Information security analyst jobs in Charlton, MA - 175 jobs
All
Information Security Analyst
Information Security Engineer
Information Security Director
Information Systems Engineer
Security System Engineer
Information Technology Analyst
Information Security Officer
Senior Security Analyst
Information Systems Security Officer
Senior Cyber Security Analyst
Senior Information Security Consultant
Information Assurance Engineer
Advanced Information Assurance Engineer
General Dynamics Mission Systems 4.9
Information security analyst job in Dedham, MA
Basic Qualifications
Requires a Bachelor's degree in Engineering, or a related Science, Technology or Mathematics field. Also requires 5+ years of job-related experience, or a Master's degree plus 3 years of job-related experience.
CLEARANCE REQUIREMENTS: Department of Defense Top Secret security clearance is required at time of hire. Applicants selected will be subject to a U.S. Government security investigation and must meet eligibility requirements for access to classified information. Due to the nature of work performed within our facilities, U.S. citizenship is required.
Responsibilities for this Position
Specific System Security Engineering Technical Skills
Supports cyber security requirements analysis, security requirements definition, survivability/Cyber resilience analysis, system security design, security architecture generation, security trade studies, and security verification and validation with little or no supervision. (ex. Cybersecurity Architecture Analysis Report - AAR)
Supports customer security requirements analysis, develops system security requirements and defines allocations to lower levels (subsystem, elements and components) (ex. Security Requirements Traceability Matrix - SRTM, Security Control Traceability Matrix - SCTM)
Understands and provides cybersecurity inputs to MBSE models and Digital Engineering (DE)
Supports assessments and mitigations of system security threats and risks throughout the program life cycle to develop cyber survivable systems - familiar with Mission Based Cybersecurity Risk Assessment (MBCRA) approaches such as Mission Risk Assessment Process - Cyber (MRAP-C) and Cyber Table Top (CTTs) exercises
Researches and analyzes data, such as vendor products, COTS components, GFE/CFE, specifications, and manuals to determine security of design - familiarity with Trusted Systems and Networks (TSN) analysis and Cybersecurity - Supply Chain Risk Management desirable
Experience with DevSecOps
CISSP or equivalent certification
General Technical Skills
Strong understanding of cyber security technology and trends
Recognizes various security architectural patterns, applies them appropriately, understands strengths/weaknesses within those security architectures
Effectively selects and implements the appropriate cyber standards, processes, procedures, and tools throughout the system development life cycle to support the generation of the security engineering products
Support development of required security documentation, including items such as security plans, risk assessments and mitigation reports, and security tests plans and procedures in compliance with the IA policy
Strong understanding of cyber security guidance such as Risk Management Framework (RMF) 800-53, STIGs, Cyber Survivability Endorsement Implementation Guide, and other government security specifications and guidelines. Experience performing vulnerability and code analysis scans in DevSecOps environment (ex. Nessus, Static Code Analysis - SCA, STIGs).
Supports the development of the RMF body of evidence for security requirements including items such as system risk assessments and mitigation reports, security plans (SP), security testing plans and procedures, Security Control Traceability Matrices (SCTM), and System Impact Analyses.
Supports the Assessment and Authorization (A&A) activities and the generation of the cyber package for the program leading to granting of the Authority To Operate (ATO)
Supports the execution of the security testing and evaluation to ensure the correct implementation of security requirements (ex. Scanning with tools for static and dynamic code analysis. Penetration Testing)
Personal skills
Excellent written and verbal communications skills
Effective ability in communicating issues, impacts, and corrective actions as they affect the cyber design and implementation
Excellent ability in reporting relevant cyber systems engineering design topics
Effective communication and coordination with project leaders, the customer program leadership, and professionals within the Engineering department and with project teams
Creative thinker, good multi-tasker
Salary Note This estimate represents the typical salary range for this position based on experience and other factors (geographic location, etc.). Actual pay may vary. This job posting will remain open until the position is filled. Combined Salary Range USD $118,519.00 - USD $131,482.00 /Yr. Company Overview
General Dynamics Mission Systems (GDMS) engineers a diverse portfolio of high technology solutions, products and services that enable customers to successfully execute missions across all domains of operation. With a global team of 12,000+ top professionals, we partner with the best in industry to expand the bounds of innovation in the defense and scientific arenas. Given the nature of our work and who we are, we value trust, honesty, alignment and transparency. We offer highly competitive benefits and pride ourselves in being a great place to work with a shared sense of purpose. You will also enjoy a flexible work environment where contributions are recognized and rewarded. If who we are and what we do resonates with you, we invite you to join our high-performance team!
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
$118.5k-131.5k yearly Auto-Apply 60d+ ago
Looking for a job?
Let Zippia find it for you.
Senior Cyber Security Analyst (42466)
Neighborhood Health Plan of Rhode Island 4.4
Information security analyst job in Smithfield, RI
Senior Cyber SecurityAnalyst is an experienced cyber security individual who maintains the security of an organization's technical environment. They study existing security hardware and software, evaluate new security options and makes recommendations for improvement. Senior Cyber SecurityAnalyst also identifies weak spots in a cyber security system that may be breached and creates procedures to manage threats. Senior Cyber SecurityAnalyst monitors networks for suspicious activity and potential cyber threats. They keep up on threat intelligence, install and maintain security software and encryption. They are responsible for aiding in the planning of security systems, implementing policy and identifying business processes that may violate intended and acceptable use policies. They monitor and remediate vulnerabilities. Senior Cyber SecurityAnalyst works on advanced, complex technical projects or business issues requiring state of the art technical or industry knowledge.
Duties and Responsibilities
Responsibilities include, but are not limited to the following:
* Assist in developing, operating, and evolving Cloud Access Security solutions and capabilities
* Performs system security administration on designated technology platforms, including operating systems, applications and network security devices, in accordance with the defined policies, standards and procedures of the organization, as well as with industry best practices and vendor guidelines
* Performs installation and configuration management of security systems and applications, including policy assessment and compliance tools, network security appliances and host-based security systems
* Performs threat and vulnerability assessments, followed by appropriate remedial action, to ensure that systems are protected from known and potential threats and are free from known vulnerabilities Research, recommend, and implement streamlined automation processes
* Develops and maintains documentation for security systems and procedures
* Conducts network monitoring and intrusion detection analysis using various computer network defense tools, such as intrusion detection/prevention systems, firewalls and host-based security systems
* Provide support to one or more projects simultaneously. Delivers projects on schedule
* Deploys cloud-centric detection to detect threats related to cloud environments and services used by the organization
* Assists and trains junior team members in the use of security tools, the preparation of security reports and the resolution of security issues
* Applies patches where appropriate and, removes or otherwise mitigates known control weaknesses, such as unnecessary services or applications or redundant user accounts, as a means of hardening systems in accordance with security policies and standards Correlates activity across assets (endpoint, network, apps) and environments (on-premises, cloud) to identify patterns of anomalous activity
* Using threat intelligence information research emerging threats and vulnerabilities to aid in the identification of incidents
* Job Knowledge - Remains up-to-date in assigned area of responsibility: possesses skills and knowledge to perform job effectively; efficiently and safely; acquires, understands, and applies technical and professional information and skills; understands and adheres to policies and procedures
* Supports the creation of security incident response, business continuity/disaster recovery plans, including conducting tests, publishing test results and making changes necessary to address deficiencies
* Analyzes problems and alternative solutions and takes appropriate timely action to achieve desired business results. Seeks unique and novel solutions to problems and considers impact of final resolution
* Perform security standards testing against computers before implementation to ensure security
* Provide Key Performance Metrics to our Risk Management team to help coordinate risk tracking.
* Educate internal teams on informationsecurity best practices.
* Assist in technical audits of IT Systems and controls.
* Other duties as assigned.
* Corporate Compliance Responsibility - As an essential function, responsible for complying with Neighborhood's Corporate Compliance Program, Standards of Business Conduct, applicable contracts, laws, rules and regulations, policies and procedures as it applies to individual job duties, the department, and the Company. This position must exercise due diligence to prevent, detect and report unlawful and/or unethical conduct by fellow co-workers, professional affiliates and/or agents
$79k-103k yearly est. 42d ago
Sr. Security Analyst
Maximus 4.3
Information security analyst job in Providence, RI
Description & Requirements Maximus is seeking a qualified Sr. Technical/SecurityAnalyst for multiple projects, current and upcoming. The qualified candidate will be involved in technical/security planning and assessment projects with potentially multiple state agencies. The position requires the candidate to produce/review security relevant documentation, such as system security plans, POA&Ms, assessment plans, etc., produce technical/security analyses, develop estimates, review and contribute to requirements for large systems-planning efforts in the Child Support, Child Welfare and/or Integrated Eligibility public-sector domains. The individual will report directly to a Senior Manager. Maximus is a matrix-managed organization, which means the individual will have secondary reporting relationships to one or more Project Managers, depending on which projects they are assigned.
*This role is remote but requires working standard business hours in the US time zone of the client.*
Essential Duties and Responsibilities:
- Collaborate with project managers on various initiatives and projects to track progress and provide support as necessary.
