Senior Security GRC Engineer
Information security analyst job in San Ramon, CA
At PriMed, your uniqueness is valued, celebrated, encouraged, supported, and embraced. Whatever your relationship with Hill Physicians, we welcome ALL that you are.
We value and respect your race, ethnicity, gender identity, sexual orientation, age, religion, disabilities, experiences, perspectives, and other attributes. Our celebration of diversity and foundation of inclusion allows us to leverage our differences and capitalize on our similarities to better serve our communities. We do it because it's right!
Job Description
We are seeking a skilled Governance, Risk, and Compliance (GRC) Engineer to strengthen our security posture and ensure adherence to healthcare regulations. The GRC Engineer will play a vital role in designing, implementing, and maintaining risk management processes, compliance frameworks, and policies that align with healthcare regulations such as HIPAA and HITECH. The ideal candidate will have experience with tools like SAI360, CyberArk, and other compliance and security platforms.
Job Responsibilities:
Develop, implement, and maintain GRC policies, processes, and controls in alignment with industry best practices and regulatory requirements (e.g., HIPAA, HITECH, NIST, ISO 27001).
Perform risk assessments and develop mitigation strategies for identified security risks.
Administer and optimize SAI360 for governance, risk management, and compliance activities, including reporting and policy management.
Collaborate with cross-functional teams to ensure new projects and systems are designed with security and compliance in mind.
Monitor and report on compliance status, identifying gaps and proposing remediation strategies.
Oversee third-party vendor risk assessments and ensure adherence to security requirements.
Support internal and external audits by providing documentation, evidence, and responses to audit findings.
Conduct security awareness training programs and promote a culture of compliance within the organization.
Required Experience/Skills/Knowledge:
5+ years of experience in Governance, Risk, and Compliance roles or a related field.
Strong knowledge of healthcare regulations, including HIPAA, HITECH, and other relevant standards.
Proficiency in GRC tools such as SAI360 for compliance and risk management.
Experience with privileged access management tools like CyberArk.
Solid understanding of risk assessment methodologies and security frameworks, including NIST CSF, ISO 27001, or COBIT.
Excellent communication and collaboration skills to engage with technical and non-technical stakeholders.
Strong analytical and organizational skills with attention to detail.
This role is critical in maintaining our organization's compliance with healthcare security standards and reducing risk exposure.
Required Education:
Bachelor's degree in computer science, Information Technology, Cybersecurity, or a related field.
Equivalent work experience may be considered in lieu of a degree.
Access Assurance Analyst - USDS
Information security analyst job in San Jose, CA
Team Intro The Access Assurance vertical within USDS Data Identity and Access Management (DIAM) Team is responsible for designing and maintaining an access management program with a mission to enforce the principle of least privilege. We strive to establish secure and compliant processes around provisioning, deprovisioning and governance of access to USDS data and infrastructure proactively identifying and reducing risks.
Job Overview:
As an Access Assurance Analyst, you will be part of the team responsible for Access Assurance within TikTok USDS. You will be responsible for supporting the team along with a team of cross-functional cyber, privacy, engineering, and data protection analysts to define, implement, manage, and measure controls to protect data in accordance with USDS policies and standards relevant to geographical regulations, contractual commitments, and confidentiality requirements. The Access Assurance Analyst will play a pivotal role in operationalization of access management programs in USDS.
In order to enhance collaboration and cross-functional partnerships, among other things, at this time, our organization follows a hybrid work schedule that requires employees to work in the office 3 days a week, or as directed by their manager/department. We regularly review our hybrid work model, and the specific requirements may change at any time.
Responsibilities:
* Design access management program that addresses data residency and fine-grained role-based access requirements and controls as necessitated by business need and regulations
* Assist in the development and implementation of Access governance frameworks, policies, and procedures.
* Build and review technical and functional requirements for in-house or external technologies to support access management and assurance needs, including applying appropriate security measures
* Operationalize access management workflows to improve efficiency
* Support periodic reviews of access to USDS data and systems
* Drive remediation of non-compliant access in a timely fashion
* Implement and enforce mechanisms to proactively monitor, respond and report on inappropriate data access events
* Work with other information security teams to classify and categorize data based on sensitivity and compliance requirements
* Support interactions with Risk and Compliance to understand control requirements and provide information to support findings for non-compliance with internal security policies
* Responsible for designing and reporting key metrics and visualizations for weekly, monthly and bimonthly cadences across multiple audiences
* Participate in security reviews to ensure compliance with access governance policies.
* Foster a principle of least privilege for access management
* Collaborate with key stakeholders to ensure alignment of access governance initiatives with organizational goals.Minimum Qualifications:
* Bachelor's degree in a related field (e.g., Information Management, Computer Science, Business Analytics, Cyber Security)
* 5+ years of experience in identity and access management or access governance & 5+ years of experience working with IAM tools and strong knowledge of Access management concepts (RBAC, PAM, Access Reviews, SOD, LCM, provisioning and deprovisioning of Access)
* Experience in designing/deploying Access management solutions, Experience analyzing large data sets across multiple database types (e.g., MySQL, Hive, Redis etc) leveraging SQL etc., Experience with industry frameworks, standards and regulations (e.g. ISO, NIST)
* Ability to write scripts, develop automations, configure tools, work with APIs and databases while being Proficient in at least one software programming language (Python,Java,Ruby etc) along with Familiarity with Cloud-based technology deployments
* Demonstrate ability to quickly assimilate to new knowledge and remain current on new developments in cybersecurity capabilities and industry knowledge
* Strong analytical and problem-solving skills with the Ability to communicate technical concepts to a broad range of technical and non-technical staff
* Comfortable working in a fast-paced, dynamic environment
Preferred Qualifications:
* Strong understanding of technology environments and various databases
* Experience working with technology partners to validate data-related problems
* Experience working with Microservices architecture
* Experience in automating access management workflows to reduce operational overhead
* Experience with risk and controls frameworks including (ISO 27001, NIST CSF, NIST RMF, FAIR, COBIT, NIST RMF, ISO 31000 etc.)
INFORMATION SECURITY ANALYST
Information security analyst job in San Jose, CA
Opportunity Type CLASSIFIED EMPLOYMENT OPPORTUNITY Position Title INFORMATION SECURITY ANALYST Posting Number S2549 Close/First Review Date 11/16/2025 Department ITSS (Information Technology Support Services) Work Location District Office Position Status Full Time Salary Range $141,330 - $172,437 Annual Salary (Range 150: Classified Salary Schedule Fiscal Year 2025-2026). Starting placement is generally at Step 1. Benefits Summary
In addition to the salary, this position qualifies for the choice of one of the District's excellent Health Benefits and Welfare plans, which the premium cost is 100% paid by the District for the employee and their eligible dependents, and one health plan costing an estimated $60,000 for the District for fiscal year 2025-2026. We offer two medical plans (Anthem Blue Cross [PPO] and Kaiser Permanente (HMO]); dental (Delta Dental PPO); vision (VSP Choice); life insurance for the employee (The Hartford); life insurance for eligible dependents (The Hartford); a long term disability/income protection plan (The Hartford); and an employee assistance plan (Anthem EAP).
In addition, the District contributes an additional 26.81% of the employee's salary towards an eligible employee's pension (CalPERS).
Employees may also elect to participate in optional plans including purchasing additional life insurance for themselves and their eligible dependent(s); enroll in a medical, transportation, and/or dependent care Flexible Spending Account(s) (with the $4 monthly administrative fee paid by the District); and set pre-taxed dollars aside to supplement their pension in a 403b (tax shelter annuity) and/or a 457 (deferred compensation) plan(s).
