Post job

Head of security work from home jobs

- 40 jobs
  • Head of Product Security

    Instacart 4.9company rating

    Remote job

    We're transforming the grocery industry At Instacart, we invite the world to share love through food because we believe everyone should have access to the food they love and more time to enjoy it together. Where others see a simple need for grocery delivery, we see exciting complexity and endless opportunity to serve the varied needs of our community. We work to deliver an essential service that customers rely on to get their groceries and household goods, while also offering safe and flexible earnings opportunities to Instacart Personal Shoppers. Instacart has become a lifeline for millions of people, and we're building the team to help push our shopping cart forward. If you're ready to do the best work of your life, come join our table. Instacart is a Flex First team There's no one-size fits all approach to how we do our best work. Our employees have the flexibility to choose where they do their best work-whether it's from home, an office, or your favorite coffee shop-while staying connected and building community through regular in-person events. Learn more about our flexible approach to where we work. Overview The Security Engineering organization at Instacart is responsible for protecting the security and privacy of Instacart's products, data, and users. With the right mix of engineering rigor, thoughtful tooling, and cross-functional partnership, we can meaningfully elevate our security posture while still moving quickly. We are seeking a Head of Product Security to lead and scale our product security programs across Instacart's consumer, shopper, retailer, and enterprise product lines. This leader will drive the long-term vision for how product security supports our business, guiding multiple teams across offensive security, secure architecture, threat modeling, and developer enablement. You will work closely with senior engineering and product leaders to embed security into fast-paced development cycles and ensure Instacart continues to ship secure, reliable products at scale. This is a high-impact role in a dynamic, rapidly evolving environment - ideal for a leader who thrives in ambiguity, enjoys building teams and systems from the ground up, and is energized by complex technical and organizational challenges. About the Job Define and lead Instacart's long-term product security strategy, driving measurable improvements across all product surfaces. Lead multiple product security teams, setting clear direction across offensive security, secure design, architecture reviews, and security tooling. Partner with engineering and product orgs to integrate security seamlessly into the SDLC, enabling high-velocity development without compromising security. Build scalable, durable capabilities by operationalizing security tooling, frameworks, and workflows used across engineering teams. Guide teams through complex offensive security engagements to uncover security defects, anti-patterns, and emerging risks, driving mitigation plans across the organization. Design and implement security controls for cloud environments (AWS, GCP, etc.) Build a security-first culture across engineering and operations teams About You Minimum Qualifications Bachelor's degree in Computer Science, Engineering, Math, or equivalent industry experience. 10+ years of progressive experience in Security Engineering, Product Security, and Offensive Security/Penetration Testing, ideally in a high-scale, dynamic environment. 5+ years leading and scaling multi-disciplinary security teams, including managing managers, responsible for large-scale production systems in high-stakes domains. Deep expertise in driving secure architecture, advanced threat modeling, and application of security research to proactively identify and mitigate emerging risks at scale in mission-critical systems. Strong understanding of emerging threats, including AI/ML related attacks, to drive measurable risk reduction across the organization, with a proven ability to manage crises and high-impact security events. Extensive experience securing cloud infrastructure (AWS, Azure, or GCP) Experience with DevSecOps, CI/CD security integration, and automation Knowledge of container security (Docker, Kubernetes) and microservices architectures Experience with infrastructure-as-code (Terraform, CloudFormation, Ansible) Strong ability to make data-driven decisions and prioritize initiatives that meaningfully improve key security metrics. Excellent communication skills with technical and non-technical stakeholders Preferred Qualifications Familiarity with compliance or privacy frameworks such as SOC 2, GDPR, PCI, or HIPAA. AI Red Teaming and Responsible AI skills Instacart provides highly market-competitive compensation and benefits in each location where our employees work. This role is remote and the base pay range for a successful candidate is dependent on their permanent work location. Please review our Flex First remote work policy here. Offers may vary based on many factors, such as candidate experience and skills required for the role. Additionally, this role is eligible for a new hire equity grant as well as annual refresh grants. Please read more about our benefits offerings here. For US based candidates, the base pay ranges for a successful candidate are listed below. CA, NY, CT, NJ$299,000-$332,000 USDWA$287,000-$319,000 USDOR, DE, ME, MA, MD, NH, RI, VT, DC, PA, VA, CO, TX, IL, HI$275,000-$305,000 USDAll other states$248,000-$276,000 USD
    $299k-332k yearly Auto-Apply 16d ago
  • Head of SEC Reporting

    Coinbase 4.2company rating

    Remote job

    Ready to be pushed beyond what you think you're capable of? At Coinbase, our mission is to increase economic freedom in the world. It's a massive, ambitious opportunity that demands the best of us, every day, as we build the emerging onchain platform - and with it, the future global financial system. To achieve our mission, we're seeking a very specific candidate. We want someone who is passionate about our mission and who believes in the power of crypto and blockchain technology to update the financial system. We want someone who is eager to leave their mark on the world, who relishes the pressure and privilege of working with high caliber colleagues, and who actively seeks feedback to keep leveling up. We want someone who will run towards, not away from, solving the company's hardest problems. Our work culture is intense and isn't for everyone. But if you want to build the future alongside others who excel in their disciplines and expect the same from you, there's no better place to be. While many roles at Coinbase are remote-first, we are not remote-only. In-person participation is required throughout the year. Team and company-wide offsites are held multiple times annually to foster collaboration, connection, and alignment. Attendance is expected and fully supported. Reporting to the Chief Accounting Officer, this role will lead the Company's Financial Reporting function and be an integral component of Finance's risk management and reporting process, driving consistent application of accounting policy and financial reporting across the company. The successful candidate will combine a strong technical skill set with exceptional organizational skills in order to successfully lead quarterly and annual reporting cycles. Further, the candidate will have a positive attitude with a proven ability to thrive successfully in a fast paced multi-task oriented environment. This is a critical and high-profile position that will play a crucial role in financial reporting and other statutory and regulatory filings. What You'll Be Doing (i.e., Job Duties): Lead the preparation of all quarterly and annual filings with the SEC, in accordance with U.S. GAAP and SEC regulations, including preparation of monthly balance sheets, income statements and quarterly statements of stockholders' equity and preparation of disclosures. Assist in coordinating the review and approval of quarterly and annual SEC filings by all relevant parties, including the Disclosure Committee, Audit and Compliance Committee, external auditors, and internal and external legal counsel. Support Investor Relations through tie out and other quality assurance review of their externally published materials, and prepare and file the earnings release 8-K. Prepare the accounting/finance portion of quarterly Disclosure Committee and Audit Committee decks and present at the Disclosure Committee meeting. Lead the Maintain SEC reporting calendar and project manage the SEC reporting process to conform to this calendar, efficiently and effectively coordinating across teams. Coordinate with accounting policy on new accounting standards issued by the FASB and accounting and reporting guidance issued by the SEC to determine the impact to the company's disclosures, including writing position papers as needed. Support management in completing special projects as assigned and be a financial reporting resource for ad-hoc questions and initiatives. Responsible for the coaching, mentoring and management of the SEC reporting team, including across multiple time zones in a mostly asynchronous environment. Ensure SEC reporting processes and disclosures represent best practices, recommending and assisting in the implementation of disclosure and process improvements as appropriate, including simplifying, standardizing, and streamline processes. Perform financial reporting controls, including clear documentation of work/review performed. What We Look For In You (ie. Job Requirements): Strong accounting background with a thorough knowledge of US GAAP, SOX 404 and SEC financial reporting standards. Demonstrated ability to research complex and vague accounting and disclosure rules and clearly and efficiently document related conclusions. Minimum 10+ years of relevant experience. Current or recent senior-level SEC reporting experience is required. Combination of private and public accounting experience strongly preferred. CPA or similar designation required. Excellent written and oral communication skills, including experience presenting to senior-most members of company leadership. Excellent organization, project management, and analytical skills. High level of enthusiasm and curiosity to grow your career in a dynamic and growing company. High energy, positivity, endurance, and resiliency. Ability to communicate across all levels of the organization. Highest levels of integrity and work ethic. Meticulous and impeccable attention to detail while also keeping in mind overall objectives. Demonstrated ability to work autonomously, coordinate the efforts of others and work well with people at a wide range of levels. Experience performing and documenting controls over financial reporting. Familiarity and experience with Workiva's WDesk. Nice to haves Financial Institutions / Fintech background. Prior technical accounting policy leadership experience. Familiarity with NetSuite. Job #: P71089 Pay Transparency Notice: The target annual base salary for this position can range as detailed below. Full time offers from Coinbase also include bonus eligibility + equity eligibility + benefits (including medical, dental, and vision) Base salary range shown. Total compensation also includes equity and bonus eligibility and benefits:$216,300-$216,300 CAD Please be advised that each candidate may submit a maximum of four applications within any 30-day period. We encourage you to carefully evaluate how your skills and interests align with Coinbase's roles before applying. Commitment to Equal Opportunity Coinbase is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, sex, gender expression or identity, sexual orientation or any other basis protected by applicable law. Coinbase will also consider for employment qualified applicants with criminal histories in a manner consistent with applicable federal, state and local law. For US applicants, you may view the Employee Rights and the Know Your Rights notices by clicking on their corresponding links. Additionally, Coinbase participates in the E-Verify program in certain locations, as required by law. Coinbase is also committed to providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please contact us at accommodations[at]coinbase.com to let us know the nature of your request and your contact information. For quick access to screen reading technology compatible with this site click here to download a free compatible screen reader (free step by step tutorial can be found here). Global Data Privacy Notice for Job Candidates and Applicants Depending on your location, the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) may regulate the way we manage the data of job applicants. Our full notice outlining how data will be processed as part of the application procedure for applicable locations is available here. By submitting your application, you are agreeing to our use and processing of your data as required. AI Disclosure For select roles, Coinbase is piloting an AI tool based on machine learning technologies to conduct initial screening interviews to qualified applicants. The tool simulates realistic interview scenarios and engages in dynamic conversation. A human recruiter will review your interview responses, provided in the form of a voice recording and/or transcript, to assess them against the qualifications and characteristics outlined in the job description. For select roles, Coinbase is also piloting an AI interview intelligence platform to transcribe and summarize interview notes, allowing our interviewers to fully focus on you as the candidate. The above pilots are for testing purposes and Coinbase will not use AI to make decisions impacting employment . To request a reasonable accommodation due to disability, please contact accommodations[at]coinbase.com
    $117k-212k yearly est. Auto-Apply 10d ago
  • Security Operations Manager