- Support leadership in ensuring that the project is delivered to specifications, is on time, and within budget.
- Work closely with management and work groups to create and maintain work plan documents.
- Track the status and due dates of projects.
- Manage relationships with project staff responsible for projects.
- Produce regular weekly and monthly status reports that could include; work plan status, target dates, budget, resource capacity, and other reports as needed.
- Facilitate regular meetings and reviews.
- Adhere to contract requirements and comply with all corporate policies and procedures.
Job Specific Duties and Responsibilities:
-Perform duties independently under the direction of their direct manager and/or Project Managers on specific projects.
-Review project documentation and client materials and provide analysis of technical and security related topics.
-Participate in client meetings and offer observations and insight on technical and security related topics.
-Identify risk areas and potential problems that require proactive attention.
-Review and author artifacts and other project documents and identify potential gaps, inconsistencies, or other issues that may put the project at risk. Such artifacts and documents may include but are not limited to:
*System Security Plan
*Plan of Action and Milestones (POA&M)
*Security Assessment Plan
*Risk Assessment reports
*CMS ARC-AMPE forms and documentation
*Data Conversion and Migration Management Plan
*Deployment and/or roll-out plans
-Perform security assessments, lead security audit and assessment activities, and provide direct security oversight support to assigned clients and projects.
-Identify and escalate to the Senior Manager / Project Manager risks, alternatives, and potential quality issues.
-Attend interviews, focus groups, or other meetings necessary to gather information for project deliverables in accordance with the project scope of work.
-Attend project meetings with the client, subcontractors, project stakeholders, or other Maximus Team members, as requested by the Senior Manager / Project Manager.
-Complete project work in compliance with Maximus standards and procedures.
-Support team to complete assigned responsibilities as outlined in the Project schedule.
-Support all other tasks assigned by Senior Manager / Project Manager.
Minimum Requirements
- Bachelor's degree in related field.
- 7-10 years of relevant professional experience required.
- Equivalent combination of education and experience considered in lieu of degree.
Job Specific Requirements:
-Be available to work during standard client business hours. Projects may involve clients from any US time zone, so it is possible that work outside of the individual's local business hours will be required.
-Bachelor's degree from an accredited college or university, or equivalent work experience.
-7+ years of experience in informationsecurity, with at least 3 years of security-compliance work in a regulated industry.
-5+ years of experience working with HIPAA, NIST 800-53 and/or CMS MARS-E or ARC-AMPE security frameworks.
-Familiar with operating systems: Windows, Linux/UNIX, OS/X.
-Familiar with AI tools, capabilities.
-Strong command of cloud computing topics.
-Strong command of agile software development practices as well as waterfall development practices.
-Strong desktop software skills: proficient in MS Office, Excel, Word, Project.
-Ability to explain and communicate technical subjects to non-technical audiences.
-Ability to develop advanced concepts, techniques, and standards requiring a high level of interpersonal and technical skills.
-Ability to work independently.
-Good organizational skills and the ability to manage multiple tasks and deadlines simultaneously.
-Strong interpersonal and team building skills, as well as an understanding of client relationship building are essential.
-Excellent verbal and writing skills and be comfortable working with customers.
-Ability to multi-task with supervision.
-Self-motivated fast learner.
Preferred Skills:
-Prefer a candidate with experience in the Health & Human Services industry, which may include working with programs such as Child Support, Child Welfare, or Integrated Eligibility (SNAP, TANF, and Medicaid).
-Preference for security related certifications, such as the CISSP (Certified Information Systems Security Professional).
EEO Statement
Maximus is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, age, national origin, disability, veteran status, genetic information and other legally protected characteristics.
Pay Transparency
Maximus compensation is based on various factors including but not limited to job location, a candidate's education, training, experience, expected quality and quantity of work, required travel (if any), external market and internal value analysis including seniority and merit systems, as well as internal pay alignment. Annual salary is just one component of Maximus's total compensation package. Other rewards may include short- and long-term incentives as well as program-specific awards. Additionally, Maximus provides a variety of benefits to employees, including health insurance coverage, life and disability insurance, a retirement savings plan, paid holidays and paid time off. Compensation ranges may differ based on contract value but will be commensurate with job duties and relevant work experience. An applicant's salary history will not be used in determining compensation. Maximus will comply with regulatory minimum wage rates and exempt salary thresholds in all instances.
Accommodations
Maximus provides reasonable accommodations to individuals requiring assistance during any phase of the employment process due to a disability, medical condition, or physical or mental impairment. If you require assistance at any stage of the employment process-including accessing job postings, completing assessments, or participating in interviews,-please contact People Operations at **************************.
Minimum Salary
$
120,000.00
Maximum Salary
$
140,000.00
$96k-130k yearly est. Easy Apply 2d ago
Senior Manager, Information Security Office Consultant
Dev 4.2
Information security analyst job in Providence, RI
Company DescriptionJobs for Humanity is partnering with Capital One to build an inclusive and just employment ecosystem. Therefore, we prioritize individuals coming from the following communities: Refugee, Neurodivergent, Single Parent, Blind or Low Vision, Deaf or Hard of Hearing, Black, Hispanic, Asian, Military Veterans, the Elderly, the LGBTQ, and Justice Impacted individuals. This position is open to candidates who reside in and have the legal right to work in the country where the job is located.
Company Name: Capital One
Job Description201 Third Street (61049), United States of America, San Francisco, CaliforniaSenior Manager, InformationSecurity Office Consultant
At Capital One, you will help consult on initiatives, programs, and projects to raise their game in InformationSecurity. You are pragmatic and practical in your understanding of risk and security, but also willing to know when to pull in experts and escalate. You collaborate and innovate with other teams within Capital One to push the envelope. You are comfortable with Cloud Service technologies like Storage Services, Security & Access Control Management, Container Services, and API Implementation and Management. You are familiar with various Cloud computing models to include IaaS, PaaS, and SaaS along with their architectural differences. Security is essential to what we do here, from protecting our customers to our associates.
What You'll Do:
Act as a central InformationSecurity point of contact for the Enterprise Platform team
Coordinate and execute proactive InformationSecurity consulting to the business and technology teams covering Infrastructure Security, Resiliency, Data Security, Network Architecture and Design, and User Access Management
Serve as an expert in Capital One's InformationSecurity capabilities, solutions, policies, procedures and standards
Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes
Escalate and manage cyber security risk
Provide ad hoc support on special InformationSecurity hot topics for the business
Provide regular updates to executive leadership with your line of business on the overall InformationSecurity health and risk environment
Work with line of business leadership to anticipate their objectives and needs to better serve the line of business
Product security consulting in Authentication/Access Management /Identity application and experienced in Authentication and industry-standard protocol for authorization/authorization
Basic Qualifications:
High School Diploma, GED or equivalent certification
At least 8 years of experience working in cybersecurity or information technology
At least 7 years of experience providing guidance and oversight of Security concepts
At least 7 years of experience performing security risk assessments and security architecture reviews
At least 7 years of experience with architecture, software design, networking, and cloud infrastructure
At least 5 years of experience with cloud security engineering
Preferred Qualifications:
Bachelor's Degree
3+ years of experience in securing a public cloud environment (e.g. AWS, GCP, Azure)
4+ years of experience in IAM or related areas
Experience building software utilizing public cloud (e.g. AWS, GCP, Azure)
Familiarity with Cloud patch management practices such as system rehydration and image management
Experience utilizing Agile methodologies
Experience with Software Security Architecture
Experience with Application Security
Experience with Threat Modeling
Experience with Penetration Testing or Vulnerability Management
Experience with integrating SaaS products into an Enterprise Environment
Experience with securing Container services
Splunk-Fu / Enterprise Monitoring experience
Financial services industry experience
Professional certifications such as AWS Certified Solutions Architect and Certified Information Systems Security Professional (CISSP)
Experience in Offensive and Defensive Security techniques
Experience in a regulated environment
Strong conceptual thinking, influence and communication skills
At this time, Capital One will not sponsor a new applicant for employment authorization for this position.
The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.
New York City (Hybrid On-Site): $230,100 - $262,700 for Sr Manager, Cyber TechnicalSan Francisco, California (Hybrid On-Site): $243,800 - $278,200 for Sr Manager, Cyber Technical
Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter.
Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.
This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to sex (including pregnancy, childbirth or related medical conditions), race, color, age, national origin, religion, disability, genetic information, marital status, sexual orientation, gender identity, gender reassignment, citizenship, immigration status, protected veteran status, or any other basis prohibited under applicable federal, state or local law. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.
If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at ************** or via email at [email protected]. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
For technical support or questions about Capital One's recruiting process, please send an email to [email protected]
Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.
Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).