Classified employees also earn 10 to 22 days per year of vacation (based on years of service), and up to 12 sick leave days (pro-rated for less than full-time positions). There are currently 20 paid holidays.
Position Description
POSITION SUMMARY
The Information Security Analyst reports to Executive Director of ITSS (Information Technology Support Services) at the District Office. The work schedule is 12 months per year; 40 hours per week; Monday - Friday; 8:00 a.m. - 5:00 p.m.
This position is represented by CSEA (California School Employees Association), Chapter 363.
POSITION PURPOSE
Reporting to Executive Director, ITSS or an assigned administrator, the Information Security Analyst performs complex work related to the District's information security program including testing, analysis and evaluation of the integrity and confidentiality of enterprise systems, network, assets and communication technology throughout the District. The position monitors security systems and conducts periodic risk assessments to identify, troubleshoot, diagnose, resolve and report security problems and breaches; assists in coordinating and conducting investigations involving District technology resources, and assists with security awareness training.
DISTINGUISHING CHARACTERISTICS
This position focuses on threat and vulnerability management with exposure and support on all aspects of the cybersecurity practice. Incumbent in this position should have advanced knowledge on risk identification, protection and compliance, threat detection, incident response plan development and annual review, and recovery services to achieve business resilience.
KEY DUTIES AND RESPONSIBILITIES
1. Analyze, evaluate and implement security applications, policies, standards and procedures intended to prevent the unauthorized use, disclosure, modification, loss or destruction of data; work with the campus community and other staff to ensure the integrity and security of the information technology infrastructure.
2. Lead the development, testing and implementation of information security products and control techniques in all locations throughout the District.
3. Work with campus and district technology teams to ensure the security of all applications and assets.
4. Monitor and review security systems and logs. Identify, troubleshoot, diagnose, resolve, document and report security problems and incidents; help coordinate and conduct investigations of suspected breaches; respond to emergency information security situations.
5. Collaborate with application programming team and other IT staff to ensure production applications meet established security policies and standards.
6. Assist with training and education on information security and privacy awareness topics for District administrators, faculty and staff; assist in the development of appropriate security-incident notification procedures for District management.
7. Work with vendors to conduct vulnerability assessments to identify existing or potential electronic data and assets compromises and their sources; participate in investigative matters with appropriate law enforcement agencies.
8. Perform audits and periodic inspections of District information systems to ensure security measures are functioning and effectively utilized and recommend appropriate remedial measures to eliminate or mitigate future system compromises.
9. Review, evaluate, and recommend software products related to IT systems security, such as virus scanning and repair, encryption, firewalls, internet filtering and monitoring, intrusion detection, etc.
10. Monitor and maintain the District's security event information system (SEIM) and data loss prevention software.
11. Manage security systems and policies including but not limited to servers, firewalls, email security, and Microsoft 365 environment.
12. Recommend and implement security policies, protocols, practices and lead in creation of security training and guidance to staff.
13. Assist in the secure management and maintenance of the District's network authentication systems for wired and wireless network access.
14. Review security practices and controls of third-party service providers that handle District sensitive data, and review security controls and features of third-party software systems.
15. Ensure that maintenance, configuration, repair and patching of systems occurs on a scheduled and timely basis utilizing best practices in change management and consistent with policies and procedures.
16. Keep current with latest emerging security issues and threats through list servers, blogs, newsletters, conferences, user groups, and networking and collaboration with peers in other institutions.
17. Perform other duties reasonably related to the job classification.
EMPLOYMENT STANDARD
Knowledge of:
1. Compliance and industry cybersecurity standards frameworks such as NIST 800 and ISO standards.
2. Emerging technologies and the possible impact on existing information systems, instructional processes and business operations.
3. Incident response best practices and software license compliance laws.
4. Troubleshooting tools for computing hardware, servers and network equipment including but not limited to switches, routers, and firewalls.
5. Enterprise resource planning systems, Microsoft 365 and Active Directory and Azure Active Directory.
6. Principles of program design, coding, testing and implementation.
7. Advanced knowledge of desktop and server operating systems including Windows and Linux.
8. Disaster recovery and backup including business continuity planning.
9. Principles of training, support, and services to end-users.
10. General research techniques and data driven analytics.
11. Modern office administrative practices and use of tools including computers, websites and other applications related to this job.
Skills and Ability to:
1. Apply current NIST and ISO standards to current operations.
2. Respond to incidents and events in a timely manner.
3. Prepare clear and concise system documentation and reports.
4. Prioritize assigned tasks and projects.
5. Communicate complicated technical issues and the risks they pose to stakeholders and management.
6. Establish and maintain effective and cooperative working relationships with others.
7. Analyze situations accurately and adopt effective course of action.
8. Coordinate, develop, and implement projects.
9. Work with attention to detail and independently with minimum supervision.
Required Qualifications
EDUCATION AND EXPERIENCE
1. A Bachelor's degree from an accredited institution with major course work in computer information systems, computer science, business administration, or related field.
2. Two years of experience performing information security duties, which may include implementing, overseeing, and/or managing information security technologies, process, or programs, including identification, protection, detection, response, and recovery activities.
Certification:
1. Professional security or privacy certification, such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or other similar credentials.
District's Diversity
* Demonstrated sensitivity, knowledge and understanding of the diverse academic, socioeconomic, gender identity, sexual orientation, cultural, disability, and ethnic background of groups historically underrepresented, and groups who may have experienced discrimination.
* Success integrating diversity as appropriate into the major duties outlined in the job description and in the duties listed in the District's hiring policy; or demonstrated equivalent transferable skills to do so.
Desired Qualifications
1. Bilingual abilities, desirable.
Foreign Degree
For positions that require a degree or coursework:
Degree(s) must have been awarded by a college or university accredited by an accrediting body recognized by the U.S. Council on Post-Secondary Accreditation and/or the U.S. Department of Education.
All degrees and credits earned outside of the United States must have a U.S. evaluation (course by course) of the transcripts and must be submitted with the application.
Degrees earned outside of the U.S. without a U.S. credential evaluation attached, will not be considered.
Working Environment
Physical Demands:
1. Must sit for long periods of time, use hands and fingers to operate an electronic keyboard, reach with hands and arms, and speak clearly and distinctly to ask questions and provide information, hear and understand voices over telephone and in person.
2. The physical demands described here are representative of those that must be met by an individual to successfully perform the essential functions of this job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.
About San Jose/Evergreen Community College District
The District is represented by dedicated and talented employees who are passionate about providing our student population with the best educational experience possible. The District recognizes that cultural diversity in the academic environment promotes academic excellence; fosters cultural, racial and human understanding; provides positive roles models for all students, and creates an inclusive and supportive educational and work environment for its employees, students, and the community it serves.
As of Spring 2024, with enrollment of approximately 15,655 students per semester, and an extremely diverse student population (Hispanic/Latino 45.20%, Black/African-American 3.45%, Asian/Pacific Islander 31.70%, American Indian/Native American 0.36%, White/Caucasian 12.76%) attaining educational goals reflecting 56% - Transfer to a 4-Year College/ University, the District's emphasis on student success makes it a recognized educational leader in the State.
The District encourages a diverse pool of applicants to serve as colleagues to an existing diverse classified staff consisting of 43.9% Latinx, 25.3% Asian/Pacific Islander, 4.2% Black/African American, 0.3% American Indian/Native American, 17.9% White/Caucasian, and as well as encouraging applications from all qualified, outstanding applicants.
