Information assurance security officer jobs near me - 279 jobs
Let us run your job search
Sit back and relax while we apply to 100s of jobs for you - $25
Information Security Engineer - Black Lotus Labs Threat Researcher (Crimeware)
Lumen Technologies 4.1
Remote information assurance security officer job
Lumen connects the world. We are igniting business growth by connecting people, data and applications - quickly, securely, and effortlessly. Together, we are building a culture and company from the people up - committed to teamwork, trust and transparency. People power progress.
We're looking for top-tier talent and offer the flexibility you need to thrive and deliver lasting impact. Join us as we digitally connect the world and shape the future.
The Role
Black Lotus Labs is seeking a Security Engineer on the Research & Analysis team to specialize in Threat Research with an emphasis on the Crimeware and Ransomware ecosystem, proactively identifying and disrupting adversary infrastructure. This team leverages Lumen's global visibility of one of the world's largest and most interconnected IP backbones and a petabyte-scale compute cluster to perform cutting edge threat research, hunting and tracking advanced persistent threat actors (APTs) and emerging criminal activity as the threat actors traverse the internet. They empower customers to stay ahead of the evolving threat landscape.
Location
This is a remote position open to candidates based anywhere in the U.S.
The Main Responsibilities
Conduct threat research across technical data sets, fusing Black Lotus Labs telemetry with third party data sets, to automate detection of the latest threat attacker tools, techniques and procedures (TTPs) with a goal of automating detection.
Use industry-leading technical knowledge of adversary capabilities and infrastructure and define, develop, and implement techniques to lead the team in tracking sophisticated adversaries, delivering actionable threat intelligence data to Lumen customers.
Serve as Threat Research Subject Matter Expert, offering guidance and support to the Black Lotus Labs team on threat hunting activities, such as identifying knowledge gaps, troubleshooting technical challenges, developing solutions, and mentoring team members in overcoming obstacles. Set priorities for what threats to analyze to maximize team's impact.
Lead and enhance threat hunting operations by actively engaging with other research teams, building strong partnerships to achieve shared goals, exploring new data sources, and mentoring team members in executing workflows and solving complex challenges.
Provide expert analysis and strategic insights on emerging threats and vulnerabilities, translating complex technical information into actionable intelligence for executive leadership and external stakeholders.
Spearhead thought leadership initiatives by leading Black Lotus Lab's voice at security conferences and internal executive briefings.
What We Look For in a Candidate
Fluency in the ransomware attack chain, adversary TTPs, and detection techniques with an emphasis on detections of adversary infrastructure using network telemetry.
Proven experience in threat hunting and in-depth technical security research, demonstrating a strong track record of successfully identifying, tracking, and disrupting cybercriminal threat actors.
Deep understanding of advanced threat hunting methodologies, attacker tactics, techniques, and procedures (TTPs), and the ability to derive actionable threat hunts from complex data sets.
Demonstrated experience building prototype threat hunting solutions and large data analysis tools with Python (or other equivalent languages) on distributed computing frameworks.
Proven experience initiating and coordinating technical projects focused on telemetry collection, TTP based threat hunting, or developing threat hunt tools that have cross-organization impact on threat visibility, including leading private-public partnerships and multi-company collaborations.
Exceptional communication and presentation skills, including the ability to clearly and concisely convey complex technical information to both technical and non-technical audiences, ranging from executives and board members to conference attendees and internal stakeholders.
Experience developing threat research thought leadership such as blogs and presenting at industry conferences and in the media.
Highly organized with the ability to manage multiple tasks, prioritize effectively, and triage competing demands in a fast-paced environment.
Proven ability to lead and manage complex technical projects, effectively driving them to successful completion.
Well-experienced candidates may also have the following skills:
Proficiency in malware reverse engineering and incident response.
5+ years of experience leading teams of technical threat discovery professionals.
Software development experience in Docker and big data technologies like Hadoop, Spark, and Tensor Flow.
Compensation
This information reflects the anticipated base salary range for this position based on current national data. Minimums and maximums may vary based on location. Individual pay is based on skills, experience and other relevant factors.
Location Based Pay Ranges:
$129,639 - $172,852 in these states: AL, AR, AZ, FL, GA, IA, ID, IN, KS, KY, LA, ME, MO, MS, MT, ND, NE, NM, OH, OK, PA, SC, SD, TN, UT, VT, WI, WV, and WY.
$136,121 - $181,494 in these states: CO, HI, MI, MN, NC, NH, NV, OR, and RI.
$142,603 - $190,137 in these states: AK, CA, CT, DC, DE, IL, MA, MD, NJ, NY, TX, VA, and WA
#GSS
#LI-MG1
Lumen offers a comprehensive package featuring a broad range of Health, Life, Voluntary Lifestyle benefits and other perks that enhance your physical, mental, emotional and financial wellbeing. We're able to answer any additional questions you may have about our bonus structure (short-term incentives, long-term incentives and/or sales compensation) as you move through the selection process.
If you are selected for a position, there will be a background screen, which may include checks for criminal records and/or motor vehicle reports and/or drug screening, depending on the position requirements. For more information on these checks, please refer to the Post Offer section of our FAQ page . Job-related concerns identified during the background screening may disqualify you from the new position or your current role. Background results will be evaluated on a case-by-case basis.
We are committed to providing equal employment opportunities to all persons regardless of race, color, ancestry, citizenship, national origin, religion, veteran status, disability, genetic characteristic or information, age, gender, sexual orientation, gender identity, gender expression, marital status, family status, pregnancy, or other legally protected status (collectively, “protected statuses”). We do not tolerate unlawful discrimination in any employment decisions, including recruiting, hiring, compensation, promotion, benefits, discipline, termination, job assignments or training.
Disclaimer
The job responsibilities described above indicate the general nature and level of work performed by employees within this classification. It is not intended to include a comprehensive inventory of all duties and responsibilities for this job. Job duties and responsibilities are subject to change based on evolving business needs and conditions.
In any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information.
Please be advised that Lumen does not require any form of payment from job applicants during the recruitment process. All legitimate job openings will be posted on our official website or communicated through official company email addresses. If you encounter any job offers that request payment in exchange for employment at Lumen, they are not for employment with us, but may relate to another company with a similar name.
Job Segment: InformationSecurity, Data Analyst, Engineer, Technology, Data, Security, Engineering
#J-18808-Ljbffr
$142.6k-190.1k yearly 4d ago
Looking for a job?
Let Zippia find it for you.
Chief Compliance & Information Security Officer (Fintech)
Lendswift
Remote information assurance security officer job
A modern consumer lending company is seeking a Chief Compliance Officer/CISO to lead compliance and informationsecurity programs. The ideal candidate has over 8 years in the industry with a strong background in bank partnerships and regulatory compliance. Key responsibilities include maintaining compliance management systems and overseeing data security. This role offers a highly flexible remote work environment, unlimited PTO, and competitive compensation.
#J-18808-Ljbffr
$89k-136k yearly est. 1d ago
Remote Information Security Engineer: SIEM, EDR & Cloud
Isaca 4.5
Remote information assurance security officer job
A well-respected law firm in Washington, DC is seeking an experienced InformationSecurity Engineer to enhance its security operations. This role offers the flexibility to work entirely remote or on-site. The ideal candidate will have a strong background in informationsecurity, excellent communication skills, and the ability to collaborate remotely. Competitive salary range is $122,000 to $160,000 annually, with additional benefits available.
