A leading entertainment and media enterprise is seeking a Senior Software Engineer to enhance cybersecurity efforts. The role involves designing internal tools, managing security frameworks, and collaborating with compliance teams. Candidates should possess at least 5 years of software development experience, knowledge in DevSecOps, and familiarity with cloud technologies. This position is integral to securinginformation systems across various Disney platforms, supporting innovative consumer experiences and operational excellence.
#J-18808-Ljbffr
$149k-229k yearly est. 3d ago
Looking for a job?
Let Zippia find it for you.
Lead AI Security Engineer
Capital Group 4.4
Information security analyst job in Irvine, CA
"I can be myself at work."
You are more than a job title. We want you to feel comfortable doing great work and bringing your best, authentic self to everything you do. We value your talents, traditions, and uniqueness-and we're committed to fostering a strong sense of belonging in a respectful workplace.
We intentionally seek diverse perspectives, experiences, and backgrounds, investing in a culture designed to celebrate differences. We believe that belonging leads to better outcomes and a stronger community of associates united by our mission. At Capital, we live our core values every day: Integrity, Client Focus, Diverse Perspectives, Long-Term Thinking, and Community.
"I can influence my income."
You want to feel recognized at work. Your performance will be reviewed annually, and your compensation will be designed to motivate and reward the value that you provide. You'll receive a competitive salary, bonuses and benefits. Your company-funded retirement contribution will factor in salary and variable pay, including bonuses.
"I can lead a full life."
You bring unique goals and interests to your job and your life. Whether you're raising a family, you're passionate about where you volunteer, or you want to explore different career paths, we'll give you the resources that can set you up for success.
Enjoy generous time-away and health benefits from day one, with the opportunity for flexible work options
Receive 2-for-1 matching gifts for your charitable contributions and the opportunity to secure annual grants for the organizations you love
Access on-demand professional development resources that allow you to hone existing skills and learn new ones
"I can succeed as a Lead AI Security Engineer at Capital Group"
As aLeadAISecurity Engineer, you willbe responsible forsecuring Capital Group's enterprise AI Platforms.You willhelp enable Capital Group's AIstrategy bybuilding and/orprocuringsolutions toprotecta diverse set of enterprise AI platforms being built and deployed at Capital Group.You'llcollaborate with platformengineering, security engineering, and risk teams toensure their solutions support scalable, secureadoption of AI.
Additionally,you'llbe expected toprovidementoring,advising diverse teams across the organization, andpromoting AI Securityprinciples across Capital Group.
AISecurityProcurementManagements:You willprocureand/or build technical solutionsto reducethe riskof misconfiguration, exploitation, andother security issues formultipleenterprise AI platforms.
Embedding Security in the AIPlatform Ecosystem:Working closely withplatform teams tointegrate securityintoeverycomponentof the AI Platform.
Implementing Security Controls & "Guardrails" for GenAI:Designing, deploying, andoperatingtechnical controls to prevent misuse of AI systems.Guardrails designincludescontent filtering systems, usage policies, and safety checks that mitigate issues like prompt injection attacks, unauthorized data extraction, model bias or hallucinations, and other misuse of generative AIplatforms.
AI Runtime Security:Engineer continually tests and updatestothe guardrails, replacing weaker controls with more robust solutions as threats evolve.
AI Governance:You will work cross functionally with architecture and platform teams tomonitoralignment of solutions to AI Governance processes
Contribute to Standards and Policies:You will providethought leadership for InformationSecurity policies and standards for AIin collaboration with technology risk
AI/Agent SME:Youwill provide AI/Agent subject matterexpertisefor AI Incidentsand Security Reviews, and helpdevelop incident response playbooks for AI-related security incidents
"I am the person Capital Group is looking for."
You have 8+yearsof experience in informationsecurity, application security, platform security, or penetration testing,DevSecOps, networksecurityand other security disciplines.
You have experience securing AI platforms, whetherinternal AIplatforms or offerings such as CoPilot Studio, Amazon Bedrock, and/or Azure AI Gateway
Proficient in Programming & ML Tool.Strong Python skillsrequired, with experience in AI/ML frameworks.Abilityto review and write ML code to implement security measures (e.g., model validation, adversarial testing) isdesired.
You have5+ years of relevant professional experience ordemonstrated anequivalent level ofexpertisein security engineering, such as cloud, API, or platform security.
You have3+ years of experience embedded identity, network, and encryption controls into enterprise platforms
Youcaneffectively partner and collaborate with stakeholder teams.
You have effective communication skills andthe abilityto outline security riskstoleadership.
You are familiar with cloud and API security vendors and managed services providers.
Preferred Qualifications:
You have knowledge and experience with technologies including Kubernetes, Containers, CI/CD, and Cloud Service Providers
You are familiar withfunctionand purpose of key AI platform components such as AI gateways (Kong, Databricks Mosaic AI Gateway, custom API orchestration), Model Orchestration (ExamplesLangChain,LlamaIndex, etc.)
You are familiar with key AI regulatory frameworks such as NIST AI RMF, MITRE ATLAS, GDPR, EU AI Act,etc
You have informationSecurity certifications (CISSP, SANS GIAC, CISA, etc.)
"I can apply in less than 4 minutes."
You've reviewed this job posting and you're ready to start the candidate journey with us. Apply now to move to the next step in our recruiting process. If this role isn't what you're looking for, check out our other opportunities and join our talent community.
"I can learn more about Capital Group."
At Capital Group, the success of the people who invest with us depends on the people in whom we invest. That's why we offer a culture, compensation and opportunities that empower our associates to build successful and prosperous careers. Through nine decades, our goal has been to improve people's lives through successful investing. We know that our history is a testament to the strength of the people we hire. More than 9,000 associates in 30+ offices around the world help our clients and each other grow and thrive every day. Find us on LinkedIn, Instagram, YouTube and Glassdoor.
Southern California Base Salary Range: $179,273-$286,837San Antonio Base Salary Range: $147,378-$235,805New York Base Salary Range: $190,040-$304,064
In addition to a highly competitive base salary, per plan guidelines, restrictions and vesting requirements, you also will be eligible for an individual annual performance bonus, plus Capital's annual profitability bonus plus a retirement plan where Capital contributes 15% of your eligible earnings.
You can learn more about our compensation and benefits
here
.
* Temporary positions in the United States are excluded from the above mentioned compensation and benefit plans.
We are an equal opportunity employer, which means we comply with all federal, state and local laws that prohibit discrimination when making all decisions about employment. As equal opportunity employers, our policies prohibit unlawful discrimination on the basis of race, religion, color, national origin, ancestry, sex (including gender and gender identity), pregnancy, childbirth and related medical conditions, age, physical or mental disability, medical condition, genetic information, marital status, sexual orientation, citizenship status, AIDS/HIV status, political activities or affiliations, military or veteran status, status as a victim of domestic violence, assault or stalking or any other characteristic protected by federal, state or local law.
$190k-304.1k yearly 2d ago
Information Security Analyst
Cathay Bank-Headquarters 4.4
Information security analyst job in Rancho Cucamonga, CA
People Drive Our Success Are you enthusiastic, highly motivated, and have a strong work ethic? If yes, come join our team! At Cathay Bank - we strive to provide a caring culture that supports your aspirations and success. We believe people are our most valuable asset and we proudly foster growth and development empowering you to achieve your professional goals. We have thrived for 60 years and persevered through many economic cycles due to our team members' drive and optimism. Together we can make a difference in the financial future of our communities.
Apply today!
What our team members are saying:
Video Clip 1
Video Clip 2
Video Clip 3
Learn more about us at cathaybank.com
GENERAL SUMMARY
This position is responsible for ensuring that the Bank's Security operations and preventive controls are managed and maintained in accordance with established InformationSecurity policies, standards and procedures, published regulations and industry best practices.
Primarily responsible for the constant review of vendor security controls in comparison with policies and industry frameworks, risk assessments, determination of control gaps and their remediation.
ESSENTIAL FUNCTIONS
Performs vendor security risk assessments to determine inherent risk on proposed projects and assesses vendor security controls to determine residual risk.
Evaluates the potential exposure to application security risks and threats based on industry security frameworks and recommends appropriate mitigation.
Assesses security practices including InformationSecurity governance, Identity and access control, Incident monitoring and response, Vulnerability assessment and Penetration tests, Network Security and Endpoint Security, among others.
Acts as liaison with Third Party Risk Management, Information Technology and business department Relationship Managers related to vendor risk assessments.
Reports informationsecurity risks and follows-up remediations.
Remediates audit and regulatory findings and recommendations related to InformationSecurity and Vendor Risk Management.
QUALIFICATIONS
Education:
College degree in Information Technology or InformationSecurity or equivalent;
Security+, SSCP, CISSP, CISM or similar informationsecurity certifications preferred.
Experience:
Minimum two years of experience in InformationSecurity Risk, InformationSecurity Operations or Security Auditing.
Proven experience on third-party risk management and vendor security assessments.
Working knowledge of security practices such as Endpoint Security, Network Security, Security Operations and Security Governance required.
Experience working with Vendor Risk Management (VRM) applications preferred.
Skills/Ability:
Proven ability to initiate and manage projects.
Excellent communication and problem-solving skills.
Strong inter-personal communication and collaboration skills.
Self-starter, highly motivated, and able to work with general supervision.
OTHER DETAILS
$28.84 - $33.65 / hour
Pay determined based on job-related knowledge, skills, experience, and location.
This position may be eligible for a discretionary bonus.
Cathay Bank offers its full-time employees a competitive benefits package which is a significant part of their total compensation. It is our goal to provide employees with a comprehensive benefits package to fit their needs which includes, coverage for medical insurance, dental insurance, vision insurance, life insurance, long-term disability insurance, and flexible spending accounts (FSAs), health saving account (HSA) with company contributions, voluntary coverages, and 401(k).
Cathay Bank may collect personal information from potential job candidates and applicants. For more information on how we handle personal information and your applicable rights, please review our Privacy Policy.
Cathay Bank is an Equal Opportunity and Affirmative Action Employer. We welcome applications for employment from all qualified candidates, regardless of race, color, ethnicity, ancestry, citizenship, gender, national origin, religion, age, sex (including pregnancy and related medical conditions, childbirth and breastfeeding), reproductive health decision-making, sexual orientation, gender identity and expression, genetic information or characteristics, disability or medical condition, military status or status as a protected veteran, or any other status protected by applicable law.
Click here to view the "Know Your Rights: Workplace Discrimination is Illegal" Poster:
Poster- English
Poster- Spanish
Poster- Chinese Traditional
Poster- Chinese Simplified
Cathay Bank endeavors to make **************************** to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact, Mickey Hsu, FVP, Employee Relations Manager, at or . This contact information is for accommodation requests only and cannot be used to inquire about the status of applications.