$243.8k-278.2k yearly 60d+ ago
Information Systems Security Officer (ISSO) III
GDIT
Information security analyst job in Bedford, MA
Type of Requisition:
Regular
Clearance Level Must Currently Possess:
Top Secret/SCI
Clearance Level Must Be Able to Obtain:
Top Secret SCI + Polygraph
Public Trust/Other Required:
None
Job Family:
Cyber and IT Risk Management
Job Qualifications:
Skills:
InformationSecurity, InformationSecurity Management, Information System Security
Certifications:
None
Experience:
5 + years of related experience
US Citizenship Required:
Yes
Job Description:
The Information Systems Security Officer (ISSO) III is responsible for ensuring the appropriate operational security posture is maintained for an information system and as such, works in close collaboration with the ISSM and ISO. The position shall have the detailed knowledge and expertise required to manage the security aspects of an information system and, in many organizations, is assigned responsibility for the day-to-day security operations of a system.
This will include physical and environmental protection, personnel security, incident handling, and security training and awareness. It will be required to work in close coordination with the ISSM and ISO in monitoring the information system(s) and its environment of operation to include developing and updating the authorization documentation, implementing configuration management across authorization boundaries.
This will include assessing the security impact of those changes and making recommendation to the ISSM. The primary function is working within Special Access Programs (SAPs) supporting Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense (OSD) and Military Compartments efforts. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities.
Performance shall include:
Assist the ISSM in meeting their duties and responsibilities.
Prepare, review, and update authorization packages.
Ensure approved procedures are in place for clearing, sanitizing, and destroying various types of hardware and media.
Notify ISSM when changes occur that might affect the authorization determination of the information system(s).
Conduct periodic reviews of information systems to ensure compliance with the security authorization package.
Coordinate any changes or modifications to hardware, software, or firmware of a system with the ISSM and AO/DAO prior to the change.
Monitor system recovery processes to ensure security features and procedures are properly restored and functioning correctly.
Ensure all IS security-related documentation is current and accessible to properly authorized individuals.
Ensure audit records are collected, reviewed, and documented (to include any anomalies)
Attend required technical and security training (e.g., operating system, networking, security management) relative to assigned duties.
Execute the cyber security portion of the self-inspection, to include security coordination and review of all system assessment plans.
Identify cyber security vulnerabilities and assist with the implementation of the countermeasures for them.
Prepare reports on the status of security safeguards applied to computer systems.
Perform ISSO duties in support of in-house and external customers.
Conduct continuous monitoring activities for authorization boundaries under your preview.
Assist Department of Defense, National Agency and Contractor organizations with the development of assessment and authorization (A&A) efforts.
Experience:
5+ years related experience, especially in developing RMF packages or bodies of evidence.
2+ years SAP experience required.
Prior performance in roles such as System, Network Administrator or ISSO.
Education:
Bachelor's degree OR Associate's degree in a related area + 2 years' experience OR equivalent experience (4 years)
Certifications:
IAT Level II ( Security+ CE, CCNA Security, etc) or IAM Level II .
Clearance Required to Start:
TS/SCI required. .
Must be able to Attain - TS/SCI with CI Polygraph.
#AirforceSAPOpportunities #ISSO III
The likely salary range for this position is $102,000 - $138,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
Scheduled Weekly Hours:
40
Travel Required:
10-25%
Telecommuting Options:
Onsite
Work Location:
USA MA Bedford
Additional Work Locations:
USA MA Avon, USA MA Boston, USA MA Braintree, USA MA Burlington, USA MA Cambridge, USA MA Fort Devens, USA MA Hanscom AFB, USA MA Norwood, USA MA Peabody, USA MA Quincy, USA MA Taunton, USA MA Waltham, USA MA Westwood
Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.Join our Talent Community to stay up to date on our career opportunities and events at
gdit.com/tc.
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
$102k-138k yearly Auto-Apply 2d ago
Director Information Security
Care New England 4.4
Information security analyst job in Warwick, RI
The Director, InformationSecurity holds primary responsibility for safeguarding the Care New England (CNE) computing environment. This includes securing systems across all CNE operating units, directing enterprise-wide cybersecurity strategy, and ensuring compliance with HIPAA, PCI, and all applicable federal, state, local, and industry regulations.
The Director serves as the Chief InformationSecurity Officer (CISO) for CNE, providing leadership in risk assessment, incident response, regulatory compliance, and cybersecurity governance. The role oversees informationsecurity tools, policies, vulnerability assessments, and monitoring systems; responds to security threats; leads mitigation activities; and collaborates closely with IS teams, Audit/Compliance, HR, Finance, and Legal.
This leader develops and manages the InformationSecurity program, directs security staff, sets security standards, leads incident management, evaluates emerging technologies, manages vendor relationships, and ensures organizational readiness through education, training, and participation in business continuity and disaster recovery planning.
Duties and Responsibilities:
Develop and maintain the enterprise InformationSecurity Program.
Establish protection goals, objectives, and metrics aligned with organizational strategy.
Serve as the Chief InformationSecurity Officer (CISO) for CNE.
Coordinate with the Chief Privacy Officer to ensure compliant reporting of security incidents.
Implement, manage, and maintain enterprise security systems and applications.
Lead vulnerability assessments and ensure timely remediation.
Oversee security incident response, forensic investigations, and threat mitigation efforts.
Examine emerging technologies and assess their security implications.
Lead ongoing risk assessment programs addressing informationsecurity and privacy.
Ensure compliance with HIPAA, PCI, and applicable state and federal regulations.
Develop and implement security policies, standards, guidelines, and procedures.
Coordinate with IS teams, Audit/Compliance, HR, Finance, and Legal to align security efforts.
Participate in disaster recovery and business continuity planning.
Lead security education and awareness initiatives for staff across CNE.
Manage security vendors responsible for operations, maintenance, and enhancements.
Ensure vendor service delivery aligns with organizational security requirements and policies.
Negotiate and manage contracts and service-level agreements with external partners.
Manage, mentor, and develop informationsecurity staff.
Promote professional growth and maintain awareness of industry trends.
Provide input on resource allocation and security budgeting.
Maintain 24-hour on-call availability to support critical operational needs.
Perform other job-related duties as assigned.
Requirements:
Bachelor's Degree Required (computer science, MIS or related field)
Minimum of 7-10 years of progressive experience in informationsecurity, Strong technical background in infrastructure, network security, firewalls, and cloud environments, Experience conducting forensic investigations and managing enterprise security products.
Security certifications required: CISSP, GIAC, SANS, or similar. Audit certification preferred: CISA.
Participation in national and regional security organizations preferred.
Deep knowledge of cybersecurity principles, threat landscapes, and protection technologies.
Strong working knowledge of enterprise infrastructure, network security, firewalls, and cloud platforms.
Expertise in vulnerability management, forensic investigation, risk assessment, and incident response.
Ability to develop enterprise-wide policies and governance frameworks.
Strong communication skills for engaging executive leadership and cross-functional stakeholders.
Exceptional organization, analytical, and decision-making abilities.
Ability to manage technical teams and develop staff.
Strong vendor management and contract negotiation skills.
Ability to maintain confidentiality and uphold ethical and regulatory standards
Additional Information:
Care New England Health System (CNE) and its member institutions, Butler Hospital, Women & Infants Hospital, Kent Hospital, VNA of Care New England, Integra, The Providence Center, and Care New England Medical Group, and our Wellness Center, are trusted organizations fueling the latest advances in medical research, attracting top specialty-trained doctors, and honing renowned services and innovative programs to engage in the important discussions people need to have about their health.
EEOC Statement: Care New England is an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.
Ethics Statement: Employee conducts himself/herself consistent with the ethical standards of the organization including, but not limited to hospital policy, mission, vision, and values.
Americans with Disability Act Statement: External and internal applicants, as well as position incumbents who become disabled must be able to perform the essential job-specific functions either unaided or with the assistance of a reasonable accommodation, to be determined by the organization on a case-by-case basis.
$129k-189k yearly est. 41d ago
Director of Information Security
Rxvantage
Information security analyst job in Providence, RI
We're seeking an experienced Director of InformationSecurity to join our dynamic team and help drive our growth. In this role, your job will be to coordinate people and processes to instill a “security first” mindset for information management, systems development, acceptable use of these systems, staff awareness, and oversight of our vendors and partners.
This security professional will lead the management of risk and compliance of intellectual property, including day-to-day network and cyber tool monitoring, oversight, and ongoing security testing. The individual performing this role will enforce policies and procedures that ensure compliance with state, federal, and industry standards and requirements, ensuring our customers' and company's data are protected.
As the Director of InformationSecurity, you will implement a security-readiness plan and provide guidance on how to quickly and effectively respond to any and all security incidents. In addition, this role will be instrumental in implementing controls and monitoring capabilities that provide visibility into the organization's security posture.
At RxVantage we transform how medical practices engage with life sciences resources and expertise to improve patient care. Our platform intelligently connects healthcare providers with the precise life sciences experts that they need, when they need them. As a result, medical practices stay on the cutting edge of patient care without disrupting workflows. Trusted by more than tens of thousands of healthcare practitioners and all major life sciences companies, RxVantage has powered millions of educational exchanges between healthcare teams and life sciences companies.
What you'll be doing:
Creating and implementing a security roadmap based on current and ongoing assessments
Ensuring policies are developed and maintained from both a business & technical perspective for the application, data, and security needs of the organization
Working with Legal to ensure agreements are congruent with policies
Overseeing the GRC (Governance Risk and Compliance) process
Ensuring compliance with industry laws and regulations for data security and privacy to include CCPR, 21 CFR Part 11, SOC2, NIST SP800-53
Monitoring the Identity and Access Management Framework
Benefits:
Competitive Salary
100% Company-Paid Premiums for Employee's Medical Health (HDHP 4500), Vision, and Dental Plans + $4,400 company sponsored contribution into an HSA
Short-term and Long-term Disability
Life Insurance
401k Matching
Work from Anywhere within the US
Flexible PTO
100% Paid Parental Leave
Post-Parental Leave Program - $5k stipend to assist with expenses, 4 week 100% paid “Ease-Back” return to work transition period
Charitable donation matching
Location:
Our “Work from Anywhere” philosophy is aimed at making sure that we recruit a diverse range of thought leadership to ensure that our technology is better able to serve local health care providers. Our goal is to hire the country's top talent and allow them to create an environment within the U.S. where they can do their best work.
About Our Organization:
At RxVantage, we're a small company with a big mission: to connect healthcare providers with the right life science experts and resources they need, exactly when they need them, to improve patient care. We've built a software platform that's changing the way providers learn about the latest medical advancements and technologies. Every year, our platform powers over 1 million educational exchanges between medical practices and life science companies, making it easier for them to stay informed and provide better care.
We have a proven product, a strong mission, and a passionate team. Now, we're looking for talented people to help us grow even more. If you're driven, eager to make an impact, and ready to be part of something meaningful, we want to hear from you!
---
RxVantage is an equal opportunity employer and dedicated to ensuring that we represent the local communities where our health and wellbeing providers serve as pillars of support to our family, friends, and neighbors. Our representation within these communities allows us to embody a diverse set of backgrounds, experiences, abilities and perspectives; and provide an inclusive environment for our team to feel empowered to be their authentic selves, without fear of harassment or discrimination.
$114k-170k yearly est. Auto-Apply 5d ago
Information Security Officer
Kabafusion Holdings, LLC
Information security analyst job in Lexington, MA
Come join a company that is putting the "CARE" back in healthcare.
Why do IT Professionals want to work here? The reason people love working for KabaFusion is because of the impact we have on our patients. Here, it doesn't matter what your role is, you will be part of a team that works collaboratively to change lives. You will go home knowing you've made a difference and improved someone's life.
About us:
What started as a single pharmacy in 2010 has grown into KabaFusion becoming the largest privately held home infusion company in the country. We have a national network of pharmacies and nursing offices strategically placed to service 40+ states. Couple that with over 30 years of combined experience and it's no wonder why KabaFusion is the industry leader in home infusion.
About the role:
As an InformationSecurity Officer, you will collaboratively with other members of our IT team to ensure that KabaFusion is as protected as possible when it comes to security threats. This will include auditing our current systems and analyzing areas of vulnerability then recommend remediations. This may also lead to gap analysis projects where you'll recommend and assist in the implementation of remedies to ensure we are mitigating risk.
Essential Duties & Responsibilities:
Design, implement, and maintain robust IT controls across our network, systems, and applications.
Conduct advisory projects for key system implementations and business process changes to provide proactive risk and control guidance.
Analyzing business and IT process controls, understanding the relationship with the data supporting them, identifying risks and design, and developing innovative data analytic test approaches applicable to audit objectives
Owns audits and project engagements. Responsible for overseeing the IT audit staff on engagements and interacting with audit customers during planning, fieldwork and testing, reporting, and follow-up.
As an InformationSecurity Officer , you bring:
Bachelor's degree or equivalent experience
8+ years of IT audit, cybersecurity, system administration, or network administration experience
CISSP, CEH, CCSP, GSEC, CISM certification
2+ years of experience in SaaS application, AWS, or Azure Cloud
Previous experience in cybersecurity incident response, auditing, or informationsecurity compliance, including expertise in access management, change management, IT operations, and vulnerability management, is desired.
Our Benefits:
Benefits start on your 1st day of employment.
401k w 4% match - no waiting or vesting period
PTO / Floating Holidays / Paid Holidays
Company paid life insurance and short-term disability
Employee Assistance programs to help with mental health / wellness
Learning & Development Programs
Perks… includes discounts on travel, cell phone, clothing and more…
Generous employee referral program
KabaFusion is a mission driven company with a focus on innovation and patient care so, as a IT professional, if that sounds like something you want to be a part of, then look no furthe r.
$116k-173k yearly est. Auto-Apply 60d+ ago
Information Security Officer
Kabafusion
Information security analyst job in Lexington, MA
Come join a company that is putting the "CARE" back in healthcare.
Why do IT Professionals want to work here? The reason people love working for KabaFusion is because of the impact we have on our patients. Here, it doesn't matter what your role is, you will be part of a team that works collaboratively to change lives. You will go home knowing you've made a difference and improved someone's life.
About us:
What started as a single pharmacy in 2010 has grown into KabaFusion becoming the largest privately held home infusion company in the country. We have a national network of pharmacies and nursing offices strategically placed to service 40+ states. Couple that with over 30 years of combined experience and it's no wonder why KabaFusion is the industry leader in home infusion.
About the role:
As an InformationSecurity Officer, you will collaboratively with other members of our IT team to ensure that KabaFusion is as protected as possible when it comes to security threats. This will include auditing our current systems and analyzing areas of vulnerability then recommend remediations. This may also lead to gap analysis projects where you'll recommend and assist in the implementation of remedies to ensure we are mitigating risk.
Essential Duties & Responsibilities:
Design, implement, and maintain robust IT controls across our network, systems, and applications.
Conduct advisory projects for key system implementations and business process changes to provide proactive risk and control guidance.
Analyzing business and IT process controls, understanding the relationship with the data supporting them, identifying risks and design, and developing innovative data analytic test approaches applicable to audit objectives
Owns audits and project engagements. Responsible for overseeing the IT audit staff on engagements and interacting with audit customers during planning, fieldwork and testing, reporting, and follow-up.
As an InformationSecurity Officer, you bring:
Bachelor's degree or equivalent experience
8+ years of IT audit, cybersecurity, system administration, or network administration experience
CISSP, CEH, CCSP, GSEC, CISM certification
2+ years of experience in SaaS application, AWS, or Azure Cloud
Previous experience in cybersecurity incident response, auditing, or informationsecurity compliance, including expertise in access management, change management, IT operations, and vulnerability management, is desired.
Our Benefits:
Benefits start on your 1
st
day of employment.
401k w 4% match - no waiting or vesting period
PTO / Floating Holidays / Paid Holidays
Company paid life insurance and short-term disability
Employee Assistance programs to help with mental health / wellness
Learning & Development Programs
Perks… includes discounts on travel, cell phone, clothing and more…
Generous employee referral program
KabaFusion is a mission driven company with a focus on innovation and patient care so, as a IT professional, if that sounds like something you want to be a part of, then look no further.
$116k-173k yearly est. Auto-Apply 60d+ ago
Engineer, Information Security and Risk
Cardinal Health 4.4
Information security analyst job in Hartford, CT
Cardinal Health, Inc. (NYSE: CAH) is a global healthcare services and products company. We provide customized solutions for hospitals, healthcare systems, pharmacies, ambulatory surgery centers, clinical laboratories, physician offices and patients in the home. We are a distributor of pharmaceuticals and specialty products; a global manufacturer and distributor of medical and laboratory products; an operator of nuclear pharmacies and manufacturing facilities; and a provider of performance and data solutions. Working to be healthcare's most trusted partner, our customer-centric focus drives continuous improvement and leads to innovative solutions that improve the lives of people every day. With approximately 50,000 employees worldwide, Cardinal Health ranks among the top fifteen in the Fortune 500.
**_Department Overview:_**
**Information Technology** oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value.
**InformationSecurity and Risk** develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure, or destruction. This job family develops system back-up and disaster recovery plans, conducts incident responses, threat management, vulnerability scanning, virus management and intrusion detection as well as completes risk assessments.
Lead IAM work for new customer onboardings and migrations. Collaborate with CAH Account Management, Application Teams, and Customers to design, implement, and test federated SSO solution based on customer login requirements. Provide technical guidance and act as primary point of contact for business partners and customer related to IAM work for onboarding. Additional responsibilities include supporting application integrations and enhancing SSO self service application onboarding.
**Responsibilities:**
+ **Customer Onboarding IAM Efforts - Strategy & Execution :** Lead the planning, design, and execution for Customer Onboarding via federated SSO, ensuring alignment with overall business and security objectives. This includes assessing multiple Cardinal Health e-commerce applications, understanding login requirements for new/existing customers, designing, testing and implementing solutions etc to ensure top notch user login experience and enhancing Cardinal Health's security posture.
+ **Collaboration & Communication:** Coordinate cross-functional teams, including Customer Business and IT teams, Cardinal Health's Account Management/Sales and Application teams, InformationSecurity and others to ensure effective IAM implementation and seamless integration with business processes. Communicate complex security concepts to technical and non-technical internal and external stakeholders.
+ **Application Integration Leadership:** Lead the integration of various enterprise applications (SaaS, on-premise, custom-built) with our core IAM infrastructure, ensuring secure authentication, authorization, and user provisioning/de-provisioning.
+ **User Lifecycle Management:** Streamline and automate user provisioning, de-provisioning, and periodic access reviews for employees, contractors, and partners across all integrated systems, ensuring smooth onboarding and offboarding during M&A transitions.
+ **Solution Design & Implementation:** Design, implement, and maintain IAM solutions including Single Sign-On (SSO), Multi-Factor Authentication (MFA), and Role-Based Access Control (RBAC) frameworks.
+ **Technical Troubleshooting & Support:** Troubleshoot, identify, and resolve technical identity and access management-related issues, providing expert support to internal teams and end-users during and after integration.
+ **Documentation & Best Practices:** Develop, review, and maintain comprehensive technical documentation, including architecture diagrams, configuration guides, and operational procedures. Stay up-to-date with IAM best practices, regulatory requirements, and security trends.
**Qualifications:**
+ **Education:** Bachelor's degree in Computer Science, Information Technology, InformationSecurity, or a related field, or equivalent practical experience.
+ **Experience:** 5+ years of progressive experience as an IAM Engineer, designing and implementing enterprise scale solutions with significant experience in supporting M&A integration projects preferred.
+ **Technical Expertise:**
+ Extensive knowledge and experience with authentication standards and technologies such as SSO (SAML, OAuth, OpenID Connect), MFA
+ Proficiency in directory services (e.g., Active Directory, Azure AD, LDAP).
+ Hands-on experience with leading IAM platforms (e.g., Okta, Microsoft Azure AD, CyberArk, ForgeRock, Ping Identity, SailPoint).
+ Strong understanding of security principles, risk management, and access control models (e.g., RBAC).
+ Familiarity with Zero Trust architecture principles.
+ Familiarity with AI/ML concepts and their practical application in security and risk management, especially in IAM context.
+ Strong communication and interpersonal skills to collaborate effectively with various teams and stakeholders.
+ Detail-oriented mindset to ensure precise access control configurations and compliance.
+ Excellent problem-solving and analytical abilities to troubleshoot access issues and design solutions for unique business requirements
+ Must be a self-starter who takes full ownership of projects from inception to completion , holding oneself accountable for the security and operation integrity of IAM platform.
+ Ability to manage multiple priorities and meet tight deadlines in a fast-paced M&A environment.
**Anticipated salary range:** $94,900 - $135,600
**Bonus eligible:** No
**Benefits:** Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
+ Medical, dental and vision coverage
+ Paid time off plan
+ Health savings account (HSA)
+ 401k savings plan
+ Access to wages before pay day with my FlexPay
+ Flexible spending accounts (FSAs)
+ Short- and long-term disability coverage
+ Work-Life resources
+ Paid parental leave
+ Healthy lifestyle programs
**Application window anticipated to close:** 12/20/2025 *if interested in opportunity, please submit application as soon as possible.
The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.
_Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply._
_Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal_ _Opportunity/Affirmative_ _Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law._
_To read and review this privacy notice click_ here (***************************************************************************************************************************
$94.9k-135.6k yearly 56d ago
IT Helpdesk Analyst
The Silk Companies 3.6
Information security analyst job in Warwick, RI
WHY WORK AT SILK TITLE CO.
Silk Title Co. is a privately owned, fast-growing company which handles billions of dollars a year in real estate transactions for some of the nation's top fin-tech institutions. Our motto, Service at Scale, combines our technology, proprietary processes, and talented team to deliver title insurance, search, and settlement services across the nation.
Stuffy cover letters and fancy sounding resumes are not our thing. We want people with focused energy, solid work ethic and curious minds capable of absorbing everything we can teach about our business.
Our employees are what make our company exceptional; we are a diverse team of problem solvers, QA experts, and business process gurus. We work hard but also know how to incorporate some fun through team building challenges. Our workplace exemplifies our core values of quality, communication, experience, transparency, and respect.
ESSENTIAL RESPONSIBILITIES INCLUDE BUT ARE NOT LIMITED TO:
• Provide Help Desk support to internal staff, clients, and partners through troubleshooting in person, on the phone, or remotely
• Provide customer service by supporting enterprise PC, VoIP, and mobile devices
• Champions IT policies and best practices
• Configures user accounts through active directory and other proprietary systems
• Provisioning, installing, and supporting infrastructure such as switches, firewalls, access points, PCs, printers, and scanners
• Analyzing and monitoring systems and reports
• Participates in other duties as assigned
***The IT Helpdesk Analyst must live within a commutable distance to the Warwick, RI office.***
$83k-114k yearly est. 60d+ ago
IT Security and Compliance Engineer
Aquinas Consulting 4.3
Information security analyst job in East Hartford, CT
Job Description
Aquinas Consulting is currently looking to fill an IT Security and Compliance Engineer job for our direct client in East Hartford, CT. In this role, you will design, implement, and manage security controls across cloud and on-prem environments while guiding clients through compliance requirements. You will support audits, assess gaps, and respond to incidents - ensuring clients maintain strong security postures.
IT Security and Compliance Engineer Job Responsibilities:
Design and implement security architectures across cloud, on-prem, and hybrid client environments
Manage and optimize security tools including EDR, MDR, MFA, SIEM, firewalls, and VPNs
Collaborate with NOC/SOC partners to monitor threats and respond to incidents
Conduct gap assessments and advise on remediation plans for compliance frameworks such as NIST, CMMC, and PCI
Support client audits by coordinating evidence collection and documentation
Perform vulnerability scans, risk assessments, and configuration reviews
Create and maintain security policies, procedures, and environment documentation
Deliver security awareness training for internal teams and client personnel
Develop and execute incident response playbooks and handle security events
Improve security processes and tools, ensuring audit readiness and SLA compliance
Stay current on industry trends and recommend new security measures
Qualifications:
Strong knowledge of servers, network infrastructure, and security technologies (firewalls, VPNs, MFA, SIEM, MDR, EDR)
Experience securing cloud platforms such as AWS, Azure, or GCP, including IAM and native controls
Familiarity with compliance frameworks such as NIST, CMMC, PCI, ISO 27001, etc.
Excellent troubleshooting skills and experience supporting incident response
Strong written and verbal communication skills with both technical and non-technical audiences
Bachelor's degree in InformationSecurity, Computer Science, or related field (or equivalent experience)
4+ years in cybersecurity engineering (MSP/MSSP/SOC experience preferred)
Relevant certifications such as CompTIA Security+, CISSP, CISM, GIAC, or ISO 27001 Lead Implementer preferred
If you are interested in this IT Security and Compliance Engineer job in East Hartford, CT, please apply now to be connected with a member of our team.
Please note: Applying to this role is an agreement to have your information entered into our database and acknowledgement that a recruiter will reach out to you either by phone, email, and/or text message regarding this and similar job opportunities.
Aquinas Consulting is a woman and minority owned company headquartered in Milford, CT that provides Engineering, Information Technology (IT), and Manufacturing staffing solutions throughout the US. We take pride in 20 years of service to our clients, our hiring managers, our consultants, and our local community. Aquinas is an affirmative action, equal opportunity employer and committed to considering all qualified applications without regard to race, genetic information, sex, age, color, religion, national origin, veteran status, disability or any other characteristic protected by law. *************************
$71k-91k yearly est. 12d ago
Information Systems Security Engineer (ISSE)
Applied Research Solutions 3.4
Information security analyst job in Bedford, MA
ARS is seeking candidates to fill an ISSE Journeyman role located on Hanscom AFB in Bedford, Massachusetts. Our desire is to build a team of highly qualified professionals that will provide expertise in Cybersecurity, Cloud, and Systems Engineering, who will support the development and sustainment of unique secure enclaves at the edge, that provide enterprise services and cyber network defense capabilities to customers across the DoD. This team will provide engineering expertise using technologies such as ePO, Splunk, ACAS, Azure Automation, STIG/SCAP, and other enterprise capabilities.
The ISSE will have an active role in monitoring a system and its environment of operation to include developing and updating a System Security Plan, managing and controlling changes to the system, and assessing the security impact.
ISAE II certification. CISSP, CASP, CSSLP, CISSP-ISSEP, or CISSP-ISSAP preferred.
Why Work with us?
Applied Research Solutions (ARS) is respected as a world-class provider of technically integrated solutions as we deliver premier talent and technology across our focused markets for unparalleled, continuous mission support. Awarded a Best Places to Work nominee since 2020, ARS recognizes that without our career- driven, loyal professionals, we would not be able to deliver state-of-the-art results for our mission partners. We firmly believe that prioritizing our employees is of the upmost importance. We provide a culture where our employees are challenged to meet their career goals and aspirations, while still obtaining a work/life balance. ARS employees are motivated through our industry competitive benefits package, our awards and recognition program, and personalized attention from ARS Senior Managers.
Responsibilities include:
Maintain the operational security posture of systems.
Monitor systems and environments for security compliance.
Develop and update System Security Plans (SSPs).
Manage and control system changes and assess their security impact.
Handle physical, personnel, and environmental security.
Conduct incident response and security awareness training.