Important Information
EQUAL OPPORTUNITY EMPLOYER STATEMENT:
San José-Evergreen Community College District is an Equal Opportunity Employer committed to nondiscrimination on the basis of ethnic group identification, race, color, language, accent, immigration status, ancestry, national origin, age, gender, gender identity, religion, sexual orientation, transgender, marital status, veteran status, medical condition, and physical or mental disability consistent with applicable federal and state laws.
CONTACT:
Employment Services,
Human Resources, SJECCD
40 S. Market Street, San Jose, CA 95113
Phone: **************
Email: *******************************
Employment Website: ******************************
District Website: **************
APPLICATION PROCEDURES:
Interested applicants MUST SUBMIT ONLINE ALL of the following materials by the First Review Date/Closing Date as listed on the job announcement. Applications received after the First Review Date will only be forwarded to the hiring committee at their request.
1. A completed online San José-Evergreen Community College District APPLICATION.
2. A COVER LETTER (Stating how you feel you meet the qualifications as outline in the job announcement).
3. A current RESUME/CURRICULUM VITAE
4. TRANSCRIPT - (If Required) If a degree is listed as a requirement, transcripts (Not Diplomas) MUST INCLUDE confer or award date of stated degree. Unofficial transcripts will be accepted; however if the position is offered, official transcripts will be required prior to employment. If the transcripts or degrees are from outside of the United States, an official certification of equivalency to U.S. degrees by a certified U.S. credential review service (course by course of the transcripts) MUST also be submitted. (See below for a list of suggested services that provide foreign degree equivalency evaluation to U.S. degrees).
Note: Some positions may require additional documents and/or certificates, in addition to the items listed above. Please refer to the job announcement.
OTHER APPLICANT INFORMATION:
1. Only complete application materials will be considered. No exceptions.
2. Letters of Recommendation are NOT required and will not be forwarded to the hiring committee.
3. Upon hire the successful candidate must provide the required documents of identity and authorization to work and attest he/she is authorized to work in the United States.
4. Application materials become the property of the District and will not be returned or duplicated.
5. Travel expenses to attend the interview are the responsibility of the candidate.
6. Meeting the minimum qualifications does NOT assure an interview.
7. The District may re-advertise, delay, choose not to fill the position, or choose to fill more than one position.
Suggested services that provide foreign degree equivalency evaluation to U.S. degrees:
Academic Credentials Evaluation Institute, Inc.
Website: ***************************
Education Records Evaluation Services
Website: ************
International Education Research Foundation
Website: ********************
World Education Services
Website: ***********
Easy ApplySenior Physical Security System Engineer
Information security analyst job in San Jose, CA
Team Introduction The Physical Security System and Technology Team, falls under the physical security department of the Corporate Services. Its core responsibility is to leverage technological means to guard against security risks within the workplace. In addition, the team undertakes the daily operation, maintenance, and upgrade of global physical security and prevention systems (such as Lenel, Hikvision, Avigilon, etc.), and is also responsible for the management and maintenance of physical security-related data.
Responsibilities:
* Provide technical support to users, document system issues reported, analyse & identify root-cause, recommend solutions, fix issues, provide status updates to users, and provide periodical incident reports & updates to management.
* Experienced with SQL database open connectivity development. Able to provide guidance to the internal R&D team members on the integration between internal developed applications and security systems.
* Coordinate with security system vendors to ensure outstanding issues raised by internal R&D teams are being addressed by vendors in a timely manner. Document issues and provide status updates to management on a periodical basis.
* Act as the primary point of contact to the security system vendor. Attend a periodical meeting with the security system vendor as required.
* Perform periodical system health checks to ensure safe, stable and efficient operation of the security system on a global basis.
* Perform application & system upgrade based on recommendation by the vendor to ensure the version in used meets standard operation. Enhances existing software capabilities, and develops direct system testing and validation procedures.Minimum Qualifications:
* Studied in any of these faculties: Computer Science, Information Technology, Programming & Systems Analysis, Science.
* Experienced in one or more programming languages, such as scripting experience in Shell and Python, and SQL.
* Experienced in designing, building, and maintaining large-scale distributed applications & systems or experience in databases, operating systems, and server management & maintenance.
Preferred Qualifications:
* Be highly self-motivated, able to proactively identify problems, and promote the continuous development and progress of related projects.
* Lenel physical security-related applications & systems certified/trained.
Principal Cyber Security Engineer
Information security analyst job in San Ramon, CA
Key Responsibilities
Architectural Leadership: Design, develop, and maintain the comprehensive security architecture for Cloud Software Group's products and corporate infrastructure.
Cloud Security Expertise: Lead the security strategy for our cloud environments, including AWS, Azure, and Google Cloud, ensuring best practices and compliance.
Security Domain Knowledge: Provide expert guidance across a broad range of security domains, including application security, network security, identity and access management (IAM), data protection, and incident response.
Collaboration and Communication: Work closely with engineering, DevOps, product, and leadership teams to embed security into every stage of the software development lifecycle. Present complex security concepts to both technical and non-technical audiences.
Threat Modeling & Risk Analysis: Conduct threat modeling and risk assessments to identify vulnerabilities and recommend mitigation strategies.
Mentorship: Mentor and guide junior security professionals, fostering a culture of security awareness and continuous improvement.
Compensation may vary depending on your location, qualifications including job-related education, training, experience, licensure, and certification, that could result at a level outside of these ranges. Certain roles are eligible for additional rewards, including annual bonus, and sales incentives depending on the terms of the applicable plan and role as well as individual performance. NY generally ranges: $190,720-$286,080 CA generally ranges: $199,012-$298,518 All other locations fall under our General State range: $165,843-$248,765 Benefits may vary depending on the nature of your employment with Cloud Software Group and the country where you work. U.S. based employees are typically offered access to healthcare, life insurance and disability benefits, 401(k) plan and company match, among others. This requisition has no specific deadline for completion.
About Us:
Cloud Software Group is one of the world's largest cloud solution providers, serving more than 100 million users around the globe. When you join Cloud Software Group, you are making a difference for real people, each of whom count on our suite of cloud-based products to get work done - from anywhere. Members of our team will tell you that we value passion for technology and the courage to take risks. Everyone is empowered to learn, dream, and build the future of work. We are on the brink of another Cambrian leap -- a moment of immense evolution and growth. And we need your expertise and experience to do it. Now is the perfect time to move your skills to the cloud.
Cloud Software Group is firmly committed to Equal Employment Opportunity (EEO) and to compliance with all federal, state and local laws that prohibit employment discrimination. All qualified applicants will receive consideration for employment without regard to age, race, color, creed, sex or gender, sexual orientation, gender identity, gender expression, ethnicity, national origin, ancestry, citizenship, religion, genetic carrier status, disability, pregnancy, childbirth or related medical conditions (including lactation status), marital status, military service, protected veteran status, political activity or affiliation, taking or requesting statutorily protected leave and other protected classifications.
Cloud Software Group will consider qualified applicants with a criminal history and conduct the recruiting process in accordance with the California Fair Chance Act, Los Angeles County Fair Chance Ordinance for Employers and San Diego Fair Chance Ordinance. For access to the laws see the following links: California FCA and Los Angeles FCO.
If you need a reasonable accommodation due to a disability during any part of the application process, please contact us at **************, HR directly via ************** or email at *************** for assistance.
Auto-ApplyAMD-XILINX: Senior Security Operations Specialist
Information security analyst job in San Jose, CA
As a key member of the Security Operations team, the security administrator will implement and provide support for operations of Firewalls, Proxies, Load Balancers, IPS / IDS, SIEM, Vulnerability Management and other technologies. The security administrator will ensure appropriate security controls and monitoring are in place for external network connections by coordinating with project teams, users and company partners.
Key Responsibilities:
- Create and maintain security infrastructure that follows industry best practices including a high level of availability and ease of user access.