    ECS Federal 4.3company rating

    Remote job

    ECS is seeking a Security Operations Manager to work remotely. Please Note: This position is contingent upon contract award. ECS is seeking an experienced Security Operations Manager to work remotely providing Cyber Security operations support for NIH NIAID Enabling and Advancing Technologies (NEAT). This engagement provides a spectrum of management, technologies development, applications/software engineering, bioinformatics support, and professional development. Please Note: This position is contingent upon contract win. The Security Operations Manager will be the single POC providing ongoing status and progress to the NIAID CO and COR. In this role, you will be responsible for cyber security incident resolution, monitoring of NIAID systems and components to detect potential threats, and project management and engineering support for the improvement and automation of security operation tools and processes. Requirements/Duties: * Cybersecurity incident resolution including investigation and response to minimize the impact or likelihood of incidents; * Monitoring of NIAID systems and components to detect potential threats; and * Project management and engineering support for the improvement and automation of security operations tools and processes. * Project support for projects to improve and automate security operations capabilities including developing solutions and options for project milestones, developing project plans in a task and completion tracking tool such as Jira, and reporting on progress in real-time using an IT Service Management tool such as ServiceNow. * Respond to and resolve security and privacy incidents and coordinate with the NIH Threat Management and Incident Response (TMIR) team and privacy coordinators according to NIH or Federal format and timelines. * Advise and assist with SOC architecture activities, for all SOC information systems initiatives supporting all SOC tools and capabilities. Salary Range: $150,000 - $190,000 General Description of Benefits * Bachelor's degree in Cybersecurity, Computer Science, or related field. * Active Public Trust or higher security clearance. * Minimum of 10 years of experience in cybersecurity. 15 years' experience in cybersecurity preferred. * 8+ years' experience leading and delivering in security operations programs and incident management for comparably sized federal agencies and security programs. * Shall have at least one of the following industry-recognized certifications: * Certified Information System Security Professional (CISSP) * Global Information Assurance Certification (GIAC) * Certified Enterprise Defender (GCED) * GIAC Certified Incident Handler (GCIH) * Certified Network Defender (CND) * Systems Security Certified Practitioner (SSCP) * Proven ability to consistently understand threats, evaluate the impact of potential incidents, and recommend risk reduction techniques based on a knowledge of different operation threat environments, general attack stages, incident categories, cyber defense tool data collection, and playbooks for resolving common incidents. * Demonstrated expertise in analyzing and providing clear and concise risk reports, dashboards, and other visualizations to federal risk executives, system operators, and system stakeholders. * Knowledge of and experience overseeing the administration and configuration of workstation and infrastructure security tools including but not limited to: Anti-malware/Anti-virus software, Data Loss Prevention software, endpoint detection and response (EDR), vulnerability assessment tools, asset discovery and management software, SIEM, Cloud Access Security Broker (CASB). * Knowledge of and experience supporting enterprise-wide penetration testing remediation to comply with agency remediation standards in a federated model like NIH. * Documented experience in monitoring an enterprise-wide environment including cloud-based systems for potential security incidents and in all steps to resolve incidents to minimize the impact and likelihood to operations. * Experience with establishing and enhancing security operations capabilities and proactively identifying potential risks that may lead to an incident including coordination with multi-contractor teams and across agency groups. * Experience in setting up, administering, and enhancing cybersecurity tools and security operations processes to reduce alerting on false positives, to proactively identify configurations that may lead to a potential incident, and to automate incident resolution playbooks. * Knowledge of different operational threat environments (e.g., first generation [script kiddies], second generation [non-nation state sponsored], and third generation [nation state sponsored]); general attack stages (e.g., footprinting and scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks, etc.); incident categories, incident responses, and timelines for responses; as well as penetration testing techniques and tools. * Reside within the Washington DC Metro area. * Travel within the Washington DC Metro Area, and CONUS as needed.
    $150k-190k yearly 31d ago
  • Security Lead

    Aretec Open Opportunites

    Remote job

    Aretec seeks a Security Lead for a 100% remote opportunity with a minimum of 10 years of experience leading a security delivery team with experience: collaborating with ISSOs to define and develop cybersecurity test plans utilizing cloud automation capabilities prioritizing and coordinating security remediation activities developing cross-program summary reporting and tracking for key security metrics
    $32k-59k yearly est. 60d+ ago
  • Security Lead (Vulnerability Management) - SF/NYC/Remote (US)

    Cogent Security

    Remote job

    Cogent Security is on a mission to stop breaches and prevent cybercrime by innovating at the frontier of generative AI systems. We are building the world's first AI cyber taskforce, composed of AI agents capable of human-caliber reasoning and execution of cybersecurity tasks, that autonomously protects organizations from emerging threats. The early adopters of our technology include some of the world's most important institutions, spanning public companies, elite universities, and Fortune 500 corporations across industries. Cogent was founded by a seasoned team of former engineering and product leaders, who bring decades of experience across cybersecurity and technology. The team is fully in-person in San Francisco and New York, and consists of the top software engineering and machine learning talent from leading companies such as Abnormal Security, Coinbase, Microsoft, Tesla, Stripe and more. To support our ambitious growth plans, we recently raised a large Seed round led by Greylock Partners and leading angels across AI, cybersecurity, and enterprise software (e.g. Reid Hoffman and founders of Abnormal, Datadog, and other top companies). As we execute on our mission, we are constantly pushing ourselves to ACHIEVe: Ambition for Excellence We work backwards from the way things should be and constantly measure our progress against it Customer Centricity We obsess over the problems our customers face and relentlessly innovate to find the best solutions Intellectual Honesty We embrace hard conversations and actively seek the truth Intentionality We exhibit good judgment and are thoughtful about tradeoffs Extreme Ownership We take pride in our work and never say the words “not my problem” Velocity / Bias for Action We don't leave for tomorrow what can be done today About the Role As Security Lead, you will be both a key architect of our product and a steward of Cogent's own operational security. What You'll Do Shape the Cogent product at the frontier of AI and cybersecurity Work hand-in-hand with machine learning engineers to build AI agents grounded in real-world security workflows Contribute deep domain insight to shape product strategy, roadmap, and core capabilities Build the world's first AI-native cybersecurity Org Extend and evolve Cogent's security posture, systems, and incident response capabilities to create the strongest cyber program in the industry Implement processes and tools to protect Cogent and our customers end to end Educate the market and elevate the industry Write thought-provoking content, partner with customers, and speak credibly about the role of AI in vulnerability management Help define how the industry thinks about autonomous security What You'll Bring You are a top 1% builder who thrives at the intersection of security and engineering. You bring: 10+ years of deep, hands-on experience in security engineering Expertise in vulnerability management across the attack surface Fluency in Python or a comparable language, with a passion for automation A track record of operating at scale in high-stakes, fast-paced environments A bias for clarity, velocity, and technical rigor (Bonus) Experience working closely with ML, AI, or data science teams For California Based Applicants The standard base salary range for this position is $100,000 - $300,000 annually. Compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for variable compensation, equity, and benefits. We are committed to building an inclusive and diverse company. We do not discriminate based on gender, ethnicity, sexual orientation, religion, civil or family status, age, disability, or race.
    $32k-59k yearly est. Auto-Apply 60d+ ago
  • Cybersecurity Security Operations Center Manager

    Sherwin-Williams 4.5company rating

    Remote job

    The Cybersecurity Security Operations Center (CSOC) Manager's core function is to provide leadership and oversee the administration of the CSOC, including security engineers and security analysts. The CSOC is responsible for monitoring and alerting on cybersecurity events, ensuring the maintenance of the current and future technologies, and continually analyzing threat data to find ways to improve the organization's security posture. This position requires both the ability to tactically focus on immediate threats at hand as identified in alerts and intelligence as well as strategically remain focused on Initiatives tasked by senior leadership. Candidates must be highly analytical, technically competent, and have an ability to provide focus and calm during incident response scenarios. The ability to lead groups or move forward initiatives is essential. In addition, the ability to plan for future team needs requires staying informed of current events in technology platforms and the Cybersecurity industry. Formal Education & Certification Bachelor's Degree (or foreign equivalent) or in lieu of a degree, at least 12 years in experience in the field of Information Technology or Business (work experience or a combination of education and work experience in the field of Information Technology or Business) Knowledge & Experience 10+ years IT experience. 8+ years IT security experience 4+ years of leading and managing a team of direct reports Minimum 1 year experience with cyber-security investigations and incident response. Minimum 1+ years of experience in process analysis and improvement. Background in metrics/reporting. Experience identifying and implementing solutions to complex business problems. Understanding of various operating systems (z/OS, Window, UNIX, Linux, AIX, etc.) with an emphasis on vulnerability assessment and hardening. Ability to analyze reports by reviewing incident or threat frequency, severity, and duration data. Preferred Experience Experience in a Security Operations Center (SOC) or working with a Managed Security Service Provider (MSSP) Supervisory and/or Management experience preferred. Budget management Vendor Management Understand Log Management process and program Certifications: Lean, CISSP, SANS GIAC, or CISM Project Management concepts: use of JIRA, Planner, etc. Delivery of Metrics demonstrating proof of value and key performance indicators Understanding of CVSS, CVE, CWE, CPE, CCE, CWE, OVAL, SCAP and/or other standards. Familiar with both IT and OT detect and respond functions Familiar with email security tools such as Proofpoint, Abnormal Security, O365, etc. Understanding of Threat Analysis and Threat Intelligence. Experience with Security and Information and Event Monitoring (SIEM) products such as Sumo Logic, Splunk, etc. Experience with Vulnerability Management products such as Qualys and WIZ. Utilize key performance indicators to track analyst workloads as well as the efficiency of detection signatures/rules and associated monitoring technologies. Benchmark and implement industry best practices to mitigate potential threats. Support the preparation of appropriate reports and communicate status and results. Familiarity with SOC-CMM Personal Attributes Strong analytical, evaluative, and problem-solving abilities. Strong leadership skills Ability to motivate in a team-oriented, collaborative environment. Ability to set and manage priorities. Strong written and oral communication skills. Strong interpersonal skills. Ability to present ideas in business-friendly and user-friendly language. Self-motivated and directed. Keen attention to detail. Commitment to fostering a culture of inclusion and diversity Hybrid on-site and remote work. Minimal travel is required. Work outside the standard office 7.5-hour workday may occasionally be required for on call coverage or overseeing after hours team investigations. Operational Management Manage team employees reporting directly to you. Responsibilities include preparing midyear and annual staff evaluations and addressing both opportunities for growth (such as promotions) or improvement (such as employee performance improvement plans) as performances warrant. Manage the on-call rotation and time off for the SOC Providing regular training sessions and mentorship opportunities to facilitate knowledge-sharing within the team. Hiring new staff members or contracting outside services to supplement your team's capabilities when needed. Responsible for vendor management - existing and future contractual relationships with technology and service providers. This includes working to address support issues, contract renewals / discrepancies, bi-weekly meetings, Quarterly Business Reviews, etc. Track tool performance / utilization to measure return on investment and support future evaluation / rationalization needs. Responsible for identifying tool / service evaluation opportunities. Working closely with the Security Threat Architect. Responsible for day-to-day CSOC budget management Lead your team and communicate with management during incident response (IR) to ensure timely notification and containment occur. Responsibilities include ensuring communicating, documenting IR progress, and following through with post-mortem reviews. Ensure CSOC meets regulatory compliance of both internal and external auditors by adherence to policies and procedures. Ensure version control of SOC alerts as well as least privilege access to logs and investigation data. Ensure synchronization and collaboration between the CSOC and Cyber Threat Intelligence team. Work with other departments to identify the root causes of security incidents and develop strategies to mitigate these risks. Strategy & Planning Work with employees on Individual Development plans. Interface with management and Human Resources to ensure plans meet business needs and provide measurable advancement steps to employee promotion and realization of career goals. Responsible for building and briefing at the monthly Governance Board meetings for existing or future spend as appropriate. Responsible for planning and prioritizing annual spend for CSOC in support of Operational Plan Development and advising upper management on budget forecasting. Improve incident response times, reduce false positives and other extraneous alerts, and enhancing threat detection capabilities. Work with CSOC and architecture in determining technology and resource requirements. Participate in engagement with other service families and departments in addressing CSOC logging and monitoring needs. Engage with same groups in developing Enterprise logging and monitoring strategies and solutions. Stay abreast of business and technological developments to properly prepare CSOC future posture. Acquisition & Deployment Work with upper management to understand budget availability to shape CSOC efforts. Supervise team and/or perform compliance assessments to include Proof of Value (PoV) or Proof of Concept (PoC) for new program security tools. Provide an accurate technical evaluation of the software application, system, or network, documenting the security posture, capabilities, and vulnerabilities against relevant information assurance policies. Incidental Functions Assist with other projects as required to contribute to efficiency and effectiveness of the organization. Travel may be required but should not exceed 10% of work time. Work outside the standard office 7.5-hour workday may be required with on-call availability. This position is not eligible for sponsorship for work authorization now or in the future, including conversion to H1-B visa. This is a remote position. This position is not eligible for sponsorship for work authorization now or in the future, including conversion to H1-B visa. Must be legally authorized to work in the country of employment without needing sponsorship for employment work visa status now or in the future. Job duties include contact with other employees and access confidential and proprietary information and/or other items of value, and such access may be supervised or unsupervised. The Company therefore has determined that a review of criminal history is necessary to protect the business and its operations and reputation and is necessary to protect the safety of the Company's staff, employees, and business relationships. Must be eighteen years or older
    $44k-81k yearly est. Auto-Apply 12h ago
  • Manager, Security Operations Center (SOC)