Assist the ISSM and assume ISSM duties when necessary.
Assist the ISSM in meeting their duties and responsibilities. The ISSO shall assume ISSM responsibilities in the absence of the ISSM;
Ensure systems are operated, maintained, and disposed of in accordance with security policies and procedures as outlined in the security authorization package;
Maintain equivalent IAM Level 2 certifications based off of DoD 8140 standard;
Ensure all users have the requisite security clearances, authorization, need-to-know, and are aware of their security responsibilities before granting access to the IS;
Report all security-related incidents to the ISSM
Conduct periodic reviews of information systems to ensure compliance with the security authorization package;
Serve as member of the CCB, if designated by the ISSM;
Coordinate any changes or modifications to hardware, software, or firmware of a system with the ISSM and AO/DAO prior to the change;
Formally notify the ISSM and AO/DAO when changes occur that might affect system authorization;
Monitor system recovery processes to ensure security features and procedures are properly restored and functioning correctly;
Ensure all IS security-related documentation is current and accessible to properly authorized individuals; and
Ensure audit records are collected, reviewed, and documented (to include any anomalies).
Participate in joint agile backlog planning and provide feedback to the software development team and infrastructure teams around high to medium risk items that require information system owner approval.
Other duties as assigned.
Qualifications/Technical Experience Requirements:
Must be a US citizen
Active Secret Security Clearance
Advanced technical competency and experience in one or more of the following areas: Active Directory Domain Services, Active Directory Federated Services, Active Directory Certificate Services, Windows Server Update Services, ePO, Splunk, STIG/SCAP, YUM, ACAS Automation, and Azure Monitor / Log Analytics.
ISAE II certification. CISSP, CASP, CSSLP, CISSP-ISSEP, or CISSP-ISSAP preferred.
Bachelor's degree in computer science, Engineering, Finance, Business, or related field
5-8 years demonstrated performance in related technology
The expected annual salary range: $150k - $165K. Salary is dependent upon the role, associated responsibilities, candidates experience and qualifications to include education/training and key skills.
All positions at Applied Research Solutions are subject to background investigations. Employment is contingent upon successful completion of a background investigation including criminal history and identity check.
This contractor and subcontractor shall abide by the requirements of 41 CFR 60-741.5(a). This regulation prohibits discrimination against qualified individuals based on disability, and requires affirmative action by covered prime contractors and subcontractors to employ and advance in employment qualified individuals with disabilities.
This contractor and subcontractor shall abide by the requirements of 41 CFR 60-300.5(a). This regulation prohibits discrimination against qualified protected veterans, and requires affirmative action by covered contractors and subcontractors to employ and advance in employment qualified protected veterans.
$150k-165k yearly 41d ago
IT analyst
The Panther Group 3.9
Information security analyst job in Maynard, MA
Test
$86k-117k yearly est. 10d ago
Systems Security Engineer
General Dynamics Mission Systems 4.9
Information security analyst job in Dedham, MA
Basic Qualifications
Requires a Bachelor's degree in Systems Engineering, or a related Science, Engineering, Technology or Mathematics field. Also requires 5+ years of job-related experience, or a Master's degree plus 3 years of job-related experience. Agile experience preferred.
CLEARANCE REQUIREMENTS: Department of Defense Secret security clearance is required at time of hire. Applicants selected will be subject to a U.S. Government security investigation and must meet eligibility requirements for access to classified information. Due to the nature of work performed within our facilities, U.S. citizenship is required.
Responsibilities for this Position
We are seeking a Systems Security Engineer who has experience in the design and development of NSA-certified Cybersecurity devices.
Key Responsibilities:
Design and develop specifications for mission-critical NSA-certified Cybersecurity devices
Collaborate with software and validation engineering teams to deliver high-speed data solutions
Develop real-time multi-threaded Embedded System architecture using Model-based Systems Engineering (MBSE) tools and techniques
Analyze and maintain system security requirements throughout product development lifecycle
Conduct trade studies, perform functional analysis, and design system security.
Preferred Skills and Experiences:
NSA approved Cryptography/Encryption
Security requirements analysis
Real-Time multi-threaded Embedded System architecture and development
Model-based Systems Engineering (MBSE)
CISSP certification or similar
INCOSE ASEP, CSEP, or ESEP certification
We value candidates who possess:
Drive to expand knowledge and experience in designing complex systems
Ability to define project scope, schedule, and expected results
Initiative to complete assignments and ability to engage in technical direction and leadership
Our Commitment to You:
An exciting career path with opportunities for continuous learning and development
Research-oriented work with award-winning teams
Competitive benefits package
***Please note you will be onsite 100%.
Salary Note This estimate represents the typical salary range for this position based on experience and other factors (geographic location, etc.). Actual pay may vary. This job posting will remain open until the position is filled. Combined Salary Range USD $112,924.00 - USD $125,275.00 /Yr. Company Overview
General Dynamics Mission Systems (GDMS) engineers a diverse portfolio of high technology solutions, products and services that enable customers to successfully execute missions across all domains of operation. With a global team of 12,000+ top professionals, we partner with the best in industry to expand the bounds of innovation in the defense and scientific arenas. Given the nature of our work and who we are, we value trust, honesty, alignment and transparency. We offer highly competitive benefits and pride ourselves in being a great place to work with a shared sense of purpose. You will also enjoy a flexible work environment where contributions are recognized and rewarded. If who we are and what we do resonates with you, we invite you to join our high-performance team!
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
$112.9k-125.3k yearly Auto-Apply 60d+ ago
Director Information Security
Care New England Health System 4.4
Information security analyst job in Warwick, RI
The Director, InformationSecurity holds primary responsibility for safeguarding the Care New England (CNE) computing environment. This includes securing systems across all CNE operating units, directing enterprise-wide cybersecurity strategy, and ensuring compliance with HIPAA, PCI, and all applicable federal, state, local, and industry regulations.
The Director serves as the Chief InformationSecurity Officer (CISO) for CNE, providing leadership in risk assessment, incident response, regulatory compliance, and cybersecurity governance. The role oversees informationsecurity tools, policies, vulnerability assessments, and monitoring systems; responds to security threats; leads mitigation activities; and collaborates closely with IS teams, Audit/Compliance, HR, Finance, and Legal.
This leader develops and manages the InformationSecurity program, directs security staff, sets security standards, leads incident management, evaluates emerging technologies, manages vendor relationships, and ensures organizational readiness through education, training, and participation in business continuity and disaster recovery planning.
Duties and Responsibilities:
Develop and maintain the enterprise InformationSecurity Program.
Establish protection goals, objectives, and metrics aligned with organizational strategy.
Serve as the Chief InformationSecurity Officer (CISO) for CNE.
Coordinate with the Chief Privacy Officer to ensure compliant reporting of security incidents.
Implement, manage, and maintain enterprise security systems and applications.
Lead vulnerability assessments and ensure timely remediation.
Oversee security incident response, forensic investigations, and threat mitigation efforts.
Examine emerging technologies and assess their security implications.
Lead ongoing risk assessment programs addressing informationsecurity and privacy.
Ensure compliance with HIPAA, PCI, and applicable state and federal regulations.
Develop and implement security policies, standards, guidelines, and procedures.
Coordinate with IS teams, Audit/Compliance, HR, Finance, and Legal to align security efforts.
Participate in disaster recovery and business continuity planning.
Lead security education and awareness initiatives for staff across CNE.
Manage security vendors responsible for operations, maintenance, and enhancements.
Ensure vendor service delivery aligns with organizational security requirements and policies.
Negotiate and manage contracts and service-level agreements with external partners.
Manage, mentor, and develop informationsecurity staff.
Promote professional growth and maintain awareness of industry trends.
Provide input on resource allocation and security budgeting.
Maintain 24-hour on-call availability to support critical operational needs.
Perform other job-related duties as assigned.
Requirements:
Bachelor's Degree Required (computer science, MIS or related field)
Minimum of 7-10 years of progressive experience in informationsecurity, Strong technical background in infrastructure, network security, firewalls, and cloud environments, Experience conducting forensic investigations and managing enterprise security products.
Security certifications required: CISSP, GIAC, SANS, or similar. Audit certification preferred: CISA.
Participation in national and regional security organizations preferred.
Deep knowledge of cybersecurity principles, threat landscapes, and protection technologies.
Strong working knowledge of enterprise infrastructure, network security, firewalls, and cloud platforms.
Expertise in vulnerability management, forensic investigation, risk assessment, and incident response.
Ability to develop enterprise-wide policies and governance frameworks.
Strong communication skills for engaging executive leadership and cross-functional stakeholders.
Exceptional organization, analytical, and decision-making abilities.
Ability to manage technical teams and develop staff.
Strong vendor management and contract negotiation skills.
Ability to maintain confidentiality and uphold ethical and regulatory standards
Additional Information:
Care New England Health System (CNE) and its member institutions, Butler Hospital, Women & Infants Hospital, Kent Hospital, VNA of Care New England, Integra, The Providence Center, and Care New England Medical Group, and our Wellness Center, are trusted organizations fueling the latest advances in medical research, attracting top specialty-trained doctors, and honing renowned services and innovative programs to engage in the important discussions people need to have about their health.
EEOC Statement: Care New England is an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.
Ethics Statement: Employee conducts himself/herself consistent with the ethical standards of the organization including, but not limited to hospital policy, mission, vision, and values.
Americans with Disability Act Statement: External and internal applicants, as well as position incumbents who become disabled must be able to perform the essential job-specific functions either unaided or with the assistance of a reasonable accommodation, to be determined by the organization on a case-by-case basis.
$129k-189k yearly est. 41d ago
Engineer, Information Security and Risk
Cardinal Health 4.4
Information security analyst job in Hartford, CT
Cardinal Health, Inc. (NYSE: CAH) is a global healthcare services and products company. We provide customized solutions for hospitals, healthcare systems, pharmacies, ambulatory surgery centers, clinical laboratories, physician offices and patients in the home. We are a distributor of pharmaceuticals and specialty products; a global manufacturer and distributor of medical and laboratory products; an operator of nuclear pharmacies and manufacturing facilities; and a provider of performance and data solutions. Working to be healthcare's most trusted partner, our customer-centric focus drives continuous improvement and leads to innovative solutions that improve the lives of people every day. With approximately 50,000 employees worldwide, Cardinal Health ranks among the top fifteen in the Fortune 500.
**_Department Overview:_**
**Information Technology** oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value.
**InformationSecurity and Risk** develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure, or destruction. This job family develops system back-up and disaster recovery plans, conducts incident responses, threat management, vulnerability scanning, virus management and intrusion detection as well as completes risk assessments.
We are seeking a highly skilled and experienced Identity and Access Management (IAM) Engineer to join our team. In this pivotal role, you will be instrumental in designing, implementing, and managing IAM solutions that secure our enterprise applications and facilitate the secure, efficient, and seamless integration of identity and access systems in context of our rapid growth through Mergers and Acquisitions. You will ensure robust access controls, streamline user experiences, and maintain operational continuity across our diverse IT landscape. The ideal candidate will have deep technical expertise in modern IAM principles, protocols and products along with strong management and communication skills.
**Responsibilities:**
+ **Application Integration Leadership:** Lead the integration of various enterprise applications (SaaS, on-premise, custom-built) with our core IAM infrastructure, ensuring secure authentication, authorization, and user provisioning/de-provisioning.
+ **M&A Integration Strategy & Execution:** Lead the planning, design, and execution of IAM integration strategies for M&A activities, ensuring alignment with overall business and security objectives. This includes assessing the IAM landscapes of merging entities to identify challenges and solutions.
+ **Identity System Merging & Consolidation:** Manage the complex process of merging disparate identity providers, user directories (e.g., Active Directory, Azure AD, LDAP), and access management systems from acquired companies into the existing infrastructure.
+ **User Lifecycle Management:** Streamline and automate user provisioning, de-provisioning, and periodic access reviews for employees, contractors, and partners across all integrated systems, ensuring smooth onboarding and offboarding during M&A transitions.
+ **Solution Design & Implementation:** Design, implement, and maintain IAM solutions including Single Sign-On (SSO), Multi-Factor Authentication (MFA), Privileged Access Management (PAM), and Role-Based Access Control (RBAC) frameworks.
+ **Security & Compliance:** Ensure IAM systems and processes comply with regulatory requirements (e.g., GDPR, HIPAA, SOX) and internal security policies, providing auditable records of access activities. Protect against data breaches by ensuring only authorized personnel can access sensitive information.
+ **Technical Troubleshooting & Support:** Troubleshoot, identify, and resolve technical identity and access management-related issues, providing expert support to internal teams and end-users during and after integration.
+ **Collaboration & Communication:** Coordinate cross-functional teams, including InformationSecurity, IT Operations, HR, and Application Development, to ensure effective IAM implementation and seamless integration with business processes. Communicate complex security concepts to technical and non-technical stakeholders.
+ **Documentation & Best Practices:** Develop, review, and maintain comprehensive technical documentation, including architecture diagrams, configuration guides, and operational procedures. Stay up-to-date with IAM best practices, regulatory requirements, and security trends.
**Qualifications:**
+ **Education:** Bachelor's degree in Computer Science, Information Technology, InformationSecurity, or a related field, or equivalent practical experience.
+ **Experience:** 5+ years of progressive experience as an IAM Engineer, designing and implementing enterprise scale solutions with significant experience in supporting M&A integration projects preferred.
+ **Technical Expertise:**
+ Proficiency in directory services (e.g., Active Directory, Azure AD, LDAP).
+ Extensive knowledge and experience with authentication standards and technologies such as SSO (SAML, OAuth, OpenID Connect), MFA, and privileged access management (PAM).
+ Hands-on experience with leading IAM platforms (e.g., Okta, Microsoft Azure AD, CyberArk, ForgeRock, Ping Identity, SailPoint).
+ Experience with scripting languages (e.g., PowerShell, Python) for automation and integration.
+ Strong understanding of security principles, risk management, and access control models (e.g., RBAC).
+ Understanding of DevOps practices.
+ Familiarity with Zero Trust architecture principles.
+ Familiarity with AI/ML concepts and their practical application in security and risk management, especially in IAM context.
+ **M&A Specific Skills:** Proven track record of managing complex integration projects, including assessing existing IAM capabilities, workflow, systems, and processes of acquired entities. Ability to navigate the complexities of integrating diverse identity infrastructures.
+ Strong communication and interpersonal skills to collaborate effectively with various teams and stakeholders.
+ Detail-oriented mindset to ensure precise access control configurations and compliance.
+ Excellent problem-solving and analytical abilities to troubleshoot access issues and design solutions for unique business requirements
+ Must be a self-starter who takes full ownership of projects from inception to completion , holding oneself accountable for the security and operation integrity of IAM platform.
+ Ability to manage multiple priorities and meet tight deadlines in a fast-paced M&A environment.
+ Adaptability to stay ahead of evolving IAM technologies and security threats.
**Anticipated salary range:** $94,900 - $135,600
**Bonus eligible:** No
**Benefits:** Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
+ Medical, dental and vision coverage
+ Paid time off plan
+ Health savings account (HSA)
+ 401k savings plan
+ Access to wages before pay day with my FlexPay
+ Flexible spending accounts (FSAs)
+ Short- and long-term disability coverage
+ Work-Life resources
+ Paid parental leave
+ Healthy lifestyle programs
**Application window anticipated to close:** 12/20/2025 *if interested in opportunity, please submit application as soon as possible.
The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.
_Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply._
_Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal_ _Opportunity/Affirmative_ _Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law._
_To read and review this privacy notice click_ here (***************************************************************************************************************************
$94.9k-135.6k yearly 56d ago
Information Systems Security Engineer (ISSE)
Applied Research Solutions 3.4
Information security analyst job in Bedford, MA
ARS is seeking candidates to fill an ISSE Journeyman role located on Hanscom AFB in Bedford, Massachusetts.
The selected individual will be able to perform work that involves ensuring the confidentiality, integrity, and availability of systems, networks, and data through the planning, analysis, development, implementation, maintenance, and enhancement of information systems security programs, policies, procedures, and tools.
*ISAE II certification required. CISSP, CASP, CSSLP, CISSP-ISSEP, or CISSP-ISSAP preferred.
Why Work with us?
Applied Research Solutions (ARS) is respected as a world-class provider of technically integrated solutions as we deliver premier talent and technology across our focused markets for unparalleled, continuous mission support. Awarded a Best Places to Work nominee since 2020, ARS recognizes that without our career- driven, loyal professionals, we would not be able to deliver state-of-the-art results for our mission partners. We firmly believe that prioritizing our employees is of the upmost importance. We provide a culture where our employees are challenged to meet their career goals and aspirations, while still obtaining a work/life balance. ARS employees are motivated through our industry competitive benefits package, our awards and recognition program, and personalized attention from ARS Senior Managers.
Responsibilities include:
Supporting the system/application authorization and accreditation (A&A) effort, to include assessing and guiding the quality and completeness of A&A activities, tasks, and resulting artifacts mandated by governing DoD and Air Force policies (i.e., Risk Management Framework (RMF).
Recommending policies and procedures to ensure the reliability of and accessibility to information systems and to prevent and defend against unauthorized access to systems, networks, and data.
Conducting risk and vulnerability assessments of planned and installed information systems to identify vulnerabilities, risks, and protection needs.
Promoting awareness of security issues among management and ensuring sound security principles are reflected in organizations' visions and goals.
Conducting systems security evaluations, audits, and reviews.
Recommending systems security contingency plans and disaster recovery procedures.
Recommending and implementing programs to ensure that systems, network, and data users are aware of, understand, and adhere to systems security policies and procedures.
Participating in network and systems design to ensure implementation of appropriate systems security policies. • Facilitating the gathering, analysis, and preservation of evidence used in the prosecution of computer crimes.
Assessing security events to determine impact and implementing corrective actions.
Ensuring the rigorous application of informationsecurity/cybersecurity policies, principles, and practices in the delivery of all IT services.