- Evaluate and develop systems to enhance our security posture while reducing overall digital security risk.
- Lead IT infrastructure integrations with partners from a security perspective.
- Maintain awareness of industry security threats and respond to security incidents.
- Assist in the architecting of new products, features, and capabilities.
- Coordinate with team and Global Operation peers to test and troubleshoot alarm and access control devices.
Required Skills:
- Install, configure, monitor and respond to Security Systems in an enterprise environment.
- Detailed technical experience in the installation, configuration and operation of high-end firewall appliances.
- Strong TCP/IP networking skills and solid understanding of TCP/IP stack.
- Strong understanding of core internet protocols and applications.
- Extensive knowledge of different security threats.
- Assess risk and vulnerabilities of the network Scanning, Remediation, OSH Hardening.
- Familiarity with compliance regulations and CIS Critical Security Controls frameworks and standards.
- Patch Management of security systems.
- Experience in Security Event Correlation SIEM
- Experience in securing and deployment of public cloud environments (AWS, Azure).
- Liaise with global operations groups on security incidents
- Responsible for day to day maintenance of security infrastructure.
- Practical knowledge of the following technologies: Routing, Switching, VPN, LAN, WAN, Network Security, Stateful Inspection Firewall, NGFW, Firewall policies, NAT, IPS, Botnet, DDoS, Web Filtering, Reverse proxies, Certificate management (PKI), MFA.
- Able to work independently and as a member of a high-performance team.
- Ability to manage projects using appropriate tools and communication methods.
- Ability to manage multiple tasks (many are complex) simultaneously and to bring activities to closure.
Information Security
Information security analyst job in Pleasanton, CA
This job requires relocation to the United States, Silicon Valley, through the use of a TN visa. If selected for this job, the process of coming to the United States will be handled by Tech-Mex.
The Information Security Engineer maintains 24x7 support, responds to vendor security questionnaires, performs monitoring and maintenance of the security infrastructure and components, participates in project planning and deployment of new technologies and will be responsible for remediation of identified compliance and risk gaps. He/she works independently, operating under the defined guidelines established by the Director of Information Technology and Security.
ESSENTIAL Job Duties & Responsibilities
Monitor and advise on information security issues related to the systems and workflow to ensure the internal and external security controls for the company are appropriate and operating as intended
Documenting gaps between vendor requirements and National MIs infrastructure
Coordinate and execute IT security projects
Coordinate response to information security incidents
Conduct company-wide audits and manage remediation plans
Collaborate with other areas of IT to manage security vulnerabilities
Conduct research to keep abreast of latest security issues
Ensures that system documentation is accurate and updated as needed
Participates in disaster recovery (DR) exercises as directed
Logfile review and analysis
Install and maintain new systems
Prioritize remediation of gaps based on internal and external audits
Prepares compliance reports by collecting, analyzing, and summarizing data
Evaluates information to determine compliance with laws, regulations, or standards
MINIMUM QUALIFICATIONS
3-5 plus years related work experience
Vendor audit and compliance experience, preferably with the SIG framework
Strong technical skills in anti-virus, DLP, and PKI
Strong experience with the McAfee suite of products
Solid understanding of networking concepts and system administration
Experience with Nessus, RSA envision, RedHat Linux and database security
Knowledge of data compliance and privacy standards and regulations as they apply to insurance and banking industries
Knowledge of Information Security Standards (ISO27001, NIST, etc)
Self-motivated, self-directed and shows attention to detail while working
Ability to effectively prioritize and execute reporting tasks in a fast-paced, results-driven environment
Extensive experience working in a team-oriented, collaborative environment with a diverse team of business and IT staff
Bachelor's degree in Computer Science or Information Systems preferred; Professional certifications are an advantage
Essential Worker Competencies
The ability to function independently with minimal supervision.
Works ethically and with integrity supporting organizational goals and values
Displays commitment to excellence
Completes work in a timely manner and meets deadlines
Good verbal and written communication skills
Meets productivity standards and achieves key outcomes
Is dependable and keeps commitments
Contributes to building a positive team spirit and treats others with respect
Candidate will be relocated to the United States
Security Engineer - D&R
Information security analyst job in San Jose, CA
Figure is an AI robotics company developing autonomous general-purpose humanoid robots. The goal of the company is to ship humanoid robots with human level intelligence. Its robots are engineered to perform a variety of tasks in the home and commercial markets. Figure is headquartered in San Jose, CA.
We are looking for a Security Engineer to join the Security & Privacy team at Figure, focusing on designing, implementing, and managing the detection and response tooling and processes.
Responsibilities:
Design, pilot, and implement central logging and alerting systems to detect malicious activity on Figure's infrastructure, including endpoints, networks, labs, and cloud environments
Develop tools and automation strategies to improve Figure's ability to hunt threats and respond to incidents
Participate in team operations, such as investigating events generated by the alerting pipeline and triage potential incidents, and drive response efforts in case of an active incident
Identify, analyze, and build threat intelligence on relevant trends in adversary tactics, techniques, and procedures (TTPs) for sophisticated threat actors spanning APTs and cybercrime.
Requirements:
Experience several of the following detection and response areas: digital forensics, malware analysis, incident management, host/network intrusion detection, threat intelligence
Demonstrated knowledge in threat hunting and developing logic to automate threat detection and incident response
Work record of collaborating with internal and external stakeholders at all levels of a company
Practical experience in a BeyondCorp model
Strong software engineering (beyond scripting or automation) skills in C/C++, Rust, Golang, Python or similar
Solid knowledge of operating system internals (Linux, Windows, mac OS), and experience with detection in Cloud environments (Azure, GCP, AWS)
Bachelor of Science in Computer Science, Engineering, Information Systems, or equivalent years of experience in a related technical field
6+ years of experience in the field of security monitoring or related security role
Excellent verbal and written communication skills, with high attention to detail
The US base salary range for this full-time position is between $150,000 - $350,000 annually.
The pay offered for this position may vary based on several individual factors, including job-related knowledge, skills, and experience. The total compensation package may also include additional components/benefits depending on the specific role. This information will be shared if an employment offer is extended.
Auto-ApplyCyber Security Engineer
Information security analyst job in San Jose, CA
** 9 time INC 500/5000, 9 time BBJ "Pacesetter ", 5 time SIA-fastest growing** ___________________________________________________________ Kashif Meraj | TalentBurst, Inc. Boston | San Francisco | Miami | Milwaukee | Toronto | New Delhi | Bangalore
Work: **************
575 Market Street, Suite 3025 | San Francisco, CA 94105 | *******************
Certified Minority Business Enterprise (MBE)
Job Description
Job Title: IT Security Engineer
Location: San Jose, CA 95110
Duration: 6 Months+
Responsibilities:
• Work with Client's Identity and Access Management team to administer and implement appropriate security controls and workflows.
• Work with various internal employees to help train and educate on good security practices and specifics about end-user security tools.
• Work with a team of Security Engineers to handle incoming requests, respond to issues, troubleshoot reported problems, and identify solutions.
• Work closely with the teams that provisions, customizes, monitors, manages and upgrades our enterprise password vault solution.
• Communicate with customers to address their security requirements and provide guidance.
Requirements:
• Experience with and understanding of enterprise password vault configurations and automations. Specific CyberArk experience is preferred
Additional Information
Please reach me for further query or drop your updated resume at ***********************************
Easy ApplyPrincipal Cloud Security Engineer
Information security analyst job in San Ramon, CA
We are seeking an experienced and proactive DevSecOps engineer with expertise in AWS and AZURE Platforms to join our Cybersecurity Application Platform Security Team. This role combines expertise in AWS & AZURE platforms security with a strong foundation in DevSecOps practices to ensure the ‘secure by design', ‘secure by default' principles throughout development, deployment, and operation of AWS & AZURE platforms. The ideal candidate will have hands-on experience with Cybersecurity platforms, with a deep understanding of AWS & AZURE cloud platforms. This position plays a critical role in assisting customer portfolio teams to secure SaaS, PaaS platforms, maintain compliance and availability.
DevSecOps engineer role responsible for security automation of cloud services.
Job Responsibilities
Secure the AWS & AZURE Platform: Implement best practices to ensure AWS & AZURE applications are “secure by design” and “secure by default” protecting sensitive data and workflows.
Provide guidelines on usage of AppExchange / Vendor products versus using out of box capabilities with a keen eye for cybersecurity risk.
Risk Identification & Mitigation: Proactively identify security risks across the AWS & AZURE ecosystem and implement solutions to address vulnerabilities.
DevSecOps Enablement: Drive DevSecOps practices within the organization by embedding security into the development lifecycle of AWS & AZURE applications.
Collaboration with Stakeholders: Partner with various customer portfolio teams to influence their roadmaps, ensuring security is a foundational element in their strategies.
Data Security & Compliance: Ensure compliance with data protection regulations and implement robust data security measures within AWS & AZURE and integrated systems.
Cloud Integration Expertise: Leverage your knowledge of AWS & AZURE to secure integrations
Continuous Improvement: Stay up to date on emerging threats, trends, and technologies in application security to continuously improve our security posture.
Communication & Advocacy: Act as a trusted advisor on security matters, effectively communicating complex technical concepts to both technical and non-technical stakeholders.
Qualifications
We're looking for someone with:
Recent 5+ years of experience in IT focused on DevSecOps, DevOps or Security Engineering roles.
Recent 3+ years of shell scripting, aws-cli, python, lambda.
Recent 1+ years of Terraform deployments and Terraform templates (Infrastructure as Code).
Knowledge of and experience with CI/CD technologies.
Knowledge of and experience with continuous security practices.
Knowledge of infrastructure automation and infrastructure as code.
Demonstrated ability to integrate security practices into AWS & AZURE applications.
Proficiency in data protection techniques such as encryption, tokenization, and access controls.
Bachelor's degree in computer science, Information Security, or a related field.
Desired Skills
Experience with Salesforce, SAP, and MuleSoft architecture, development, and administration with a focus on platform security (e.g., profiles, roles, permissions, encryption).
Excellent Communication Skills: Ability to clearly articulate security concepts to diverse audiences, including engineers, product managers, and executives.
Collaboration & Influence: Proven ability to work cross-functionally with teams to align on security priorities and influence roadmaps.
Preferred Technical Skills/ Qualifications
Relevant certifications in Cybersecurity - SSCP, CISSP, CISM preferred.
AWS certifications (e.g., AWS Certified Solutions Architect or AWS Certified Security Specialty).
AZURE certifications.
Experience with regulatory frameworks like GDPR, CCPA, or HIPAA.
The ideal candidate will be passionate about security, have a proactive mindset, and be able to balance security requirements with business needs. They should be comfortable working in a fast-paced environment and be able to adapt to evolving security threats and technologies
Salary Range
$63.58 - $100.38 USD (Hourly)
Please note that the salary information provided herein is base pay only (gross); it does not include other forms of compensation which may or may not apply to this specific position, namely, performance-based bonuses, benefits-related payments, or other general incentives - none of which are guaranteed, may be subject to specific eligibility requirements, and are wholly within the discretion of Astreya to remit.
Further, the salary information noted above is a range that consists of a minimum and maximum rate of pay for this specific position. Where an applicant or employee is placed on this range will depend and be contingent on objective, documented work-related considerations like education, experience, certifications, licenses, preferred qualifications, among other factors.
Astreya offers comprehensive benefits to all Regular, Full-Time Employees, including:
Medical provided through Cigna (PPO, HSA, EPO options) / Medical provided through Kaiser (HMO option only) for California employees only
Dental provided through Cigna (DPPO & DHMO options)
Nationwide Vision provided through VSP
Flexible Spending Account for Health & Dependent Care
Pre-Tax Account for Commuter Benefit/Parking & Transit (location-specific)
Continuing Education and Professional Development via various integrated platforms, e.g. Udemy and Coursera
Corporate Wellness Program
Employee Assistance Program
Wellness Days
401k Plan
Basic Life, Accidental Life, Supplemental Life Insurance
Short Term & Long Term Disability
Critical Illness, Critical Hospital, and Voluntary Accident Insurance
Tuition Reimbursement (available 6 months after start date, capped)
Paid Time Off (accrued and prorated, maximum of 120 hours annually)
Paid Holidays
Any other statutory leaves, paid time, or other fringe benefits required under state and federal law
Auto-ApplyCloud Security Analyst-AWS or Azure, Devops
Information security analyst job in San Ramon, CA
Hands-on cloud security engineer who has a deep understanding of emerging technologies including Openstack, PaaS - Pivotal cloud foundry, Mesos, Docker container, Security, Software defined networks, Cloud integration technologies.
Hands-on deployment of AWS\Azure IaaS components necessary to support the Cyber Security deployment needs, as well as approved Cyber Security specific solutions in the AWS\Azure environment to support these efforts.
Qualifications
Bachelor's Degree in STEM and/or a minimum of 4 years of equivalent experience
Minimum of 6 years of experience of application design and architecture
Minimum of 6 years of experience with deployment of cloud controls for infrastructure, platform, and applications (IaaS/SaaS/PaaS)
AWS and Azure experience a must
Additional Information
All your information will be kept confidential according to EEO guidelines.
Analyst V IT Solutions Delivery - UKG Pro WFM
Information security analyst job in Pleasant Hill, CA
Ahold Delhaize USA, a division of global food retailer Ahold Delhaize, is part of the U.S. family of brands, which includes five leading omnichannel grocery brands - Food Lion, Giant Food, The GIANT Company, Hannaford and Stop & Shop. Our associates support the brands with a wide range of services, including Finance, Legal, Sustainability, Commercial, Digital and E-commerce, Technology and more.
The Solutions Delivery Analyst V role is designed to serve as the lead technical subject matter expert for assigned systems, services, or applications they deliver & support for specific functional areas. This role will lead Solution Delivery execution of mid to large-sized IT initiatives in partnership with the business driving value for Ahold Delhaize USA & our Brands. In addition to delivering new and innovative solutions for the business, this role will provide complete third level production support, engage with engineers, follow up to ensure all business services are operationally stable, monitor supplier performance/execution and hold suppliers accountable for meeting contractual obligations. In addition, in this role the Solution Delivery Analyst V is responsible for making long term recommendations for operational improvements and overseeing implementation of those recommendations to improve overall system stability for identified functional areas. This role is responsible for providing high quality technical support including knowledge updates, configuration and routine application updates, application patch management and overall continuous improvement expectations.
Our flexible/ hybrid work schedule includes 3 in-person days at one of our core locations and 2 remote days.
Our core office locations are Salisbury, NC, Scarborough, ME, and Carlise, PA.
Applicants must be currently authorized to work in the United States on a full-time basis.
Duties & Responsibilities:
Lead Technical SME for systems, services and applications ranging from simple to most complex for an identified functional area.
Responsible for coaching and mentoring other members of the functional area to increase overall technical knowledge within the organization.
Responsible for leading primarily large-scale projects including driving the below listed activities:
Resource management allocation and budget management associated with assigned project delivery in coordination with the PMO
Oversee activities of lower level Solution Delivery Analysts associated with delivery on mid to large scale projects including determining work assignments, tracking progress and making necessary adjustments in order to meet delivery objectives
In partnership with IT Sourcing and Solution Delivery Managers works on contracts and Statements of Work (SOW's) within their identified Bill of Authority (BOA)
Oversees the translation of business needs identified by either the business and/or production owners by lower-level team members into either agile stories or waterfall business requirements ensuring needs of the business are clearly understood and documented
Partners with Solution Engineers in building out technical specifications that will deliver on identified business requirements and outcomes
Leads the business and Quality Assurance in building out test cases/matrices that will ensure proper testing of solutions prior to production deployment
Leads team members through System Integration Testing, record passed test cases, provide detailed documentation on failed tests and re-execute tests as needed.
Work with Solution Engineers on failed test cases and oversees changes to technical specifications needed to meet solution outcomes
In partnership with Service Delivery manage the completion of RUN Book Documentation and prepare for production support turnover
Participate in Solution Implementation & Post Production Hyper Care Support leading any efforts to resolve cutover issues ensuring the initiative is closed out properly.
Responsible for and drives all third level technical support for application and systems services for a specifical functional area
Technical Support SME for the identified service or application and serves as the technical resolver and knowledge provider. Coaches and mentors lower level Solution Delivery Analysts on a daily basis.
Accountable and responsible for supplier performance to deliver on technical support needs and service level expectations. Manages support relationship for mid to large-size software supplier relationships holding suppliers accountable for their contractual obligations
Responsible for engagement with Engineers and Product Teams to ensure operational support needs are met and responsible for all technical engagement with suppliers.
Leads root cause analysis on complex issues, recommends and implements opportunities for continuous performance improvement of systems including those delivered through suppliers.
Partners with Engineers, Product Teams, and business groups to deliver standard to complex configuration and operational changes for the services/applications within established standards.
Leads efforts to determine integration needs, design improvements, and design patterns with Engineers, Developers, Suppliers, and Product teams
Responsible for identifying and driving end to end proactive improvement through monitoring tools integration, continuous improvement activities and reporting on service availability
Ensure operational stability of a 24/7/365 grocery retail environment by providing technical support, system monitoring, and issue resolution which may be required during off-hours, weekends, and holidays as needed.
Qualifications:
Bachelors Degree in Computer Science or Technical field and Masters Degree in Technology and/or Business related field; equivalent trainings/certifications/experience equivalency will be considered
8 or more years of equivalent experience in relevant job or field of technology.
5 or more years of equivalent experience in an advanced role or technical capacity, leading teams directly or indirectly
5 or more years experience directly responsible for guiding, training or onboarding team members in relevant technologies, capabilities or skills
Masters the use professional concepts and functional expertise
Takes on mid to large projects from start to finish and works independently on these efforts with minimal direction required,
Works on complex problems where analysis of situations or data requires a review of a variety of factors
Possess an innate desire to produce quality work
Has the desire and ability to trace issues to their source-even when those issues lie outside the boundaries of the code
Exercises judgment within defined procedures and practices to determine appropriate action
Preferred Qualifications:
Masters Degree in relevant field of study, Additional trainings or certifications in relevant field of study
3 or more years experience in Agile teams and Product/Platform based operating model.
3 or more years of experience in leading teams or advancing technical capability in teams.
Experience in retail or grocery preferred.
UKG PRO WFM experience
Boomi certified and development experience
ME/NC/PA/SC Salary Range: $108,880 - $163,320
IL/MA/MD/NY Salary Range: $125,200 - $187,800
Actual compensation offered to a candidate may vary based on their unique qualifications and experience, internal equity, and market conditions. Final compensation decisions will be made in accordance with company policies and applicable laws.
#LI-Hybrid #LI-NG1
At Ahold Delhaize USA, we provide services to one of the largest portfolios of grocery companies in the nation, and we're actively seeking top talent.
Our team shares a common motivation to drive change, take ownership and enable our brands to better care for their customers. We thrive on supporting great local grocery brands and their strategies.
Our associates are the heartbeat of our organization. We are committed to offering a welcoming work environment where all associates can succeed and thrive. Guided by our values of courage, care, teamwork, integrity (and even a little humor), we are dedicated to being a great place to work.
We believe in collaboration, curiosity, and continuous learning in all that we think, create and do. While building a culture where personal and professional growth are just as important as business growth, we invest in our people, empowering them to learn, grow and deliver at all levels of the business.
Information Security Consultant
Information security analyst job in San Jose, CA
Assist Manager of Information Security on all application and network security activities
Evaluate, design, deploy, support, and monitor information security systems
Identify security exposures and develop mitigation plans
Work with our operations team to implement information security solutions
Advocate security awareness and teach secure behavior and methods
Lead technical security incident response activities and forensic investigations
Implement best-practice security procedures, standards, and guidelines
Support Paydiant customers in developing and maturing their own mobile application security programs.
Assist in compliance activities such as external audits from customers, regulatory compliance projects, and overall information security reviews
Support integration with the Client's Security Operations center and be central point of contact for any esclations.
Qualifications
Information Security, PCI-DSS, Compliance, Audit, SOX
Additional Information
Multiple Openings
Senior Security Engineer
Information security analyst job in San Jose, CA
Our Company Changing the world through digital experiences is what Adobe's all about. We give everyone-from emerging artists to global brands-everything they need to design and deliver exceptional digital experiences! We're passionate about empowering people to create beautiful and powerful images, videos, and apps, and transform how companies interact with customers across every screen.
We're on a mission to hire the very best and are committed to creating exceptional employee experiences where everyone is respected and has access to equal opportunity. We realize that new ideas can come from everywhere in the organization, and we know the next big idea could be yours!
Position summary:
The Senior Security Engineer position will be part of the Enterprise Security organization consisting of IAM professionals across several technologies. This specific position will have a specialized role in directory services and SaaS applications! It will focus on large implementations of Entra ID with integrations with other directories, IDPs, applications, and automated workflows. We give technical direction, administer tools, and provide support for various security technologies. We participate in driving Enterprise Security projects that use our cloud directory services for various internal and external Adobe services. We work with other specialists, architects, security teams, and software engineer teams across Adobe and collectively provide services, guidance, and strategies that protect services and data as well as adhere to various global government regulations. You will work with business customers, management teams, infrastructure teams, development teams, project managers, and other security teams to help implement the vision, structure, standards, and plan solutions that support the future architecture.
At Adobe, you will be immersed in an exceptional work environment that is recognized throughout the world on Best Companies lists! You will also be surrounded by colleagues who are committed to helping each other grow through our Check-In approach where ongoing feedback flows freely.
If you're looking to make an impact, Adobe is the place for you. Discover what our employees are saying about their career experiences on the Adobe Life blog and explore the meaningful benefits we offer.
Adobe is an equal opportunity employer. We welcome and encourage diversity in the workplace regardless of race, gender, religion, age, sexual orientation, gender identity, disability or veteran status.
Primary Responsibilities May Include, but Are Not Limited To:
* Managing deep and complex directory architectures and services span directories, IDPs, and federated environments.
* Providing guidance and architecting solutions for directory service strategies across a variety of internal customers at Adobe.
* We help test, implement, and support secure services used by end-users, devices, and application workflows to all of Adobe.
* We engineer secure identity solutions for on-premises and cloud environments.
* We are a team of Security Engineers that handle incoming requests, respond to issues, solve reported problems, and develop solutions.
* We meet with teams to get business requirements, understand workflows, and devise solutions.
* We help assess SaaS implementations for identity integrations and general security.
* We generate useful metrics to help make decisions, identify issues, and manage our sevices.
Requirements:
* Possess a Bachelor's or advanced degree in MIS, Computer Science, Cybersecurity, or Engineering OR 10+ years in IT or Cybersecurity
* Comfortable working on and leading different projects with many teams at one time
* In-depth understanding of Windows, Mac and UNIX/Linux based systems, permissions, and interoperability.
* Strong knowledge of machine to machine and application to machine connections using MFA, certificates, tokens, and other methods.
* Strong understanding of the identity lifecycle, secure by design, least privileged and zero trust.
* An in-depth knowledge and understanding of managing and securing cloud directories (e.g. Entra ID/AWS/Okta) and integrating with traditional directories (e.g. Active Directory/389DS/ LDAP based directories).
* Proficient in written and verbal communications, skilled at working alongside differing viewpoints to accomplish shared objectives.
* Able to work independently and as a team member.
* Capable of conveying technical concepts to diverse audiences including non-technical users, architects, and senior leadership.
* Professional written, verbal, and presentation communication skills to engage with senior leadership.
* A deep understanding of Cloud Directories, especially Entra ID, and how to secure it, use conditional access policies, and apply/create automation.
* Ability to teach and mentor others while fostering a collaborative environment.
* Can model leadership behavior and help to grow other's leadership behavior.
Preferred:
* Understanding of Desktop operating systems including Windows, Linux, and Mac
* Experience or knowledge of Public Key Infrastructure
* Strong abilities in programming/scripting languages for automating repeatable tasks like Python, PowerShell, etc.
* Experience and/or Knowledge of dashboarding and log correlation engines such as Grafana, Telegraph, Splunk, etc.
* Experience with SaaS Security Posture Management technologies.
* Experience with developing PowerBI dashboards.
The Person Should:
* Have strong social skills, ability to "win people over" and be a great teammate.
* Be able to communicate, influence and mentor across business and executive leadership as well as partners while being able to explain the benefits for their teams.
* Be neutral toward technology, vendor and product choices; more interested in results than in personal preferences.
* Have the ability to think creatively and to solve complex tasks and problems with minimal direction.
Our compensation reflects the cost of labor across several U.S. geographic markets, and we pay differently based on those defined markets. The U.S. pay range for this position is $160,900 -- $297,400 annually. Pay within this range varies by work location and may also depend on job-related knowledge, skills, and experience. Your recruiter can share more about the specific salary range for the job location during the hiring process.
At Adobe, for sales roles starting salaries are expressed as total target compensation (TTC = base + commission), and short-term incentives are in the form of sales commission plans. Non-sales roles starting salaries are expressed as base salary and short-term incentives are in the form of the Annual Incentive Plan (AIP).
In addition, certain roles may be eligible for long-term incentives in the form of a new hire equity award.
State-Specific Notices:
California:
Fair Chance Ordinances
Adobe will consider qualified applicants with arrest or conviction records for employment in accordance with state and local laws and "fair chance" ordinances.
Colorado:
Application Window Notice
Nov 10 2025 12:00 AM
If this role is open to hiring in Colorado (as listed on the job posting), the application window will remain open until at least the date and time stated above in Pacific Time, in compliance with Colorado pay transparency regulations. If this role does not have Colorado listed as a hiring location, no specific application window applies, and the posting may close at any time based on hiring needs.
Massachusetts:
Massachusetts Legal Notice
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Adobe is proud to be an Equal Employment Opportunity employer. We do not discriminate based on gender, race or color, ethnicity or national origin, age, disability, religion, sexual orientation, gender identity or expression, veteran status, or any other applicable characteristics protected by law. Learn more.
Adobe aims to make Adobe.com accessible to any and all users. If you have a disability or special need that requires accommodation to navigate our website or complete the application process, email accommodations@adobe.com or call **************.
Information Security Engineer I - Full Time
Information security analyst job in Fremont, CA
Salary Range: $46.86 - $63.25
Summary of Duties: Evaluates, builds, tests, operates and supports a wide variety of enterprise level information security systems and tools. Develops technical security standards and drives implementation of them within the organization.
Educational Requirements: Bachelor's degree in Computer Science or related field required or equivalent combination of education and experience.
Experience Requirements: Must have hands-on experience with many enterprise-level information security systems. Examples: anti-virus, encryption, SSO, intrusion detection.
Washington Hospital Health System does not utilize any form of electronic chatting, such as Google chat for the purposes of interviewing candidates for employment. If you are contacted by any entity or individual attempting to engage you in this format, do not disclose any personal information and contact Washington Hospital Healthcare System.
Auto-ApplyQA Automation and Security Test Architect
Information security analyst job in Pleasanton, CA
QA Automation and Security Test Architect Job ID: 21-14390 Top must haves are: * 5+ years of experience as Automation Architect and doing web application security testing as per OWASP standards * 5+ years of experience designing, developing and executing Automation Scripts using Selenium
* Ability to provide application security risk assessment of technologies stack used in cloud or web applications.
TECHNICAL KNOWLEDGE AND SKILLS:
* 5+ years of experience as an Automation Architect and doing web application security testing as per OWASP standards
* 5+ years of experience designing, developing and executing Automation Scripts using Selenium
* Knowledge and experience in other Automation tools (like QTP, Rational Robot, AutoIT)
* Understanding and working knowledge with Data Driven, Keyword Driven and Hybrid frameworks
* Knowledge of Defect Management Tool (Quality Center, JIRA)
* Exploit application security flaws and vulnerabilities with attack simulations on multiple projects working against specific client-focused scopes of work.
* Ability to provide application security risk assessment of technologies stack used in cloud or web applications.
* Ability to perform application vulnerability assessments or application penetration testing, utilizing tools commercial and open source tools.
* Perform, review and analyze security vulnerability data to identify applicability and false positives.
* Create risk based security code reviews (Static, Dynamic and Interactive).
* Conduct application security testing in line with OWASP (Open Web application Security Project)
* Mentor junior engineers to build their skills and contribution levels
* Write technical reports that include suggested resolution for identified problem areas and perform operational risk assessment.
* Perform Proof of Concept testing and do evaluation of new security technologies and tools.
* Assist and support Security Test Analysts as they perform vulnerability, network and network security assessments.
* Experience DevOps tools like DynaTrace, Chef, Splunk and Vagrant.
* Experience with scripting languages (e.g. python, PERL, SQL) a plus
* Ability to perform below tasks:
o Dynamic Application Security Testing (DAST)
o Static Application Security Testing (SAST)
o Interactive Application Security Testing (IAST)
o Web Application Penetration Testing
o Product Security Testing
o Cloud Application Security Testing
o Web Services Security Testing
o Security Code Review
o Network Security Assessment
* Application Security Testing Tools: VeraCode, Synopsys, Contrast IAST, Burp Suite, Tamper Data, Live http Headers, Client Fortify, VeraCode, OWASP Top 10, N-Stealth, Hailstorm, Paros, SANS Top 20, Acunetix, Nessus
* Fast learning, problem solving and analytical skills
* Excellent communication, presentation, and interpersonal skills
* Track record of good time management
* Efficient in effort estimation, planning and prioritization
* Ability to understand Business Requirements and transform them to functional units
* Knowledge of SDLC and implementation
* Knowledge of SoapUI
* Proficiency in Java language
* Proficiency in SQL
* Job details
*
Security Engineer
Information security analyst job in San Jose, CA
At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation.
Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive.
Join a team using leading edge security technology and processes to protect the F5 enterprise
and product environment. The Security Engineer position will execute strategic processes
and implement technical solutions to enable our information security program and address day-to-day security challenges amidst the industry's evolving technology landscape.