#J-18808-Ljbffr
$122k-160k yearly 3d ago
Information Security Engineer
Unilin 4.6
Remote information assurance security officer job
Within our Unilin Infrastructure team, we are looking for an InformationSecurity Engineer with strong technical expertise, entrepreneurship and a passion for applying innovative technology to strengthen our Unilin Group's cybersecurity posture.
You will be part of the Unilin InformationSecurity team, part of the global Mohawk cybersecurity organization, giving you exposure to international operations and standards. You will be working with leading security platforms andwill have a wide variety of responsibilities including incident management, vulnerability management, security assessments, awareness initiatives and several security projects.
As Informationsecurity engineer, you will:
Enhance and maintain cybersecurity operations processes, identifying gaps, analyzing trends, and recommending improvements to strengthen detection, response, and prevention capabilities.
Support incident management activities by assisting with investigations, coordinating mitigation efforts with the MDR partner, and ensuring that procedures are followed correctly to minimize business impact.
Maintain strong technical expertise in key platforms used across the environment, such as Palo Alto Cortex XDR, SIEM, and Tanium.
Contribute to the vulnerability management programme, including scanning, prioritization, and coordination of remediation efforts with IT and OT teams.
Support cybersecurity assessments, assisting with internal vulnerability assessments, penetration testing, and cyber exercises.
Contribute to cybersecurity awareness and training initiatives through the KnowBe4 platform, helping to strengthen the organization's overall security culture.
Lead or support cybersecurity projects that enhance the overall security posture of the Unilin Group
Who are you?
Bachelor's or Master's degree in IT, Computer Science, Engineering, or equivalent practical experience.
At least 5 years of experience in cybersecurity operations, system administration, or incident response.
Proven expertise in network and endpoint security and threat analysis.
Experience with tools such as Cortex XDR, Tanium, or Prisma is an advantage.
Strong analytical skills with a solution-oriented, hands-on mindset.
Independent and self-motivated, able to manage tasks and projects autonomously.
Proficient in English and Dutch; knowledge of French is a plus.
What can you expect?
A competitive remuneration package.
An extensive leave system and a flexible work schedule with the option of home working.
Luncheon vouchers, hospitalisation and group insurance.
Possibility of bike leasing.
We invest in your development and we believe in lifelong learning. In our state-of-the-art training centre The Dive you are bound to find training courses that will help you grow.
Countless possibilities to build your career.
An employer with a transparent sustainability strategy (for our planet, customers and employees).
In different locations we have a company restaurant with a varied menu.
Benefit from attractive discounts on our products.
Child care is an option during a number of school holidays.
Make the most of discounts at a number of partners through our Benefits at Work platform.
You will often find us at sporting events. You and your family can participate for free.
In short, you'll be working for a Top Employer!
Who are we?
Unilin is a global reference in interior design and construction with a strong focus on sustainability and innovation. Our floors, panels, insulation materials, and technologies can be found in the homes and workplaces of millions of people and public spaces around the world. Our brands Quick-Step, Pergo, and Moduleo probably ring a bell. Worldwide, around 7,900 employees work every day to push boundaries and innovate. Want to know more about our story? Be sure to check out our website.
#J-18808-Ljbffr
$100k-145k yearly est. 5d ago
Staff Security Engineer
Parafin Inc.
Remote information assurance security officer job
About Us:
At Parafin, we're on a mission to grow small businesses.
Small businesses are the backbone of our economy, but traditional banks often don't have their backs. We build tech that makes it simple for small businesses to access the financial tools they need through the platforms they already sell on.
We partner with companies like DoorDash, Amazon, Worldpay, and Mindbody to offer fast and flexible funding, spend management, and savings tools to their small business users via a simple integration. Parafin takes on all the complexity of capital markets, underwriting, servicing, compliance, and customer service for our partners.
We're a tight-knit team of innovators hailing from Stripe, Square, Plaid, Coinbase, Robinhood, CERN, and more - all united by a passion for building tools that help small businesses succeed. Parafin is backed by prominent venture capitalists including GIC, Notable Capital, Redpoint Ventures, Ribbit Capital, and Thrive Capital. Parafin is a Series C company, and we have raised more than $194M in equity and $340M in debt facilities.
Join us in creating a future where every small business has the financial tools they need.
About the Position
We're looking for an experienced security-focused engineer to help shape and scale Parafin's security posture across our cloud and platform environments. Our Security and Infrastructure team owns the foundational systems that power all of Parafin - from compute and networking to identity and compliance - and you'll play a central role in ensuring those systems are secure, reliable, and compliant.
In this role, you'll design and operate controls, tooling, and processes that keep our infrastructure resilient and compliant while enabling developers to move quickly and safely. You'll partner closely with teams across engineering and compliance to strengthen how we manage access, secure applications, monitor threats, and respond to incidents.
What You'll Be Doing
Lead efforts to improve Parafin's overall security posture across infrastructure, applications, and data systems.
Develop and maintain frameworks for identity, access management, and least-privilege enforcement.
Establish and operate best-in-class security monitoring, alerting, and incident response processes.
Partner with product and infrastructure engineers to embed secure-by-default patterns in our systems and applications.
Define and enforce standards for vulnerability management, secrets handling, and dependency integrity.
Collaborate with compliance and risk teams to build and maintain controls aligned with frameworks such as SOC 2, PCI DSS, and other fintech regulations.
Support audits and security assessments by ensuring controls are properly implemented and evidenced.
Contribute to security awareness and training efforts across engineering teams.
Influence long-term strategy on secure architecture, detection, and response automation.
What We're Searching For
8+ years of experience in security operations or application security, preferably in a cloud-native and regulated environment.
Strong understanding of AWS security, including IAM, VPC, and network segmentation best practices.
Experience with threat detection and response, vulnerability management, and incident response workflows.
Familiarity with Kubernetes and container security principles, including RBAC, admission controls, and runtime monitoring.
Knowledge of compliance frameworks (SOC 2, PCI DSS, ISO 27001) and how to operationalize them in engineering environments.
Strong communication and collaboration skills - comfortable working across engineering, product, and compliance teams.
We Prefer If You Have
Experience building or maturing a security operations or application security program at scale.
Background in security automation, threat modeling, or secure architecture reviews.
Familiarity with developer-focused security enablement - e.g., SAST/DAST integration, dependency scanning, or security education.
Experience in regulated or fintech environments where security and speed must coexist.
What We Offer
Salary Range: $235k - $280k
Equity grant
Medical, dental & vision insurance
Unlimited PTO
Work From Home flexibility
Commuter benefits
Free lunches
Paid parental leave
401(k)
Employee assistance program
If you require reasonable accommodation in completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please contact us.
#J-18808-Ljbffr
$235k-280k yearly 5d ago
Corporate Security Engineer
Workos
Remote information assurance security officer job
WorkOS builds tools and services for developers to help them implement authentication, identity, authorization, and overall enterprise readiness. We're a fully distributed team with employees across North American time zones. We're well‑funded, having raised $100m in funding from top investors including Greenoaks Capital, Lachy Groom, and Lightspeed Ventures. Our fast‑growing customer base includes rapidly growing SaaS companies like OpenAI, Cursor, Perplexity, Vercel, Plaid, and hundreds of others.
About the Security Team
The Security team at WorkOS is responsible for keeping our company and customer data safe. As a CorpSec Engineer, you'll focus on the internal side of security-ensuring our people, devices, and systems are secure by default. We support a remote‑first, fast‑moving engineering organization and need strong, pragmatic security systems that scale with us.