Perform the Information System Security Engineer (ISSE) duties in an Information Assurance Workforce System Architecture and Engineering (IASAE) position as outlined in AFI 33-200, AFI 33-210 and AFMAN 33-285 for assigned systems.
Perform the Information System Security Manager (ISSM) duties as outlined in DoDI 8510.01 for assigned systems/applications.
Perform the Information System Security Officer (ISSO) duties as outlined in DoDI 8510.01 for assigned systems/applications.
Other duties as assigned.
Qualifications/Technical Experience Requirements:
Must be a US citizen
DoD 8570.01 MMGT512 compliant certification.
Experience with the Risk Management Framework (RMF).
ISAE II certification. CISSP, CASP, CSSLP, CISSP-ISSEP, or CISSP-ISSAP preferred.
Active Secret Security Clearance
The expected salary range: $155K -$165k. Salary is dependent upon the role and associated responsibilities, candidate's experience and qualifications to include education/training and key skills.
All positions at Applied Research Solutions are subject to background investigations. Employment is contingent upon successful completion of a background investigation including criminal history and identity check.
This contractor and subcontractor shall abide by the requirements of 41 CFR 60-741.5(a). This regulation prohibits discrimination against qualified individuals based on disability, and requires affirmative action by covered prime contractors and subcontractors to employ and advance in employment qualified individuals with disabilities.
This contractor and subcontractor shall abide by the requirements of 41 CFR 60-300.5(a). This regulation prohibits discrimination against qualified protected veterans, and requires affirmative action by covered contractors and subcontractors to employ and advance in employment qualified protected veterans.
$155k-165k yearly 60d+ ago
Systems Security Engineer
General Dynamics Mission Systems 4.9
Information security analyst job in Dedham, MA
Basic Qualifications
CLEARANCE REQUIREMENTS: Department of Defense Secret security clearance is required at time of hire. Applicants selected will be subject to a U.S. Government security investigation and must meet eligibility requirements for access to classified information. Due to the nature of work performed within our facilities, U.S. citizenship is required.
Responsibilities for this Position
We are seeking a Systems Security Engineer who has experience in the design and development of NSA-certified Cybersecurity devices.
Key Responsibilities:
Design and develop specifications for mission-critical NSA-certified Cybersecurity devices
Collaborate with software and validation engineering teams to deliver high-speed data solutions
Develop real-time multi-threaded Embedded System architecture using Model-based Systems Engineering (MBSE) tools and techniques
Analyze and maintain system security requirements throughout product development lifecycle
Conduct trade studies, perform functional analysis, and design system security.
Preferred Skills and Experiences:
NSA approved Cryptography/Encryption
Security requirements analysis
Real-Time multi-threaded Embedded System architecture and development
Model-based Systems Engineering (MBSE)
CISSP certification or similar
INCOSE ASEP, CSEP, or ESEP certification
We value candidates who possess:
Drive to expand knowledge and experience in designing complex systems
Ability to define project scope, schedule, and expected results
Initiative to complete assignments and ability to engage in technical direction and leadership
Our Commitment to You:
An exciting career path with opportunities for continuous learning and development
Research-oriented work with award-winning teams
Competitive benefits package
Salary Note This estimate represents the typical salary range for this position based on experience and other factors (geographic location, etc.). Actual pay may vary. This job posting will remain open until the position is filled. Combined Salary Range USD $100,219.00 - USD $111,180.00 /Yr. Company Overview
General Dynamics Mission Systems (GDMS) engineers a diverse portfolio of high technology solutions, products and services that enable customers to successfully execute missions across all domains of operation. With a global team of 12,000+ top professionals, we partner with the best in industry to expand the bounds of innovation in the defense and scientific arenas. Given the nature of our work and who we are, we value trust, honesty, alignment and transparency. We offer highly competitive benefits and pride ourselves in being a great place to work with a shared sense of purpose. You will also enjoy a flexible work environment where contributions are recognized and rewarded. If who we are and what we do resonates with you, we invite you to join our high-performance team!
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
$100.2k-111.2k yearly Auto-Apply 60d+ ago
Engineer, Information Security and Risk
Cardinal Health 4.4
Information security analyst job in Hartford, CT
Cardinal Health, Inc. (NYSE: CAH) is a global healthcare services and products company. We provide customized solutions for hospitals, healthcare systems, pharmacies, ambulatory surgery centers, clinical laboratories, physician offices and patients in the home. We are a distributor of pharmaceuticals and specialty products; a global manufacturer and distributor of medical and laboratory products; an operator of nuclear pharmacies and manufacturing facilities; and a provider of performance and data solutions. Working to be healthcare's most trusted partner, our customer-centric focus drives continuous improvement and leads to innovative solutions that improve the lives of people every day. With approximately 50,000 employees worldwide, Cardinal Health ranks among the top fifteen in the Fortune 500.
**_Department Overview:_**
**Information Technology** oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value.
**InformationSecurity and Risk** develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure, or destruction. This job family develops system back-up and disaster recovery plans, conducts incident responses, threat management, vulnerability scanning, virus management and intrusion detection as well as completes risk assessments.
**Responsibilities:**
+ **M&A Integration Execution:** Collaborate and engage with IAM Lead and other business partners on planning, design, and execution of IAM integration strategies for M&A activities, ensuring alignment with overall business and security objectives. This includes assessing the IAM landscapes of merging entities to identify challenges and solutions.
+ **Design and Implement Sailpoint IIQ Solutions:** Configure and customize Sailpoint IIQ components (Lifecycel Manager, Compliance Manager etc). Also develop workflows, rules, and connectors for identity governance.
+ **Application integration with Sailpoint IIQ:** Integrate Sailpoint IIQ with enterprise applications, directories and cloud platforms in addition to developing and maintaining connectros for provisioning and de-provisioning.
+ **Sailpoint IIQ Development and Scripting:** Write and maintain BeanShell scripts, Java code and XML configurations, develop customer Sailpoint tasks and workflows.
+ **Identity System Merging & Consolidation:** Manage the complex process of merging disparate identity providers, user directories (e.g., Active Directory, Azure AD, LDAP), and access management systems from acquired companies into the existing infrastructure.
+ **User Lifecycle Management:** Streamline and automate user provisioning, de-provisioning, and periodic access reviews for employees, contractors, and partners across all integrated systems, ensuring smooth onboarding and offboarding during M&A transitions.
+ **Security & Compliance:** Ensure IAM systems and processes comply with regulatory requirements (e.g., GDPR, HIPAA, SOX) and internal security policies, providing auditable records of access activities. Protect against data breaches by ensuring only authorized personnel can access sensitive information.
+ **Technical Troubleshooting & Support:** Troubleshoot, identify, and resolve technical identity and access management-related issues, providing expert support to internal teams and end-users during and after integration.
+ **Collaboration & Communication:** Coordinate cross-functional teams, including InformationSecurity, IT Operations, HR, and Application Development, to ensure effective IAM implementation and seamless integration with business processes. Communicate complex security concepts to technical and non-technical stakeholders.
+ **Documentation & Best Practices:** Develop, review, and maintain comprehensive technical documentation, including architecture diagrams, configuration guides, and operational procedures. Stay up-to-date with IAM best practices, regulatory requirements, and security trends.
**Qualifications**
+ Experience with SailPoint IdentityIQ (IIQ) is a must
+ Experience with SailPoint IIQ Integrations (Workday, Active Directory/LDAP, Webservices, SCIM, JDBC, SAP)
+ Experience implementing Life Cycle Manager (LCM) Configuration workflow tasks that model business functions, including Lifecycle Requests (Role or Entitlement), Lifecycle Events (Joiner, Mover, or Leaver), and LCM Workflow Details (Workflows and Subprocesses)
+ Solid understanding of the SailPoint object model, rules, and policies
+ Experience with both lifecycle manager (LCM) and compliance manager (CM) modules
+ Knowledge of Active Directory, LDAP, Workday, and cloud platforms (GCP, MS Entra ID) is required
+ Proven track record of successful IAM implementations including large scale enterprise deployments.
+ Experience working within regulatory standards and requirements such as, SOX, HIPAA, GDPR etc. is desired.
**Anticipated salary range:** $94,900 - $135,600
**Bonus eligible:** No
**Benefits:** Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
+ Medical, dental and vision coverage
+ Paid time off plan
+ Health savings account (HSA)
+ 401k savings plan
+ Access to wages before pay day with my FlexPay
+ Flexible spending accounts (FSAs)
+ Short- and long-term disability coverage
+ Work-Life resources
+ Paid parental leave
+ Healthy lifestyle programs
**Application window anticipated to close:** 12/20/2025 *if interested in opportunity, please submit application as soon as possible.
The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.
_Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply._
_Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal_ _Opportunity/Affirmative_ _Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law._
_To read and review this privacy notice click_ here (***************************************************************************************************************************
$94.9k-135.6k yearly 56d ago
Learn more about information security analyst jobs
How much does an information security analyst earn in Charlton, MA?
The average information security analyst in Charlton, MA earns between $73,000 and $142,000 annually. This compares to the national average information security analyst range of $71,000 to $135,000.
Average information security analyst salary in Charlton, MA