$28.8-33.7 hourly 2d ago
Information Security Analyst II
Mach Industries 4.5
Information security analyst job in Huntington Beach, CA
Founded in 2022, Mach Industries is a rapidly growing defense technology company focused on developing next-generation autonomous defense platforms. At the core of our mission is the commitment to delivering scalable, decentralized defense systems that enhance the strategic capabilities of the United States and its allies. With a workforce of approximately 220 employees, we operate with startup agility and ambition.
Our vision is to redefine the future of warfare through cutting-edge manufacturing, innovation at speed, and unwavering focus on national security. We are dedicated to solving the next generation of warfare with lethal systems that deter kinetic conflict and protect global security.
The Role
We're seeking an InformationSecurityAnalyst II to drive our efforts to build, maintain, and continuously improve our security and compliance posture across the breadth of our network infrastructure, facilities, and endpoints. You'll continuously collaborate with cross-functional teams, including IT, physical security, product security, GRC, software development, operations, engineering, manufacturing, and legal, to ensure our informationsecurity programs exceed both technical and regulatory standards.
The ideal candidate has a cybersecurity background with hands-on expertise in network security tools and cloud environments, particularly within regulated and compliance-heavy programs. You are familiar with NIST SP 800-171, CMMC, DFARS, ATO authorization workflows, and/or ISO 27001, and you can translate these requirements into practical, auditable security controls that support mission and compliance objectives.
Key Responsibilities
* Monitor, triage, and investigate security alerts from SIEM, EDR/XDR, IDS/IPS, and other detection tools.
* Respond to security incidents (phishing, malware, unauthorized access, data loss events), perform root cause analysis, and document findings.
* Create and refine alert logic, detections, and security playbooks to improve response efficiency.
* Conduct vulnerability scans, validate findings, prioritize remediation, and track closure.
* Support patch management and secure configuration baselines in partnership with IT and infrastructure teams.
* Assist in threat modeling, security assessments, and identifying systemic weaknesses.
* Support security controls testing and evidence gathering for audits (SOC 2, ISO 27001, NIST, ATO, CMMC, as applicable).
* Maintain and improve security policies, standards, and procedures.
* Contribute to risk assessments and third-party/vendor risk reviews.
* Help build security awareness initiatives such as phishing simulation programs and secure behavior training.
* Provide guidance to internal teams on secure processes and best practices.
* Participate in security projects such as MFA rollouts, IAM improvements, cloud security hardening, logging standardization, etc.
* Assist with access reviews, permissions validation, and identity lifecycle processes.
* Partner with engineering and IT to enhance security architecture and controls.
Required Qualifications
* 3-5 years of experience in informationsecurity, security operations, or a related technical security role.
* Experience working with security tooling (examples: SIEM like Splunk/Elsastic/Sentinel, EDR like CrowdStrike/MDE, vulnerability tools like Tenable/Qualys).
* Familiarity with incident response processes and frameworks (NIST, SANS).
* Strong understanding of common attack techniques and defensive strategies (MITRE ATT&CK).
* Ability to analyze logs, network traffic, and endpoint activity to investigate suspicious behavior.
* Strong written and verbal communication skills, with the ability to write clear incident reports and recommendations.
Preferred Qualifications
* Security certifications (one or more preferred): Security+, GSEC, SSCP, CySA+, CEH, CISSP (Associate), Splunk certification, Microsoft security certifications, etc.
* Experience with cloud security (AWS / Azure / GCP), including logging and access control best practices.
* Familiarity with security automation/SOAR, scripting (Python, PowerShell), or query languages (KQL, SPL).
* Experience supporting compliance frameworks (SOC 2, ISO 27001, NIST 800-53).
* Strong understanding of identity and access management, network segmentation, and endpoint hardening.
Disclosures
This position may require access to information protected under U.S. export control laws and regulations, including the Export Administration Regulations (EAR) and the International Traffic in Arms Regulations (ITAR). Please note that any offer for employment may be conditioned on authorization to receive software or technology controlled under these U.S. export control laws and regulations without sponsorship for an export license.
Mach participates in E-Verify and will provide the federal government with your Form I-9 information to confirm that you are authorized to work in the U.S.
The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary offers may vary based on (but not limited to) work experience, education and training, critical skills, and business considerations. Highly competitive equity grants are included in most offers and are considered part of Mach's total compensation package. Mach offers benefits such as health insurance, retirement plans, and opportunities for professional development.
Mach is an equal opportunity employer committed to creating a diverse and inclusive workplace. All qualified applicants will be treated with respect and receive equal consideration for employment without regard to race, color, creed, religion, sex, gender identity, sexual orientation, national origin, disability, uniform service, Veteran status, age, or any other protected characteristic per federal, state, or local law, including those with a criminal history, in a manner consistent with the requirements of applicable state and local laws. If you'd like to defend the American way of life, please reach out!
$95k-134k yearly est. 3d ago
Information Security Analyst- INTL Brazil
Insight Global
Information security analyst job in Los Alamitos, CA
The InformationSecurityAnalyst will be tasked with monitoring and identifying organizational security risks, detecting attack methods and sources, and preserving electronic evidence when required. This role requires expertise in analyzing, recommending, designing, implementing, and maintaining systems and processes that safeguard business and client data. Core responsibilities include conducting risk assessments, performing security analyses, and creating remediation strategies. The individual should be capable of working independently while contributing to security programs as part of the incident response team. Strong written communication skills are essential for preparing formal reports. Professional fluency in English and Portuguese is required. This is an onsite position in Brazil, five days per week, offered as a 6-12 month contract with potential for extension or conversion to a full-time role.
Responsibilities but not limited to:
- IT Security Administration: Focus on minimizing downtime and ensuring scalability by addressing security risks across systems and networks.
- Application Security Alignment: Guarantee that security architecture, designs, plans, controls, and policies comply with IT standards and overall security requirements.
- Documentation: Develop and maintain detailed records for all security systems and networks, updating documentation whenever changes occur.
- Project Participation: Contribute to initiatives and projects centered on informationsecurity.
- Program Support: Assist with implementing, maintaining, and monitoring the informationsecurity program, including gap analysis, risk assessments, third-party evaluations, procedure development, recurring processes, and incident response.
- Solution Deployment: Handle integration, initial configuration, and upgrades of new and existing security solutions following industry best practices.
- Operating Systems Expertise: Demonstrate advanced knowledge of Linux, Windows, and OS X environments.
- Cloud Security: Apply experience in securing cloud infrastructures such as AWS and Azure.
- Vulnerability Management: Lead efforts to identify and remediate security weaknesses in networks and systems, providing technical guidance and support.
- Policy Development: Create, implement, and maintain internal procedures to safeguard data and manage incident response effectively.
- Collaboration: Work with project teams and system architects to design secure systems and project plans that meet established security standards.
- Threat Awareness: Stay informed on current and emerging security threats and design architectures to mitigate potential risks.
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to ********************.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: ****************************************************
Skills and Requirements
· Knowledge with Security solutions: SIEM, IAM, PAM, EDR/XDR, CSAM, CASB, Proxies, ZTNA
· Solid security understanding with Microsoft security controls (AD, Entra, O365, Intune MDM, etc)
· Minimum 7+ years of experience in information technology security or equivalent combination of education and experience
· Security+, CISSP, CISA or SANS GIAC certification
· Understanding of application, network, operating system, and core infrastructure security concepts.
· Knowledge on security monitoring tools such as UTM, IPS, IDS and other security appliances
· Project management, organizational and prioritizing skills
· Understanding of WAN, MPLS, and technologies such as VoIP beneficial
· Working knowledge of common information technology management frameworks such as ISO/IEC 27001, ITIL, COBIT, and NIST
$89k-131k yearly est. 37d ago
Sr. Information Security Engineer
Alignment Healthcare 4.7
Information security analyst job in Orange, CA
Sr. InformationSecurity Engineer
External Description:
Alignment Healthcare is a data and technology driven healthcare company focused on partnering with health systems, health plans and provider groups to provide care delivery that is preventative, convenient, coordinated, and that results in improved clinical outcomes for seniors.
We are experiencing rapid growth (backed by top private equity firms), and our team is looking for the best and brightest individuals. We love our customers and understanding them better makes it possible to provide the best clinical outcomes and care experience.
Are you an InformationSecurity Engineer with experience in automation, cloud technologies, and endpoint security? Would you like to work in an environment where your skills can be utilized effectively, and you have opportunities to make significant impact? If you are passionate about security and can reduce risk in practical ways that scale, we want to hear from you!
Major Responsibilities
Contributes to the daily operational aspects of the InformationSecurity Team, primarily from a technical implementation perspective.
Assists with break/fix of tools and automation that are owned by the InformationSecurity Team.
Works with internal and external customers on a variety of issues, from a simple security review of a mundane and routine ask, to a complex deep dive into a new feature implementation in O365, Azure, or AWS.
Balances operational work (approximately 70% of the day) to help meet team SLAs, and project work (approximately 30% of the day) to meet assigned team deliverables.
Contributes to the design, implementation, and documentation of new security tools.
Collaborates with other internal information technology teams (networking, cloud, traditional architecture, developers, and data scientists) to support internal and external systems.
Utilizes scripting and DevOps to provide automation and orchestration between:
informationsecurity tools, such as the SIEM (Logstash, FortiSIEM, IBM QRadar, etc.);
endpoint protection (Symantec, McAfee, Cylance, CrowdStrike Falcon, etc.);
vulnerability scanners (Rapid7, Nessus, etc.);
patch management (SCCM, Altiris, PDQ, etc.);
other applications;
OS' (Windows, MacOS, Linux, iOS, Android);
cloud platforms (AWS, Azure); and
IAM platforms (Active Directory, Okta, Auth0, PingIdentity, SAML, OIDC).
Clearly documents designed automation and system relationships.
Contributes and participates in the InformationSecurity Team daily stand-ups and other meetings as necessary.
Participates in regular reporting, maintaining accountability and transparency within the InformationSecurity Team.
Remains current on industry trends in cyber risk with industry standards (ISO 27001/2, NIST, CIS) and regulatory requirements (HIPAA, HITECH, HITRUST, etc.)
Technical knowledge of common informationsecurity tools and systems: DLP, MAM/MDM, Firewall/VPN, endpoint protection, PKI, RBAC, IAM, etc.
Demonstrated practical experience with one or more programming or scripting languages. (PowerShell, Python, C#, VB, VBA, Ruby, NodeJS, SQL, etc.) We're not picky, but you must be able to deliver practical automation!
Demonstrated practical experience with one or more of the major cloud providers (AWS, Azure, GCP).
Excellent oral and written communication skills, and an ability to present and discuss technical information in a way that establishes rapport and trust.
Detail orientated, with an ability and desire to build to 100%, but being ok with building to 90% as tasked.
An ability to be productive as an individual contributor with little supervision to meet agreed upon deliverables.
Preferred
Prior experience in the healthcare or a related HIPAA regulated industry.