Primary Responsibilities
* Build and implement new security controls, processes and tools.
* Identify organizational risks to confidentiality, integrity, and availability, and determine appropriate mitigations.
* Leverage native Azure, GCP, and AWS cloud services to automate and improve existing security and control activities.
* Develop or implement open-source/third-party tools to assist in detection, prevention and analysis of security threats.
* Perform technical security assessments against product and enterprise cloud hosted, virtual, and on-premise systems including static and dynamic analysis, and threat modeling.
* Review and test changes to services, applications, and networks for potential security impacts.
* Collaborate with Architecture, Site Reliability Engineering and Operations teams to develop and implement technical solutions and security standards.
* Stay abreast on security best practices and secure design principles.
* Review changes to and ongoing operations of enterpise environments and supporting systems for security and compliance impacts.
* Assist in incident detection and response efforts.
* Implement zero-trust patterns with cloud agnostic tools to support enterprise business units.
* Implement, design, develop, administer, and manage enterprise security tooling.
Knowledge, Skills and Abilities
* Experience working with high-availability enterprise production environments
* Familiarity with scripting languages (e.g., (Go, Python, Ruby, Rust,etc.). and building scripts for process improvements
* Experience automating security testing and reporting outputs
* Technical knowledge and hands-on experience with security and networking security, basic networking protocols, cloud security, network security design, intrusion prevention/detection, and firewall architecture
* Experience assessing and implementing technical security controls
* Willingness to innovate and learn new technologies
* Excellent interpersonal and relationship skills with a collaborative mindset
* Knowledge or familiarity with technological stack (Big-IP, Azure, AWS, GCP, CentOS, Hashicorp Vault, Palo Alto, Qualys).
* Experience with network and application vulnerability and penetration testing tools.
* Baseline competency in administration of Microsoft Azure Cloud, Amazon Web Services (AWS), Google Cloud Platform (GCP) or equivalent public cloud infrastructure.
* Exposure to DevOps tooling, CI/CD pipelines, container orchestration, and infrastructure as code approach (e.g. Puppet, Chef, Ansible, Terraform, Jenkins, CircleCI, Artifactory, Git)
* Strong written and verbal cowimmunication skills.
* Strong self-directed work habits, exhibiting initiative, drive, creativity, maturity, self-assurance and professionalism.
* Agile, tactful, and proactive attitude that can manage prioritization and know when to escalate.
Qualifications
* B.S. or M.S. in Computer Science, Engineering, or related field, or equivalent experience.
* 3+ years of relevant security and networking experience
LI-KT1
The Job Description is intended to be a general representation of the responsibilities and requirements of the job. However, the description may not be all-inclusive, and responsibilities and requirements are subject to change.
The annual base pay for this position is: $120,000.00 - $180,000.00
F5 maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, geographic locations, and market conditions, as well as to reflect F5's differing products, industries, and lines of business. The pay range referenced is as of the time of the job posting and is subject to change.
You may also be offered incentive compensation, bonus, restricted stock units, and benefits. More details about F5's benefits can be found at the following link: ******************************************** F5 reserves the right to change or terminate any benefit plan without notice.
Please note that F5 only contacts candidates through F5 email address (ending with @f5.com) or auto email notification from Workday (ending with f5.com or @myworkday.com).
Equal Employment Opportunity
It is the policy of F5 to provide equal employment opportunities to all employees and employment applicants without regard to unlawful considerations of race, religion, color, national origin, sex, sexual orientation, gender identity or expression, age, sensory, physical, or mental disability, marital status, veteran or military status, genetic information, or any other classification protected by applicable local, state, or federal laws. This policy applies to all aspects of employment, including, but not limited to, hiring, job assignment, compensation, promotion, benefits, training, discipline, and termination. F5 offers a variety of reasonable accommodations for candidates. Requesting an accommodation is completely voluntary. F5 will assess the need for accommodations in the application process separately from those that may be needed to perform the job. Request by contacting accommodations@f5.com.
Auto-ApplyAMD-XILINX: Senior Security Operations Specialist
Information security analyst job in San Jose, CA
The Senior Security Operations Specialist will provide expert support, analysis and research into complex problems and processes relating to the security infrastructure environment. As a key member of the Security Operations team, the security administrator will implement and provide support for operations of Firewalls, Proxies, Load Balancers, IPS / IDS, SIEM, Vulnerability Management and other technologies.
The security administrator will ensure appropriate security controls and monitoring are in place for external network connections by coordinating with project teams, users and company partners.
Key Responsibilities:
Create and maintain security infrastructure that follows industry best practices including a high level of availability and ease of user access.
Evaluate and develop systems to enhance our security posture while reducing overall digital security risk.
Lead IT infrastructure integrations with partners from a security perspective.
Maintain awareness of industry security threats and respond to security incidents.
Assist in the architecting of new products, features, and capabilities.
Coordinate with team and Global Operation peers to test and troubleshoot alarm and access control devices.
Security Engineer, Application Security
Information security analyst job in San Jose, CA
Figure is an AI Robotics company developing a general purpose humanoid. Our humanoid robot, Figure 02, is designed for commercial tasks and the home. We are based in San Jose, CA and require 5 days/week in-office collaboration. It's time to build.
We are looking for a Security Engineer to join the Security & Privacy team at Figure, focusing on security of the robot as well as associated backend services. We are looking for excellent security engineers who have experience in breaking and building complex software systems, with experience in AI and embedded systems.
Responsibilities
Conduct security assessments of applications, embedded systems, back-end services, and business integrations, as well as build tooling for a secure development lifecycle
Design technical solutions to mitigate security weaknesses on the robot and our service stack. Work with teams across the company to implement them.
Build frameworks and systems to prevent classes of vulnerabilities
Hunt for vulnerabilities and insecure coding patterns on our product stack (backend services and robot internal systems)
Be a champion for security and user privacy
Requirements
Experience in several of the following application security domains: penetration testing, vulnerability research, security assessment, secure coding practices, security architecture & design, hardware security
Strong software engineering (not scripting or automation) skills in C/C++, Rust, Golang, Python or similar
Experience with securing embedded systems, including secure boot, secure identity, OTA, or others
Solid foundation in web security, mobile security, or cryptography
Ability to collaborate with internal and external stakeholders whilst prioritizing tasks and work independently under minimal supervision.
BS in Computer Science, Engineering, Information Systems, or equivalent years of experience in a related technical field
3+ years of experience in the field of application security or related security role
Passion for learning and helping others
Excellent verbal and written communication skills, with high attention to detail
The US base salary range for this full-time position is between $150,000 - $350,000 annually.
The pay offered for this position may vary based on several individual factors, including job-related knowledge, skills, and experience. The total compensation package may also include additional components/benefits depending on the specific role. This information will be shared if an employment offer is extended.
Auto-ApplyCloud Security Analyst-AWS or Azure, Devops
Information security analyst job in San Ramon, CA
Hands-on cloud security engineer who has a deep understanding of emerging technologies including Openstack, PaaS - Pivotal cloud foundry, Mesos, Docker container, Security, Software defined networks, Cloud integration technologies. Hands-on deployment of AWS\Azure IaaS components necessary to support the Cyber Security deployment needs, as well as approved Cyber Security specific solutions in the AWS\Azure environment to support these efforts.
Qualifications
Bachelor's Degree in STEM and/or a minimum of 4 years of equivalent experience
Minimum of 6 years of experience of application design and architecture
Minimum of 6 years of experience with deployment of cloud controls for infrastructure, platform, and applications (IaaS/SaaS/PaaS)
AWS and Azure experience a must
Additional Information
All your information will be kept confidential according to EEO guidelines.