communicating complex technical concepts to both technical and non-technical audiences. • Demonstrated experience coordinating and performing security testing. • Demonstrated experience developing risk assessment and certification reports. • Demonstrated experience leading security accreditation efforts for enterprise systems. • Demonstrated experience recommending mitigating countermeasures to identified threats, vulnerabilities, or shoflfalls. • Demonstrated experience with Linux operating system. • Demonstrated experience writing and reviewing documents such as requirements specifications, system architecture, design documents, test plans, or security plans. • Demonstrated experience decomposing functional requirements into technical requirements. Demonstrated experience analyzing existing systems and identifying necessary corrective actions and improvements. • Demonstrated experience preparing program documentation such as CONOPS, SSP, and preparing materials to support system accreditation. DESIRED SKILLS • Demonstrated experience with creating and maintaining integrated master schedules. • Demonstrated experience with offensive security practices. • Demonstrated experience explaining protocols, technical procedures and processes clearly and accurately to both technical and non-technical audiences.
    $86k-113k yearly est. 60d+ ago
  • Full stack Engineer- Cyber analytics

    Tata Consulting Services 4.3company rating

    Phoenix, AZ jobs

    Job Title : Full stack Engineer- Cyber analytics Experience Required - 5+ Years Must Have Technical/Functional Skills Full Stack Python (Django, Flask, or FastAPI, plus front-end frameworks like React, Angular, or Vue). Full Stack Java (Spring Framework, Hibernate, plus front-end frameworks like React, Angular, or Vue). Strong knowledge of databases (SQL and NoSQL: MS SQL, PostgreSQL, MySQL, MongoDB). Hands-on experience with Microsoft Graph APIs. Proficiency in RESTful APIs, GraphQL, and microservices architecture. Familiarity with cloud platforms (AWS, Azure, or GCP). Experience with Git, CI/CD pipelines, and DevOps practices. Experience with event-driven architecture and messaging systems (Kafka, RabbitMQ). Roles & Responsibilities Full Stack Development: Build, test, and deploy features across the entire stack, with strong emphasis on either Python (e.g., Django/Flask/FastAPI) or Java (e.g., Spring Framework). API Integration: Design and implement integrations with Microsoft Graph APIs and other third-party systems. Architecture & Design: Contribute to system architecture and ensure scalability, security, and maintainability. Continuous Improvement: Stay up-to-updated with best practices, frameworks, and tooling to enhance productivity and code quality. Quality Assurance: Drive engineering excellence through unit tests, integration tests, and CI/CD practices. Salary Range - $95,000 to $115,000 per year TCS Employee Benefits Summary: Discretionary Annual Incentive. Comprehensive Medical Coverage: Medical & Health, Dental & Vision, Disability Planning & Insurance, Pet Insurance Plans. Family Support: Maternal & Parental Leaves. Insurance Options: Auto & Home Insurance, Identity Theft Protection. Convenience & Professional Growth: Commuter Benefits & Certification & Training Reimbursement. Time Off: Vacation, Time Off, Sick Leave & Holidays. Legal & Financial Assistance: Legal Assistance, 401K Plan, Performance Bonus, College Fund, Student Loan Refinancing. #LI-JS2
    $95k-115k yearly 41d ago
  • Senior Cyber Security Engineer

    Local Government Federal Credit Union 4.2company rating

    Raleigh, NC jobs

    CIVIC CULTURE Our organization believes we can all do well by doing good. We value the contributions of diverse minds and prioritize the success and well-being of our employees. We also believe every person in our organization plays a role in supporting a healthy environment and helping to achieve our goal of prosperity for all. To this end, we recruit bright, energetic, and talented people to be members of our team. In return, we offer a dynamic workplace that presents opportunities for professional advancement and individual growth. We strive to always display integrity, self-awareness, courage, and respect for one another while continuing to seek opportunities to learn. We really believe that when our employees succeed, our community wins. ABOUT THE POSITION The individual who excels in this position will have demonstrated experience in multiple information security technologies, including, but not limited to: SIEM, SOAR, email security, vulnerability management, network, and endpoint security controls. The individual will also play a key role in deployment, troubleshooting, testing, risk rating, and maintaining cyber security tools, platforms, and programs within the credit union. The successful candidate will display a passion for developing new skills in the field of information security. The Senior Cyber Security Engineer will actively participate in incident response, security program and control implementation, administration, automation, and documentation. The individual will assist internal teams as well as external service providers on technical projects. NORMAL DAY-TO-DAY WORK Research, engineer, design, and implement security solutions to enhance the management of cyber security risks within the credit union. Support the day-to-day maintenance of all cyber security applications, including administration, deployment, troubleshooting and maintaining all cyber security tools. Create and maintain playbooks, standards, automation, processes, and procedures around security disciplines with a focus on administration of platforms. Identify, design and complete regular security audits related to administrative access and activities for security platforms as well as perform regular security audits as required. Research, recommend, implement changes and additions to security controls and business application solutions. Identify and track metrics related to performance and improvements to related cyber security tools. Develop, respond to and investigate alerts related to misuse of credit union technology. Create and edit scripts for integration and analysis of all cyber security controls for coverage and effectiveness. Serve as a backup for incident response, ensuring readiness to take immediate action in the event of security breaches or system incidents, providing support in containment, analysis, and remediation efforts. Stay informed of tools, techniques and components utilized in the industry through research and apply this knowledge to system(s) being secured. Work with end-users to identify and mitigate security threats. Understand and support team, department, applicable credit union regulations (NCUA), policies and procedures, strategic goals, and vision. Take ownership for actions, decisions, and results; openly accept feedback and demonstrate both the willingness and ability to improve. JOB QUALIFICATIONS Here are a few skills you MUST have to be qualified for this position. Minimum 7 - 9 years' experience in an information security, systems administration or IT engineering role. Solid experience and understanding of incident response, vulnerability management, security engineering, security automation, risk rating, network security, threat intelligence and systems administration concepts. Experience tuning rules that identify anomalous and/or suspicious behavior within SIEM, IDS/IPS, and similar platforms. Ability to work flexible hours and weekends as needed, as well as participate in a 24/7 rotation schedule. Ability to function in a Consumer business office environment and utilize standard office equipment including but not limited to: PC, copier, telephone, etc. Ability to lift a minimum of 25 lbs. (file boxes, computer). Travel required on occasion. Here are a few qualities we'd LIKE for you to have to make you more suited for this position. BA/BS in Information Technology, Information Security, Information Assurance or equivalent experience. Experience managing Active Directory, and ADFS. Experience with regular expressions and scripting (PowerShell, python, bash, etc.). Familiarity with network and systems administration and operations concepts. Comfortable with multiple operating systems, including Windows, mac OS, and Linux. Certifications in one or more Information Security Domains or on security platforms (Security+, GSEC, CISSP, GCIH, GCED, GDSA, etc.).
    $92k-117k yearly est. 12d ago
  • Cyber Security Analyst