A working knowledge of the NIST CSF and/or CIS Critical Security Controls (CSC).
A working knowledge of Git and GitHub.
Previous experience contributing to projects using agile tools (Jira, Azure DevOps, Pivotal) and processes (Scrum, Kanban).
One or more cloud security certifications.
Education
Bachelor's degree in Computer Science, Computer Engineering, or related technical discipline, and/or equivalent work experience.
3+ years' experience working in a technical, hands-on, informationsecurity role.
One or more current security related certifications (e.g., CISSP, SANS GIAC, etc.)
City: Orange
State: California
Location City: Orange
Schedule: Full Time
Location State: California
Community / Marketing Title: Sr. InformationSecurity Engineer
Company Profile:
Alignment Healthcare was founded with a mission to revolutionize health care with a serving heart culture. Through its unique integrated care delivery models, deep physician partnerships and use of proprietary technologies, Alignment is committed to transforming health care one person at a time.
By becoming a part of the Alignment Healthcare team, you will provide members with the quality of care they truly need and deserve. We believe that great work comes from people who are inspired to be their best. We have built a team of talented and experienced people who are passionate about transforming the lives of the seniors we serve. In this fast-growing company, you will find ample room for growth and innovation alongside the Alignment community.
EEO Employer Verbiage:
On August 17, 2021, Alignment implemented a policy requiring all new hires to receive the COVID-19 vaccine. Proof of vaccination will be required as a condition of employment subject to applicable laws concerning exemptions/accommodations. This policy is part of Alignment's ongoing efforts to ensure the safety and well-being of our staff and community, and to support public health efforts. Alignment Healthcare, LLC is proud to practice Equal Employment Opportunity and Affirmative Action. We are looking for diversity in qualified candidates for employment: Minority/Female/Disable/Protected Veteran. If you require any reasonable accommodation under the Americans with Disabilities Act (ADA) in completing the online application, interviewing, completing any pre-employment testing or otherwise participating in the employee selection process, please contact ******************.
$125k-156k yearly est. Easy Apply 60d+ ago
Information Security Analyst
Vesync
Information security analyst job in Tustin, CA
The Company: VeSync is a portfolio company with brands that cover different categories of health & wellness products. We wouldn't be surprised if you have one of our Levoit air purifiers in your living room or a COSORI air fryer whipping up healthy and delicious meals for you every night.
We're a young and energetic company, we've had tremendous success, and we are constantly growing our team. As we garner more industry attention - just check out our accomplishments and awards by CES Innovation, iF Design, IGA, and Red Dot - we also need driven and talented people to join our team.
That brings us to you, and what you'll be joining. Our teams are smart and diligent and take ownership of their work - they're confident in their work but know how to collaborate with open ears and a spirit of learning. If you're down-to-earth, approachable, and easy to strike up a conversation with, this may be a great fit for you.
Check out our brands:levoit.com | cosori.com | etekcity.com
The Opportunity:
The InformationSecurityAnalyst is responsible for supporting the organization's security posture by implementing, monitoring, and maintaining security controls across systems, networks, and cloud environments. This role works closely with senior security team members to identify risks, respond to incidents, and ensure compliance with security standards and regulatory requirements.What you will do at VeSync:
InformationSecurity Operations & Planning
Support the implementation and maintenance of informationsecurity controls to protect company data and assets across on-premise and cloud environments.
Assist in analyzing business processes, systems, and data flows to identify security gaps and improvement opportunities.
Apply industry best practices and frameworks such as the NIST Cybersecurity Framework (CSF) to support confidentiality, integrity, and availability of information assets.
Policy Support & Compliance
Assist in the development, implementation, and maintenance of informationsecurity policies, standards, and procedures.
Support compliance efforts with industry standards and regulations (e.g., ISO 27001, NIST, GDPR).
Help track evidence and controls using compliance and GRC tools such as OneTrust, Drata, or similar platforms.
Monitor regulatory and security trends and escalate relevant changes to senior team members.
System, Network, and Cloud Security
Monitor and help maintain security controls for systems, networks, and public cloud platforms (AWS, Azure, GCP).
Assist with configuration, monitoring, and tuning of cloud security services and tools.
Use security tools and dashboards (e.g., SIEM, security scorecards) to identify potential threats and vulnerabilities.
Support AWS security services and baseline configurations.
Security Monitoring & Incident Response
Monitor security alerts and events using SIEM and security monitoring tools.
Participate in incident response activities, including investigation, containment, remediation, and post-incident analysis.
Assist with blue team activities, tabletop exercises, and response drills to improve readiness.
Document incidents and lessons learned.
Identity & Access Management
Support user access reviews, permission audits, and access control processes.
Assist with identity management systems to ensure appropriate authentication and authorization controls.
Help identify and remediate excessive or inappropriate access.
Risk Assessment & Vulnerability Management
Participate in risk assessments and vulnerability identification efforts.
Assist with vulnerability scanning, tracking, and remediation coordination.
Support risk documentation and reporting aligned with frameworks such as NIST CSF.
Help track and report basic security metrics and KPIs.
Security Awareness & Documentation
Support the delivery of security awareness training and phishing simulations.
Assist in developing security documentation, including procedures, controls, detection rules, and response playbooks.
Maintain clear and accurate security documentation for audits and operational use.
What you bring to the role:
Bachelor's degree in InformationSecurity, Computer Science, or a related field (or equivalent experience).
3-6 years of experience in informationsecurity or a related IT/security role.
Hands-on experience with security monitoring, incident response, vulnerability management, or risk assessment.
Familiarity with cloud environments (AWS, Azure, or GCP) and basic cloud security concepts.
Working knowledge of security frameworks and standards such as NIST CSF, ISO 27001, and CIS.
Understanding of network security fundamentals, including firewalls, IDS/IPS, endpoint protection, and logging.
Experience with SIEM or security monitoring tools such as Splunk, QRadar, Rapid7, or Wazuh.
Strong analytical, troubleshooting, and communication skills.
Preferred Qualifications
Experience supporting compliance or audit activities.
Familiarity with GRC or compliance automation tools (OneTrust, Drata, or similar).
Relevant security certifications such as Security+, CEH, GSEC, or progress toward CISSP/CISM.
Location:
This is an on-site, office-based role in Tustin, CA.
Salary:
Starting at $90K Annually
Perks and Benefits:
100% covered Medical/Dental/Vision insurance for employee AND spouse + dependents!
401K with 4% employer match (eligible after 90 days of employment) and immediate 100% vesting
Generous PTO policy + paid holidays
Life Insurance
Voluntary Life Insurance
Disability Insurance
Critical Illness Coverage
Accident Insurance
Healthcare FSA
Dependent Care FSA
Travel Assistance Program
Employee Assistance Program (EAP)
Fully stocked kitchen
$90k yearly Auto-Apply 1d ago
Global Chief Information Security Officer (CISO)
Security Director In San Diego, California
Information security analyst job in Irvine, CA
Allied Universal , North America's leading security and facility services company, offers rewarding careers that provide you a sense of purpose. While working in a dynamic, welcoming, and collaborative workplace, you will be part of a team that contributes to a culture that positively impacts the communities and customers we serve.
Job Description
Allied Universal is hiring a Global Chief InformationSecurity Officer (CISO). The Global Chief InformationSecurity Officer (GCISO) will lead Allied Universal's global cybersecurity strategy and operations, serving as the single accountable executive for cybersecurity across all of Allied Universal's global operations, responsible for protecting the company's people, systems, and data. Allied Universal is the 3
rd
largest employer in North America and the 7th largest employer in the world, with approximately 800,000 employees in more than 100 countries and territories.
This role is responsible for defining, implementing, and maintaining a comprehensive, risk-based cybersecurity program designed to protect Allied Universal's assets and technology platforms against evolving threats. The GCISO must be both a strategic leader and a hands-on practitioner capable of translating complex technical risks into business terms, fostering a culture of cybersecurity accountability throughout the organization, and directly engaging in key operational, investigative, and incident-response activities when necessary.
The GCISO reports directly to the Global General Counsel to ensure independent oversight and transparency to executive leadership and the Board, with a dotted-line reporting relationship to the Chief Technology Officer for alignment with technology architecture, strategy, and operations. The GCISO directly manages Regional Cybersecurity Leaders, who implement global standards and maintain local readiness while partnering closely with Regional Chief Information Officers (CIOs) to integrate cybersecurity requirements into regional IT operations and project delivery. The GCISO will operate out of our headquarters in Irvine, CA.
RESPONSIBILITIES:
Strategic Leadership:
Develop and execute a global, risk-based cybersecurity strategy and program aligned with Allied Universal's business objectives
Establish, communicate, and oversee governance of enterprise-wide cybersecurity policies, standards, and controls that are appropriate for the company's diverse global operations
Lead, mentor and manage Regional Cybersecurity Leaders to promote consistency, accountability, and operational effectiveness across all regions
Define and monitor key risk indicators, cybersecurity metrics, and maturity objectives to inform executive decision-making and drive ongoing program improvement
Oversee global monitoring, detection, and response capabilities that provide 24×7 visibility into potential cyber risks and support timely containment activities
Identify and assess emerging threats, technologies, and vulnerabilities to support informed planning and risk mitigation efforts
Provide recommendations regarding cybersecurity investments and resource allocation, helping prioritize efforts based on risk, business impact, and value
Collaboration and Stakeholder Engagement:
Foster a culture of cybersecurity awareness, ownership, and accountability across all functions and geographies
Coordinate, develop, and implement programs designed to train Allied Universal's workforce regarding the company's cybersecurity requirements, including applicable cybersecurity laws and requirements and responding to evolving cybersecurity threats
Risk Management:
Evaluate emerging threats and vulnerabilities, driving continuous improvement of the company's cybersecurity posture as appropriate
Direct recurring global cybersecurity risk assessments; oversee associated cybersecurity risk management activities, including maintenance of a risk register, remediation tracking, and risk decisions
Oversee periodic internal and external cybersecurity audits to verify adherence to policies, standards and regulatory requirements
Report promptly on cybersecurity risks to relevant Allied Universal Leadership upon identifying risks that exceed tolerance levels
Compliance:
Support compliance with regulatory requirements as well as any Allied Universal and customer contractual obligations for cyber security
Remain current and knowledgeable regarding applicable cybersecurity laws and regulations, including laws and regulations applicable to government contractors
Lead on various external cybersecurity initiatives, including compliance for protecting sensitive data such as responding to regulators and customer audits
Incident Response:
Direct and continuously improve the enterprise incident-response program, including playbooks, tabletop exercises, and post-incident reviews
Lead cross-functional coordination with Legal, Technology, Operations, and Regional CIOs to contain and recover from major cyber incidents
Oversee specialized incident-response and investigative resources for critical events
Provide timely updates to the CEO, Global General Counsel, and Board on incident status, impact, and remediation progress
Assessments and Audits:
Review and assess the effective deployment of cybersecurity technologies, tools and software by Allied Universal, third parties, and related vendors
Coordinate and respond to various cybersecurity assessments, including, as required, certifications to process certain government-related data or other sensitive data
Monitor and manage cybersecurity aspects of the third-party lifecycle and confirm that third parties' cybersecurity practices align with Allied Universal's cybersecurity risk tolerance
Third-Party Due Diligence:
Communicate/respond to requests regarding the effectiveness of Allied Universal's cybersecurity program regarding third-party diligence, selection, and monitoring (e.g., insurance, debt financing, public accounting, initial public offering, etc.) in coordination with Allied Universal Leadership, including IT, Legal and Procurement
Communication and Reporting:
Provide regular briefings to the CEO, Global General Counsel, and Board of Directors on cybersecurity posture, key risks, and, if applicable, major incidents.