You'll work to improve access controls, endpoint security, and tooling across the company. This role is a mix of hands‑on execution and strategic thinking-perfect for someone who wants to shape how security works inside a modern startup.
Who we're looking for
Have experience with corporate security and endpoint management in a cloud‑native, remote‑friendly environment
Enjoy taking ownership of systems like Okta, MDM, and EDR and making them more reliable, secure, and easy to use
Can balance security best practices with the realities of usability and speed
Like designing scalable controls for access, identity, and device management
Are comfortable working independently and cross‑functionally with IT, Infra, and GRC
Are curious, proactive, and enjoy simplifying complexity
What you'll be doing
Own and improve our identity and access management systems (Okta, Google Workspace, etc.)
Administer and secure our MDM and endpoint protection tools (e.g. Kandji, EDRs)
Partner with Infra to implement controls for least privilege, audit logging, and change management
Develop automations and tooling for onboarding/offboarding, access reviews, and audit prep
Proactively identify security risks and lead the rollout of mitigations
Help shape security policies and practices that work well for engineers, not against them
Work with vendors and evaluate new tools as needed
Document systems and decisions clearly to support scale and clarity
Requirements
Experience with identity, access, and endpoint security tools (e.g. Okta, MDM, EDR)
Familiarity with cloud‑native IT/security operations and SaaS environments
Comfort working in a fast‑paced, high‑autonomy environment
A practical mindset and a bias for simplicity and security‑by‑default
Nice to have
Experience working at a startup or on a small security team
Familiarity with SOC 2, ISO 27001, or other compliance frameworks
Scripting or automation experience (e.g. Python, Bash, Terraform)
The annual US base salary falls within the range of $175,000 to $250,000. This range does not encompass the full spectrum of benefits such as equity, health insurance, vacation time, and paid parental leave. This salary range covers multiple levels of engineering roles and final compensation will be determined considering various factors, including experience, skills, and qualifications.
For candidates outside the US, including Canada, compensation is adjusted based on local market benchmarks.
Benefits (US Only)
At WorkOS, we offer resources that emphasize personal and familial well‑being. We offer healthcare coverage for you and your family, including medical, dental, and vision. We offer parental leave, paid‑time off and fully remote working arrangements.
Benefits include:
Competitive pay
Substantial equity grants
Healthcare insurance (Medical, Dental and Vision) for you and your family
401k matching
Wellness and fitness monthly allowances
PTO + paid holidays + unlimited sick leave
Autonomy and flexibility with remote work
Please inquire directly with our recruiting team for benefits available to those working outside the US.
Equal Opportunity Employer
WorkOS is an equal opportunity employer, committed to diversity and inclusiveness. We will consider all qualified applicants without regard to race, color, nationality, gender, gender identity or expression, sexual orientation, religion, disability or age.
#J-18808-Ljbffr
$175k-250k yearly 2d ago
Remote Security Observability Engineer - Data Pipelines
Openai 4.2
Remote information assurance security officer job
A leading company, OpenAI, is seeking a Software Engineer, Security Observability to enhance their security infrastructure in a collaborative environment. The role focuses on designing scalable systems, improving data visibility, and requires strong software engineering skills, particularly in Python and Golang. Expansion into cloud platforms like Azure is also essential in this high-impact position.
#J-18808-Ljbffr
A leading consulting firm in Washington is seeking an experienced IDS and IPS Cyber Security Engineer to join their cybersecurity team. The role requires expertise in Linux and YAML configuration management for network intrusion systems. Responsibilities include designing and maintaining IDS/IPS across multiple networks, optimizing YAML configurations, and troubleshooting system issues in a Red Hat environment. The compensation range is competitive, offering a long-term career with strong professional development opportunities.
#J-18808-Ljbffr
$91k-121k yearly est. 2d ago
Offensive Security Engineer
Teksystems 4.4
Remote information assurance security officer job
The ideal candidate will have deep experience in adversary simulation, red teaming, and offensive security operations across hybrid environments (on-prem, cloud, and physical). This role requires strong technical acumen, creativity, and the ability to communicate complex findings to both technical and executive audiences.
Key Responsibilities
* Lead and execute adversary emulation engagements using intelligence-driven threat scenarios aligned with frameworks such as MITRE ATT&CK.
* Design and conduct full-scope red team operations, including initial access, lateral movement, privilege escalation, and data exfiltration simulation.
* Conduct physical, external/internal, and wireless network assessments, as well as web and mobile application testing.
* Perform security assessments across cloud platforms (Google Cloud, Microsoft Azure, AWS) and embedded systems.
* Develop and test threat actor emulation tools, tactics, and procedures for the Red Team to employ on-demand in assessments of application, system, and network security controls.
Preferred Certifications
* Offensive Security Certified Professional (OSCP)
* Offensive Security Certified Expert (OSCE)
* Offensive Security Experienced Penetration Tester (OSEP)
* Certified Red Team Professional (CRTP)
* GIAC Penetration Tester (GPEN)
* GIAC Web Application Penetration Tester (GWAPT)
* CREST Registered Penetration Tester / CBEST Qualifications
*Skills*
Security, Cyber security, Cloud, automated pen testing, tenable, servicenow, cobalt strike, metasploit, metahound
*Top Skills Details*
Security,Cyber security,Cloud
*Additional Skills & Qualifications*
-Looking for 6+ years of experience in Red Teaming for the mid-level role
-any experience with automated pen testing is a plus
*Job Type & Location*
This is a Permanent position based out of Cleveland, OH.
*Pay and Benefits*The pay range for this position is $115000.00 - $130000.00/yr.
More details in file.
Medical, Dental, Vision offered through United Health Group.
4 weeks of PTO
Holidays: 8 observed and 3 floating
*Workplace Type*This is a fully remote position.
*Application Deadline*This position is anticipated to close on Jan 16, 2026.
h4>About TEKsystems:
We're partners in transformation. We help clients activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 clients, including 80% of the Fortune 500, across North America, Europe and Asia. As an industry leader in Full-Stack Technology Services, Talent Services, and real-world application, we work with progressive leaders to drive change. That's the power of true partnership. TEKsystems is an Allegis Group company.
The company is an equal opportunity employer and will consider all applications without regards to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.
About TEKsystems and TEKsystems Global Services
We're a leading provider of business and technology services. We accelerate business transformation for our customers. Our expertise in strategy, design, execution and operations unlocks business value through a range of solutions. We're a team of 80,000 strong, working with over 6,000 customers, including 80% of the Fortune 500 across North America, Europe and Asia, who partner with us for our scale, full-stack capabilities and speed. We're strategic thinkers, hands-on collaborators, helping customers capitalize on change and master the momentum of technology. We're building tomorrow by delivering business outcomes and making positive impacts in our global communities. TEKsystems and TEKsystems Global Services are Allegis Group companies. Learn more at TEKsystems.com.
The company is an equal opportunity employer and will consider all applications without regard to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.
$115k-130k yearly 6d ago
Information System Security Officer (ISSO)
Dynanet Corporation
Remote information assurance security officer job
Full-time Description
Job Title: Information System SecurityOfficer (ISSO)
Job Type: Full-time
Salary Range: $150,000 - $175,000
Dynanet started with a focus on IT infrastructure and operations, helping organizations enhance their networks and overcome the limitations of 1990s technology. From strengthening communication channels to introducing innovative ways to collaborate and share information, Dynanet played a crucial role in shaping the early stages of digital transformation. The company's efforts helped organizations build the very fabric of connectivity that now powers our modern world. Over the last three decades, Dynanet has grown into a trusted partner for organizations looking to innovate boldly and transform seamlessly. While technology continues to evolve and unlock new opportunities, for nearly 30 years, Dynanet remains committed to delivering cutting-edge solutions that drive lasting change for its customers. Through agility, foresight, and an unwavering dedication to excellence, Dynanet continues to empower organizations to thrive in a rapidly changing digital landscape. Our story is more than just a story of technology - it's a story of vision, growth, and transformation that has shaped the past and continues to pave the way for the future.
About the Role:
The Information System SecurityOfficer (ISSO) is responsible for ensuring the security and compliance of organizational information systems by implementing, monitoring, and managing cybersecurity policies, procedures, and controls. The ISSO serves as a key resource for system security, compliance, and risk management, working to protect systems and sensitive information from cybersecurity threats.
Roles & Responsibilities:
Compliance and Risk Management: Ensure systems comply with security frameworks (e.g., RMF, NIST 800-53, FISMA) and manage ongoing system risk through assessments and reviews.
Security Documentation: Develop, maintain, and update System Security Plans (SSPs), security assessments, and Plans of Action and Milestones (POA&Ms).
Monitoring and Incident Response: Monitor information systems for vulnerabilities and security events, and coordinate incident response efforts where needed.
Assessment and Authorization (A&A): Support the A&A process and ensure systems meet necessary requirements for Authority to Test (ATT) and Authority to Operate (ATO) or meet other regulatory accreditations.
Vulnerability and Configuration Management: Perform regular vulnerability scans, monitor patch management, and ensure secure system configurations.
Security Training and Awareness: Provide cybersecurity training and foster awareness among users to promote adherence to security policies.
Collaboration with Stakeholders: Work with IT teams, management, and external authorities to maintain alignment on security goals and address identified risks.
Required Professional Skills:
Must have an existing CBP Full BI
Certifications: CISSP, CAP, Security+, CISM, or other applicable certifications
Dynanet Team Requirements and Expectations:
Possess Strong written and verbal communication skills.
Highly organized with an ability to prioritize, balance, and effectively advance multiple competing priorities in a high-volume, fast-paced environment.
Ability to interact in a professional and collaborative manner with fellow Dynanet Teammates and the clients, and business partners that we work with.
Ability and desire to challenge and educate yourself to support and advance IT services delivery in the Federal agencies we serve.
Excellent judgment and creative problem-solving skills.
Respond to team member and client requests via email, MS teams, or other communication means during core business hours.
Active listening skills to understand clients' needs, and collaboration skills to work with other developers and designers.
Education/Experience Requirements:
Bachelor's degree in Cybersecurity, IT, or related field (or equivalent experience)
Must have an existing CBP Full BI
Education: Bachelor's degree in IT, Cybersecurity, or related field (or equivalent experience).
Certifications: CISSP, CAP, Security+, CISM, or other applicable certifications
Experience: Eight (8) years of experience in informationsecurity, risk management, or related fields.
Skills: Knowledge of RMF, NIST standards, vulnerability management, incident response, and security tools (e.g., Nessus, SIEM).
Employee Benefits Overview:
Industry Competitive Compensation
Medical and Dental Insurance
Paid Time Off/Holidays
401(k) Retirement Plans with Matching
Remote Work*
(Contract dependent)
Paid Training
Employee Referral Program
Employee Development Program
$150k-175k yearly 29d ago
Information Security Compliance Senior Analyst
Crypto.com 3.3
Remote information assurance security officer job
At Crypto.com, our dedication to user security is led by our highly experienced Security Team. Comprising an international roster of seasoned cybersecurity experts, our team leads the company's Security, Privacy, and Security Compliance endeavors. The team includes holders of international patents for technologies integrated in our security architecture. Under the stewardship of a distinguished CISO recognized by the Forbes Technology Council and among the Global Top 100 CISOs, our team has consistently championed industry standards, acquiring certifications like ISO27001, ISO27701, ISO22301, PCI:DSS 3.2.1 (Level 1), NIST Tier 4, and SOC 2 Type II, in addition to the MPI License from Singapore MAS. Our Chief InformationSecurityOfficer reports directly to the CEO, underscoring the prioritization of security in our organization's hierarchy.
Our Security Team not only places great emphasis on credentials and expertise but also deeply values hands-on experience, rapid cognition, and dynamic learning. The challenges in the world of crypto are ever-evolving, and as such, our team prides itself on quick adaptability and robust teamwork, ensuring that we stay ahead of potential threats and always safeguard our user base.
About the Role
As our Security Compliance Senior Analyst, you will be tasked with security compliance activities along with our journey. You are expected to take the initiative to assist us with several security compliance programs and certifications. You are required to address and review compliance gaps and give recommendations and support on remediation activities. You will also be trusted to provide technical advice to ensure that security compliance requirements are met throughout all business units. This role requires technical knowledge of network security, especially on-prem and cloud native architectures. A familiarity with US derivatives regulatory frameworks would be advantageous. Job Responsibilities:
Assist in our security compliance programs, including ISO27001, ISO27701, PCI-DSS, SOC2 Type 2, and local regulations
Participate in internal security and privacy assessments, internal and external audits, compliance certifications, and risk management
Provide complete and accurate responses to internal and third-party enquiries on security compliance
Perform security compliance assessment activities, including periodic technical, organizational, and third-party risk and control assessments, and managing remediation activities to completion
Design and manage necessary control and framework required to comply with international standards and US local regulations
Identify and drive process improvements for streamlining global security compliance operations
Qualifications:
3-5 years of experience in informationsecurity, privacy, IT audit or IT risk management related roles.
Prefer experience with one or more of the following: In-house security and privacy operations, conducting security control assessments, risk assessments or audits.
Prefer experience with any of the following: ISO27001, ISO27701, SOC1, SOC2, PCI, SOX, COSO, cloud technologies, and data protection regulations and requirements.
Ability to analyze and review US and Global privacy and informationsecurity compliance and provide guidance.
Holders of security-related certifications/qualifications will be an advantage: CISSP, CRISC, CISM, CISA, ISO27001 LA, CIPT, CIPP/E, or other relevant certifications
Experience leading compliance initiatives and working with auditors and/or external regulators
It's a plus if you:
Have experience in informationsecurity and privacy management in virtual assets, fintech, online services, platform services, or global services.
Have experience in establishing informationsecurity and privacy framework to meet US regulations, (CFTC, FINRA, SEC, and other US based regulators.)
Are a strong commitment to personal learning and development
Are detail minded with an analytical mindset
Have good communication skills with an ability to explain complex technical issues to non-technical business users
Have prior experience with project management
Have an interest and understanding of Blockchain and AI technologies
***************** Empowered to think big. Try new opportunities while working with a talented, ambitious and supportive team.Transformational and proactive working environment. Empower employees to find thoughtful and innovative solutions.Growth from within. We help to develop new skill-sets that would impact the shaping of your personal and professional growth.Work Culture. Our colleagues are some of the best in the industry; we are all here to help and support one another.One cohesive team. Engage stakeholders to achieve our ultimate goal - Cryptocurrency in every wallet. Work Flexibility Adoption. Flexi-work hour and hybrid or remote set-up Aspire career alternatives through us - our internal mobility program offers employees a new scope.
Are you ready to kickstart your future with us?
BenefitsCompetitive salary Attractive annual leave entitlement including: birthday, work anniversary 401(k) plan with employer match Eligible for company-sponsored group health, dental, vision, and life/disability insurance Work Flexibility Adoption. Flexi-work hour and hybrid or remote set-up Aspire career alternatives through us. Our internal mobility program can offer employees a diverse scope.
Our Crypto.com benefits packages vary depending on region requirements, you can learn more from our talent acquisition team.
About Crypto.com:Founded in 2016, Crypto.com serves more than 150 million customers and is the world's fastest growing global cryptocurrency platform. Our vision is simple: Cryptocurrency in Every Wallet™. Built on a foundation of security, privacy, and compliance, Crypto.com is committed to accelerating the adoption of cryptocurrency through innovation and empowering the next generation of builders, creators, and entrepreneurs to develop a fairer and more equitable digital ecosystem.
Learn more at *******************
Crypto.com is an equal opportunities employer and we are committed to creating an environment where opportunities are presented to everyone in a fair and transparent way. Crypto.com values diversity and inclusion, seeking candidates with a variety of backgrounds, perspectives, and skills that complement and strengthen our team.
Personal data provided by applicants will be used for recruitment purposes only.
Please note that only shortlisted candidates will be contacted.
$81k-120k yearly est. Auto-Apply 2d ago
Information Systems Security Officer (ISSO)
Contact Government Services, LLC
Remote information assurance security officer job
ISSOEmployment Type: Full-Time, Experienced Department: Information Technology CGS is seeking an Information Systems SecurityOfficer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment documentation to support Dept. of Commerce systems and efforts to achieve their Authorization to Operate (ATO). This position is located at the client site in the Herbert Hoover building in Washington, DC. The scope of this position includes full life-cycle Assessment and Authorization (A&A) management through all 6 Steps of the RMF process in support of the Government ISSM.In this role, you'll conduct security assessment, and information system security oversight activities in accordance with NIST 800.53 that support systems from the perspective RMF requirements.
CGS brings motivated, highly skilled, and creative people together to solve the government's most dynamic problems with cutting-edge technology. To carry out our mission, we are seeking candidates who are excited to contribute to government innovation, appreciate collaboration, and can anticipate the needs of others. Here at CGS, we offer an environment in which our employees feel supported, and we encourage professional growth through various learning opportunities.
Skills and attributes for success:- Review systems to identify potential security weaknesses and recommend improvements to amend vulnerabilities, implement changes, and document upgrades. - Maintain responsibility for managing cybersecurity risk from an organizational perspective. - Identify organizational risks, prioritize those risks, and maintain a risk registry for escalating and presenting those risks to senior leadership.- Provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies.- Providing configuration management (CM) recommendations for information system security software, hardware, and firmware and coordinating changes and modifications with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO).- Maintain vulnerability scanning tool compliance, such as HBSS or ACAS, and patch management, such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance with all applicable directives, manage system changes, and assess the security impact of those changes.- Support security authorization activities, including transitioning from the legacy InformationAssurance Certification and Accreditation Process (DIACAP) to compliance with the DoC RMF.- Provide subject matter expertise for cyber security and trusted system technology. - Apply advanced technical knowledge and analysis of specialized functional areas in task requirements to develop solutions to complex problems.- Research, write, review, disposition feedback, and finalize recommendations regarding cyber security policy, assessment and authorization assessments (A&As), security test and evaluation reports, and security engineering practices and processes. - Conduct research and write risk assessment reports to include risk thresholds, evaluation, and scoring.- Support analysis of the findings and provide expert technical guidance for mitigation strategies, including implementation advice on the cyber security risk findings, and other complex problems.
Qualifications:- Bachelor's Degree.- A minimum of five (5) years experience as an InformationAssurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development, including generating security documentation for requirements, security control assessment, STIG and IAVA compliance, Standard Operating Procedures, test results, etc.- eMASS experience.- Professional security certification such as: CCNA Security, CySA+, GICSP, GSEC, CompTIA Security+ CE, SSCP, or higher.- Strong desktop publishing skills using Microsoft Word and Excel.- Experience with industry writing styles such as grammar, sentence form, and structure.- Ability to multi-task in a deadline-oriented environment.
Ideally, you will also have:- CISSP, CASP, or a similar certificate is preferred.- Master's Degree in Cybersecurity or related field.- Strong initiative, detail orientation, organizational skills, and aptitude for analytical thinking.- Demonstrated ability to work well independently and as a part of a team.- Excellent work ethic and a high commitment to quality.
Our Commitment:Contact Government Services (CGS) strives to simplify and enhance government bureaucracy through the optimization of human, technical, and financial resources. We combine cutting-edge technology with world-class personnel to deliver customized solutions that fit our client's specific needs. We are committed to solving the most challenging and dynamic problems.
For the past seven years, we've been growing our government contracting portfolio, and along the way, we've created valuable partnerships by demonstrating a commitment to honesty, professionalism, and quality work.
Here at CGS we value honesty through hard work and self-awareness, professionalism in all we do, and to deliver the best quality to our consumers mending those relations for years to come.
We care about our employees. Therefore, we offer a comprehensive benefits package.Health, Dental, and VisionLife Insurance 401k Flexible Spending Account (Health, Dependent Care, and Commuter) Paid Time Off and Observance of State/Federal Holidays
Contact Government Services, LLC is an Equal Opportunity Employer. Applicants will be considered without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Join our team and become part of government innovation!Explore additional job opportunities with CGS on our Job Board:**************************************** more information about CGS please visit: ************************** or contact:Email: *******************
#CJ
$78k-105k yearly est. Auto-Apply 60d+ ago
Information System Security Officer II - Mid-Level
The One 23 Group
Remote information assurance security officer job
At The One 23 Group, our mission is to set the benchmark for excellence in government services. We empower our clients in the Department of Defense, intelligence community, and federal civilian sectors to excel with our advanced capabilities. Our dedication lies in fostering a people-first culture, underpinned by steadfast ethical principles. Embracing innovative technologies and process improvements, we are steadfast in our journey toward a future that is both bright and transformative.
Our expertise spans consulting and analytics, digital workplace solutions, and cyber compliance. With our global footprint, we place a strong emphasis on nurturing our people and culture, which forms the core of our successful strategies in leadership and financial management. We pride ourselves on our extensive experience and effective approach, ensuring that we lead with both innovation and integrity.
Responsibilities
Contractor to provide cyber security management, oversight, and customer support for maintaining the continuity of DHS Management Information System compliance in accordance with DHS, National Institute of Standards and Technology (NIST), and other applicable Federal standards. This Position is 100% Remote.
Applies specialized knowledge of sensitive system Cybersecurity requirements and Privacy Act requirements.
Applies specialized knowledge and experience with the implementation of the NIST Special Publication (SP) 800 family of publications, particularly those associated with NIST's Risk Management Framework and the Federal Risk and Authorization Management Program (FedRAMP).
Applies specialized knowledge and experience with evaluating system, network, or infrastructure security controls against requirements such as FISMA, Federal Information Processing Standards (FIPS, and NIST guidelines.
Applies knowledge of DHS InformationSecurity Policy Directives and Handbooks is preferred.
Applies knowledge and experience with standard IA concepts, practices, and procedures. Working independently to solve problems quickly and completely.
Applies specialized experience with three (3) of the four (4) following criteria is required:
Vulnerability scanning execution, assessment, and analysis.
Operating system and network knowledge (i.e., Local Area Networks [LAN] and Wide Area Networks [WAN]).
Informationsecurity and assurance principles (e.g., Defense-in-depth) and associated supporting technologies.
Application security, database security, and network security.
Possess ability to assess and weigh current and evolving security threats in an operational environment.
Possess good oral and written communication skills.
Team player who can collaborate with multiple stakeholders to arrive at the best solution.
Qualifications
Master's degree and 4 years of Cybersecurity & Federal InformationSecurity Modernization Act (FISMA) experience, or a Bachelor's Degree and 5 years of Cybersecurity & FISMA experience or a total of 7 years of Cybersecurity & Federal InformationSecurity Modernization Act (FISMA) experience
Must be a US citizen with ability to obtain/maintain a Top Secret clearance
Possesses
one (1) of the following professional security certifications
or
can be obtained within six (6) months of hire:
Certified Information System Security Professional (CISSP)
CompTIA Advanced Security Practitioner (CASP)
Certified Information Systems Auditor (CISA)
Certified Ethical Hacker (CEH)
Systems Security Certified Practitioner (SSCP)
Certified InformationSecurity Manager (CISM)
GIAC InformationSecurity Professional (GISP)
GIAC Security Leadership (GSLC)
We can recommend jobs specifically for you! Click here to get started.
$78k-105k yearly est. Auto-Apply 60d+ ago
Information Systems Security Officer (Remote from US)
Jobgether
Remote information assurance security officer job
This position is posted by Jobgether on behalf of a partner company. We are currently looking for an Information Systems SecurityOfficer in the United States.In this role, you will provide expert cybersecurity oversight and governance for mission-critical IT systems, ensuring compliance with federal frameworks and organizational policies. You will lead security risk management, continuous monitoring, and authorization processes while collaborating closely with system owners, engineering teams, auditors, and executive leadership. The position requires translating complex technical system details into actionable security requirements, overseeing vulnerability management, and guiding secure system design and modernization efforts. You will serve as a key security liaison, delivering insights and briefings to stakeholders and helping maintain a secure, compliant, and resilient IT environment. Strong analytical, communication, and federal cybersecurity expertise are essential.Accountabilities:
Lead security compliance and governance activities aligned with federal standards such as NIST, FISMA, and organizational directives
Manage and maintain system security documentation, including SSPs, SARs, POA&Ms, and risk assessments
Oversee continuous monitoring, vulnerability remediation, and security control assessments to mitigate risks
Provide guidance on secure system design, configuration changes, and integration efforts
Support incident response activities, root cause analysis, and implementation of compensating controls
Act as a security liaison to program leadership, system owners, and cybersecurity offices, preparing briefings and dashboards
Collaborate with cross-functional teams to ensure security requirements are clearly understood and applied
Requirements:
7+ years of experience as an ISSO or similar cybersecurity role supporting federal agencies
Direct experience with VA environments, ATO processes, eMASS, Archer, CSAM, and applicable federal policies
Strong understanding of NIST SP 800-53, RMF, FISMA, and federal cybersecurity governance
Experience managing POA&Ms, vulnerability remediation, and continuous monitoring activities
Ability to interpret technical system details and translate them into actionable security requirements
Excellent communication skills, including executive-level reporting
Ability to obtain and maintain a Public Trust clearance
Preferred Experience:
Support experience with federal healthcare or enterprise IT programs (e.g., VA OIT, EHRM, VHA, VBA, ICAM)
Familiarity with cloud security platforms such as AWS, Azure, or VAEC
Security certifications such as CISSP, CAP, or Security+
Experience with Zero Trust architectures, identity modernization, or large-scale federal IT transformations
Benefits:
Comprehensive medical, dental, and vision coverage
Wellness programs to support employee health
401(k) retirement plan with company matching
Short-term and long-term disability insurance
Life insurance coverage
Employee Assistance Program
Education and professional training support
Generous leave policy including federal holidays, PTO, and military leave
Why Apply Through Jobgether?We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.We appreciate your interest and wish you the best! Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
$78k-105k yearly est. Auto-Apply 5d ago
Information System Security Officer (ISSO)
Istari Digital
Remote information assurance security officer job
[ABOUT ISTARI DIGITAL]Istari is a digital engineering software company enabling our customers to turn the physical world into the digital to accomplish their specific mission or business objectives. Istari was founded with the vision of making open, scalable digital engineering ecosystems a reality - where new technologies and systems are created digitally, free from the real-world constraints of costs and schedules. We are creating the world's best engineering model sharing platform, allowing our customers to simply and securely integrate their models across different engineering disciplines, organizations, and security levels.
At Istari, we are passionate about our mission of creating the world's first open and scalable industrial metaverse. Whether our customers are designing prototypes, performing virtual testing, or training AI and autonomy for complex systems, we know that going digital will save them time, resources, and reduce their environmental impact.
While we are a distributed team with most team-members working remotely, we place an emphasis on staying connected and collaborative, prioritizing in-person opportunities to build trust as a team. At Istari, we still believe that trust is best built in-person. To do this, we have an engineering headquarters in Cambridge, MA for focused technical development and several times per year we gather for an off-site that allows us to develop our professional skills and our team relationships.
[VALUES]At Istari, we live by our values, which include:
- Focus is rewarded. Finish is remembered. - Facts are friendly. Even when they are not fun.- Fellowship is fundamental. Make others successful.
Equal Opportunity Istari is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.
We are seeking a highly experienced and knowledgeable Information System SecurityOfficer (ISSO) to join our Cybersecurity team. The ISSO will serve as a principal advisor on all matters, technical and otherwise, involving the cybersecurity of information systems under their purview. This role requires a deep understanding of cybersecurity principles, practices, and frameworks, as well as the ability to develop, implement, and evaluate information system security program policy consistent with Federal and Commercial regulatory requirements, both on premises and in cloud environments. The ISSO will work closely with various stakeholders across the organization to ensure the confidentiality, integrity, and availability of our information systems.Key Responsibilities
Serve as the principal advisor on all matters involving the cybersecurity of assigned information systems.
Develop, implement, and evaluate information system security program policy consistent with Federal and Commercial regulatory requirements, including JSIG, NIST 800-171, NIST 800-53, CMMC, and ITAR.
Conduct risk assessments and identify vulnerabilities in information systems.
Develop and implement security controls to mitigate identified risks.
Monitor and evaluate the effectiveness of security controls.
Develop and deliver cybersecurity awareness training to employees.
Investigate security incidents and breaches.
Maintain security documentation, including system security plans (SSPs), risk assessments, and incident reports.
Stay up-to-date with the latest cybersecurity threats and vulnerabilities.
Collaborate with the engineering and customer success teams to ensure secure implementation and configuration of systems.
Required Qualifications
Active Top Secret Security Clearance, with SCI eligibility.
Minimum of 5 years of experience in a relevant field.
Deep understanding of cybersecurity principles, practices, and frameworks, including JSIG, NIST 800-171, NIST 800-53, ITAR, ISO, and CMMC.
Experience with risk assessments, vulnerability identification, and security control implementation.
Experience with security incident investigation and response.
Excellent communication and collaboration skills, with the ability to effectively communicate with both technical and non-technical audiences.
Strong analytical and problem-solving skills.
Relevant certifications (e.g., Sec+, CISSP, CISM).
Must be a US citizen living within the United States.
Preferred Qualifications
Bachelor's degree in computer science, information systems, or a related field.
Experience with SOC compliance and audits.
BENEFITSWe offer highly competitive benefits, including:
Health and Family- Medical/Dental/Vision- Employee Premiums are 100% Company Paid- Life Insurance- Flexible Work Hours - Unlimited Paid Time Off (PTO) with federal government holidays
Financial- Competitive Compensation - 401k - Company Stock Options- Home Office Setup Budget
Learning- Reimbursement for approved trainings and subscriptions- Conferences (travel, lodging, and fees)
Note - some benefits are not available to interns or contractors.