    Ultraviolet Cyber

    Remote job

    Make a difference here. UltraViolet Cyber is a leading platform-enabled unified security operations company providing a comprehensive suite of security operations solutions. Founded and operated by security practitioners with decades of experience, the UltraViolet Cyber security-as-code platform combines technology innovation and human expertise to make advanced real-time cybersecurity accessible for all organizations by eliminating risks of separate red and blue teams. By creating continuously optimized identification, detection, and resilience from today's dynamic threat landscape, UltraViolet Cyber provides both managed and custom-tailored unified security operations solutions to the Fortune 500, Federal Government, and Commercial clients. UltraViolet Cyber is headquartered in McLean, Virginia, with global offices across the U.S. and in India. UltraViolet Cyber is a leading platform-enabled unified security operations company providing a comprehensive suite of security operations solutions. Founded and operated by security practitioners with decades of experience, the UltraViolet Cyber security-as-code platform combines technology innovation and human expertise to make advanced real-time cybersecurity accessible for all organizations by eliminating risks of separate red and blue teams. UltraViolet Cyber is seeking a technically proficient, process-driven Manager to lead our Shared Services team. This role oversees a group of Security Analysts responsible for maintaining the quality, integrity, and availability of client environments during incident handling and investigations. The Manager will develop operational strategies, implement innovative security technologies, and coordinate timely, effective responses to emerging threats and incidents. This role blends leadership and hands-on technical expertise to ensure we have a world class analyst and operations. What You'll Do: Lead day-to-day SOC operations including monitoring, detection, analysis, and incident response. Develop and maintain SOC policies, procedures, and playbooks aligned with frameworks MITRE Oversee deployment, tuning, and optimization of SIEM, SOAR, IDS/IPS, EDR, and threat intel platforms. Coordinate cross-functional incident response and lead post-incident reviews. Work with IT, legal, compliance, and business units to align with risk management goals. Monitor emerging threats and adjust defenses and strategies proactively. Recruit, mentor, and develop SOC staff, fostering continuous improvement. Prepare and present SOC performance, threat landscape, and risk posture to internal and external stakeholders Define and track KPIs and metrics to measure the effectiveness of the team Use automation and scripting (e.g., Python, KQL, PowerShell) to enhance detection efficiency What You've Done: US Citizenship is Required 7+ years in cybersecurity with at least 2+ years in leading and mentoring teams Ability to communicate complex cybersecurity issues to both technical and non-technical stakeholders 3+ years of experience with dark web, OSINT tools Proficiency with SIEM, EDR, and cloud-native security tools (e.g., Sentinel, Splunk, Defender, Elastic, CrowdStrike). Hands-on experience scripting in Python, Bash, KQL, PowerShell, or similar languages. Ability to work with Linux, including command line for analysis of large datasets. Ability to communicate complex cybersecurity issues to both technical and non-technical stakeholders Excellent written and verbal communication skills, including the ability to brief executives on complex technical issues. Ability to work under pressure and manage multiple priorities in a fast-paced environment Preferred Education and Certifications: Bachelor's degree in Cybersecurity, Computer Science, or related field (or equivalent experience). Industry certifications such as GCTI, GCFA, GCIA, GREM, or OSCP. What We Offer: 401(k), including an employer match of 100% of the first 3% contributed and 50% of the next 2% contributed Medical, Dental, and Vision Insurance (available on the 1st day of the month following your first day of employment) Group Term Life, Short-Term Disability, Long-Term Disability Voluntary Life, Hospital Indemnity, Accident, and/or Critical Illness Participation in the Discretionary Time Off (DTO) Program 11 Paid Holidays Annually UltraViolet Cyber maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect our company's differing products, services, industries and lines of business. Candidates are typically placed into the range based on the preceding factors. We sincerely thank all applicants in advance for submitting their interest in this position. We know your time is valuable. UltraViolet Cyber welcomes and encourages diversity in the workplace regardless of race, gender, religion, age, sexual orientation, gender identity, disability, or veteran status. If you want to make an impact, UltraViolet Cyber is the place for you!
    $43k-81k yearly est. Auto-Apply 59d ago
  • Technical Security Operations Center (SOC) Manager (R-00102)

    True Zero Technologies

    Remote job

    True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that said outcomes begin and end with our people, and that is what we have built, a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top tier services to our customers. In 2023, True Zero was recognized as a “Best Places to Work” in two categories ("Prosperous and Thriving" ($5MM - $50MM in gross revenue) and "Mid-Atlantic Region" (DC, DE, MD, NC, VA, WV)) and in 2022, was recognized as one of Inc. Magazine's Top 5000 Fastest Growing Companies. Job Summary: TZT is seeking a highly skilled and experienced Security Operations Center (SOC) Program Manager to join our team. As a SOC Program Manager, you will be responsible for overseeing the successful implementation and management of Security Operations Centers (SOCs) and Information Technologies (IT) projects. This is a critical role that requires a strong understanding of SOC operations, information security principles, and Splunk architectures (or alternate Splunk experience). As a TZT consultant, the candidate will receive access to the full knowledge base which is driven by the True Zero community as well as the technical backing of the entire PS team. True Zero encourages collaboration and growth through information sharing and knowledge workshops. The candidate will also have access to our internal Slack channel to stay connected with the team as well as the necessary tools to train, demo, test and grow their professional skills.SOC Manager Responsibilities Manage end-to-end program delivery for Security Operations Centers and Information Technologies projects. Define, manage, and monitor project scope, goals, deliverables, and projct status in collaboration with stakeholders Develop and maintain project plans, schedules, and budgets. Coordinate and collaborate with cross-functional teams to ensure project objectives and deliverables are met. Provide guidance and mentorship to project teams to drive successful project execution. Monitor project progress, identify risks and issues, and implement mitigation strategies. Facilitate effective communication between project stakeholders, including technical and non-technical audiences. Ensure adherence to project management best practices and industry standards. Conduct regular project status meetings and provideaccurate reporting to senior management. Manage SOC resources, establish SOC staffing/shift plans, identify/manage analyst tasks, provide status reporting and escalation to senior leadership SOC PM Requirements Bachelor's degree in Computer Science, Information Systems, or a related field (or equivalent experience). Proven experience (5+ years) in program management for Security Operations Centers and Information Technologies projects. Strong knowledge and understanding of SOC operations, information security principles, and best practices. Proficiency in Splunk architecture or alternate Splunk experience. Excellent project management skills, including the ability to prioritize tasks, manage resources, and meet deadlines. Solid understanding of project management methodologies and frameworks. Exceptional communication and interpersonal skills, with the ability to effectively engage with stakeholders at all levels. Strong analytical and problem-solving abilities. Project/program management and/or technical certifications, such as PMP, CISSP, or CISM are highly desirable. Proven experience in leading and managing complex cybersecurity projects. Familiarity with other security technologies and tools, such as SIEM, IDS/IPS, and vulnerability management. Experience in managing and mentoring project teams, ensuring high performance and accountability. Knowledge of regulatory compliance frameworks, such as GDPR, HIPAA, or PCI DSS. Ability to adapt to changing priorities and thrive in a fast-paced, dynamic environment. Strong leadership skills and the ability to influence and motivate team members. Attention to detail and a commitment to delivering high-quality results. U.S. Citizenship is required as this is in support of a Federal Customer. We're actively searching for talented security and technology practitioners who are ready to experience the True Zero difference. As a True Zero team member, you'll enjoy: - Competitive salary, paid twice per month- Best in class medical coverage- 100% of medical premiums covered by True Zero- Company wide new business incentive programs- Contribution Incentives (i.e. white papers, blog posts, internal webinars, etc.)- 3 weeks of PTO starting + 11 Paid Holidays Annually- 401k Program with 100% company match on the first 4%- Monthly reimbursement of Cell Phone and Home Internet costs- Paternity/Maternity Leave- Investment in training and certifications to broaden and deepen your technical skills
    $43k-81k yearly est. Auto-Apply 60d+ ago
  • Senior Security Officer - Michael C. Carlos Museum