Communicate with internal and external stakeholders (including government and prime contractor customers) regarding Allied Universal's cybersecurity program
Prepare and present reports on Allied Universal's cybersecurity posture to the CEO and Board of Directors, and other Allied Universal Leadership
Business Continuity and Disaster Recovery:
Partner with IT and Operations to ensure business-continuity and disaster-recovery programs incorporate cybersecurity risk considerations, are regularly tested, and effectively support enterprise resilience objectives
QUALIFICATIONS (MUST HAVE):
Bachelor's degree in computer science, Information Technology, cybersecurity, or a related field
Minimum of fifteen (15) years of progressive experience in cybersecurity
Minimum of seven (7) years in a senior management role in an informationsecurity function
Experience in managing, responding to, and mitigating cyber incidents
Experience or familiarity with government contracting and public and private company cybersecurity reporting requirements
Hands-on cyber incident response coordination and oversight experience
Expertise in risk-based frameworks (NIST CSF, ISO 27001, SOC 2, CMMC, NIST 800-171) and familiarity with applicable regulatory regimes (SEC, GDPR, state breach laws, etc.)
Proven ability to engage with CEO, Board of Directors, and Executive Team on cybersecurity strategy and governance
Ability to operate effectively as both strategist and practitioner, a player-coach who drives global cybersecurity direction while engaging hands-on to guide, mentor, and resolve complex technical and operational challenges
Strong leadership skills as well as the ability to work and communicate (verbal, written, and interpersonal) effectively with other leadership and their teams
An entrepreneurial and innovative mindset regarding cybersecurity development and operations
A strong understanding of the business impact of cybersecurity policies, tools, and technologies, including leveraging existing assets and talent to efficiently manage cybersecurity spend
PREFERRED QUALIFICATIONS (NICE TO HAVE):
Recognized security certifications such as Certified Information Systems Security Professional (CISSP), Certified InformationSecurity Manager (CISM), etc.
COMPENSATION AND BENEFITS:
Base salary range: $275,000 to $350,000 (based on skills, qualifications, and relevant experience), annual bonus, equity package
Medical, dental, vision, supplemental income plan with a company match, basic life, AD&D, and disability insurance
Eight paid holidays annually, five sick days, and four personal days
Executive Flex Vacation Plan
Closing
Allied Universal is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race/ethnicity, age, color, religion, sex, sexual orientation, gender identity, national origin, genetic information, disability, protected veteran status or relationship/association with a protected veteran, or any other basis or characteristic protected by law. For more information: ***********
If you have difficulty using the online system and require an alternate method to apply or require an accommodation, please contact our local Human Resources department. To find an office near you, please visit: ***********/offices.
Requisition ID 2026-1510953
$275k-350k yearly Auto-Apply 2d ago
Senior Information Security Engineer
Vast 4.7
Information security analyst job in Long Beach, CA
At Vast, our mission is to contribute to a future where billions of people are living and thriving in space. We are building artificial gravity space stations, allowing long-term stays in space without the adverse effects of zero-gravity. Our initial crewed space habitat will be Haven-1, scheduled to be the world's first commercial space station when it launches into low-Earth orbit in 2026. It is part of our stepping stone approach to continuous human presence in LEO. Our team is all-in, committed to executing our mission safely and on time. If you want to work with the most talented people on Earth furthering space exploration for humanity, come join us.
Vast is looking for a(n) Senior InformationSecurity Engineer reporting to the InformationSecurity Manager, to support the development of the systems that will be required for the design and build of artificial-gravity human-rated space stations.
This will be a full-time, exempt position located in our (Long Beach) location.
Responsibilities:
Design, deploy, and manage enterprise security technologies including firewalls, intrusion detection/prevention systems (IDS/IPS), endpoint protection, and securityinformation and event management (SIEM) platforms.
Implement/maintain solutions and configurations to achieve compliance with government regulations like NIST 800-171, CMMC 2.0, and ITAR/EAR.
Work cross-functionally with other teams to ensure the security of the systems they use or build.
Automate our security infrastructure to the maximum extent possible.
Collaborate with SOC analysts and other teams to enhance detection and response capabilities.
Support monitoring of security systems, networks, and applications for suspicious activities.
Minimum Qualifications:
2+ years of hands-on experience.
Experience securing Windows, MacOS, and Linux endpoints.
Proficiency in configuring, deploying, and maintaining security tools such as SIEM, IDS/IPS, antivirus, and vulnerability scanning.
Proficient understanding of cloud technologies such as AWS, Google, and Azure.
Proficient in using automation scripts (i.e. Powershell, Bash, Python).
Knowledge of network protocols, firewalls, and intrusion detection/prevention systems.
Preferred Skills & Experience:
Technical certifications such as OSCP, eCPPT, or platform specific certifications.
Familiarity with Kali Linux.
Understanding of cyber deception.
Experience conducting social engineering campaigns.
Experience supporting audits and assessments.
Understanding of compliance requirements and certifications like NIST 800-171, CMMC 2.0, DFARS ************, ITAR/EAR.
Familiarity with security SaaS solutions and relevant integrations.
Prior experience working in a fast-paced startup environment.
Additional Requirements:
Ability to travel up to 10% of the time.
Willingness to work overtime, or weekends to support critical mission milestones.
Pay Range:
Senior InformationSecurity Engineer: $143,500 - $203,700
Staff InformationSecurity Engineer: $158,100 - $226,900
Pay Range: California$143,000-$226,900 USDCOMPENSATION AND BENEFITS Base salary will vary depending on job-related knowledge, education, skills, experience, business needs, and market demand. Salary is just one component of our comprehensive compensation package. Full-time employees also receive company equity, as well as access to a full suite of compelling benefits and perks, including: 100% medical, dental, and vision coverage for employees and dependents, flexible paid time off for exempt staff and up to 10 days of vacation for non-exempt staff, paid parental leave, short and long-term disability insurance, life insurance, access to a 401(k) retirement plan, One Medical membership, ClassPass credits, personalized mental healthcare through Spring Health, and other discounts and perks. We also take pride in offering exceptional food perks, with snacks, drip coffee, cold drinks, and dinner meals remaining free of charge, and lunch subsidized as part of Vast's ongoing commitment to providing high-quality meals for employees.
U.S. EXPORT CONTROL COMPLIANCE STATUS
The person hired will have access to information and items subject to U.S. export controls, and therefore, must either be a “U.S. person” as defined by 22 C.F.R. § 120.62 or otherwise eligible for deemed export licensing. This status includes U.S. citizens, U.S. nationals, lawful permanent residents (green card holders), and asylees and refugees with such status granted, not pending.
EQUAL OPPORTUNITY
Vast is an Equal Opportunity Employer; employment with Vast is governed on the basis of merit, competence and qualifications and will not be influenced in any manner by race, color, religion, gender, national origin/ethnicity, veteran status, disability status, age, sexual orientation, gender identity, marital status, mental or physical disability or any other legally protected status.
$158.1k-226.9k yearly Auto-Apply 3d ago
Software Security Analyst
TP-Link Systems 3.9
Information security analyst job in Irvine, CA
About Us:
Headquartered in the United States, TP-Link Systems Inc. is a global provider of reliable networking devices and smart home products, consistently ranked as the world's top provider of Wi-Fi devices. The company is committed to delivering innovative products that enhance people's lives through faster, more reliable connectivity. With a commitment to excellence, TP-Link Systems serves customers in over 170 countries and continues to grow its global footprint.
We believe technology changes the world for the better! At TP-Link Systems Inc, we are committed to crafting dependable, high-performance products to connect users worldwide with the wonders of technology.
Embracing professionalism, innovation, excellence, and simplicity, we aim to assist our clients in achieving remarkable global performance and enable consumers to enjoy a seamless, effortless lifestyle.
Overview:
We are seeking many highly skilled and experienced Software SecurityAnalyst (aka Source Code Auditor) to join our cybersecurity team. In this role, you will be responsible for reviewing and analyzing source code to identify potential security vulnerabilities, ensure compliance with coding standards, and enhance the overall security posture of our applications. You will work closely with development teams, security professionals, and stakeholders to provide actionable insights and recommendations for improving code quality and security.
Key Responsibilities
Conduct thorough audits of source code to identify vulnerabilities, security weaknesses, and coding inefficiencies.
Review and analyze code across a variety of programming languages and frameworks, including but not limited to Python, Java, C++, JavaScript, Swift and Kotlin.
Develop and maintain code auditing standards, processes, and tools to ensure consistent and high-quality reviews.
Collaborate with development teams to provide feedback and guidance on secure coding practices and remediation strategies.
Prepare detailed audit reports that outline findings, risks, and recommendations for improving code security and quality.
Stay up to date with the latest security threats, coding standards, and best practices to continuously improve audit processes.
Mentor junior auditors and provide guidance on auditing techniques, tools, and best practices.
Work with cross-functional teams to integrate security practices into the software development lifecycle (SDLC).
Assist in developing and conducting security training and awareness programs for development teams.
Requirements
Qualifications:
Bachelor's degree in Computer Science, InformationSecurity, or a related field, or equivalent experience.
5+ years of experience in source code auditing, software development, or application security.
Strong understanding of secure coding principles, software vulnerabilities, and common attack vectors (e.g., SQL injection, cross-site scripting, buffer overflow).
Proficiency in multiple programming languages and familiarity with a variety of development frameworks and environments.
Experience with automated code review tools (e.g., SonarQube, Coverity, Checkmarx, Veracode) and manual code review techniques.
Excellent analytical and problem-solving skills with a keen eye for detail.
Strong communication skills, with the ability to explain complex technical concepts to non-technical stakeholders.
Relevant certifications such as Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), or Certified Information Systems Security Professional (CISSP) are a plus.