Thank you for your interest in Istari. Expect to hear back from us soon with next steps.
$78k-105k yearly est. Auto-Apply 60d+ ago
Information System Security Officer
Zermount
Remote information assurance security officer job
MILITARY FRIENDLY & PREFERRED - HOH SPONSOR
The Information Systems SecurityOfficer (ISSO) is responsible for supporting the full lifecycle of security assessment and authorization (A&A) activities for information systems. The ISSO ensures that assigned systems comply with federal cybersecurity standards and maintain their Authority to Operate (ATO) through continuous monitoring and documentation.
The ISSO will be responsible for developing and providing risk assessments, Security Control Assessments (SCA), A&A documentation and various reports, based on NIST guidelines and client's policies, procedures and request. The ISSO will be responsible for providing security recommendations on any system changes or new technologies, analysis on vulnerability scans, conducting continuous monitoring activities, and provide mitigation recommendations for any risks or threats.
RESPONSIBILITIES:
Lead and conduct Pre-Security Assessment and Authorization (A&A) activities, including stakeholder identification, change request submissions, appointment memorandums, and IT Security Kickoff meetings.
Supports the ISBO in day-to-day IT security activities.
Assists the ISBO with reviews of the security posture of the system and report any findings to the ISBO, CISO, and the AO.
Conduct Information System Categorization by identifying information types, completing FIPS-199 assessments, and facilitating Business Impact Analyses (BIA), Privacy Threshold Analyses (PTA), and Privacy Impact Assessments (PIA).
Develop and maintain system security documentation, including:
System Administration Plan (SAM)
Configuration Management Plan (CMP)
IT Contingency Plan (ITCP)
InformationSecurity Continuous Monitoring (ISCM) Plan
Incident Response Plan (IRP)
Security Assessment Report (SAR)
System Security Plan (SSP)
Coordinate initial and annual ITCP testing in collaboration with the OCIO Business Continuity and Disaster Recovery (BCDR) Office.
Develop and manage inter-agency agreements and documentation such as MOUs, MOAs, ISAs, IT Security Waivers, and Risk Acceptance Memorandums.
Document and maintain Security Control Implementation details, ensuring updates are made according to required frequency.
Coordinate vulnerability and compliance scans, Security Control Assessments (SCA), and track remediation efforts with the IT Security Test Team.
Manage and update Plan of Action and Milestones (POA&M) entries, submitting remediated findings for closure.
Prepare and present SAR to Authorizing Officials to obtain or renew ATO.
Perform InformationSecurity Continuous Monitoring (ISCM) activities to ensure ongoing compliance and security posture of systems.
Develop and update project schedule, including A&A / SCA task and milestones, task dependencies, and personnel resources.
Conduct A&A activities and tasks and obtain ATO in line with NIST and client guidance and directives.
Determining the baseline IT Security requirements for IT Systems, identifying system boundaries, determining information categories, assisting with FIPS-199.
Ensure that IT Systems are operated, used, maintained, and disposed of in accordance with internal security policies and practices.
Enforce security policies and safeguards on all personnel having access to the IT System for which the ISSO has responsibility.
Ensure users and system support personnel have the required authorization and need-to-know; have been indoctrinated; and are familiar with internal security practices before access to the IT System.
Implement security controls based on IT System FIPS categorization.
Document security control implementation in the system's Security Plan using the client's GRC tool.
Document system's risk assessment per client directives and requirements.
Review and monitoring system security and audit logs.
Develop and maintain Plan of Actions and Milestones (POA&Ms) for IT systems.
Update A&A documentation and artifacts on a regular basis (e.g. annually, after approved change).
QUALIFICATIONS:
A minimum of five (5) years of demonstrated experience in the InformationSecurity or IT field.
Demonstrates a proficiency with developing, maintaining and managing SA&A packages.
Experience with developing and managing POA&M's.
Strong problem solving and analysis skills, self-motivated, and able to work and communicate in a team environment.
Strong understanding of federal cybersecurity frameworks (e.g., NIST RMF, FIPS-199, FISMA).
Experience in developing and maintaining security documentation and plans.
Possess experience conducting CPT's.
Experience conducting audit log reviews.
Technical experience with conducting vulnerability management, compliance scanning, and providing mitigation techniques.
Excellent communication and coordination skills with technical and non-technical stakeholders.
Ability to manage multiple systems and projects simultaneously in a dynamic environment.
Excellent communication (written and verbal) skills.
CERTIFICATION:
A minimum of at least one (1) certification that meet DOD 8570 IAT Level II (e.g., Security+, GSEC, CASP) requirements or any equivalent or more advanced.
CLEARANCE:
Client Suitability and Public Trust
LOCATION and HOURS:
Location: Primary location is at Zermount HQ (Arlington, VA) and the Client Site (Washington, D.C.). Remote work is authorized.
Onsite work at the primary location., may be occasionally required.
Hours of Operation (Business Hours): 8:00 am ET - 5:30 pm ET
$78k-105k yearly est. 52d ago
Senior Information Systems Security Officer (ISSO) Philadelphia, PA
Watershed Security
Remote information assurance security officer job
Watershed Security, is a Veteran Owned Small Business with over 20 years' Cybersecurity and Government Contracting experiencing. Watershed is looking for a Senior Information Systems SecurityOfficer (ISSO) to support the Naval Surface Warfare Center (NSWC) in Philadelphia, PA. The successful candidates will have experience coordinating and enacting required security changes, with in various levels of an organization, ensuring compliance with published policies; conducting cybersecurity vulnerability and threat analysis; and support cyber incident-response by isolating potentially effected assets, initial investigation and data collection, through status updates/reporting.
REQUIRED QUALIFICATIONS
Bachelor's degree in computer science, information technology, communications systems management, or an equivalent science, technology, engineering & mathematics (STEM) degree from an accredited college or university.
Must have at least one of the following active certifications: CCNA-Security, CySA+, GICSP, GSEC, Security+ CE, CND, SSCP,
Years of Experience: 6 years practical experience in a cybersecurity or A&A related field.
Collaborate with various levels of the organization to implement required security changes and ensure compliance with established security policies and standards.
Conduct comprehensive cybersecurity vulnerability and threat assessments to identify and mitigate risks to information systems.
Lead cyber-incident-response efforts, including isolating affected systems, conducting initial investigations, collecting relevant data, and providing status updates and reports to leadership.
Provide guidance on best practices and recommend improvements to the organization's security posture.
Perform risk assessments and develop mitigation strategies to protect sensitive data from internal and external threats.
Support continuous monitoring of information systems and provide regular status reports on security compliance.
Maintain up-to-date knowledge of emerging cybersecurity threats and industry best practices.
Clearance Level: SECRET; US Citizen.
Ability to possibly provide onsite support in Philadelphia, PA or Norfolk, VA. Some/all remote work may be an option, however the norm will be onsite support. This will be dependent upon customer needs and classification level of work being performed.
Some travel may be required.
Experience with the Navy RMF Process Guide (RPG), and Navy A&A tools such as ACAS, eMASS and eMASSter.
Proficient with Microsoft Office Suite (Word, Excel, Teams, Project). Self Starter; detail oriented; able to brief senior level staff.
DESIRED QUALIFICATIONS
Experience supporting 10 or more Navy Packages (achieving and/or maintaining ATO)
Experience with the NAVSEA RMF Business Rules
Contingent upon award
PAY RANGE
Final salary is influenced by factors such as location, contract labor categories, experience, skills, education, and certifications. Watershed offers competitive compensation, medical and dental benefits, educational reimbursement, 401K plans with matching, 15 days of PTO to start and 11 paid holidays per year. The proposed salary range for this position is: $70,000.00 - $100,000.00 USD.
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
$70k-100k yearly Auto-Apply 60d+ ago
Senior Information System Security Officer
Onyx Point
Remote information assurance security officer job
TO BE CONSIDERED FOR THIS POSITION YOU MUST HAVE AN ACTIVE TS/SCI W/ POLYGRAPH SECURITY CLEARANCE (U.S. CITIZENSHIP REQUIRED). Please see the following ISSO requirements. Provides aid to the program, organization, system, or enclave's informationassurance program.
Lends assistance for proposing, coordinating, implementing, and enforcing information systems security policies, standards, and methodologies.
Maintains operational security posture for an information system or program to ensure information systems security policies, standards, and procedures are established and followed.
Assists with the management of security aspects of the information system and performs day-to-day security operations of the system.
Evaluates security solutions to ensure they meet security requirements for processing classified information.
Performs vulnerability/risk assessment analysis to support certification and accreditation.
Provides configuration management (CM) for information system security software, hardware, and firmware.
Manages changes to system and assesses the security impact of those changes.
Prepares and reviews documentation to include System Security Plans (SSPs), Risk Assessment Reports, Certification and Accreditation (C&A) packages, and System Requirements Traceability Matrices (SRTMs).
Assists security authorization activities in compliance with Information System Certification and Accreditation Process (NISCAP) and DoD Risk Management Framework (RMF).
What Sets You Apart:
Bachelor of Science degree in Computer Science, InformationAssurance, InformationSecurity, or related discipline and 12 or more years of related experience.
Minimum of 7+ years of experience as an ISSO supporting IC or DoD programs and contracts of similar scope, type, and complexity.
DoD 8570 compliance with IAM Level II or IAT Level III (i.e., CASP, CISSP, or Associate)
Clearance Required:
Active TS/SCI with Polygraph Security Clearance
Compensation: We are committed to providing fair and competitive compensation. The salary range for our positions vary depending on accepted contractual position skill level. These salaries fall within the range of $78,000 to $275,000 per year. This range reflects the compensation offered across the locations where we hire. The exact salary will be determined based on the candidate's work location, specific role, skill set, and level of expertise.
Benefits: We offer a comprehensive benefits package, including:
• Health Coverage: Medical, dental, and vision insurance
• Additional Insurance: Basic Life/AD&D, Voluntary Life/AD&D, Short and Long-Term Disability, Accident, Critical Illness, Hospitalization Indemnity, and Pet Insurance
• Retirement Plan: 401(k) plan with company match
• Paid Time Off: Generous PTO, paid holidays, parental leave, and more
• Wellness: Access to wellness programs and mental health support
• Professional Development: Opportunities for growth, including tuition reimbursement
Additional Perks:
• Flexible work arrangements, including remote work options
• Flexible Spending Accounts (FSAs)
• Employee referral programs
• Bonus opportunities
• Technology allowance
• A diverse, inclusive, and supportive workplace culture
$65k-88k yearly est. 60d+ ago
Staff Information Security Analyst
Playstation 4.8
Remote information assurance security officer job
Why PlayStation?
PlayStation isn't just the Best Place to Play - it's also the Best Place to Work. Today, we're recognized as a global leader in entertainment producing The PlayStation family of products and services including PlayStation 5, PlayStation 4, PlayStation VR, PlayStation Plus, acclaimed PlayStation software titles from PlayStation Studios, and more.
PlayStation also strives to create an inclusive environment that empowers employees and embraces diversity. We welcome and encourage everyone who has a passion and curiosity for innovation, technology, and play to explore our open positions and join our growing global team.
The PlayStation brand falls under Sony Interactive Entertainment, a wholly-owned subsidiary of Sony Group Corporation.
Sony Interactive Entertainment LLC seeks a Staff InformationSecurity Analyst in San Mateo, CA to define strategic GRC (Governance, Risk and Compliance) input in global initiatives, including Artificial Intelligence (AI) and Machine Learning (ML) adoption, cloud security, and enterprise wide policies, ensuring resilience while balancing business and regulatory needs. Requires a Master's degree in Cybersecurity, InformationSecurity, or related field or equivalent, and four (4) years of experience conducting risk assessments on critical information systems to maintain and manage risk registers; facilitating the Security Risk Assessment methodology, policy, strategy and process; writing security assessment reports following security breaches and detailing the associated impact; monitoring and reviewing IT Security controls to identify operational effectiveness; mapping security controls to policies, standards, procedures and processes to ensure compliance with security measures; managing security remediation efforts and tracking status of security deficiencies; translating security risk mitigation plans into actionable items to mitigate risk in coordination with technical and business teams; developing and implementing policy frameworks for emerging technologies, including AI/ML and cloud security, with governance and legal stakeholders; applying industry standards including NIST, ISO 27001, and PCI DSS in support of organizational security objectives; supporting the evaluation of third-party vendor security through documentation review and risk assessment; contributing to the enhancement of vendor onboarding and compliance workflows; and, in executing duties, utilizing Archer GRC, ServiceNow, Splunk, JIRA, Confluence, SharePoint, Palo Alto Prisma Cloud and AWS. Telecommuting and/or working from home may be permissible pursuant to company policies. Sony is an EOE.
Salary range: $185,639.00 - $261,000.00/year
Equal Opportunity Statement:
Sony is an Equal Opportunity Employer. All persons will receive consideration for employment without regard to gender (including gender identity, gender expression and gender reassignment), race (including colour, nationality, ethnic or national origin), religion or belief, marital or civil partnership status, disability, age, sexual orientation, pregnancy, maternity or parental status, trade union membership or membership in any other legally protected category.
We strive to create an inclusive environment, empower employees and embrace diversity. We encourage everyone to respond.
PlayStation is a Fair Chance employer and qualified applicants with arrest and conviction records will be considered for employment.
$185.6k-261k yearly Auto-Apply 8d ago
Information Security Expert
Cyberthink 4.2
Information assurance security officer job in Columbus, OH
Title: InformationSecurity SME/Developer with .NET development Duration : 5 Months contract (High possibility of Extension) Interview Type: Both iLinc Web Cam and In Person Interview Skills Required Experience working in Microsoft Identity Integration Server (MIIS) 2003 Required 2 Years
Experience with Identity Lifecycle Manager (ILM) 2007 Required 2 Years
Experience with Forefront Identity Manager (FIM) 2010 including design and implementation Required 2 Years
Experience and strong development skills in the MS Metadirectory Services Namespace in C# Required 2 Years
.NET development experience Required 5 Years
Thanks
Naimesh Solanki
Sr. Technical Recruiter
Phone: ************ x 6578
Qualifications
Experience working in Microsoft Identity Integration Server (MIIS) 2003 Required 2 Years
Experience with Identity Lifecycle Manager (ILM) 2007 Required 2 Years
Experience with Forefront Identity Manager (FIM) 2010 including design and implementation Required 2 Years
Experience and strong development skills in the MS Metadirectory Services Namespace in C# Required 2 Years
Additional Information
All your information will be kept confidential according to EEO guidelines.
$62k-80k yearly est. 1d ago
Learn more about information assurance security officer jobs