    Emory Healthcare/Emory University 4.3company rating

    Remote job

    **Discover Your Career at Emory University** Emory University is a leading research university that fosters excellence and attracts world-class talent to innovate today and prepare leaders for the future. We welcome candidates who can contribute to the excellence of our academic community. **Description** KEY RESPONSIBILITIES: + Ensures a safe and secure environment for staff, students, patients and visitors. + Maintains open channels of communication to ensure regulations are understood and properly enforced. + Contacts medical personnel in emergency situations and provides first aid or CPR for stabilization until appropriate staff arrives. + Monitors the quality of security services and recommends changes to improve or enhance them. + Supervises security personnel and serves as a resource for customers. Performs related responsibilities as required. MINIMUM QUALIFICATIONS: + A high school diploma or equivalent. + Two years of military or security experience. + Ability to exercise physical restraint. + Positions in this classifications may require a valid Georgia driver's license and insurable driving record NOTE: Position tasks are required to be performed in-person at an Emory University location; working remote is not an option. Emory reserves the right to change this status with notice to employee. **Additional Details** Emory is an equal opportunity employer, and qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by state or federal law. Emory University does not discriminate in admissions, educational programs, or employment, including recruitment, hiring, promotions, transfers, discipline, terminations, wage and salary administration, benefits, and training. Students, faculty, and staff are assured of participation in university programs and in the use of facilities without such discrimination. Emory University complies with Section 503 of the Rehabilitation Act of 1973, the Vietnam Era Veteran's Readjustment Assistance Act, and applicable executive orders, federal and state regulations regarding nondiscrimination, equal opportunity, and affirmative action (for protected veterans and individuals with disabilities). Inquiries regarding this policy should be directed to the Emory University Department of Equity and Civil Rights Compliance, 201 Dowman Drive, Administration Building, Atlanta, GA 30322. Telephone: ************ (V) | ************ (TDD). Emory University is committed to ensuring equal access and providing reasonable accommodations to qualified individuals with disabilities upon request. To request this document in an alternate format or to seek a reasonable accommodation, please contact the Department of Accessibility Services at accessibility@emory.edu or call ************ (Voice) | ************ (TDD). We kindly ask that requests be made at least seven business days in advance to allow adequate time for coordination. **Connect With Us!** Connect with us for general consideration! **Job Number** _156715_ **Job Type** _Regular Full-Time_ **Division** _Emory University Libraries_ **Department** _Museum Security_ **Job Category** _Public Safety and Security_ **Campus Location (For Posting) : Location** _US-GA-Atlanta_ **_Location : Name_** _Emory Campus-Clifton Corridor_ **Remote Work Classification** _No Remote_ **Health and Safety Information** _Not Applicable_
    $25k-34k yearly est. 45d ago
  • Intel Security Specialist with TS and SCI Eligible

    Watershed Security

    Remote job

    Watershed Security, is a Veteran Owned Small Business with over 20 years' Cybersecurity and Government Contracting experiencing. Watershed is looking for a Intel Security Specialist to support the Naval Surface Warfare Center (NSWC) Dahlgren Division Dam Neck Anex (NSWCDD-DNA) in Dam Neck, VA. The successful candidates will have experience coordinating and enacting required security changes, with in various levels of an organization, ensuring compliance with published policies; conducting cybersecurity vulnerability and threat analysis; and be experienced as an ISSO or ISSE. REQUIRED QUALIFICATIONS Bachelor of Science in Information Systems or Bachelor of Science in Information Technology or Bachelor of Science in Computer Science or Bachelor of Science in Computer Engineering. Years of Experience: Ten (10) years of full-time professional experience in performing Risk Management Framework (RMF) activities; (or) 15 years of RMF experience and a GED/High School Diploma. Must be able to maintain IAT-II designation with at least one of the following active certifications: CCNA-Security, CySA+, GICSP, GSEC, Security+ CE, CND, SSCP. Any level of Demonstrated experience in all of the following areas: Performing STIG assessments to include using SCAP benchmarks and EvaluateSTIG Performing vulnerability assessments with the Assured Compliance Assessment Solution tool Using eMASS or XACTA for RMF package management Developing Plans of Actions and Milestones (POA&M) entries Completing Risk Management Framework Step 5 authorizations in the ISSE capacity or Information System Security Officer (ISSO) capacity Communicating risk reduction recommendations to stakeholders Managing privileged user documentation, training, and CSWF requirements Researching and evaluating Cyber Task Orders (CTOs) and detailing implementation requirements Tracking documentation requirements and coordination with POCs for updates Reviewing Interconnection Security Agreements (ISAs) for technical details and ensuring within ATO parameters Maintaining inventory, tracking, and destruction of removable media Clearance Level: TOP SECRET with SCI Eligibility; US Citizen. Ability to possibly provide onsite support in Dam Neck VA. Some/all remote work may be an option, however the norm will be onsite support. This will be dependent upon customer needs and classification level of work being performed. Some travel may be required. Proficient with Microsoft Office Suite (Word, Excel, Teams, Project). Self-Starter; detail oriented; able to brief senior level staff. DESIRED QUALIFICATIONS Experience supporting 10 or more Navy Packages (achieving and/or maintaining ATO) Experience with Navy Cybersecurity requirements Experience with the NAVSEA RMF Business Rules Contingent upon award PAY RANGE Final salary is influenced by factors such as location, contract labor categories, experience, skills, education, and certifications. Watershed offers competitive compensation, medical and dental benefits, educational reimbursement, 401K plans with matching, 15 days of PTO to start and 11 paid holidays per year. The proposed salary range for this position is: $100,000.00 - $115,000.00 USD. Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
    $100k-115k yearly Auto-Apply 21d ago
  • ServiceNow Security Specialist (REMOTE)

    Koniag Government Services 3.9company rating

    Remote job

    Koniag Management Solutions, LLC a Koniag Government Services company, is seeking a ServiceNow Security Specialist to support KMS and our government customer. This position is remote. This position requires the candidate to be able to obtain a Public Trust. We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more. Koniag Management Solutions (KMS) is seeking an experienced ServiceNow Security Manager to lead the security, compliance, and governance of our ServiceNow (SNOW) platform. This role is responsible for defining and implementing security policies, managing user access controls, ensuring compliance with regulatory requirements, and establishing security best practices across all ServiceNow applications and modules. The ideal candidate will have deep expertise in ServiceNow security architecture, identity and access management, and information security principles, combined with strong leadership and risk management capabilities. The ServiceNow Security Manager will serve as the primary security authority for the ServiceNow platform, working closely with IT Security, Compliance, Development, and Business teams to ensure the platform is secure, compliant, and aligned with organizational security standards. This individual will be responsible for managing security configurations, conducting security assessments, and providing security guidance for all ServiceNow initiatives. **Essential Functions, Responsibilities & Duties may include, but are not limited to:** + Design, implement, and maintain comprehensive security architecture for the ServiceNow platform + Define and enforce security policies, configurations, standards, and procedures for ServiceNow applications and data + Create and maintain security documentation, including Access Control Lists (ACLs), roles, groups, and user permissions across all ServiceNow modules + Conduct regular security assessments, audits, and vulnerability analyses of the ServiceNow platform + Implement and maintain security compliance controls for regulatory requirements (SOX, HIPAA, GDPR, PCI-DSS, etc.) + Develop and maintain role-based access control (RBAC) frameworks and security models + Monitor and investigate security incidents, access violations, and anomalous activities + Collaborate with development teams to ensure secure coding practices and security by design + Manage ServiceNow Single Sign-On (SSO), multi-factor authentication (MFA), and identity integration + Lead security aspects of ServiceNow upgrades, patches, and platform changes + Provide security guidance and training to ServiceNow administrators and developers + Manage third-party integrations and API security configurations + Coordinate with internal and external auditors for ServiceNow security reviews + Stay current with ServiceNow security features, vulnerabilities, and industry best practices + Participate in incident response and disaster recovery planning for the ServiceNow platform + Generate security reports and metrics for leadership and compliance purposes + Build and maintain strong relationships with business leaders and key stakeholders + Support change management activities related to ServiceNow implementation **Education and Experience:** + Bachelor's degree in Business Administration, Management, Computer Science, Engineering, or related field + Minimum 5-7 years of experience in information security, with at least 3-5 years focused on ServiceNow security + Proven experience implementing and managing ServiceNow security controls and access management + Experience with ServiceNow platform administration and configuration + Strong understanding of security frameworks and compliance requirements (ISO 27001, NIST, CIS Controls) + Experience conducting security assessments and managing security incidents + Track record of implementing security best practices in enterprise environments + Must hold at least one of the following certifications: + Certified Information Systems Security Professional (CISSP) certification + Certified Information Security Manager (CISM) certification + Certified Information Systems Auditor (CISA) certification + Certified Ethical Hacker (CEH) or other relevant security certification **Required Skills and Competencies:** + Expert knowledge of ServiceNow security architecture and security controls + Deep understanding of ServiceNow ACLs, roles, groups, and security rule configurations + Proficiency in ServiceNow security modules (Security Operations, Vulnerability Response, Threat Intelligence) or other similar security tools + Strong knowledge of identity and access management (IAM) principles and technologies + Experience with ServiceNow authentication methods (SSO, SAML, OAuth, LDAP, Active Directory) + Understanding of encryption technologies and data protection mechanisms + Knowledge of network, cloud, & application security logging, monitoring, and SIEM integration + Experience with security audits, security assessments, vulnerability scanning, & compliance reporting + Understanding of API security and secure integration patterns + Knowledge of ServiceNow scripting for security implementations (JavaScript, Business Rules, Script Includes) + Excellent problem-solving, analytical, risk assessment, and critical thinking skills with ability to anticipate security threats and trends + Outstanding communication skills with ability to explain security concepts to technical and non-technical audiences + Ability to balance security requirements with business needs and usability + Customer service mindset with focus on Stakeholder management and collaboration skills + Self-motivated with ability to work with moderate supervision **Desired Skills and Competencies:** + Master's degree in Information Security, Cybersecurity, or related field + Additional ServiceNow certifications (Implementation Specialist, Mainline Specialist) + Experience managing security teams or programs + Background in security consulting or advisory roles + Strong presentation and training delivery skills + Experience with security awareness program development + Knowledge of privacy regulations and data protection laws + Change management and security culture transformation experience **Security Requirement:** + Ability to obtain Public Trust **Travel:** + Minimal travel required (less than 10%) **Our Equal Employment Opportunity Policy** The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment. The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website, please get in touch with Heaven Wood via e-mail at accommodations@koniag-gs.com or by calling ************ to request accommodations. _Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit_ _****************** _._ **_Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352_** **Job Details** **Job Family** **Engineering** **Pay Type** **Salary** **Hiring Min Rate** **160,000 USD** **Hiring Max Rate** **180,000 USD**
    $60k-112k yearly est. 16d ago
  • Remote Security Officer ($24/hr, 2 weeks on, 2 weeks off) - Yukon-Kuskokwim Health Corporation

    NMS USA 4.2company rating

    Remote job

    The Remote Security Officer provides services for a variety of large and small business clients in remote settings where health, safety and security is our #1 priority. All duties are to be performed in accordance with NMS' mission, vision, and values. Responsibilities * Personally monitors and patrols either visually or electronically a variety of assigned buildings, areas, or grounds. * Permits only properly authorized individuals to enter the property. * Patrols premises and examines doors, windows, and gates to determine they are secure. * Records data such as property damage, unusual occurrences, etc. * Warns violators of rule infractions and may apprehend or expel violators. * Notifies on-site individuals of visitors wishing to see them. * Assists in properly responding to a variety of emergencies or disasters in order to preserve life and property. * Operates camp billeting and access control systems and maintains a list of visitors or authorized companies/personnel who are allowed access to various areas. * May check heating, lighting, sprinkling, security, ventilation, fire, etc., systems to make sure they are operational. * Provides transportation services using a variety of vehicles ranging from standard passenger vehicles to large passenger buses and off-road vehicles. * Provides emergency medical intervention including CPR, AED, and patient movement. * Notify supervisor if safety and sanitation standards are not being met. * Other duties that are pertinent to the department or unit's success also may be assigned. * This position has no supervisory responsibilities. Qualifications * High school diploma or GED equivalent. * Must have at least one (1) year of full-time professional security, law enforcement or military experience. * Post-secondary education in a related field may be substituted for experience. * A valid Driver's License and an acceptable driving record for the past three (3) years to be eligible under NMS' vehicle insurance policy. * Must be able to obtain and pay the Alaska Guard License fee of $97.00 prior to beginning work. * Must have basic computer skills to include but not limited to Microsoft office and contract specific software. * Must pass all pre-employment contract requirements which may include but are not limited to: hair follicle drug test, physical and fit for duty assessment and hearing test. Applicants not located near a testing facility are responsible for paying for travel to the nearest testing facility. * Must be able to live in dormitory style settings and meet cleanliness requirements of the remote camp. * Must be able to cooperate and work as part of a team with fellow employees, customers and clients. * Must be able to make decisions in the moment with little to no supervision. * Must be able to be on your feet for 12 hours per shift for the scheduled rotation. * Contract requires employees to speak, understand, read and write English. * Must meet and adhere to all safety guidelines and regulations set forth by the company and client. CANDIDATES RESIDING OUTSIDE ANCHORAGE AREA: Candidates residing in the Lower 48 for any contract and/or hired for the BP contract: For the purposes of pre-employment testing, Anchorage will be considered the point of hire (with the exception of drug testing, which will be conducted near the candidate's place of residence). Employee is responsible for any travel expenses and needed accommodations related to pre−employment tasks that need to be completed in Anchorage, AK. This includes, but is not limited to, any safety training requirements, required pre−employment testing and/or training such as physical, DOT physical/medical card, fit for duty, audiogram, and/or other testing required by contract/company (such as NSTC, APICC training, security licensing requirements, etc. Candidates residing in Alaska for Alyeska and Hillcorp contracts: pre-employment testing will be scheduled near the candidate's area of residence within the state. The only exception is when the candidate lives in a region without the necessary service providers to complete all requirements. Flights to Remote Locations: All employees are responsible for all expenses related to reporting to point of hire (Anchorage, AK) for scheduled trips paid for by the company for remote locations. Working Conditions and Physical Requirements Weather: Indoors and Outdoors, frequently exposed to arctic weather conditions. Noise level: Moderate to Loud. Description of environment: Environment will vary based on the facility assigned to. Physical requirements: Employee is frequently to constantly required to sit, stand, walk, use hands/fingers to handle or feel, climb, stoop, kneel, crouch or crawl, talk/hear, see, taste/smell, and carry weight/lift. Fit For Duty Test * Lift: Lift 20 lbs. from floor to knuckle x 2, * Lift: Lift 20 lbs. from floor to waist x 2, * Carry: Carry 20 lbs. with two hands for a minimum distance of 20 feet, self-paced but continuous, * Kneel: Kneel on one knee and stand. Return to kneel on opposite knee. Repeat alternate kneeling sequence x 3 for each knee, self-paced but continuous, * Stand from Supine Position Test: From a supine, recumbent position, while wearing arctic gear, test recipient must be able to stand without assistance x 3, self-paced (this task must be accomplished safely without significant loss of balance or falling and without assistance). Allow one re-test when there is a loss of balance considered unsafe or a fall.) * Stoop & Twist: Perform alternate cross over toe touches x 5 each side, self-paced but continuous, * Walk: Walk on a treadmill at 3 MPH for 10 minutes with good balance * Stairs: Climb up and down 10 steps x 2 for a total of 20 steps, self-paced. Competencies * Customer Service - Provides outstanding customer service; manages difficult or emotional situations; responds promptly to customer needs; responds to requests for service and assistance; meets commitments in a timely manner. * Interpersonal Skills - Focuses on solving conflict; maintains confidentiality; listens to others without interrupting; keeps emotions under control; remains open to other ideas. * Oral Communication - Speaks clearly and persuasively in positive or negative situations; listens and gets clarification; responds well to questions; demonstrates group presentation skills; participates in meetings. * Written Communication - Writes incidents, logs and other reports clearly; able to read and interpret written information.
    $31k-36k yearly est. Auto-Apply 13d ago
  • Security Specialist III

    JSOP8

    Remote job

    JT4, LLC provides engineering and technical support to multiple western test ranges for the U.S. Air Force, Space Force, and Navy under the Joint Range Technical Services Contract, better known as J-Tech II. JT4 develops and maintains realistic, integrated test and training environments and prepares our nation's war-fighting aircraft, weapons systems, and aircrews for today's missions and tomorrow's global challenges. RANGE POSITION DESCRIPTION - ESSENTIAL FUNCTIONS/DUTIES This position includes support in ongoing development and implementation of general and program specific security processes and procedures to include the advisement, planning, implementation, oversight, monitoring, analysis, reporting and assistance in the execution of security operations for a Special Access Programs (SAPs) and associated Facilities (SAPFs). Candidates with certification under the Security Personnel Education and Development program are highly preferred. Candidates with knowledge and experience with JADE are highly preferred. An Active TOP SECRET clearance is required for this position. Primary hours can change as dictated by mission requirements. Performs the daily administrative tasks in support of the site security department. Communicates with the clearance granting agency regarding status of clearances and periodic re-investigations for employees/consultants. Obtains certification of existing clearance levels for employees/consultants and for prospective employees from appropriate customer/agency sponsor. Issues security badges to designated employees and visitors. Maintain logs and records of badges issued and related information. Schedules initial, periodic and exit briefings and notifies supervisors and employees of schedule. Coordinates with employees/consultants for timely submittal of documents for initial clearances and periodic reinvestigations; fingerprint employees/consultants as required. Assists in facilitating security briefings for individuals/groups as required. Performs other related tasks as directed. REQUIREMENTS - EDUCATION, TECHNICAL, AND WORK EXPERIENCE Associate's Degree or equivalent military or technical school and 5 years specifically related work experience in the NISPOM/SAP/SCI security fields, complemented by formal training such as successful completion of the Industrial Security Management Course. Must be knowledgeable with the rules and regulations of the National Industrial Security Program Operation Manual (NISPOM) pertaining to all aspects of security. Must have excellent communication skills, both written and oral. Must be proficient operating personal computers using Microsoft Word, Excel, and graphics software, and possess database management experience. Familiar with a mainframe computer terminal, laminating machine and professional instamatic camera. Must possess a current, State issued driver's license. Must have a current government security clearance and special access. Must be a U.S. citizen. SALARY The expected pay range for this position is $84,000 to $92,000 annually. Note: The salary range offered for this position is a good faith description of the expected salary range this role will pay. JT4, LLC considers factors such as (but not limited to) responsibilities of the position, candidate's work experience, education/training, key skills, internal peer equity, as well as, market and business considerations when extending an offer. BENEFITS Medical, Dental, Vision Insurance **Benefits Active on Day 1 Life Insurance Health Savings Accounts/FSA's Disability Insurance Paid Time Off 401(k) Plan Options with Employer Match JT4 will match 50%, up to an 8% contribution 100% Immediate Vesting Tuition Reimbursement OTHER RESPONSIBILITIES Each employee must read, understand, and implement the general and specific operational, safety, quality, and environmental requirements of all plans, procedures, and policies pertaining to their job. WORKING CONDITIONS This position involves work typical of an office environment with no unusual hazards. There is occasional lifting (up to 20 pounds), constant sitting and use of a computer terminal, constant use of sight abilities while writing, reviewing, and editing documents, constant use of speech/hearing abilities for routine communications. Must maintain constant mental alertness. Routine travel to remote work locations may be required. DISCLAIMER The above statements are intended to describe the general nature and level of work being performed by personnel assigned to this classification. They are not intended to be construed as an exhaustive list of all responsibilities, duties, and skills required of persons so classified. Tasking is in support of a Federal Government Contract that requires U.S. citizenship. Some jobs may require a candidate to be eligible for a government security clearance, state-issued driver's license or other licenses/certifications, and the inability to obtain and maintain the required clearance, license or certification may affect an employee's ability to maintain employment. SCC: JSOP8, JCIS11, A1412TW
    $84k-92k yearly 16h ago
  • Security Specialist III