Benefits
Salary range: $100,000-$140,000
Free snacks and drinks, and provided lunch on Fridays
Fully paid medical, dental, and vision insurance (partial coverage for dependents)
Contributions to 401k funds
Bi-annual reviews, and annual pay increases
Health and wellness benefits, including free gym membership
Quarterly team-building events
At TP-Link Systems Inc., we are continually searching for ambitious individuals who are passionate about their work. We believe that diversity fuels innovation, collaboration, and drives our entrepreneurial spirit. As a global company, we highly value diverse perspectives and are committed to cultivating an environment where all voices are heard, respected, and valued. We are dedicated to providing equal employment opportunities to all employees and applicants, and we prohibit discrimination and harassment of any kind based on race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws. Beyond compliance, we strive to create a supportive and growth-oriented workplace for everyone. If you share our passion and connection to this mission, we welcome you to apply and join us in building a vibrant and inclusive team at TP-Link Systems Inc.
Please, no third-party agency inquiries, and we are unable to offer visa sponsorships at this time.
Job Description
At Turion Space, our Platform Engineering team is building the infrastructure backbone that powers the next generation of space exploration. As a Senior Secure Cloud Engineer, you'll architect and scale secure cloud infrastructure that enables our engineering teams to deploy spacecraft control systems, autonomous satellite operations, and mission-critical applications with speed and confidence - securing the infrastructure that protects our most sensitive national security missions.Our team's mission is to enable Turion engineers to efficiently and reliably deliver products at scale, supporting missions that can't afford downtime when hardware is operating hundreds of miles above Earth. You'll create the infrastructure and deployment capabilities that are as reliable, secure, and cutting-edge as the spacecraft they support.
Key Responsibilities
Deploy and manage core infrastructure components including microservices, databases, and supporting services
Design and implement improvements to our container orchestration platform
Develop abstraction layers that enable infrastructure portability across different deployment targets
Build and optimize reusable infrastructure components and templates for consistent cross-environment deployments
Define and implement standardized deployment patterns and workflows
Collaborate with other engineering teams to understand their requirements and translate them into functional cloud solutions with industry best practices
Identify operational bottlenecks and architect innovative solutions that maximize system availability and reliability
Minimum Qualifications
Bachelor's degree in computer science, information systems/IT, or an engineering discipline
5+ years of experience in Site Reliability Engineering, DevOps, or Cloud Infrastructure Engineering type roles
Active DoD Secret Clearance required. Top Secret (TS/SCI‑eligible) clearance preferred
In-depth knowledge of integrating security and automation for classified IT (JSIG, RMF, NIST 800-53, NIST 800-218)
Strong hands-on experience with Kubernetes in production environments
Deep expertise with AWS services and architectures, particularly around containerization, orchestration, networking, and AWS Control Tower
Proven experience designing and implementing cloud-native architectures, microservices, and distributed systems
Proficiency with infrastructure as code tools (AWS CDK, Terraform, or similar)
Development experience in at least one programming language (e.g., Python, Go, TypeScript)
Preferred Qualifications
AWS certifications (e.g., AWS Certified Security - Specialty)
Experience automating FedRAMP High or IL6 environments
Experience with ATO/authorization processes for DoD/IC environments
Prior work with cross domain solutions in cloud
Experience implementing GitOps practices in large-scale production environments
Deep knowledge of Linux distributions and their management at scale
Knowledge of multiple cloud providers and their architectural differences (AWS, Azure, GCP, etc)
Experience building infrastructure control planes using Crossplane or similar frameworks
Experience enabling continuous deployment for large scale application suites with tools like ArgoCD
ITAR Requirements:
This position may include access to technology and/or software source code that is subject to U.S. export controls. To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State.
Benefits:
We offer a comprehensive compensation and benefits package designed to support the well-being and professional growth of our employees. In addition to a competitive base salary and company stock, determined by factors such as job-related knowledge, education, skills, experience, and market demand, full-time employees are eligible for:
Equity: Receive equity in Turion Space, letting you benefit from the company's success
Health Insurance: Comprehensive medical, dental, and vision coverage for employees and their dependents.
Retirement Plans: Access to a 401(k) plan to help you plan for your future.
Paid Time Off: Generous vacation days, personal days, sick days, and holidays to ensure you have time to recharge.
Professional Development: Opportunities for ongoing training, workshops, and courses to advance your skills and career growth.
Team Building Activities: Regular social events, team outings, and company-sponsored activities to foster a positive work environment.
We are dedicated to providing a supportive and enriching environment for our team members, recognizing that our collective success is built upon the well-being and satisfaction of each individual.
Turion Space is an Equal Opportunity Employer; employment with Turion Space is governed on the basis of merit, competence and qualifications and will not be influenced in any manner by race, color, religion, gender, national origin/ethnicity, veteran status, disability status, age, sexual orientation, gender identity, marital status, mental or physical disability or any other legally protected status.
Compensation Range: $165K - $230K
$165k-230k yearly 12d ago
Clinical Cyber Security Engineer
Renovo Solutions 3.1
Information security analyst job in Long Beach, CA
As a hybrid biomedical equipment/IT technician, a Clinical Cyber Security Engineer usually has a four-year degree or the associated experience to maintain a diverse population of patient care equipment and networked medical devices. A Clinical Cyber Security Engineer has a good knowledge of electronics, schematics, computer operating systems, networking, and security. This individual must have strong project management skills and organizational skills. Often, they must collaborate with the Manager of Clinical Cyber Security Engineering and the facility's IT department and must demonstrate excellent customer service skills.
Essential Duties & Responsibilities:
Responsible for support and oversight of the clinical information systems under his/her care. This includes the tracking of hardware (configuration items), software and network documentation.
Provides user support, systems technical service and support, and participates in system projects as requested.
Coordinates and/or implements software patches / updates in collaboration with Clinical Staff, Original Equipment Manufactures and the Hospitals SIT Department.
Demonstrates cost containment and financial acumen
Maintains a good personal relationship with fellow co-workers, hospital staff, and vendors
Maintains an accurate inventory of Networked Medical Devices or devices containing ePHl
Works with IT and security staff to identify and mitigate risks; helps to enforce policies and procedures on medical devices and IoT systems
Utilizes system management tools and industry best practices to asses security vulnerabilities and risk to medical devices and IoT management
Uses project management tools to manage system implementations and change management procedures
Acts as a consultant to the facility regarding system hardware/software evaluation and selection
Coordinates installation and maintenance of networked medical devices containing PC hardware with facility IT department
Performs other duties as assigned**
Required Skills
Possesses a comprehensive knowledge of electromechanical devices and principles, as well as a thorough understanding of general patient care equipment and can demonstrate the usage of supported devices
Basic understanding of life-support and diagnostic support devices and their usage within the healthcare setting
Configuration of computer hardware and software, cyber security systems
Use and management of operating systems including Microsoft, Linux/Unix and RTOS
Configuration and deployment of computer software support tools (i.e. Configuration,
Remote Management, Antivirus, Backup and Recovery, Monitoring tools, etc.)
Proficient in the use of Microsoft Office products, and the creation of network diagrams using Microsoft Visio or similar software
Configuration of basic network components and understanding of routing and subnetting processes
Application of CIS, NIST, HITRUST best practices and guidelines to technology devices & systems
Knowledge and understanding of human anatomy and physiology
Required Competencies
Accountability - takes ownership of assigned work and responsibilities, follows through and closes the loop
Communication - clearly expresses thoughts and ideas both in written and verbal communications, provides timely information
Financial Acumen - Considers financial impact of all decisions
Integrity - Can admit mistakes, is direct and truthful
Customer Service - demonstrates a "customer-first" mentality, focused on meeting the needs of customers and captures feedback to make improvements Priority Setting - Prioritizes assigned schedules and workload
Knowledge - Stay current with technological developments, security trends and best practices in the information technology field.
Information Technology - Possesses knowledge and understanding of basic cyber security and IT terminology as it pertains to medical devices and facility IT systems
Team Building - Mentors newer technicians, facilitates clear communication amongst the team, demonstrates care and respect for co-workers and colleagues
Regulatory - understands the various regulations and best practices that apply to the HTM space (HIPAA, HITECH, Omnibus, SOC, COBIT, ITIL)
Attributes
Culture - promotes the Vision, Mission and Values that make up the RENOVO culture as well as the culture of the healthcare facility
Mechanically inclined - technical skills and abilities to figure out how things work Self-motivated - can work on their own or under limited direction while prioritizing equipment schedules and repair activities. Advanced projects or activities require supervision
Open-minded - Willing to listen to opinions and criticism, can switch directions quickly
Agility - Can break complex projects into smaller iterative tasks
Improvement - willing to learn and grow, wants to update job skills for career growth
Confidence - Self-reliant decision maker that doesn't second guess decisions Multi-tasker - Is organized and efficient, handles multiple projects or tasks simultaneously
Education/Special Training
H.S. Diploma or equivalent required
Technical Certificate or DOD training required
4-year College Degree, Certification, or other higher level of education pertaining to this job description preferred
CompTIA A+ & Network+ or equivalent certification,
CISSP, CCNA, MSCE desired
Required Work Hours
Forty hours per week during daytime and evening hours. Scheduled work hours may change. Overtime may be required or permitted with prior approval. This position may be included in the on-call rotation for the facility.
Reporting and Supervisor Responsibilities
The Clinical Systems Engineer reports to - Manager, Biomedical Engineering
This position has no supervisory responsibilities
Physical Requirements
The Clinical Systems Engineer must be able to speak, hear, see, read, write, type, dial, reach, bend, climb, crawl, crouch, kneel, squat, and twist. Must have near vision, far vision, depth perception, and be able to distinguish colors. Must have sensory ability to distinguish hot, cold, range of temperatures, surfaces, fine motor skills, manual dexterity, and detect/distinguish odors. Must be able to carry or lift up to 50 pounds routinely.
Travel
Travel will be required for this position, unless otherwise specified. Total travel based on project needs and locations
Classification
FLSA: Non-exempt
Administration:
Understand and observe company policies and procedures.
Relationships:
Utilize teamwork in your daily activity and ensure customer satisfaction.
Other:
Housekeeping - Maintain a clean, orderly appearance of all work areas.
Personal appearance - Must observe company dress code always and must have good personal hygiene.
Maintain all RENOVO owned equipment including tools, test equipment, computers, and others as specified in proper working condition and ensure annual calibration where appropriate.
**Note: This position description does not list every activity, duty, and responsibility of the position and may be altered by RENOVO at any time.
$92k-128k yearly est. 24d ago
Sr. Information Security GRC Analyst
Loandepot 4.7
Information security analyst job in Irvine, CA
at loan Depot
Responsible for driving the development, implementation, communication, and maintenance of loan Depot's technology policies, standards and procedures that are aligned to industry standards and regulatory requirements. Ensures that loan Depot technology processes adheres to regulatory requirements, manages risks effectively, and establishes strong governance practices. Develops and implements controls, monitors compliance, and supports risk management activities.
Responsibilities:
Leads the development and implementation of comprehensive cybersecurity and IT policies, standards, and guidelines.
Continuously evaluates and updates cybersecurity and IT policies to ensure they remain current and effective.