    Orange Business 3.3company rating

    Atlanta, GA jobs

    Orange Business is here! About us Orange Business is a network and digital integrator that understands the entire value chain of the digital world, freeing our customers to focus on the strategic initiatives that shape their business. Every day, you will collaborate with a team dedicated to providing consistent, sustainable global solutions, no matter where our customers operate. With over 30,000 employees across Asia, the Americas, Africa, and Europe, we offer a dynamic environment to develop and perfect your skills in a field filled with exciting challenges and opportunities. About the role Orange Cyberdefense specializes in the design, implementation and support of the most reliable and innovative security solutions and services - we are seeking a SOC Analyst to join our global team for a major account. As a SOC Analyst you are responsible for the detection, investigation and defense against cyber-attacks. In our SOC, you will work with security experts and use the latest technologies to analyze potential security incidents. As the team is working based on FTS (follow-the-sun) model involving Brazil, France & Malaysia teams, shift work is required for this role. Your key responsibilities as a SOC Analyst will include to: Ensure that customer environments are always protected against cyber-attacks Triage and investigate alarms generated by SIEM tools, endpoint protection tools, network anomaly detection tools, etc. by performing in-depth analysis Undertake threat hunting investigations and campaigns Escalate relevant threats to customers and providing advice based on these threats Detect anomalies and attack patterns along the entire cyber-kill chain as described by MITRE ATT&CK Support our customers during a security incident and ensure effective defense against attacks Continuously develop improvements and detection methods to optimize detections Report monthly on the status of customer environments Advice customers on cyber trends. About you Cybersecurity needs to be your passion, securing the customers assets your mission. As security is often a tradeoff between different aspects, you need to be pragmatic and result driven to get your message delivered while reducing the risk for the customer. Excellent English written/verbal and communication skills. Minimum of 2 years of experience in a similar role Experience using SIEM and/or EDR/XDR security tools - Knowledge in SPLUNK technology is a plus. A degree in Computer Science, Cyber Security, Digital Forensics or Engineering - or equivalent industry recognized certification/experience Ideally have experience with penetration testing, incident detection, incident response and malware analysis Broad knowledge on threat analysis and experience in intelligence reporting. Ideally have experience with penetration testing, incident detection, incident response and malware analysis. Ideally have certifications such as CySA+, CEH, OSCP, OSDA, Splunk Power Ideally have experience working within a SOC, if not then any experience within an IT Department providing customer support Experience in reversing malware is a plus Industry certifications like CISA, CISM, CISSP is a plus What we offer Our Competitive Benefits Package Includes: Comprehensive health coverage (medical, dental, vision) for you and your family Financial protection: life, disability, AD&D, and business travel insurance 401(k) plan with company match Pre-tax savings through HSA and FSA accounts Employee assistance program, tuition reimbursement, and adoption support Healthy living and wellness reimbursements Group-rate insurance options: home, auto, pet, and more Generous PTO and paid volunteer days Legal assistance, critical illness, hospital indemnity, and ID theft protection plans Only your skills matter Regardless of your age, gender identity, race, ethnic origin, religion/belief, sexual orientation, marital status, neuroatypia, disability, veteran status or appearance, we encourage diversity within our teams because it is a strength for the collective and a vector of innovation. Orange Group is a disabled-friendly company and equal opportunity employer: don't hesitate to tell us about your specific needs.
    $75k-102k yearly est. Auto-Apply 58d ago
  • Cyber Security Analyst

    Orange Business 3.3company rating

    Atlanta, GA jobs

    Orange Business is here! About us Orange Business is a network and digital integrator that understands the entire value chain of the digital world, freeing our customers to focus on the strategic initiatives that shape their business. Every day, you will collaborate with a team dedicated to providing consistent, sustainable global solutions, no matter where our customers operate. With over 30,000 employees across Asia, the Americas, Africa, and Europe, we offer a dynamic environment to develop and perfect your skills in a field filled with exciting challenges and opportunities. About the role Orange Cyberdefense specializes in the design, implementation and support of the most reliable and innovative security solutions and services - we are seeking a SOC Analyst to join our global team for a major account. As a SOC Analyst you are responsible for the detection, investigation and defense against cyber-attacks. In our SOC, you will work with security experts and use the latest technologies to analyze potential security incidents. As the team is working based on FTS (follow-the-sun) model involving Brazil, France & Malaysia teams, shift work is required for this role. Your key responsibilities as a SOC Analyst will include to: Ensure that customer environments are always protected against cyber-attacks Triage and investigate alarms generated by SIEM tools, endpoint protection tools, network anomaly detection tools, etc. by performing in-depth analysis Undertake threat hunting investigations and campaigns Escalate relevant threats to customers and providing advice based on these threats Detect anomalies and attack patterns along the entire cyber-kill chain as described by MITRE ATT&CK Support our customers during a security incident and ensure effective defense against attacks Continuously develop improvements and detection methods to optimize detections Report monthly on the status of customer environments Advice customers on cyber trends. About you What you bring to the table Cybersecurity needs to be your passion, securing the customers assets your mission. As security is often a tradeoff between different aspects, you need to be pragmatic and result driven to get your message delivered while reducing the risk for the customer. Excellent English written/verbal and communication skills. Minimum of 2 years of experience in a similar role Experience using SIEM and/or EDR/XDR security tools - Knowledge in SPLUNK technology is a plus. A degree in Computer Science, Cyber Security, Digital Forensics or Engineering - or equivalent industry recognized certification/experience Ideally have experience with penetration testing, incident detection, incident response and malware analysis Broad knowledge on threat analysis and experience in intelligence reporting. Ideally have experience with penetration testing, incident detection, incident response and malware analysis. Ideally have certifications such as CySA+, CEH, OSCP, OSDA, Splunk Power Ideally have experience working within a SOC, if not then any experience within an IT Department providing customer support Experience in reversing malware is a plus Industry certifications like CISA, CISM, CISSP is a plus What we offer Our Competitive Benefits Package Includes: Comprehensive health coverage (medical, dental, vision) for you and your family Financial protection: life, disability, AD&D, and business travel insurance 401(k) plan with company match Pre-tax savings through HSA and FSA accounts Employee assistance program, tuition reimbursement, and adoption support Healthy living and wellness reimbursements Group-rate insurance options: home, auto, pet, and more Generous PTO and paid volunteer days Legal assistance, critical illness, hospital indemnity, and ID theft protection plans Only your skills matter Regardless of your age, gender identity, race, ethnic origin, religion/belief, sexual orientation, marital status, neuroatypia, disability, veteran status or appearance, we encourage diversity within our teams because it is a strength for the collective and a vector of innovation. Orange Group is a disabled-friendly company and equal opportunity employer: don't hesitate to tell us about your specific needs.
    $75k-102k yearly est. Auto-Apply 58d ago
  • Systems Engineer - Physical Security

    Hudson River Trading 3.2company rating

    New York, NY jobs

    Hudson River Trading (HRT) is looking for a Systems Engineer with a focus on physical security systems to join our Enterprise Technology team. This role will liaise closely with our Workplace and various Security teams to conduct research, design, and maintain physical security platforms. You'll join a lean and technical team with opportunities to architect, own, and evolve HRT's global physical security infrastructure, driving both strategic vision and hands-on execution, to help HRT stay secure while providing a great employee experience. Responsibilities Research, architect, and deploy physical security systems across our offices and supporting sites around the globe Conduct audits and risk assessments of the physical security of equipment and locations globally Curate an enjoyable employee experience while helping to maintain safety, security and compliance Manage user roles, permissions, and system access in compliance with company policies and best practices Troubleshoot hardware/software issues, perform diagnostics, and provide Level 2/3 support Create and maintain documentation of configurations, procedures, and system architecture Help lead technical response and forensic analysis for physical security incidents in collaboration with Workplace and Security Operations teams Collaborate with internal stakeholders to evaluate and adopt next-generation physical security technologies, such as AI-driven analytics, mobile credentials, or zero-trust physical systems Qualifications 5+ years of experience in the systems architecture, engineering, and administration of physical security systems (camera infrastructure, badge platforms, biometrics, environmental sensors, access control, etc.) Experience with open protocols and standards in physical security (OSDP, SNMP, etc.) Experience with consolidating and automating identity management, configuration, and logging for disparate physical security, access control, and digital IAM platforms Experience with data center physical security systems (VSS, ACS, IDS, anti-tailgating, anti-passback, mantraps, etc.) Experience automating through code (Python, Go, PowerShell) and working with SDKs/APIs Strong knowledge of networking concepts and protocols Familiarity with securing IP-based physical systems and awareness of modern physical security threats (e.g., firmware supply chain, OT/IT convergence) Willing to travel 20% of time to visit other offices and facilities as needed A certification like Certified Protection Professional (CPP) or Physical Security Professional (PSP) is a plus Experience using Linux is a plus Experience with public cloud providers (GCP, AWS, Azure) is a plus The estimated base salary range for this position is $150,000 - $250,000 per year, based on job-related skills and experience. This role will also be eligible for discretionary performance-based bonuses and a competitive benefits package. Culture Hudson River Trading (HRT) brings a scientific approach to trading financial products. We have built one of the world's most sophisticated computing environments for research and development. Our researchers are at the forefront of innovation in the world of algorithmic trading. At HRT we welcome a variety of expertise: mathematics and computer science, physics and engineering, media and tech. We're a community of self-starters who are motivated by the excitement of being at the cutting edge of automation in every part of our organization-from trading, to business operations, to recruiting and beyond. We value openness and transparency, and celebrate great ideas from HRT veterans and new hires alike. At HRT we're friends and colleagues - whether we are sharing a meal, playing the latest board game, or writing elegant code. We embrace a culture of togetherness that extends far beyond the walls of our office. Feel like you belong at HRT? Our goal is to find the best people and bring them together to do great work in a place where everyone is valued. HRT is proud of our diverse staff; we have offices all over the globe and benefit from our varied and unique perspectives. HRT is an equal opportunity employer; so whoever you are we'd love to get to know you.
    $150k-250k yearly Auto-Apply 60d+ ago
  • Cyber Security Analyst III

    United Wholesale Mortgage Corp.(DBA UWM 4.6company rating

    Pontiac, MI jobs

    We are growing our Information Security Threat Intelligence and Compliance team here at UWM. This is a new position where you will be responsible for translating threat intelligence into actionable defensive measures, creating and maintaining procedural documentation and mentoring more junior analysts. Additionally, you will be detecting and analyzing suspicious or malicious events. This role will also actively participate on the Incident Response team. WHAT YOU WILL BE DOING * Review and analyze logs from a variety of sources * Monitor detection systems for signs of attack or unusual activity * Create documentation to assist with repeatable tasks and decision making * Actively participates in incident response * Monitors and analyzes threat intelligence sources and recommends appropriate actions * Use penetration testing tools and techniques * Works closely with other teams to understand the flow of sensitive data between systems and applications * Translate threat intelligence into actionable defensive measures * Mentor other Security Analysts * Ability to provide on-call support on a rotating basis WHAT WE NEED FROM YOU Required: * 5+ years of professional IT experience * 2+ years of information security experience * Subject matter expert in SIEM, forensics, malware analysis or incident handling * Understanding of network protocols (TCP, UDP, DNS, FTP, SMTP, DHCP, etc.) * Familiarity with industry regulations (eg. GLBA, NYCRR, etc.) * Microsoft Windows troubleshooting skills * GIAC or equivalent certification * On-site attendance * Computer related degree or equivalent * 100% onsite attendance THE PLACE & THE PERKS Ready to join thousands of talented team members who are making the dream of home ownership possible for more Americans? It's all happening on UWM's campus, where our award-winning workplace packs plenty of perks and amenities that keep the atmosphere buzzing with energy and excitement. It's no wonder that out of our six pillars, People Are Our Greatest Asset is number one. It's at the very heart of how we treat each other, our clients and our community. Whether it's providing elite client service or continuously striving to improve, our pillars provide a pathway to a more successful personal and professional life. From the team member that holds a door open to the one that helps guide your career, you'll feel the encouragement and support on day one. No matter your race, creed, gender, age, sexual orientation and ethnicity, you'll be welcomed here. Accepted here. And empowered to Be You Here. More reasons you'll love working here include: * Paid Time Off (PTO) after just 30 days * Additional parental and maternity leave benefits after 12 months * Adoption reimbursement program * Paid volunteer hours * Paid training and career development * Medical, dental, vision and life insurance * 401k with employer match * Mortgage discount and area business discounts * Free membership to our large, state-of-the-art fitness center, including exercise classes such as yoga and Zumba, various sports leagues and a full-size basketball court * Wellness area, including an in-house primary-care physician's office, full-time massage therapist and hair salon * Gourmet cafeteria featuring homemade breakfast and lunch * Convenience store featuring healthy grab-and-go snacks * In-house Starbucks and Dunkin * Indoor/outdoor café with Wi-Fi DISCLAIMER All the above duties and responsibilities are essential job functions subject to reasonable accommodation and change. All job requirements listed indicate the minimum level of knowledge, skills and/or ability deemed necessary to perform the job proficiently. Team members may be required to perform other or different job-related duties as requested by their team lead, subject to reasonable accommodation. This document does not create an employment contract, implied or otherwise. Employment with UWM is "at-will." UWM is an Equal Opportunity Employer. By selecting "Apply for this job online" you provide consent to UWM to record phone call conversations between you and UWM to be used for quality control purposes.
    $87k-105k yearly est. Auto-Apply 11d ago
  • Physical Security Systems Engineer

    Centersquare 4.0company rating

    Washington jobs

    Centersquare is a global data center leader in retail colocation and interconnection services. Centersquare brings proven operational excellence, global scale, flexibility, and customer-focused innovation together to provide a comprehensive portfolio of data center and interconnection solutions. The Security Systems Engineer (SSE) position has a high degree of responsibility and strategic impact on critical business functions. The SSE serves as an expert for physical security systems and technologies in a data center environment including access control, Closed-Circuit Television (CCTV) surveillance cameras and recorders, biometric equipment, anti-tailgating equipment and wireless devices. The SSE is responsible for providing technical problem solving or troubleshooting on security asset fault escalations and outages in support of the 24x7 Physical Security Operations Center (PSCC) and the test/turn-up support of security assets in Centersquare data centers. Primary Responsibilities Implement, administer, and maintain physical security systems and programs. Perform Tier 2 technical problem solving or troubleshooting and/or testing of security systems on both client and server-side issues. Design and manage critical physical security global infrastructure. Maintain physical security build standards. Manage the system health of access control and video surveillance platforms. Perform system upgrades and maintenance. Implement, administer, and maintain physical security systems by creating and maintaining security information systems, databases, reports, perform back-ups and other security systems application software at company facilities as assigned. Complete projects involving security systems, hardware, building systems and technology as assigned, ensuring status reports are regularly submitted to department management and that targeted completion dates are met. Serve as an expert for physical security systems and technologies, staying up-to-date and recommending new security technologies for implementation based on objectives and business needs. Recognize, respond to, and recommend actions to address both potential and realized physical security threats and emergencies affecting personnel or property. Be responsible for frontline support and maintenance of physical security systems and applications and serve as a subject matter expert on physical security systems. Debug and resolve application, server, database issues with a variety of operating system combinations (Linux, Windows, and Mac), server hardware and network topologies. Manage/configure/debug specialized endpoints such as card readers, surveillance cameras, biometric equipment, wireless devices. Automate patch application, hotfixes, and custom functionality using scripts and packaging tools. Project manage the buildout of new systems and remediation of existing systems while coordinating with physical security team members, system administrators and database engineers. Enforcement of company policies and procedures. Travel required. Experience & Qualifications Bachelor's degree in Computer Science, Computer Engineering, Telecommunications, or 4-years' experience with physical security systems or security integrator field experience. Hands-on experience with physical security systems, including access control, digital and analog video surveillance and/or identity management solutions. Knowledge of Microsoft Office Productivity Tools and SharePoint. Strong analytical and problem-solving skills. Able to exercise good judgment under pressure and critical conditions. Excellent verbal and written communication skills. Demonstrate flexibility and the ability to quickly adapt to changes and prioritize tasks/responsibilities. Able to respond to system issues on a 24-hour basis and to work a flexible work schedule as required. Strong customer service, organizational, prioritization, multitasking, communication, and leadership skills. Strong working knowledge and experience with electronics, PCs, networks, communications devices, door & locking hardware, alarm devices, CCTV technology and software with emphasis on card access systems. Support experience with various operating systems (Linux/Mac/Windows) in the context of both clients and servers. Extensive experience with access control systems. Lenel certification is preferred. Experience implementing, configuring, and integrating third-party software solutions. Experience with various mantrap and anti-tailgating technologies (Newton T-Dar, IEE). Understanding of LAN/WAN and mobile computing environments. Physical Security Professional (PSP) or Certified Protection Professional (CPP) is preferred. The employer will not sponsor visas for this role Centersquare is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.
    $85k-121k yearly est. 60d+ ago
  • Information Assurance Analyst

    First Financial Credit Union 3.8company rating

    Albuquerque, NM jobs

    Full-time Description Information Assurance Analyst analyzes supporting documentation to validate general computer, automated, and operational controls are working as intended and adhere to FFCU's information security policies, procedures, and controls. The Information Assurance Analyst works closely with internal teams to review security practices, detect potential threats, and provide recommendations for improving the overall security posture of the organization. This role involves assessing security risks, performing audits, and identifying vulnerabilities in systems and processes to ensure compliance with industry regulations and internal security standards. This individual serves as the Internal Audit teams' subject matter expert (SME) in identifying technology and cybersecurity risks. The role requires attention to detail, strong analytical skills, and a deep understanding of cybersecurity frameworks, standards, and best practices. Essential Functions 30% 1. Information Assurance Audits - Plan, lead, and execute audits of information security controls associated with FFCU applications and systems on behalf of the Internal Audit and Information Security departments. This includes developing audit plans, conducting audits, reporting on findings, providing recommendations, and monitoring remediation status; as well as participating with the Internal Audit department annual audit plan and IT risk assessment. 15% 2. Operational Security Reviews - Conduct periodic operational security reviews to ensure that critical controls are operating as intended. These may include reviews of traffic flow/firewall configurations, access controls, vulnerability management and other areas as needed. 15% 3. Control Documentation Library - Maintain Information Security Control Documentation and Artifacts library. This library will contain documentation and /or evidence that demonstrates FFCU's current security control status. This information is utilized for responding to audits and risk assessments. 10% 4. Security Event Management - Monitor information security events for unauthorized or unusual activity. Respond to or escalate events as required. Develop and maintain alerts on applicable security systems. These may include FFCU's in-house Security Information and Event Management system, Microsoft 365 or other system as required. 10% 5. Configuration and Change Control Monitoring - Monitor compliance of FFCU configuration and change control management processes. This includes conducting system reviews to identify systems not in compliance with approved configuration baselines or changes that did not follow FFCU change control standards. Request and monitor remediation. 10% 6. System Authorization - Ensure that appropriate information security reviews are completed, and that information systems or services are authorized prior to being promoted to production. This may include verification of secure configurations, patching status, required contracting reviews, change requests and other required actions that result in a documented formal system authorization. This also includes ensuring that system or services that have reached end of life are appropriately and completely decommissioned. Non-essential Functions 10% 1. Perform any other duties as requested by the Director of Information Security or VP of Internal Audit other team members. Embody CU's mission, vision, and core values. Abide by First Financials policies, procedures, and standards. Expectations Perform essential functions of the position, special projects and other work assignments within timeframes and quality standards established by the Chief Information Officer. Possess the ability to work independently within deadlines and manage multiple tasks and projects. Must demonstrate good analytical/problem solving, verbal and written communication skills. Must be able to multi-task and be a team player and have good time management and prioritization skills. Must be willing to work from our main office in Albuquerque, NM. Ability to travel out of town as needed. Requirements Qualifications Education: Bachelor's degree in related technical or business area. Certifications such as a CISA, CISM, or CISSP are desirable. Experience: Minimum of 5 years experience in a related Information Technology, Information Security, or audit function. Knowledge, Skills, Abilities: Must have good working knowledge and understanding of the technologies and concepts supporting the essential functions of the position listed above. Must be able to lift up to 50 lbs. Normal office conditions, but hours & days worked must be flexible based on needs of position; highly concentrated mental & visual alertness, majority of day may be spent sitting, typing & reading computer screen for extended periods, frequent up/down activity, position involves a great deal of physical activity involved w/ maintaining & working on computers.
    $39k-58k yearly est. 60d+ ago
  • Cyber Security Awareness Analyst [2026 EDGE Program]

    DTCC 4.9company rating

    Tampa, FL jobs

    Are you ready to make an impact at DTCC? Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development? At DTCC, we are at the forefront of innovation in the financial markets. We're committed to helping our employees grow and succeed. We believe that you have the skills and drive to make a real impact. We foster a thriving internal community and are committed to creating a workplace that looks like the world that we serve. About the EDGE Program: The Exploration, Development, Growth and Experience (EDGE) Program supports DTCC's commitment to identifying and selecting diverse early career talent across the organization, ensuring you have a comprehensive understanding of our industry, our company, the technical / functional skills needed for the various business areas, and the leadership competencies needed for overall success within DTCC. What to expect as an EDGE Analyst: A program that provides accelerated development opportunities designed to cultivate the future leaders for DTCC Week-long orientation A comprehensive learning and engagement plan Assigned to your own mentor and EDGE buddy to gain a well-rounded view of the company Networking and exposure to senior management Pay and Benefits: Competitive compensation, including base pay and annual incentive Comprehensive health and life insurance and well-being benefits, based on location Pension / Retirement benefits Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being. DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee). The impact you will have in this role: Being a member of the Cyber Security Awareness and Training (CSAT) team as a Cyber Security Awareness and Training Analyst, you will be the driving force behind cultivating a security-first culture across the organization. Your work will empower employees to recognize and respond to cyber threats confidently, reduce human risk, and ensure compliance with regulatory standards. Through innovative training programs, engaging campaigns, and strategic collaboration, you will help transform cybersecurity from a technical concern into a shared responsibility, making every employee a proactive defender of our digital ecosystem. Your Primary Responsibilities: Assist in engaging, interactive training modules tailored to different roles and risk levels across the organization Participate in sessions on topics such as phishing, social engineering, password hygiene, and AI-based deception Incorporate gamification, storytelling, and real-world scenarios to improve retention and participation Assist in maintaining the annual and quarterly training calendar, including mandatory new hire orientation, monthly phishing simulations, and ad-hoc events like Cyber Spotlight Series and Coffee Talks Analyze metrics from simulations and awareness campaigns to identify gaps and improve future programming Collaborate with internal stakeholders to embed security practices into daily operations Assist with initiatives during Cyber Security Awareness Month, including speaker sessions, pop-up events, and team challenges Stay current with emerging threats and update training materials accordingly Ensure content reflects the latest industry standards and internal risk posture, including role-based training and incident response protocols *NOTE: The Primary Responsibilities of this role are not limited to the details above. * Selection and Program Timeline: (timing may vary) August - October 2025: Applications open October - December 2025: Interview and Selection process January - July 2026: Early engagement and onboarding process July 2026: Start of program Qualifications: Candidates must be working towards a bachelor's degree in the following curriculums and graduating no later than May 2026: Cybersecurity, Business, Finance , Computer Science, MIS or Business & Technology Management Candidates must have authorization to work permanently in the US without the need for sponsorship (now or in the future) Candidates must have minimum of a 3.2 GPA upon graduation Talents Needed for Success: Must demonstrate superior analytical and communication skills Strong interest in the financial services industry, with previous internship experience a plus Ability to engage cross-functional teams and promote a security-first culture Strong communication and storytelling skills to translate complex cybersecurity concepts into accessible language for diverse audiences The salary range is indicative for roles at the same level within DTCC across all US locations. Actual salary is determined based on the role, location, individual experience, skills, and other considerations. We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, sex, gender, gender expression, sexual orientation, age, marital status, veteran status, or disability status. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.
    $73k-93k yearly est. Auto-Apply 6d ago
  • Technology, Cyber Security, Full Time Analyst, Irving - USA, 2026

    Citigroup 4.6company rating

    Irving, TX jobs

    **You are the brains behind our work ...** At Citi, we do not just adapt to change - we drive it. Our Full Time Technology Analyst Program is where forward-thinking talents meet unparalleled opportunities. This is your chance to innovate, influence, and make an impact in the most global financial institution! Citi Technology partners to ensure that Citi's platforms can "Be the Best" for clients globally, with a diverse and ethical workforce that applies innovation and automation to deliver a world class client experience and strengthen our reputation. We have over 30,000 technologists globally who are dedicated to serving our clients' needs across the firm. By utilizing a broad range of technologies, we are at the forefront of innovation. We seek to drive our systems and processes towards scalable, low-latency, high frequency enterprise systems to support Citi's strategic priorities. **We provide you with the knowledge and skills you need to succeed...** We're committed to teaching you the ropes. The 2-year Analyst Program starts in July and begins with a robust training program. Here at Citi, rotational programs are intended to help you build a broad skillset and accelerate your career growth by gaining exposure to more than one team in Cyber Security. Our rotational program will help you discover the best fit for your skills and long-term career goals at Citi. **Your time here will look something like this...** Our technological solutions are the foundations of everything we do. We keep the bank safe and provide the technical tools our workers need to be successful. We design our digital architecture and ensure our platforms provide a first-class customer experience. Our operations teams manage risk, resources, and program management. We focus on enterprise resiliency and business continuity. We develop, coordinate, and execute strategic operational plans. Essentially, Chief Information Security Office (CISO) works together to ensure the safety of Citi's and our clients' assets and information. You will make tangible contributions to high-impact, real-world projects that directly influence the evolution of banking. Your work could involve anything from developing next-generation digital banking solutions and fortifying our cybersecurity defenses to driving data-powered innovations and transforming customer experiences. Be a part of impactful initiatives that shape the future of finance. **As a member in our program, you can expect:** + **Global Exposure:** Work in globally scoped projects with cross-functional teams and gain insights into how technology drives the financial sector worldwide. + **Continuous Learning:** Benefit from structured learning, networking, mentoring, and development programs that are designed to sharpen your technical prowess, enhance your business insight, and cultivate your leadership skills. + **Real Impact:** Contribute to real-world projects that shape the future of banking, from developing next-gen digital banking solutions to enhancing our cybersecurity defenses and driving data-powered innovations. **We want to hear from you if...** We are in a hunt for trailblazers with a passion for technology and drive to make a difference. To join this elite program, you should: + Be graduating between December 2025 and May 2026. + Pursuing bachelor's degree in Cyber Security, Computer Science, Computer Engineering, Information Technology, Management Information Systems, or other tech related degree. + GPA of 3.0 or better is preferred. + You will not require sponsorship for U.S. work authorization now or anytime in the future. + You have an interest working in a high-tech global technology environment and have a fundamental understanding of technologies, including by not limited to programing languages (C++, Java, etc.), application development, or basic concepts of relational databases. + Be a problem solver who thrives on innovation and enjoys tackling challenges head-on. + Possess a global outlook and a willingness to collaborate across cultures and time zones. + Have excellent communication skills, project management, leadership, attention to detail, and the ability to work well within diverse teams. + Ability to pass technical interviews consisting of basic algorithmic programming exercises. + Must be collaborative and adaptable, with excellent communication skills. Prior experience working on agile teams is desirable. **Who we think will be a great fit...** A dedication to learning and a true passion for business are vital. As industries all over the globe continue to restructure and grow, we are hiring professionals who have a global perspective on the future of banking and want to make an impact. We value diversity and so do you. We will also be looking for the following: + Are ambitious, with relentless drive to succeed in a fast-paced, dynamic environment. + Are curious about how technology can revolutionize finance and are eager to be at the forefront of this transformation. + Want to grow into a future tech leader, with a passion for both technology and its application in the global financial industry. Annual Salary = $90,000USD ------------------------------------------------------ **Job Family Group:** Management Development Programs ------------------------------------------------------ **Job Family:** Training ------------------------------------------------------ **Time Type:** Full time ------------------------------------------------------ **Primary Location:** Irving Texas United States ------------------------------------------------------ **Primary Location Full Time Salary Range:** $80,000.00 - $115,000.00 In addition to salary, Citi's offerings may also include, for eligible employees, discretionary and formulaic incentive and retention awards. Citi offers competitive employee benefits, including: medical, dental & vision coverage; 401(k); life, accident, and disability insurance; and wellness programs. Citi also offers paid time off packages, including planned time off (vacation), unplanned time off (sick leave), and paid holidays. For additional information regarding Citi employee benefits, please visit citibenefits.com. Available offerings may vary by jurisdiction, job level, and date of hire. ------------------------------------------------------ **Most Relevant Skills** Please see the requirements listed above. ------------------------------------------------------ **Other Relevant Skills** For complementary skills, please see above and/or contact the recruiter. ------------------------------------------------------ **Anticipated Posting Close Date:** Nov 21, 2025 ------------------------------------------------------ _Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law._ _If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi (*************************************************************************** ._ _View Citi's EEO Policy Statement (*********************************************** and the Know Your Rights (*********************************************************************************************** poster._ Citi is an equal opportunity and affirmative action employer. Minority/Female/Veteran/Individuals with Disabilities/Sexual Orientation/Gender Identity.
    $80k-115k yearly 27d ago
  • Information Security Specialist

    Federal Reserve Bank of San Francisco 4.7company rating

    Kansas City, MO jobs

    CompanyFederal Reserve Bank of Kansas CityWhen you join the Federal Reserve-the nation's central bank-you'll play a key role, collaborating with leading tech professionals to strengthen and protect our economic, financial and payments systems. We invest in contemporary and emerging technology each year to support the Federal Reserve and our economy, and we're building a dynamic and diverse team for our future. This role is responsible for modernizing the methods and procedures for performing cybersecurity risk management and assessing cybersecurity risk. This involves assessing the current approach, data, and tools to identify gaps and enhancements. It requires strong partnerships with key stakeholders and business leaders, conveying cyber risk to them in a way that allows them to make risk informed decisions and improve the Organization's security posture. Important Information Open to US Citizens, Green Card holders or Permanent Residents with at least 3 years of residency. No sponsorship is available. Candidates must have valid work authorization, without an end date to be considered. No H1-B, OPT, STEM OPT, CPT, TN, J-1, etc. This position requires working on-site with 5 days per month remote work flexibility. Key Activities Risk Assessment & Analysis Modernize the current approach to cybersecurity risk management and assessments. Research and evaluate methodologies and frameworks and subsequently apply them for use in the organization. Identify and implement risk quantification and scoring approaches within the organization. Perform in-depth data analysis to identify patterns, trends, and areas of focus and priority. Incorporate threat intelligence into risk assessments to provide context-aware risk evaluations. Conduct business impact analyses to understand how security incidents affect critical business functions. Evaluate and quantify risks associated with third-party vendors and supply chain. Assess specific risks related to cloud environments and services. Program Development Develop reports and dashboards to illustrate the organization's risk posture. Ensure that cybersecurity risk is integrated with IT risk, and informs overall Enterprise risk. Research and identify options to establish a risk register. Develop and track risk treatment plans including mitigation strategies, acceptance justifications, or transfer options. Map cybersecurity risks to relevant regulatory requirements and compliance frameworks. Continuously improve risk management processes based on industry trends and organizational needs. Communication & Collaboration Meet with technical experts and business leaders to convey cybersecurity risk in a way they can understand. Partner with incident response teams to incorporate lessons learned into risk models. Translate complex technical risk scenarios into actionable insights for all levels of the organization. Qualifications Experience Typically requires at least 6 years of relevant cybersecurity risk management experience. Experience with risk scoring methods and risk quantification. Experience with generating reports and dashboards to convey cybersecurity risk in a way that is easy to consume. Experience establishing or running an Enterprise cybersecurity risk management program. Experience with NIST SP 800-53 security standards. Experience presenting risk information to executive leadership. Education & Certifications Bachelor's degree specializing in an information technology field from an accredited college or university, or equivalent combination of directly related education and/or experience. Information Security industry certification (SSCP, CISSP, GIAC, CISM, CISA, etc.) preferred. Technical Knowledge Strong knowledge of and experience applying cybersecurity risk frameworks and assessment methodologies; examples may include Factor Analysis of Information Risk (FAIR), NIST Cybersecurity Framework (CSF). Strong skills and experience with data analysis. Experience with GRC (Governance, Risk, and Compliance) tools. Knowledge of business impact analysis methodologies. Familiarity with cloud security frameworks (CCSK, CCSP). Skills & Abilities Ability to understand technical details of cybersecurity risk. Ability to communicate complicated technical risk scenarios to all levels of the organization. Demonstrated self-motivation and ability to perform work independently, and also collaborate in a team environment. Additional Information How We Work (HWW): On-site: 5 days per month remote work flexibility Location: Kansas City, Denver, Oklahoma City, Omaha Remote Eligible: No Salary: $98,600 - $139,000 / Senior Level $117,300 - $165,400 / Advanced Level Final offers are determined by factors including the candidate's qualifications, internal alignment considerations, district assignment, and geographic location. Screening: US Citizens or Green Card holders and Permanent Residents with at least 3 years of residency. This position has additional screening requirements due to the information accessed while performing the job. These additional screenings would be initiated at the time of offer acceptance and could take up to a couple of months to complete. You can begin work before the screening is completed; however, continued employment is contingent on acceptable screening results. The areas screened may include education/employment verification, criminal history, credit history, and reference checks. Sponsorship: The Federal Reserve Bank of Kansas City will not sponsor a new applicant for employment authorization for this position. Applicants must be currently authorized to work in the United States without the need for visa sponsorship now or in the future. About Us Total Rewards & Benefits Who We Are What We Do Follow us on LinkedIn , Instagram, X (formerly Twitter) , and YouTube #KCFedIT Full Time / Part TimeFull time Regular / TemporaryRegularJob Exempt (Yes / No) YesJob CategoryInformation Technology Family GroupWork ShiftFirst (United States of America) The Federal Reserve Banks are committed to equal employment opportunity for employees and job applicants in compliance with applicable law and to an environment where employees are valued for their differences. Always verify and apply to jobs on Federal Reserve System Careers (************************************* or through verified Federal Reserve Bank social media channels. Privacy Notice
    $117.3k-165.4k yearly Auto-Apply 27d ago
  • Information Security Operations Analyst II

    Mastercard 4.7company rating

    OFallon, MO jobs

    Our Purpose Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential. Title and Summary Information Security Operations Analyst IIOverview The Security Awareness team is looking for an Information Security Operations Analyst II to drive continued improvements to the education and training offerings we have for our Mastercard colleagues. Our award winning SecurIT First program must continue to remain relevant and effective in how we keep security awareness top of mind for all employees and contingent staff. The ideal candidate is passionate about the internal customer experience, is highly motivated, intellectually curious, analytical, and possesses an entrepreneurial mindset. Role In this Security Awareness position, you will: • Liaise between the Security Awareness team and all others at Mastercard. • Build new content and design awareness events to positively impact the security behaviors of Mastercard staff. • Partner with external providers to deliver effectives solutions with quality and integrity. • Manage our collaboration with the M&A Team and manage all Audit and Regulatory requests that come into our team. All About You The ideal candidate for this position should: • Possess advanced knowledge in security awareness concepts and principals. • Be comfortable meeting with business leaders to discuss and educate their teams about the desired security behaviors and how to influence and improve those behaviors. • Be able to identify appropriate security awareness solutions to further reduce the human risk at Mastercard. • Analyze, recognize and escalate trends in security behaviors and identify ways to improve our offerings. • Lead vendor relationships with those providers of contract solutions for the Security Awareness program. • A professional certification in Security Awareness is not required but highly encouraged. Corporate Security Responsibility Every person working for, or on behalf of, Mastercard is responsible for information security. All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and therefore, it is expected that the successful candidate for this position must: Abide by Mastercard's security policies and practices; • Ensure the confidentiality and integrity of the information being accessed. • Report any suspected information security violation or breach. • Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.Mastercard is a merit-based, inclusive, equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law. We hire the most qualified candidate for the role. In the US or Canada, if you require accommodations or assistance to complete the online application process or during the recruitment process, please contact reasonable_accommodation@mastercard.com and identify the type of accommodation or assistance you are requesting. Do not include any medical or health information in this email. The Reasonable Accommodations team will respond to your email promptly. Corporate Security Responsibility All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must: Abide by Mastercard's security policies and practices; Ensure the confidentiality and integrity of the information being accessed; Report any suspected information security violation or breach, and Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines. In line with Mastercard's total compensation philosophy and assuming that the job will be performed in the US, the successful candidate will be offered a competitive base salary and may be eligible for an annual bonus or commissions depending on the role. The base salary offered may vary depending on multiple factors, including but not limited to location, job-related knowledge, skills, and experience. Mastercard benefits for full time (and certain part time) employees generally include: insurance (including medical, prescription drug, dental, vision, disability, life insurance); flexible spending account and health savings account; paid leaves (including 16 weeks of new parent leave and up to 20 days of bereavement leave); 80 hours of Paid Sick and Safe Time, 25 days of vacation time and 5 personal days, pro-rated based on date of hire; 10 annual paid U.S. observed holidays; 401k with a best-in-class company match; deferred compensation for eligible roles; fitness reimbursement or on-site fitness facilities; eligibility for tuition reimbursement; and many more. Mastercard benefits for interns generally include: 56 hours of Paid Sick and Safe Time; jury duty leave; and on-site fitness facilities in some locations. Pay Ranges O'Fallon, Missouri: $76,000 - $127,000 USD
    $76k-127k yearly Auto-Apply 11d ago
  • Systems Engineer - Physical Security

    Hudson Valley Trading Co 3.2company rating

    Day, NY jobs

    Hudson River Trading (HRT) is looking for a Systems Engineer with a focus on physical security systems to join our Enterprise Technology team. This role will liaise closely with our Workplace and various Security teams to conduct research, design, and maintain physical security platforms. You'll join a lean and technical team with opportunities to architect, own, and evolve HRT's global physical security infrastructure, driving both strategic vision and hands-on execution, to help HRT stay secure while providing a great employee experience. Responsibilities Research, architect, and deploy physical security systems across our offices and supporting sites around the globe Conduct audits and risk assessments of the physical security of equipment and locations globally Curate an enjoyable employee experience while helping to maintain safety, security and compliance Manage user roles, permissions, and system access in compliance with company policies and best practices Troubleshoot hardware/software issues, perform diagnostics, and provide Level 2/3 support Create and maintain documentation of configurations, procedures, and system architecture Help lead technical response and forensic analysis for physical security incidents in collaboration with Workplace and Security Operations teams Collaborate with internal stakeholders to evaluate and adopt next-generation physical security technologies, such as AI-driven analytics, mobile credentials, or zero-trust physical systems Qualifications 5+ years of experience in the systems architecture, engineering, and administration of physical security systems (camera infrastructure, badge platforms, biometrics, environmental sensors, access control, etc.) Experience with open protocols and standards in physical security (OSDP, SNMP, etc.) Experience with consolidating and automating identity management, configuration, and logging for disparate physical security, access control, and digital IAM platforms Experience with data center physical security systems (VSS, ACS, IDS, anti-tailgating, anti-passback, mantraps, etc.) Experience automating through code (Python, Go, PowerShell) and working with SDKs/APIs Strong knowledge of networking concepts and protocols Familiarity with securing IP-based physical systems and awareness of modern physical security threats (e.g., firmware supply chain, OT/IT convergence) Willing to travel 20% of time to visit other offices and facilities as needed A certification like Certified Protection Professional (CPP) or Physical Security Professional (PSP) is a plus Experience using Linux is a plus Experience with public cloud providers (GCP, AWS, Azure) is a plus The estimated base salary range for this position is 150,000 to 250,000 USD per year (or local equivalent). The base pay offered may vary depending on multiple individualized factors, including location, job-related knowledge, skills, and experience. This role will also be eligible for discretionary performance-based bonuses and a competitive benefits package. Culture Hudson River Trading (HRT) brings a scientific approach to trading financial products. We have built one of the world's most sophisticated computing environments for research and development. Our researchers are at the forefront of innovation in the world of algorithmic trading. At HRT we welcome a variety of expertise: mathematics and computer science, physics and engineering, media and tech. We're a community of self-starters who are motivated by the excitement of being at the cutting edge of automation in every part of our organization-from trading, to business operations, to recruiting and beyond. We value openness and transparency, and celebrate great ideas from HRT veterans and new hires alike. At HRT we're friends and colleagues - whether we are sharing a meal, playing the latest board game, or writing elegant code. We embrace a culture of togetherness that extends far beyond the walls of our office. Feel like you belong at HRT? Our goal is to find the best people and bring them together to do great work in a place where everyone is valued. HRT is proud of our diverse staff; we have offices all over the globe and benefit from our varied and unique perspectives. HRT is an equal opportunity employer; so whoever you are we'd love to get to know you. Please be advised: Use of AI tools during interviews or assessments is strictly prohibited, unless otherwise instructed or agreed upon. We employ various methods to evaluate the authenticity of candidate responses. If we determine that AI assistance was used during any stage of the hiring process, we reserve the right to immediately disqualify your candidacy or rescind any job offers extended.
    $84k-119k yearly est. Auto-Apply 7d ago

Learn more about Fidelity Investments jobs

View all jobs