    JT3 4.3company rating

    Remote job

    JT4, LLC provides engineering and technical support to multiple western test ranges for the U.S. Air Force, Space Force, and Navy under the Joint Range Technical Services Contract, better known as J-Tech II. JT4 develops and maintains realistic, integrated test and training environments and prepares our nation's war-fighting aircraft, weapons systems, and aircrews for today's missions and tomorrow's global challenges. JOB SUMMARY -- ESSENTIAL FUNCTIONS/DUTIES Provide administrative and personnel security support to the unit manager and security staff. Employee will be responsible to perform the following functions/duties: Performs the daily administrative tasks in support of the site security department Communicates with the clearance granting agency regarding status of clearances and periodic re-investigations for employees/consultants Obtains certification of existing clearance levels for employees/consultants and for prospective employees from appropriate customer/agency sponsor Issues security badges to designated employees and visitors Maintain logs and records of badges issued and related information Schedules initial, periodic and exit briefings and notifies supervisor and employee of schedule Oversees departmental coordination with employees/consultants for timely submittal of documents for initial clearances and periodic reinvestigations; fingerprint employees/consultants as required Facilitates security briefings for individuals/groups as required Provides work direction to lower level department clerical/administrative personnel Performs other related tasks as directed REQUIREMENTS -- EDUCATION, TECHNICAL AND WORK EXPERIENCE Associate's degree or equivalent military or technical school and five years specifically related work experience in the NISPOM/SAP/SCI security fields, complemented by formal training such as successful completion of the Industrial Security Management Course. Must be very knowledgeable with the rules and regulations of the National Industrial Security Program Operation Manual (NISPOM) pertaining to all aspects of security. In addition, a Security Specialist III must possess the following qualifications: Must have excellent communication skills, both written and oral Must be proficient operating personal computers using Microsoft Word, Excel, and graphics software, and possess data base management experience Must be familiar with a standard intel computer system, laminating machine and professional instamatic camera Must qualify for and maintain a government security clearance Must possess a valid, state-issued driver's license SALARY The expected salary range for this position is $53,976.00 to $81,244.80 annually. Note: The salary range offered for this position is a good faith description of the expected salary range this role will pay. JT4, LLC considers factors such as (but not limited to) responsibilities of the position, candidate's work experience, education/training, key skills, internal peer equity, as well as, market and business considerations when extending an offer. BENEFITS Medical, Dental, Vision Insurance Benefits Active on Day 1 Life Insurance Health Savings Accounts/FSA's Disability Insurance Paid Time Off 401(k) Plan Options with Employer Match JT4 will match 50%, up to an 8% contribution 100% Immediate Vesting Tuition Reimbursement OTHER RESPONSIBILITIES Each employee must read, understand, and implement the general and specific operational, safety, quality, and environmental requirements of all plans, procedures, and policies pertaining to their job. WORKING CONDITIONS This position involves work typical of an office environment with no unusual hazards. There is occasional lifting (up to 20 pounds), constant sitting and use of a computer terminal, constant use of sight abilities while writing, reviewing, and editing documents, constant use of speech/hearing abilities for routine communications. Must maintain constant mental alertness. Routine travel to remote work locations may be required. DISCLAIMER The above statements are intended to describe the general nature and level of work being performed by personnel assigned to this classification. They are not intended to be construed as an exhaustive list of all responsibilities, duties, and skills required of persons so classified. Tasking is in support of a federal government contract that requires U.S. citizenship. Some jobs may require a candidate to be eligible for a government security clearance, state-issued driver's license or other licenses / certifications and the inability to obtain and maintain the required clearance, license or certification may affect an employee's ability to maintain employment. SCC: JSOP8; JCIS11 #LI-JD1
    $54k-81.2k yearly 16h ago
  • Security Specialist I

    A1412TW

    Remote job

    JT4, LLC provides engineering and technical support to multiple western test ranges for the U.S. Air Force, Space Force, and Navy under the Joint Range Technical Services Contract, better known as J-Tech II. JT4 develops and maintains realistic, integrated test and training environments and prepares our nation's war-fighting aircraft, weapons systems, and aircrews for today's missions and tomorrow's global challenges. JOB SUMMARY - ESSENTIAL FUNCTIONS/DUTIES Provide administrative and personnel security support to the unit manager and security staff. Performs the daily administrative tasks in support of the site security department. Communicates with the clearance granting agency regarding status of clearances and periodic re-investigations for employees/consultants. Obtains certification of existing clearance levels for employees/consultants and for prospective employees from appropriate customer/agency sponsor. Issues security badges to designated employees and visitors. Maintain logs and records of badges issued and related information. Schedules initial, periodic and exit briefings and notifies supervisors and employees of schedule. Coordinates with employees/consultants for timely submittal of documents for initial clearances and periodic reinvestigations; fingerprint employees/consultants as required. Assists in facilitating security briefings for individuals/groups as required. Performs other related tasks as directed. RANGE POSITION DESCRIPTION This position includes support in ongoing development and implementation of general and program specific security processes and procedures to include the advisement, planning, implementation, oversight, monitoring, analysis, reporting and assistance in the execution of security operations for a Special Access Programs (SAPs) and associated Facilities (SAPFs). Candidates with certification under the Security Personnel Education and Development program are highly preferred. Performs the daily administrative tasks in support of the site security department. Communicates with the clearance granting agency regarding status of clearances and periodic re-investigations for employees/consultants. Obtains certification of existing clearance levels for employees/consultants and for prospective employees from appropriate customer/agency sponsor. Issues security badges to designated employees and visitors. Maintain logs and records of badges issued and related information. Schedules initial, periodic and exit briefings and notifies supervisors and employees of schedule. Coordinates with employees/consultants for timely submittal of documents for initial clearances and periodic reinvestigations; fingerprint employees/consultants as required. Assists in facilitating security briefings for individuals/groups as required. Performs other related tasks as directed. REQUIREMENTS - EDUCATION, TECHNICAL, AND WORK EXPERIENCE Military or technical training with 1 year specifically related work experience in the NISPOM/SAP/SCI security fields, complemented by formal training such as successful completion of the Industrial Security Management Course. Must be familiar in the rules and regulations of the National Industrial Security Program Operating Manual (NISPOM) pertaining to all aspects of Personnel Security. Must have working knowledge of site-specific procedures and security requirements. The position requires a high degree of accuracy pertaining to all aspects of Personnel Security. Must have excellent communication skills, both written and oral. Must be proficient operating personal computers using Microsoft Word, Excel, and graphics software, and possess database management experience. Familiar with a mainframe computer terminal, laminating machine and professional instamatic camera. Must possess a current, State issued driver's license. Must qualify for and maintain a Security Clearance. U.S. Citizenship is required. SALARY The expected salary range for this position is $68,640 to $72,800 annually. Note: The salary range offered for this position is a good faith description of the expected salary range this role will pay. JT4, LLC considers factors such as (but not limited to) responsibilities of the position, candidate's work experience, education/training, key skills, internal peer equity, as well as, market and business considerations when extending an offer. BENEFITS Medical, Dental, Vision Insurance **Benefits Active on Day 1 Life Insurance Health Savings Accounts/FSA's Disability Insurance Paid Time Off 401(k) Plan Options with Employer Match JT4 will match 50%, up to an 8% contribution 100% Immediate Vesting Tuition Reimbursement OTHER RESPONSIBILITIES Each employee must read, understand, and implement the general and specific operational, safety, quality, and environmental requirements of all plans, procedures, and policies pertaining to their job. WORKING CONDITIONS This position involves work typical of an office environment with no unusual hazards. There is occasional lifting (up to 20 pounds), constant sitting and use of a computer terminal, constant use of sight abilities while writing, reviewing, and editing documents, constant use of speech/hearing abilities for routine communications. Must maintain constant mental alertness. Routine travel to remote work locations may be required. DISCLAIMER The above statements are intended to describe the general nature and level of work being performed by personnel assigned to this classification. They are not intended to be construed as an exhaustive list of all responsibilities, duties, and skills required of persons so classified. Tasking is in support of a Federal Government Contract that requires U.S. citizenship. Some jobs may require a candidate to be eligible for a government security clearance, state-issued driver's license or other licenses/certifications, and the inability to obtain and maintain the required clearance, license or certification may affect an employee's ability to maintain employment. SCC: JSOP8, JCIS11, A1412TW
    $68.6k-72.8k yearly 16h ago
  • Security GRC Specialist, Audit & Assurance (R13698)

    Oportun 4.3company rating

    Remote job

    Oportun (Nasdaq: OPRT) is a mission-driven fintech that puts its members' financial goals within reach. With intelligent borrowing, savings, and budgeting capabilities, Oportun empowers members with the confidence to build a better financial future. Since inception, Oportun has provided more than $19.7 billion in responsible and affordable credit, saved its members more than $2.4 billion in interest and fees, and helped its members save an average of more than $1,800 annually. Oportun has been certified as a Community Development Financial Institution (CDFI) since 2009. WORKING AT OPORTUN Working at Oportun means enjoying a differentiated experience of being part of a team that fosters a diverse, equitable and inclusive culture where we all feel a sense of belonging and are encouraged to share our perspectives. This inclusive culture is directly connected to our organization's performance and ability to fulfill our mission of delivering affordable credit to those left out of the financial mainstream. We celebrate and nurture our inclusive culture through our employee resource groups. POSITION OVERVIEW The Security GRC Specialist, Audit & Assurance is responsible for leading Oportun's audit readiness and assurance initiatives across security and compliance programs. This role will oversee execution and continuous improvement of control frameworks supporting SOC 2, PCI DSS, and partner assurance programs, ensuring alignment with Oportun's compliance strategy and regulatory expectations. The ideal candidate will serve as a subject matter expert in security controls, evidence management, and audit coordination using AuditBoard and Microsoft Office Suite. Experience with FTC Safeguards, SOC 1, or SOX programs is beneficial but not required. This role partners closely with internal teams, external auditors, and business stakeholders to maintain a robust and transparent compliance posture. RESPONSIBILITIES • Lead the planning, coordination, and execution of internal and external audits across SOC 2, PCI DSS, and partner assurance programs. • Maintain Oportun's control framework within AuditBoard, ensuring timely updates, documentation accuracy, and evidence completeness. • Collaborate with control owners and cross-functional teams to prepare audit artifacts, track remediation activities, and communicate progress to leadership. • Develop and refine audit procedures, evidence collection methodologies, and reporting standards using Microsoft Excel, PowerPoint, and SharePoint. • Support development and maintenance of policies, standards, and procedures aligned to regulatory and industry frameworks (NIST CSF, ISO 27001, AICPA/SOC, PCI DSS). • Conduct internal readiness assessments and gap analyses to proactively identify compliance risks and improvement opportunities. • Manage auditor and partner requests, providing timely and professional responses. • Serve as a mentor and escalation point for junior GRC analysts. REQUIREMENTS • Bachelor's degree in Information Systems, Cybersecurity, Business, or related field. • 6-8 years of experience in IT audit, security governance, risk, and compliance, or related functions. • Hands-on experience supporting or leading SOC 2 and PCI DSS audits. • Proficiency with AuditBoard, Microsoft Office (Excel, Word, PowerPoint), and collaboration tools. • Strong understanding of information security frameworks (NIST, ISO 27001, AICPA/SOC, PCI DSS, FTC). • Excellent written and verbal communication skills, with the ability to translate technical topics into business terms. • Proven ability to manage multiple concurrent audits or assurance initiatives in a dynamic environment. Preferred • Certifications such as CISA, CIA, CRISC, or CISSP. • Experience coordinating SOC 1, FTC Safeguards, or SOX ITGC programs. • Experience in the financial services or fintech industry. • Demonstrated ability to build relationships across technical and non-technical teams. LEVEL VALIDATION: A7 (Specialist / Lead) Aligned to Oportun's Professional & Management Global Level Criteria: • Recognized for specialized depth in GRC and audit frameworks. • Leads complex audit initiatives with limited guidance. • Decisions have cross-functional impact on compliance and risk posture. • Provides guidance and mentorship to junior staff. The US base salary range for this full-time position is $114,500 - $183,200. Our salary ranges are determined by role, level, and location. The range displayed on each job posting reflects a national minimum and maximum range for new hire salaries for this position. Within this range, individual pay is determined by work location and additional factors, such as job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range that meets your criteria during the hiring process. Please note that the compensation range listed in this posting reflects only the base salary for this position and does not include other compensation elements or benefits. #LI-REMOTE #LI-RR1 We are proud to be an Equal Opportunity Employer and consider all qualified applicants for employment opportunities without regard to race, age, color, religion, gender, national origin, disability, sexual orientation, veteran status or any other category protected by the laws or regulations in the locations where we operate. California applicants can find a copy of Oportun's CCPA Notice here: ******************************************************* We will never request personal identifiable information (bank, credit card, etc.) before you are hired. We do not charge you for pre-employment fees such as background checks, training, or equipment. If you think you have been a victim of fraud by someone posing as us, please report your experience to the FBI's Internet Crime Complaint Center (IC3).
    $26k-36k yearly est. Auto-Apply 4d ago
  • Security Specialist

    Decentralized Masters

    Remote job

    Who Are We? Decentralized Masters is at the forefront of DeFi education globally. In just two years, we have grown from a pioneering pair of co-founders to over 130 dedicated professionals. Today, we are recognized as one of the fastest-growing enterprises in the sector, with industry insiders predicting our evolution into a unicorn company by 2030. Operating on a bootstrapped model, we are on track to achieve an impressive $50 million in revenue this year alone. Our Impact While our growth has been remarkable, we take even greater pride in the success of our clients. To date, we have empowered over 4000 investors to break into the DeFi world. At Decentralized Masters, we don't just offer education; we cultivate a powerhouse of knowledge combined with an engaging community, innovative technology, and a team of leading DeFi and blockchain experts. Our commitment is to deliver unparalleled resources designed for long-term success in the world of DeFi and Web3, ensuring our members not only safeguard but also enhance their financial future. Our Vision Our goal is to create the largest and most influential DeFi ecosystem the world has ever seen, starting with becoming the gold standard in DeFi education. This vision is ambitious, transformative, and poised to change the landscape of digital finance. Are You Ready? This is more than just a job; it's an opportunity to shape the future of Web3 technology and education. Are you ready to be part of our vision to redefine what's possible in DeFi and beyond? Apply below, and let's explore this journey together. Check us out here: ****************************** What will you be doing? We are seeking a Security Specialist to develop, maintain, and continuously improve the security infrastructure across Decentralized Masters and our new SaaS venture. This role focuses on operational security, data protection, risk prevention, and proactive threat mitigation. You'll work cross-functionally with engineering, data protection, compliance, operations, and product teams to ensure the confidentiality, integrity, and availability of our systems, data, and customer assets. This is a hands-on role, ideal for someone who thrives in a fast-moving, high-ownership environment. Key ResponsibilitiesOperational & Technical Security Monitor, analyze, and respond to security events across systems, cloud environments, applications, and internal tools. Implement and manage SIEM, IDS/IPS, endpoint protection, vulnerability scanners, and logging infrastructure. Conduct regular vulnerability assessments and coordinate remediation with engineering teams. Oversee secure configuration baselines for infrastructure, servers, cloud accounts, and internal systems. Implement and enforce Data Loss Prevention (DLP) policies, tools, and controls to prevent unauthorized data transfers, including hands-on work with data classification and monitoring systems. Perform detailed data flow mapping to understand how customer data moves across internal systems, SaaS apps, APIs, and third-party integrations. Cloud Security Secure cloud environments (AWS preferred) including data at rest and in transit using encryption and cloud-native security tools. Manage cloud access policies, network segmentation, secrets management, and continuous monitoring. Risk Management & Compliance Support compliance frameworks including GDPR, SOC 2, ISO 27001, and crypto-specific security standards as required. Develop and maintain internal security policies, procedures, and security controls. Partner with the Data Protection & Information Security Officer to ensure alignment across security, privacy, and data governance. Access & Identity Management Serve as the Access & Control Monitoring expert, managing IAM, RBAC policies, least-privilege access, MFA, and anomaly detection systems. Perform regular access reviews, privilege audits, and segregation-of-duty checks. Maintain strong audit logging practices and monitoring of access behavior. Security Awareness & Culture Deliver training, simulations, and internal education to strengthen internal security awareness. Lead phishing simulation programs and social engineering prevention initiatives. Incident Response Lead the incident response process: detection, escalation, containment, investigation, and post-incident review. Maintain and improve the incident response playbook; run annual and quarterly tabletop exercises. Secure Development & SaaS Security (Bonus) Collaborate with engineering teams to embed secure-by-design practices into our SaaS products. Conduct application security reviews, threat modeling, and code analysis (bonus). Contribute to architecture decisions for new features and infrastructure. Requirements What You Will BringMust-Have 3+ years of experience in cybersecurity, information security, or security operations. Hands-on experience with Data Loss Prevention (DLP) tools and data classification frameworks. Strong data flow mapping expertise with the ability to trace data across systems, integrations, and APIs. Solid understanding of cloud security concepts, encryption, and cloud-native security tools (AWS preferred). Expertise in IAM and Access Control Monitoring, including least-privilege models, RBAC, MFA, and anomaly detection. Familiarity with audit logging, SIEM tools, vulnerability management, and endpoint security. Experience with incident response processes and playbooks. Strong understanding of MITRE ATT&CK, threat actors, and common attack vectors. Working knowledge of compliance standards such as GDPR, SOC 2, and data protection regulations. Excellent communication skills and the ability to collaborate with technical and non-technical teams. Nice-to-Have Experience working in fintech, blockchain, or DeFi environments. Familiarity with cryptographic concepts, wallets, smart contracts, or key-management practices. Certifications such as Security+, CySA+, GSEC, GCIH, OSCP, CCSP, or similar. Experience automating security workflows using scripting languages. Exposure to ISO 27001, SOC 2 Type II audits, or similar security frameworks. Benefits What We Offer Competitive salary package Flexible 40-hour workweek Unlimited PTO and flexible work schedules Team off-sites and events Fully remote work setup - join our global team from anywhere! Are You Ready? This is more than a job; it's an opportunity to shape the future of Web3 education and finance. If you're a visionary leader ready to drive our mission and help us achieve unicorn status, we want to hear from you. Apply now to join us in redefining what's possible in DeFi and beyond.
    $25k-56k yearly est. Auto-Apply 22d ago
  • Security Specialist (Microsoft 365 / Federal Environment)

    Lucayan Technology Solutions

    Remote job

    Clearance Required: Public Trust (Minimum Background Investigation - MBI) Employment Type: Full-Time Lucayan Technology Solutions is seeking an experienced Security Specialist to support the security posture of the IRS Microsoft 365 (M365) environment. This role will focus on security analysis, compliance, risk management, and protection of cloud-based services. The ideal candidate brings deep expertise in Microsoft 365 security capabilities, federal compliance frameworks, and hands-on experience supporting high-security environments in government or large enterprises. Key Responsibilities Conduct security and privacy analysis of Microsoft 365 services to ensure compliance with IRS and federal security standards. Implement, configure, and monitor M365 security controls, compliance settings, and governance policies. Support ongoing risk assessments, vulnerability management activities, and remediation efforts. Develop, maintain, and update security documentation, including policies, procedures, and incident response plans. Collaborate with technical teams, engineers, and IRS SMEs to ensure secure architecture, integration, and operation of M365 tools. Monitor security alerts, assess potential threats, and support incident response activities. Adapt quickly to IRS-specific compliance requirements, security controls, and operational processes. Required Qualifications Minimum 5 years of IT security experience, preferably supporting Microsoft 365 environments in large government or enterprise settings. Experience supporting federal government clients or similar high-security, compliance-driven environments; IRS experience preferred. Strong understanding of Microsoft 365 security, compliance, governance, and privacy features. Hands-on experience with Azure AD, Intune, Exchange Online security, and identity protection tools. Familiarity with federal cybersecurity standards and frameworks such as NIST 800-53, FISMA, and Zero Trust. Strong analytical, troubleshooting, and problem-solving abilities. Excellent communication skills and ability to coordinate security-related activities with cross-functional teams. Security Clearance & Training Requirements Must have or be able to obtain a Public Trust (MBI) clearance. Must complete all IRS-required security, privacy, and compliance training. Must comply with federal cybersecurity guidelines and organizational security protocols. Preferred Qualifications Experience supporting IRS programs or IRS modernization efforts. Certifications such as: CISSP, CISM, Security+ Microsoft Certified: Security Operations Analyst Microsoft 365 Certified: Security Administrator Experience with incident response, threat analysis, and security automation. Knowledge of cloud governance and compliance tooling across Microsoft 365 and Azure. Work Environment Fully remote position with collaboration across distributed technical and security teams. Must be comfortable working in a compliance-focused federal environment. Occasional after-hours support may be required for incident response, maintenance windows, or urgent security issues. Requires strong attention to detail, documentation discipline, and adherence to IRS and federal security standards.
    $26k-57k yearly est. Auto-Apply 36d ago
  • Security Specialist - ACSO/DO

    LM Careers

    Remote job

    Act as a Designated Official (DO) for the Controlled Goods Program (CGP) and complete all Security Assessments - Exam and Certification through CGP required Act as an Alternate Company Security Officer (ACSO) for the Contract Security Program (CSP) supporting the initiation, review and submission of security clearance application - Certification through CSP required Understanding both CGP and CSP regulations and how they apply to data and physical access Delivery of required security and Controlled Goods (CG) briefings Completion and submission of CG exemptions for foreign visitors Processing of incoming Request for Visits (RFVs) and CG attestations in support of customers/sub-contractors visiting our sites Supporting the completion and submission of visit documentation for various programs to allow Lockheed Martin Canada Inc. (Lockheed Martin) employees to access customer/subcontractor restricted sites Completion and submission of Security Requirements Check Lists (SRCLs) for services sub-contractors Contributor in process and procedure development Manage and track all CG and security clearance expiry dates and ensure the processing of timely renewals Assist with the internal Lockheed Martin visitor management process including reviewing and approving expected visitors using online tool Support physical security as required Review data and physical access requests for security compliance and approval Provide other administrative support to the Security team including data entry, attendance logging for awareness training and digitizing of security files. Equal Opportunity Statement Lockheed Martin is committed to upholding principles of equal opportunity, fostering a work environment that is aligned with our core values of integrity, respect, and exceptional performance. We recognize the importance of leveraging the unique talents and experiences of all our employees to drive innovation, deliver superior solutions, and maximize value for our customers. Our focus is on identifying the most qualified candidate for each role, regardless of their background. If you are interested in a position, we invite you to share how your skills and perspectives could bolster our team and encourage you to apply, even if you feel your qualifications do not fully meet all the job criteria outlined in our advertisement. Furthermore, Lockheed Martin is dedicated to ensuring our recruitment process is inclusive for all individuals. We are prepared to accommodate reasonable adjustments for applicants as needed. Post secondary education 3-5 years professional experience Self-starter with strong attention to detail Familiarity with the CGP and CSP Previous experience in administrative type role Proficient with MS Word, Excel and PowerPoint Ability to multi-task Comfortable communicating with all levels of leadership Confident in navigating difficult and sensitive conversations Previous ACSO and/or DO experience would be considered an asset. About us Headquartered in Ottawa, Lockheed Martin Canada is the Canadian unit of Lockheed Martin Corporation, a global defense technology company driving innovation and advancing scientific discovery. Our all-domain mission solutions and 21st Century Security vision accelerate the delivery of transformative technologies to ensure those we serve always stay ahead of ready. We operate major facilities in Ottawa, Montreal, Halifax, Calgary and Victoria and work on a wide range of programs from advanced naval technology products, aircraft sustainment, and unmanned systems software. This position is part of the Rotary and Mission Systems business area, where employees across Canada support engineering, systems integration, training, sustainment and in-service support programs for Canadian and international military customers across land, air and sea. What we offer you We walk our talk when it comes to work/life balance! Your physical, mental and financial wellbeing matters to us. On top of working in a highly supportive, friendly, respectful environment, this is what you can expect when you join our team as a Regular Full-Time employee: Flexible, compressed work schedules, depending on business requirements, where you have the option of Fridays off, as well as the possibility to work remote part-time Competitive compensation Time to recharge with vacation, personal days, holidays, and parental leaves Comprehensive Family Medical, Dental and Vision coverage available on your first day of employment, along with: Virtual Health Care (24/7 access to medical professionals) A Wellness Spending Account to aid in your wellness journey Employee & Family Assistance Program (EFAP) which includes free face to face counselling sessions Medical Travel Insurance Onsite fitness facilities at our main office locations A Registered Retirement Savings Plan that includes matching company contributions on your first day of employment, that also includes access to Financial Advisors providing investment advice and comprehensive financial planning Employee discounts to save on goods, services and various recreational activities Access to a robust spectrum of development resources to enhance your skills and/or advance your career including: Free learning resources through a modern and engaging platform Education Assistance Program Reimbursement for a professional membership Self-directed Mentoring Controlled Goods Program
    $34k-71k yearly est. 14d ago
  • Member of Global Operations, Information & Security (Business Continuity & Disaster Recovery)

    Anchorage Digital

    Remote job

    At Anchorage Digital, we are building the world's most advanced digital asset platform for institutions to participate in crypto. Anchorage Digital is a crypto platform that enables institutions to participate in digital assets through custody, staking, trading, governance, settlement, and the industry's leading security infrastructure. Home to Anchorage Digital Bank N.A., the first federally chartered crypto bank in the U.S., Anchorage Digital also serves institutions through Anchorage Digital Singapore, Porto by Anchorage Digital, and other offerings. The company is funded by leading institutions including Andreessen Horowitz, GIC, Goldman Sachs, KKR, and Visa, with its Series D valuation over $3 billion. Founded in 2017 in San Francisco, California, Anchorage Digital has offices in New York, New York; Porto, Portugal; Singapore; and Sioux Falls, South Dakota. Learn more at anchorage.com, on X @Anchorage, and on LinkedIn. As a key Member of Global Operations, Information & Security, with a critical focus on Business Continuity and Disaster Recovery (BCDR), you will have the opportunity to develop and scale a forward-looking program that is expertly tailored to our business and compliant with necessary regulatory requirements, including those established by the FFIEC and NIST. Reporting to our Business Continuity and Disaster Recovery Lead, you will be responsible for maintaining relevant policies and procedures, and for communicating and supporting the implementation of program elements across business lines to grow and maintain a holistic program that ensures Anchorage Digital's resilience against disruption and guarantees a timely recovery of business operations in the unlikely event of an interruption. With guidance from the Business Continuity and Disaster Recovery Lead, and informed by Anchorage Digital's operational business needs, you will apply strategies and develop tactical solutions that continuously advance the maturity of Anchorage Digital's resilience to interruption via the business continuity program. You are responsible for supporting the operationalization of established strategies and the implementation of programmatic enhancement initiatives from conception to completion. You are also responsible for ensuring these initiatives continue to perform as expected once they have transitioned into business-as-usual operations. You are expected to help drive the development of company goals and objectives and guide the long-term strategy of an enterprise-wide business continuity and disaster recovery program, ensuring program processes are executed consistently and successfully. We are seeking a leader with the ability to guide complex projects and influence the overall Anchorage Digital culture. You not only understand the “why” and the “bigger picture,” you prioritize the work accordingly and with limited direction. Additionally, and in support of this work, you will have cross-team exposure and will be recognized as a reliable partner who offers expertise and leadership within and outside the CISO organization. We have created the Factors of Growth & Impact to help Villagers better measure impact and articulate coaching, feedback, and the rich and rewarding learning that happens while exploring, developing, and mastering the capabilities and contributions within and outside of the Member of Global Operations role:Technical Skills: Knowledge and experience with key regulatory and industry frameworks and standards on BCM: FFIEC IT Examination Handbook on BCM, NIST SP 800-34, or ISO 22301, and their related application to each aspect of a compliant BCM program. A deep understanding of cloud infrastructure configurations and architecture, disaster recovery plan development and management, and general concepts of information security and IT risk management. A strong ability to "translate" relevant regulation into technical controls; and, conversely, possess the ability to explain how existing and / or net-new controls are suitably designed to meet regulatory requirements. A strong ability to independently conduct and critically assess Business Impact Analysis (BIA) and Business Continuity Plan (BCP) updates, and collaborate with functional lead SMEs to accurately translate and account for speculative business impacts and recovery requirements in BIA and BCP documentation. Excellent communication and program management skills to drive stability and successful execution in a fast-moving environment. Complexity and Impact of Work: Support, scale, and improve Anchorage Digital's resilience, business continuity, and disaster recovery programs based on applicable risks, regulatory requirements, and industry guidance, and be accountable for assigned work by identifying, resolving, and escalating blockers and dependencies. Collaborate with enterprise business groups to develop and implement best practices designed to protect and restore data, systems, and business processes following anticipated or unanticipated disruptions. Track meaningful reporting, metrics, analysis, and controls commensurate with both business needs and regulatory expectations. Support the execution of established resilience, business continuity, and disaster recovery strategies, guiding initiatives from conception to completion, in concert with external technology providers. Maintain enterprise-wide business continuity and disaster recovery program documentation commensurate with regulatory guidance, such as the FFIEC IT Handbook. Maintain program-relevant Bank controls and identify, report, and control incidents relevant to Bank services. Resolve internal and external audit issues, including the implementation of management action plans. Support the execution and documentation of periodic tabletop and functional exercises in collaboration with and across business units and critical third-party service providers. Organizational Knowledge: Support and execute Anchorage Digital's business continuity and disaster recovery program elements, as well as maintain a control set and policy framework that satisfies regulatory requirements in an efficient and elegant manner. Collaborate with and guide each department to build and maintain enterprise-wide operational resilience, along with business continuity and disaster recovery programs, commensurate with changing business needs and industry and regulatory standards. Propose changes to the Bank's business continuity and disaster recovery strategy when necessary or beneficial to Anchorage Digital's objectives. Collaborate with the Anchorage Digital Third Party Risk Management team to independently conduct onboarding and ongoing monitoring due diligence evaluations of third-party service provider BCM documentation; assess and document an opinion as to the adequacy of third-party provided BCM documentation. Communication and Influence: Communicate program concepts effectively across all operational functions, as well as to business leaders at all levels. Communicate risks and influence the implementation of measures necessary to mitigate those risks to the Bank. Assist in the development of business continuity and disaster recovery program reports for senior management teams. Create effective relationships across the enterprise and communicate program goals, needs, and capabilities to stakeholders. You may be a fit for this role if you have: Exceptional attention to detail and are highly organized. A passion for improving existing processes. A highly reliable and proactive communication style. Excellent soft skills, including the ability to adapt communication for both internal and external stakeholders at all levels of seniority in an effective manner, bridging gaps with empathy, patience, and proactive communication. Experience using: the Google Workspace office suite; AuditBoard GRC tooling solutions; Linear; Notion; Slack; Jira; and Whimsical. Knowledge of cloud infrastructure dashboards and consoles (e.g., Google Cloud Platform). Exposure to or interactions with supervisory examination personnel (e.g., OCC). Although not a requirement, bonus points if: You have relevant industry certifications. You have familiarity with Operational Risk Management; Audit, Governance, Risk, and Compliance software implementation and configuration (AuditBoard). You understand and have experience with baseline physical security measures. You were emotionally moved by the soundtrack to Hamilton, which chronicles the founding of a new financial system. :) About Anchorage Digital: Who we are The Anchorage Village, what we call our team, brings together the brightest minds from platform security, financial services, and distributed ledger technology to provide the building blocks that empower institutions to safely participate in the evolving digital asset ecosystem. As a diverse team of more than 600 members, we are united in one common goal: building the future of finance by providing the foundation upon which value moves safely in the new global economy. Anchorage Digital is committed to being a welcoming and inclusive workplace for everyone, and we are intentional about making sure people feel respected, supported, and connected at work-regardless of who you are or where you come from. We value and celebrate our differences and we believe being open about who we are allows us to do the best work of our lives. Anchorage Digital is an Equal Opportunity Employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or veteran status. Anchorage Digital considers qualified applicants regardless of criminal histories, consistent with other legal requirements. “Anchorage Digital” refers to services that are offered either through Anchorage Digital Bank National Association, an OCC-chartered national trust bank, or Anchorage Lending CA, LLC a finance lender licensed by the California Department of Financial Protection and Innovation, License No. 60DBO-11976, or Anchorage Digital Singapore Pte Ltd, a Singapore private limited company, all wholly-owned subsidiaries of Anchor Labs, Inc., a Delaware corporation. Protecting your privacy rights is important to Anchorage Digital, and we work to maintain the trust and confidence of our clients when handling personal or financial information. Please see our privacy policy notices here.
    $31k-40k yearly est. Auto-Apply 35d ago

Learn more about head of security jobs