Ensures policies comply with relevant laws, regulations, and industry standards (e.g., NIST, FFIEC, GLBA, NYDFS, SOX and PCI-DSS).
Collaborates with teams, working closely with IT, legal, compliance, and other departments, to gain a deep understanding of business needs to ensure cybersecurity policies align with business objectives.
Transforms complex information and documentation into simple concepts that are easy to understand by the end-users.
Offers specialized expertise and consultation to cross-functional teams to perform framework-oriented risk assessments, identify deficiencies, generate reports, and recommends prioritized, actionable solutions to mitigate risks and enhance loan Depot's overall security posture.
Stays informed about the latest cybersecurity threats, trends, and best practices. Ensures accurate and up-to-date records of policy reviews, risk assessments, training activities, and incident responses.
Benchmarks the organization's policies against industry standards and best practices.
Develops and implements governance frameworks for cybersecurity policy management.
Monitors key performance indicators, conducts gap analysis, risk assessments and implements frameworks, as needed. Tests and monitors effectiveness of controls.
Establishes a feedback loop and analyzes metrics to continuously improve cybersecurity policies based on audit findings, incident reviews, and emerging threats.
Actively leads and supports on internal and external audits and assessments of cybersecurity policies and practices. Accountable for ensuring identified audit and assessment findings and actions are tracked to closure.
Maintains comprehensive documentation of all cybersecurity policies, procedures, and related activities. Communicates policy requirements and updates to all relevant stakeholders.
Identifies opportunities for innovation and improvement in cybersecurity policy and practice. Proposes suitable mitigation strategies and verifies the effectiveness of remediation plans
Requirements:
Bachelor's Degree in InformationSecurity, Computer Science, Information Technology, or a related field preferred.
Minimum of six (6) + years' experience working in Cybersecurity GRC, policy development, risk management, or a similar field.
Experience with GRC tools (e.g., Archer, ServiceNow, OneTrust).
Proficiency in using data analysis and reporting tools (e.g., Excel, Power BI).
Relevant certifications such as CISM and/or CISA are highly desirable.
Why work for #teamloan Depot:
Competitive compensation package based on experience, skillset and overall fit for #TeamloanDepot.
Inclusive, diverse, and collaborative culture where people from all backgrounds can thrive
Work with other passionate, purposeful, and customer-centric people
Extensive internal growth and professional development opportunities including tuition reimbursement
Comprehensive benefits package including Medical/Dental/Vision
Wellness program to support both mental and physical health
Generous paid time off for both exempt and non-exempt positions
About loan Depot:
loan Depot (NYSE: LDI) is a digital commerce company committed to serving its customers throughout the home ownership journey. Since its launch in 2010, loan Depot has revolutionized the mortgage industry with a digital-first approach that makes it easier, faster, and less stressful to purchase or refinance a home. Today, as the nation's second largest non-bank retail mortgage lender, loan Depot enables customers to achieve the American dream of homeownership through a broad suite of lending and real estate services that simplify one of life's most complex transactions. With headquarters in Southern California and offices nationwide, loan Depot is committed to serving the communities in which its team lives and works through a variety of local, regional, and national philanthropic efforts. Base pay is one part of our total compensation package and is determined within a range. This provides the opportunity to progress as you grow and develop within a role. The base pay for this role is between $99,000 and $136,500. Your base pay will depend on multiple individualized factors, including your job-related knowledge/skills, qualifications, experience, and market location. We are an equal opportunity employer and value diversity in our company. We do not discriminate based on race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
$99k-136.5k yearly Auto-Apply 60d ago
Lead Security Engineer
Swiftly, Inc.
Information security analyst job in Ontario, CA
Company DescriptionSwiftly is on a mission to help cities move more efficiently. We are the leading transit data platform for agencies to share real-time passenger information, manage day-to-day operations, and improve service performance. Today, over 180 transit agencies in 12 countries - including LA Metro, MARTA, SEPTA, and MBTA - rely on Swiftly to improve on-time performance by up to 40% and increase passenger information accuracy by up to 50%. The result is better service reliability, increased ridership, and more efficient transit operations.
Even though Swiftly's HQ office is located in San Francisco, CA, we are open to candidates in most locations across the U.S. as well as Ontario and British Columbia, Canada. At this time we are unable to provide Visa sponsorship.
Engineering at SwiftlyEngineering at Swiftly is not only about writing code - we believe in creating empowered product teams that work together to conceptualize new features and bring them to life. Each team aims to strike a balance between delivering incremental improvements, creating prototypes to test new ideas and mitigate risks, and building scalable software using industry best practices. We're guided by a mission to positively impact transit riders, and we embrace humility and intentionality in how we make technical decisions so that we best meet our customers' needs.
About the Role
We're looking for a Lead Security Engineer to join our Platform team and mature Swiftly's security posture. We believe excellent security isn't just about tools and controls; it's about empowering product, infrastructure, and corporate IT teams across our organization to make secure decisions every day. In this role, you'll partner closely with engineering, product, and go-to-market teams to design secure solutions, build DevSecOps tooling, and drive our compliance roadmap. You'll balance strategic initiatives with hands-on work in our cloud-native environment. We're looking for someone equally comfortable working on codebases and leading cross-functional initiatives, a force multiplier who can train teams, represent security to customers and executives, and make security a natural part of how Swiftly ships products.
We use AI tools for scheduling and summarization in our hiring process. We do not use AI tools to make decisions about who moves forward or to assess the strength of candidates. Every application is reviewed and all hiring decisions are made by Swiftly team members. This is an active, open role that we are currently hiring for at Swiftly.
What You'll Do
Make Swiftly Secure
- Own Swiftly's security risk register and threat models; identify, prioritize, and drive remediation of risks across application and infrastructure.- Design secure architectures for our SaaS platform, mobile applications, and IOT/Hardware Integration, focusing on authentication, authorization, data protection, and network boundaries- Recommend, implement, and manage security tools end-to-end- Build DevSecOps guardrails into CI/CD so vulnerabilities, misconfigurations, and license issues surface early- Conduct internal security assessments and coordinate engagements with external penetration testers.- Own security policies and standards; ensure they're practical, adopted, and measurable- Define standards for secure adoption of AI coding assistants, building reusable patterns, custom configurations, and guardrails that help developers move fast safely
Compliance & Customer Trust
- Lead renewals and continuous readiness for existing certifications like SOC 2- Proactively identify security frameworks required for international expansion; scope cost, level of effort, and timelines to inform market entry decisions; and lead execution of new certifications- Respond to customer security and compliance inquiries and support product marketing with security content
Incident Response & Detection
- Design and maintain security incident response plans, playbooks, and escalation paths- Serve as an escalation point for security incidents; lead triage, root cause analysis, and remediation
Security Leadership
- Define and maintain security KPIs and dashboards for executive and board reporting- Give teams visibility into their security posture and coach them to improve- Influence roadmap prioritization to ensure security and compliance are first-class concerns- Mentor engineers in secure design and help grow a security-aware culture across Swiftly by delivering security training and office hours for developers and other stakeholders- Drive corporate IT security strategy, including endpoint hardening, email security, IAM standards, and periodic access reviews What will set you up for success
5+ years of experience in security engineering with both strategic and hands-on work
Strong experience securing cloud-native environments (AWS preferred), including IAM, networking, logging/monitoring, and secrets management
Hands-on experience with infrastructure-as-code (Terraform) and policy-as-code frameworks (OPA, Sentinel, or similar)
Background building security into CI/CD pipelines and development workflows
Familiarity with container and orchestration security
Excellent threat modeling and risk assessment skills; able to translate complex risks into clear options and tradeoffs
Experience with compliance frameworks (SOC 2 preferred) and audit processes
Strong communication skills; comfortable working across technical and non-technical teams
Self-directed and comfortable operating with autonomy
Nice to Haves
Relevant certifications (CISSP, cloud security certifications)
Experience advising on security for AI/ML or LLM-powered features
Mobile application security experience (Android preferred)
Experience with GRC and compliance platforms
Background in application security or penetration testing
Experience with international compliance frameworks
Familiarity with regulated industries or public sector requirements
Experience with physical device security (IoT, embedded systems, or field-deployed hardware)
Experience with Mobile Device Management (MDM) solutions for enterprise or fleet deployments
Pay Range
In accordance with pay transparency laws, please see the approximate salary ranges below. These ranges represents the anticipated low and high end of the salary for this position. Actual salaries will vary and are based on a multitude of non-discriminatory factors including final role leveling decisions, a candidate's relevant work experiences/skills, and geographic location. Salary is one component of Swiftly's total compensation package, which also includes stock options, competitive benefits, 401(k)/ RRSP matching, a fantastic team and culture, opportunity to have a huge impact, emphasis on professional growth and holistic wellness, and other perks.
US Salary Range: $140,000 - 200,000Canadian Salary Range: $165,000 - 200,000
Beyond the SkillsWe are looking for candidates who are passionate about mobility, sustainability, or mission-oriented projects that have a significant real-world impact. Ideal candidates encompass the core values of our company:Team. Together, we are more effective and better supported Impact. Drive impact for our customers, our company, and all of our teams Diversity. See differing perspectives as ways to address our weaknesses and find new strengths Communication. Assume others internally and externally have good intentions Feedback. We share feedback because we want each other to grow professionally and personally Growth. Foster personal, professional, and company growth
Benefits:• Competitive salary• Equity compensation (company ownership) for every employee• Medical, Dental and Vision• Retirement with Employer Match• Flexible Spending Account (FSA)• Home office setup reimbursement• Monthly cell/internet reimbursement• Monthly "Be Well" stipend• Flexible PTO with a recommended minimum• Flexible work environment• 16 paid holidays - including months without US national holidays• 8 fully paid weeks of leave for child birth/adoption
Travel note: Swiftly employees can generally expect to travel 1-2 times a year for in-person company or team offsites. As a fully distributed company, we consider these offsites important for cultivating strong relationships across our teams! Attending these in-person is expected and encouraged, although we understand everyone has different personal circumstances and we will consider requests for exceptions. Customer-facing team members and other specific roles may be expected to travel more frequently.
We are an equal opportunity employer - we are committed to a workplace that is as dynamic, diverse, and passionate as the communities we serve.
$165k-200k yearly Auto-Apply 41d ago
0_IT_Software Engineer - Information Security
Summithr
Information security analyst job in Pasadena, CA
Key Qualifications:
Bachelor's degree or equivalent experience
5-10+ years of experience as a security engineer in related domains
Experienced in Cloud IDAM solutions and able to provide Tier 2 and Tier 3 security operations support and incident handling.
Assists in the development, implementation, and tuning of secure management of user interfaces, workspaces, and dashboards.
Experience with auditing tools, intrusion detection/protection devices, security Benchmarks, Incident Response Handling, and NIST publications.
Ability to perform under pressure and handle change easily while meeting deadlines.
CISSP certification is preferred, with knowledge of operating systems, file systems, and memory on OS X, Linux, Windows, or iOS/Android.
Coding or scripting proficiency in one or more languages is preferred having practical experience with attacker tactics, techniques, and procedures.
Experience and knowledge across multiple security domains, but with expertise in detection engineering, digital forensics, incident response, threat intelligence, or malware analysis
Recent digital forensic experience including memory or live analysis of mac OS, Linux, Windows, or iOS/Android systems.
Experience as an incident responder responsible for running large scale incidents.
Demonstrated engagement in the security community through talks, papers, or code.
Experience with Kubernetes, threat modeling, STRIDE and writing secure Java code.
To see new and updated job postings and job postings similar to this, please follow us on LinkedIn: *****************************************
$100k-141k yearly est. 60d+ ago
Senior Security Engineer
Goodleap 4.6
Information security analyst job in Irvine, CA
GoodLeap is a technology company delivering best-in-class financing and software products for sustainable solutions, from solar panels and batteries to energy-efficient HVAC, heat pumps, roofing, windows, and more. Over 1 million homeowners have benefited from our simple, fast, and frictionless technology that makes the adoption of these products more affordable, accessible, and easier to understand. Thousands of professionals deploying home efficiency and solar solutions rely on GoodLeap's proprietary, AI-powered applications and developer tools to drive more transparent customer communication, deeper business intelligence, and streamlined payment and operations. Our platform has led to more than $30 billion in financing for sustainable solutions since 2018.
GoodLeap is also proud to support our award-winning nonprofit, GivePower, which is building and deploying life-saving water and clean electricity systems, changing the lives of more than 1.6 million people across Africa, Asia, and South America.
Position Summary
The GoodLeap security team is responsible for both business enablement and safeguarding the organization's information assets; it is involved in virtually all aspects of the business, from product safety and resilience, to building security paved roads, customer, partner, and regulatory trust, managing technology governance and compliance, and ensuring the privacy, and safety of GoodLeap's customers, partners, and employees information.
The senior security engineer role provides a unique opportunity to shape the security and resilience of GoodLeap corporate systems, services, and operational processes. In this role, you will work closely with product, engineering, IT, and business teams within GoodLeap, acting as the key individual with both the authority and responsibility to ensure the safety and resilience of enterprise systems, products, and services.
Your oversight will encompass:
* Enterprise systems:Identifying potential misuse and abuse cases, proposing solutions to address these scenarios, and identifying product features, configuration settings, and/or mitigating or compensating controls to meet resilience requirements.
* Build-time controls: Managing applications/products security controls and activities during development.
* Runtime controls: Overseeing security measures at runtime, from prevention to detection and response.
Additionally, you will be involved with aspects of internally built products and represent all areas of security, spanning governance, risk, and compliance (GRC) to security monitoring, for a number of departments/teams. You will also have the authority and ability to involve other security team members as needed.
While you will take on multiple responsibilities-from advisor to builder and beyond-your primary focus will be designing and building security patterns and practices for services and processes, and fostering strong relationships with product, business, and engineering.
Essential Job Duties & Responsibilities
* Lead, participate in, and contribute to partnerships between security, IT, General & Administrative teams, engineering, product, and operations teams to build, orchestrate, and automate security controls and services in GoodLeap enterprise systems, products, services, and operational processes.
* Identify potential misuse and abuse cases in enterprise systems, propose solutions to address these scenarios, and identify product features, configuration settings, and/or mitigating or compensating controls to meet resilience requirements.
* Support or develop components of the security analytics platform.
* Contribute to investigations, threat hunting, and incident response activities in a supporting role.
* Collaborate with the monitoring and response team to create playbooks for specific incident response scenarios related to the products and services you oversee. These investigations, incidents, and playbooks may address security, fraud, privacy, resilience, and related concerns.
* Support the security operations team with the vulnerability management lifecycle for products and services under your purview.
* Ensure technical alignment for the products and services you oversee with team initiatives, including GRC, security operations, and monitoring and response activities.
Required Skills, Knowledge & Abilities
* Strong communicator with the ability to lead technical architecture discussions, drive technical decisions, and effectively communicate with non-technical audiences.
* Expertise in agile product lifecycles. Ideally, you have experience in a product manager or engineering manager role and understand how SaaS products (B2B, B2B2C, and B2C) are built, including roadmap planning and feature and defect prioritization.
* Experience with threat modeling methodologies, with the ability to create efficient and scalable approaches to conducting such assessments.
* Familiarity with AWS services, including KMS, SST, Container Registry, ELBs, Lambda, API Gateway, CloudTrail, and IAM (knowledge of GCP and/or Azure is a plus).
* Proven ability to establish credibility and build trust with business, engineers, and operational staff; confident yet humble.
* Hands-on experience with managing security for core enterprise systems, e.g., ERP, HCM, Salesforce, etc.
* Strong understanding of both human and non-human identity management and common enterprise and consumer authentication standards and use cases.
* Practical experience with CI/CD pipelines and DevOps tools, including Infrastructure-as-Code (IaC) tools like Terraform, Pulumi, or CDK; GitHub and GitHub Actions; artifact management; and secrets management tools like Doppler and HashiCorp Vault.
* Passionate about learning new technologies. While you're not expected to know everything, you should demonstrate a willingness and ability to learn as needed.
* Prior experience interfacing and supporting with G&A teams, internal product teams, and other cross-functional areas.
* Proficiency in writing automation scripts in multiple languages, with prior experience automating security processes in cloud or SaaS environments.
* Experience engaging with vendors in design partnerships.
* Experience overseeing vulnerability and threat management at the platform and application levels.
* Familiarity with penetration testing and red team exercises, including manual verification, exploitation, and lateral movement.
* Ability to balance a high-level view of security strategy with attention to detail, ensuring thorough and effective execution.
$146,000 - $170,000 a year
In addition to the above salary, this role may be eligible for a bonus.
Additional Information Regarding Job Duties and s:
Job duties include additional responsibilities as assigned by one's supervisor or other managers related to the position/department. This job description is meant to describe the general nature and level of work being performed; it is not intended to be construed as an exhaustive list of all responsibilities, duties and other skills required for the position. The Company reserves the right at any time with or without notice to alter or change job responsibilities, reassign or transfer job position or assign additional job responsibilities, subject to applicable law. The Company shall provide reasonable accommodations of known disabilities to enable a qualified applicant or employee to apply for employment, perform the essential functions of the job, or enjoy the benefits and privileges of employment as required by the law.
If you are an extraordinary professional who thrives in a collaborative work culture and values a rewarding career, then we want to work with you! Apply today!
We are committed to protecting your privacy. To learn more about how we collect, use, and safeguard your personal information during the application process, please review our Employment Privacy Policy and Recruiting Policy on AI.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
$146k-170k yearly 60d+ ago
Senior Security Firmware Engineer
Sandisk
Information security analyst job in Irvine, CA
Sandisk understands how people and businesses consume data and we relentlessly innovate to deliver solutions that enable today's needs and tomorrow's next big ideas. With a rich history of groundbreaking innovations in Flash and advanced memory technologies, our solutions have become the beating heart of the digital world we're living in and that we have the power to shape.
Sandisk meets people and businesses at the intersection of their aspirations and the moment, enabling them to keep moving and pushing possibility forward. We do this through the balance of our powerhouse manufacturing capabilities and our industry-leading portfolio of products that are recognized globally for innovation, performance and quality.
Sandisk has two facilities recognized by the World Economic Forum as part of the Global Lighthouse Network for advanced 4IR innovations. These facilities were also recognized as Sustainability Lighthouses for breakthroughs in efficient operations. With our global reach, we ensure the global supply chain has access to the Flash memory it needs to keep our world moving forward.
Job Description
ESSENTIAL DUTIES AND RESPONSIBILITIES:
Development of various cryptography-based security features such as data encryption, Secure Boot, and Device Attestation.
Integrate these security protocols and features into the SSD data and control flows to ensure a robust and secure system. Additionally, investigate and resolve any security protocol compatibility issues that may arise.
Investigating failures, documenting bug reports, and providing valuable assistance to product teams in identifying and resolving issues.
Debugging, optimizing, and validating the Firmware on SoC platforms, as well as bringing up of FPGA and ASIC.
Contribute to the Security Development Lifecycle of the Firmware by supporting its development at different stages, including design, threat analysis, implementation, validation, vulnerability testing, certification, and audit.
Qualifications
REQUIRED:
To qualify for this position, an ideal candidate would have/be.
A degree in Computer Science, Electrical/Computer Engineering, Software Engineering, or a related field.
3+ years of experience in embedded programming, with proficiency in C/C++ and one or more of the following: Python, Rust, Go.
Strong understanding of microcontroller architectures and debugging of hardware/firmware issues.
Experience in firmware code review, CI/CD test and validation methodology, as well as static and dynamic code analysis. Familiarity with the Agile software development process life cycle is also desired.
Proficiency in failure analysis in debugging an embedded firmware application, using JTAG/debuggers such as Lauterbach.
An engineer who can take ownership of given features and manage them from start to finish. Being self-motivated and driven is essential for this role.
Good communication skills and be able to work effectively with cross-functional teams.
What Sets You Apart
Detailed knowledge of RISC-V Instruction Set Architectures (ISA)
Technical expertise in applied cryptography and firmware/hardware security, including knowledge of data encryption, trusted execution environment, secure boot, and device attestation.
Knowledge of storage controller architectures and security protocols, such as TCG Opal/Ruby/Pyrite, IEEE 1667, SPDM, and IDE.
Develop firmware on SoC platforms, run simulation or bringing up FPGA and ASIC.
Familiarity with writing code in Github repository and it's CI/CD testing framework.
Additional Information
Sandisk is committed to providing equal opportunities to all applicants and employees and will not discriminate against any applicant or employee based on their race, color, ancestry, religion (including religious dress and grooming standards), sex (including pregnancy, childbirth or related medical conditions, breastfeeding or related medical conditions), gender (including a person's gender identity, gender expression, and gender-related appearance and behavior, whether or not stereotypically associated with the person's assigned sex at birth), age, national origin, sexual orientation, medical condition, marital status (including domestic partnership status), physical disability, mental disability, medical condition, genetic information, protected medical and family care leave, Civil Air Patrol status, military and veteran status, or other legally protected characteristics. We also prohibit harassment of any individual on any of the characteristics listed above. Our non-discrimination policy applies to all aspects of employment. We comply with the laws and regulations set forth in the "Know Your Rights: Workplace Discrimination is Illegal” poster. Our pay transparency policy is available here.
Sandisk thrives on the power and potential of diversity. As a global company, we believe the most effective way to embrace the diversity of our customers and communities is to mirror it from within. We believe the fusion of various perspectives results in the best outcomes for our employees, our company, our customers, and the world around us. We are committed to an inclusive environment where every individual can thrive through a sense of belonging, respect and contribution.
Sandisk is committed to offering opportunities to applicants with disabilities and ensuring all candidates can successfully navigate our careers website and our hiring process. Please contact us at jobs.accommodations@sandisk.com to advise us of your accommodation request. In your email, please include a description of the specific accommodation you are requesting as well as the job title and requisition number of the position for which you are applying.
Based on our experience, we anticipate that the application deadline will be 03/15/2026 (3 months from posting), although we reserve the right to close the application process sooner if we hire an applicant for this position before the application deadline. If we are not able to hire someone from this role before the application deadline, we will update this posting with a new anticipated application deadline.
#LI-RT1
Compensation & Benefits Details
An employee's pay position within the salary range may be based on several factors including but not limited to (1) relevant education; qualifications; certifications; and experience; (2) skills, ability, knowledge of the job; (3) performance, contribution and results; (4) geographic location; (5) shift; (6) internal and external equity; and (7) business and organizational needs.
The salary range is what we believe to be the range of possible compensation for this role at the time of this posting. We may ultimately pay more or less than the posted range and this range is only applicable for jobs to be performed in California, Colorado, New York or remote jobs that can be performed in California, Colorado and New York. This range may be modified in the future.
You will be eligible to participate in Sandisk's Short-Term Incentive (STI) Plan, which provides incentive awards based on Company and individual performance. Depending on your role and your performance, you may be eligible to participate in our annual Long-Term Incentive (LTI) program, which consists of restricted stock units (RSUs) or cash equivalents, pursuant to the terms of the LTI plan. Please note that not all roles are eligible to participate in the LTI program, and not all roles are eligible for equity under the LTI plan. RSU awards are also available to eligible new hires, subject to Sandisk's Standard Terms and Conditions for Restricted Stock Unit Awards.
We offer a comprehensive package of benefits including paid vacation time; paid sick leave; medical/dental/vision insurance; life, accident and disability insurance; tax-advantaged flexible spending and health savings accounts; employee assistance program; other voluntary benefit programs such as supplemental life and AD&D, legal plan, pet insurance, critical illness, accident and hospital indemnity; tuition reimbursement; transit; the Applause Program, employee stock purchase plan, and the Sandisk's Savings 401(k) Plan.
Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, benefits, or any other form of compensation and benefits that are allocable to a particular employee remains in the Company's sole discretion unless and until paid and may be modified at the Company's sole discretion, consistent with the law.
$121k-169k yearly est. 31d ago
Information Security Engineer
Lenderlive Network 4.4
Information security analyst job in Temecula, CA
It's fun to work in a company where people truly BELIEVE in what they're doing!
We're committed to bringing passion and customer focus to the business.
The InformationSecurity Engineer is responsible for contributing to the corporate InformationSecurity program by assisting in the identification, recommendation and implementation of industry leading application security tools and techniques. The incumbent will also maintain and update application security processes and procedures and train team members on any relevant updates.
This position is remote, but local to the Temecula, CA office.
Essential Functions
Assist with the development, implementation, and administration of informationsecurity policies, standards, and procedures, adhering to industry best practices
Assist in integrating regulatory compliance requirements (e.g., PCI, GLBA) into the organizational security roadmap
Assist in ensuring that the corporate IT environment is secure and complies with all external audit requirements and federal standards
Coordinate with IT Operations to ensure endpoints and network devices conform to security standards, and that security devices and controls are working as designed
Assist in the identification, evaluation and implementation of industry leading application security tools and techniques
Plan, coordinate, and implement security measures to regulate access to computer data files and prevent unauthorized modification, destruction, or disclosure of information
Perform risk assessments and execute system tests to ensure proper functioning of data processing activities and security measures
Identify potential security risks, and define and document remediation options or mitigating controls
Perform security incident investigations including: chain of custody, containment measures, root cause analysis, and identification of preventive measures
Define and assist in the management of an Incident Response Team that addresses potential or in-progress security events, establishing and adhering to escalation procedures and response times
Perform information systems evidence gathering, to support e-discovery requests and messaging searches
Perform security reviews on requests for new commercial software or material configuration changes to existing software
Perform periodic internal IT security audit functions on IT operational controls, to include system access controls, firewall rule reviews, etc.
Participate in on-call rotation
Perform related duties as requested
Essential Knowledge, Skills, & Abilities
Excellent written and verbal communication skills required
Solid presentation skills
Significant knowledge of security-oriented regulatory requirements and compliance
Excellent familiarity with IT security principles and practices including firewalling, hardening, data loss prevention, threat prevention, and identity management.
Ability to provide technical guidance to less experienced team members
Knowledge of the mortgage industry is helpful, but not required
Commitment and ability to cultivate a diverse and inclusive work environment.
Education
Bachelor's degree in computer science, Engineering, Information Systems Security or a related field is required.
Security class certifications strongly preferred
Azure certifications preferred
CISSP license preferred
Experience
5+ years of related IT experience required
2+ years in an InformationSecurity engineering role
3+ years of experience in a regulated IT environment including some combination of SOX, HIPAA, GLBA, PCI preferred
Compensation and Benefits
Covius offers an extensive benefits package for all employees, including medical, dental, vision and 401(k)!
Compensation: $96,000 to $120,000 annually with a 10% AIP opportunity
Application Guidelines:
For best consideration, please submit your resume and application materials as soon as possible. Review of applications will begin immediately.
Working Conditions
Work is performed in a climate controlled indoor administrative office setting. The noise level in the work environment is usually quiet to moderate, depending upon the office or meeting location.
Physical Demands and Activities
While performing the duties of this job, the employee is frequently required to communicate. The employee frequently is required to remain stationary. The employee is frequently required to move about the office, operate a computer and other office machinery, such as calculator, copy machine, and computer printer; rarely position self to maintain files; rarely moves boxes weighing up to 10 lbs. Close and distance observation required with the ability to observe objects at close range in presence of glare or bright lighting (e.g., computer screen). Must possess the ability to communicate information and ideas so others will understand and have the ability to interact with external and internal stakeholders.
Covius is committed to equal opportunity in all employment practices to all qualified applicants and employees without regard to race, color, religion, gender, gender identity, age, national origin, pregnancy, disability, genetics, marital status, military or veteran status or any other protected category as established by local, state, and federal law. This policy applies to all aspects of the employment relationship including recruitment and hiring, placement, promotion, transfer, compensation, disciplinary action, layoff, leaves of absence, training, and termination. All such employment decisions will be made without unlawful discrimination based on any prohibited basis.
The essential functions, working conditions and physical demands described above are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of this position.
Please note that all s are not intended to be all-inclusive. This job description is not designed to cover all activities, duties or responsibilities that are required of the employee for this job. Employees may be required to perform other duties at any time with or without notice to meet the ongoing needs of the organization.
If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us!
$96k-120k yearly Auto-Apply 52d ago
Security Engineer
Momenti, Inc.
Information security analyst job in Irvine, CA
Momenti is a dynamic and immersive content company that revolutionizestraditional media by bringing visceral experiences to all forms of content. Wespecialize in interactive video that breaks the 4th wall, creating deeperconnections and emotions with our audience. Join us in transforming the waypeople engage with content and bring moments to life. Momenti is at theforefront of the content revolution, and we want you to be part of it.
Job Summary:We are seeking a talented and experienced Security Engineer to join Momentias our first security hire and report directly to our Engineering Director. In thisrole, you will be responsible for ensuring the security and integrity of oursystems, applications, and data. You will work closely with cross-functionalteams to identify potential vulnerabilities, develop and implement securitymeasures, and provide ongoing support to maintain a secure environment. Thisis a unique opportunity to make a significant impact and shape the securitylandscape at Momenti.
Key Responsibilities:• Develop and implement effective security strategies, policies, and proceduresto protect Momenti's systems, applications, and data.• Conduct regular security assessments, vulnerability testing, and risk analysisto identify and address potential security weaknesses.• Collaborate with software engineers and other stakeholders to design andimplement secure coding practices and ensure secure applicationdevelopment.• Monitor and respond to security incidents, including investigating andresolving security breaches, intrusions, and unauthorized access attempts.• Stay up-to-date with the latest security technologies, trends, and bestpractices, and provide recommendations for enhancements to our securityposture.• Educate and train employees on security awareness and best practices topromote a culture of security throughout the organization.Preferred Qualifications:• Solid experience in a security engineering or related role, with a focus onapplication and system security.• Strong understanding of web application security, network security principles,and secure coding practices.• Familiarity with security frameworks such as OWASP, NIST, and CISbenchmarks.• Knowledge of cloud security principles and experience securing cloud-basedenvironments (e.g., GCP, AWS, Azure).• Experience with security assessment tools and techniques, such asvulnerability scanners, penetration testing, and log analysis.Basic Qualifications:• Proven experience in implementing and managing security controls in aproduction environment.• Familiarity with compliance standards and regulations (e.g., GDPR, HIPAA,PCI DSS).• Strong problem-solving and analytical skills, with the ability to assess risksand develop effective mitigation strategies.• Excellent communication and collaboration skills, with the ability to workeffectively in cross-functional teams.
$104k-149k yearly est. Auto-Apply 60d+ ago
Security Engineer
Regal Executive Search
Information security analyst job in Burbank, CA
Responsibilities: Develop and maintain informationsecurity standards and procedures to ensure that information assets are protected and the company is compliant with industry standards and best practices. Participate in security compliance efforts, such as PCI and SoX.
Develop, maintain and deliver training materials for security awareness, policies and procedures.
Run vulnerability assessments and make appropriate recommendations to ensure adequate levels of service and security.
Analyze and diagnose issues relating to a wide variety of hardware and software issues across a range of platforms.
Participate in incident response handling.
Identify projects/initiatives to enhance the Company''s security posture and mitigate risks.
Evaluate and recommend new and emerging security products and technologies.
Administer and maintain security applications used throughout the environment.
Provide regular reports to management regarding IS security.
Qualifications
Strong understanding of eCommerce based application systems.
Knowledge of security audits, risk analysis and vulnerability assessments.
5 years of experience in IT security, including designing, implementing and maintaining security infrastructure.
BS or equivalent in computer technology.
CEH, CCSP, SSCP, CISSP or other Industry certifications a plus.
Strong written and oral communication skills.
Strong documentation and teamwork skills.
Ability to multi-task and prioritize assignments.
Well organized and detail oriented.
Additional Information
Equal opportunity Employer
Please apply with resume in word format and salary needs.
$106k-152k yearly est. 1d ago
Learn more about information security analyst jobs
How much does an information security analyst earn in Glen Avon, CA?
The average information security analyst in Glen Avon, CA earns between $75,000 and $156,000 annually. This compares to the national average information security analyst range of $71,000 to $135,000.
Average information security analyst salary in Glen Avon, CA
$108,000
What are the biggest employers of Information Security Analysts in Glen Avon, CA?
The biggest employers of Information Security Analysts in Glen Avon, CA are: