Information security analyst jobs in Moreno Valley, CA - 98 jobs
All
Information Security Analyst
Security System Engineer
Senior Security Analyst
Information Systems Security Officer
Information Technology Analyst
Securities Analyst
Senior Security Engineer
Information Security Manager
Information Security Director
Senior Information Security Engineer
Sr. Information Security Engineer
Alignment Healthcare 4.7
Information security analyst job in Orange, CA
Sr. InformationSecurity Engineer
External Description:
Alignment Healthcare is a data and technology driven healthcare company focused on partnering with health systems, health plans and provider groups to provide care delivery that is preventative, convenient, coordinated, and that results in improved clinical outcomes for seniors.
We are experiencing rapid growth (backed by top private equity firms), and our team is looking for the best and brightest individuals. We love our customers and understanding them better makes it possible to provide the best clinical outcomes and care experience.
Are you an InformationSecurity Engineer with experience in automation, cloud technologies, and endpoint security? Would you like to work in an environment where your skills can be utilized effectively, and you have opportunities to make significant impact? If you are passionate about security and can reduce risk in practical ways that scale, we want to hear from you!
Major Responsibilities
Contributes to the daily operational aspects of the InformationSecurity Team, primarily from a technical implementation perspective.
Assists with break/fix of tools and automation that are owned by the InformationSecurity Team.
Works with internal and external customers on a variety of issues, from a simple security review of a mundane and routine ask, to a complex deep dive into a new feature implementation in O365, Azure, or AWS.
Balances operational work (approximately 70% of the day) to help meet team SLAs, and project work (approximately 30% of the day) to meet assigned team deliverables.
Contributes to the design, implementation, and documentation of new security tools.
Collaborates with other internal information technology teams (networking, cloud, traditional architecture, developers, and data scientists) to support internal and external systems.
Utilizes scripting and DevOps to provide automation and orchestration between:
informationsecurity tools, such as the SIEM (Logstash, FortiSIEM, IBM QRadar, etc.);
endpoint protection (Symantec, McAfee, Cylance, CrowdStrike Falcon, etc.);
vulnerability scanners (Rapid7, Nessus, etc.);
patch management (SCCM, Altiris, PDQ, etc.);
other applications;
OS' (Windows, MacOS, Linux, iOS, Android);
cloud platforms (AWS, Azure); and
IAM platforms (Active Directory, Okta, Auth0, PingIdentity, SAML, OIDC).
Clearly documents designed automation and system relationships.
Contributes and participates in the InformationSecurity Team daily stand-ups and other meetings as necessary.
Participates in regular reporting, maintaining accountability and transparency within the InformationSecurity Team.
Remains current on industry trends in cyber risk with industry standards (ISO 27001/2, NIST, CIS) and regulatory requirements (HIPAA, HITECH, HITRUST, etc.)
Technical knowledge of common informationsecurity tools and systems: DLP, MAM/MDM, Firewall/VPN, endpoint protection, PKI, RBAC, IAM, etc.
Demonstrated practical experience with one or more programming or scripting languages. (PowerShell, Python, C#, VB, VBA, Ruby, NodeJS, SQL, etc.) We're not picky, but you must be able to deliver practical automation!
Demonstrated practical experience with one or more of the major cloud providers (AWS, Azure, GCP).
Excellent oral and written communication skills, and an ability to present and discuss technical information in a way that establishes rapport and trust.
Detail orientated, with an ability and desire to build to 100%, but being ok with building to 90% as tasked.
An ability to be productive as an individual contributor with little supervision to meet agreed upon deliverables.
Preferred
Prior experience in the healthcare or a related HIPAA regulated industry.
A working knowledge of the NIST CSF and/or CIS Critical Security Controls (CSC).
A working knowledge of Git and GitHub.
Previous experience contributing to projects using agile tools (Jira, Azure DevOps, Pivotal) and processes (Scrum, Kanban).
One or more cloud security certifications.
Education
Bachelor's degree in Computer Science, Computer Engineering, or related technical discipline, and/or equivalent work experience.
3+ years' experience working in a technical, hands-on, informationsecurity role.
One or more current security related certifications (e.g., CISSP, SANS GIAC, etc.)
City: Orange
State: California
Location City: Orange
Schedule: Full Time
Location State: California
Community / Marketing Title: Sr. InformationSecurity Engineer
Company Profile:
Alignment Healthcare was founded with a mission to revolutionize health care with a serving heart culture. Through its unique integrated care delivery models, deep physician partnerships and use of proprietary technologies, Alignment is committed to transforming health care one person at a time.
By becoming a part of the Alignment Healthcare team, you will provide members with the quality of care they truly need and deserve. We believe that great work comes from people who are inspired to be their best. We have built a team of talented and experienced people who are passionate about transforming the lives of the seniors we serve. In this fast-growing company, you will find ample room for growth and innovation alongside the Alignment community.
EEO Employer Verbiage:
On August 17, 2021, Alignment implemented a policy requiring all new hires to receive the COVID-19 vaccine. Proof of vaccination will be required as a condition of employment subject to applicable laws concerning exemptions/accommodations. This policy is part of Alignment's ongoing efforts to ensure the safety and well-being of our staff and community, and to support public health efforts. Alignment Healthcare, LLC is proud to practice Equal Employment Opportunity and Affirmative Action. We are looking for diversity in qualified candidates for employment: Minority/Female/Disable/Protected Veteran. If you require any reasonable accommodation under the Americans with Disabilities Act (ADA) in completing the online application, interviewing, completing any pre-employment testing or otherwise participating in the employee selection process, please contact ******************.
$125k-156k yearly est. Easy Apply 60d+ ago
Looking for a job?
Let Zippia find it for you.
Information Security Analyst 1 (On-site Rancho Cucamonga, CA)
Arrowhead Credit Union Careers 3.6
Information security analyst job in Rancho Cucamonga, CA
Are you passionate about administrating and enforcing solutions that safeguard data? Are your interested in serving your fellow team and the community? If so, we want to talk to you - we are currently looking for Service Superstars to join our Team!
An InformationSecurityAnalyst 1 takes a lead role in the research, design, and implementation of all informationsecurity related hardware or software; including operating systems and communications products, coordinating implementations with third party vendors and supporting representatives as needed. This role also serves as a liaison between vendors and other departments on informationsecurity related projects.
Duties and Essential Functions:
Service
Personally, provides exceptional member service; uses Service Standards in every work-related interaction.
Ensures that
exceptional
member service is being provided to members and team members, at all times.
Serves as a strong example of leadership in work ethic, professionalism, and conduct.
Promotes a harmonious work environment that motivates others towards team participation, goal setting/accomplishment, and personal development.
Daily Operations
Assists in the management of multiple informationsecurity systems, ensuring proper integration of the components with computer systems, network equipment and other devices.
Assists in research of data security needs and requirements for current and future systems.
Performs regular vulnerability analysis for intentional and unintentional systems misuse and identifies appropriate counter measures.
Takes a supporting role in the management of the Credit Union's informationsecurity program including establishing, implementing and monitoring of informationsecurity, incident response procedures and policies, system configuration standards and ongoing risk assessments.
Assists the credit union management team with the creation, modification, and implementation of InformationSecurity policies and standards.
Performs routine audits of security databases including Active Directory, Anti-Virus, Data Loss Prevention (DLP), Group Policy, Remote Authentication Dial-In User Service (RADIUS), and regularly reviews other security logging systems. Designs and/or implements changes to these systems in response to any discovered vulnerabilities.
Performs regular audits of credit union procedures including new hire/transfer/separation process, configuration checklists, firewall changes, Uniform Resource Locator (URL)/Spam filter changes, DLP changes, file permission changes, inventory changes, equipment changes, and system health checks.
Takes a supporting role in the management of Credit Union patch management, anti-virus, Spam filtering, DLP, URL filtering, and intrusion prevention systems.
Assists with the development and implementation of active directory group policy objects with an emphasis on enhancing computer systems security.
Manages the creation, deletion, or alteration of systems access for Credit Union team members. Makes key decisions on whether to honor system access requests and responds appropriately.
Takes a supporting role in the research, design, and implementation of all informationsecurity related hardware or software including operating systems and communications products; assists with coordination of implementations with third party vendors and supports representatives as needed; serves as a liaison between vendors and other departments on informationsecurity related projects.
Conducts various training and instruction programs for credit union team members on the secure use of e-mail and the internet as well as operating systems, networking, computer applications and databases.
Assists in the evaluation of new projects and proposes systems for security risks and makes recommendations for implementation to management.
Takes supporting role in analyzing, planning and implementing projects including software, in-house development, hardware, and networks to provide new products and services to members of the credit union and to improve the effectiveness of member data security. Performs capacity planning and tuning of informationsecurity systems to assure maximum availability and optimal utilization; directs/assists with hardware and software upgrades as needed.
Develops project scope and timeline documents for individual projects per Information Systems (IS) Department standards.
Stays current with evolving trends in informationsecurity related hardware, applications, development, and the internet.
Provides guidance and assistance on technical skills to other IS staff.
Provides regular documentation and reports on the progress of informationsecurity initiatives as well as provides suggestions or plans to further improve the credit union's security efforts.
Other duties as deemed necessary and assigned by Supervisor to achieve the goals of the department and the Credit Union.
Benefits Include:
(not a complete list)
Wellbeing
Weekly pay
401K Retirement Savings Plan with company match
Paid time off accrual begins upon hire, 15 paid vacation days, 11 paid holidays
Paid sick leave
Company-provided life insurance at twice your annual salary
Financial Education Programs
DoorDash DashPass
Health
Medical, Dental, and Vision Insurance for part-time and full-time employees
Modern Health
Care.com subscription
Teladoc
Career Development
Career development opportunities
Team members are eligible to apply for assistance with educational expenses through ArrowHeart's scholarship program.
To learn more about Arrowhead Credit Union and our service culture, visit our Career page, and our ArrowHeart Foundation.
The pay range for this position is listed below.
Starting pay for successful applicants is
generally within the minimum to midpoint of the pay range. Our consideration for pay is designed to support career growth and development over time. Offers extended depend on a variety of job-related factors, including but not limited to individual experience, knowledge, training, education, geographic location, market demands, and internal equity.
Pay range:
Minimum: $35.11/hourly
| Midpoint: $43.89/hourly | Maximum: $52.67/hourly
$35.1-52.7 hourly 12d ago
Information Systems Security Officer
Mantech International Corporation 4.5
Information security analyst job in Camp Pendleton South, CA
General information Requisition # R64222 Posting Date 11/14/2025 Security Clearance Required TS/SCI Remote Type Onsite Time Type Full time Description & Requirements Shape the future of defense with MANTECH! Join a team dedicated to safeguarding our nation through advanced tech and innovative solutions. Since 1968, we've been a trusted partner to the Department of Defense, delivering cutting-edge projects that make a real impact. Dive into exciting opportunities in Cybersecurity, IT, Data Analytics and more. Propel your career forward and be part of something extraordinary. Your journey starts now-protect and innovate with MANTECH!
MANTECH seeks a motivated, career and customer-oriented Information Systems Security Officer with strengths in Information Systems Security to join our team at Marine Corps Base Camp Pendleton California.
This position will assist Marine Corps Warfighting Laboratory (MCWL) prepare for and maintain the IT infrastructure, IT capabilities and Audio-Visual capabilities to support emerging ICD 705 Sensitive Compartmentalized Information Facilities (SCIFs) and Special Access Control Facilities (SAPFs) through planning, activation and operations.
Responsibilities include but are not limited to:
* Experience in network design, network monitoring, systems development, and knowledge of Information Assurance (IA) policies, directives, and best practices across DoD and Marine Corps.
* Knowledge and experience with organizations within the Marine Corps responsible for facilitating network approvals and connections.
* Work with various Marine Corps, Navy, Joint, and other services to coordinate installs supporting Initial Operating Capability (IOC) and Final Operating Capability (FOC).
* Ability to communicate and provide effective staff coordination across government, Marine Corps, and contractor organizations.
* Support the facility Site Security Manager (SSM)/Special Security Representative (SSR) and Information Systems Security Manager (ISSM) to oversee the secure installations and operations of systems across multiple security domains and in accordance with policies, directives, and best practices.
* Establishes and satisfies complex system-wide informationsecurity requirements based upon the analysis of user, policy, regulatory, and resource demands. Supports Marine Corps and other customers at the highest levels in the development and implementation of doctrine and policies.
Minimum Qualifications:
* Bachelor's degree and at least 10 years' experience planning and/or operating IT infrastructure within ICD 705 facilities.
* Experience with network security aspects of installations and operations.
Preferred Qualifications:
* Experience with MS Word, MS Power Point
Clearance Requirements:
* Candidate must have a current/active Top Secret clearance with the ability to obtain and maintain a TS/SCI clearance prior to starting this position.
Physical Requirements:
* Ability to maintain construction security oversight in outdoor environment; walk (with personal protective equipment) to inspect and document delivery of components and assembly/construction of structure.
The projected compensation range for this position is $112,400.00-$186,500.00. There are differentiating factors that can impact a final salary/hourly rate, including, but not limited to, Contract Wage Determination, relevant work experience, skills and competencies that align to the specified role, geographic location (For Remote Opportunities), education and certifications as well as Federal Government Contract Labor categories. In addition, MANTECH invests in its employees beyond just compensation. MANTECH's benefits offerings include, dependent upon position, Health Insurance, Life Insurance, Paid Time Off, Holiday Pay, short-term and long-term Disability, Retirement and Savings, Learning and Development opportunities, wellness programs as well as other optional benefit elections.
MANTECH International Corporation considers all qualified applicants for employment without regard to disability or veteran status or any other status protected under any federal, state, or local law or regulation.
If you need a reasonable accommodation to apply for a position with MANTECH, please email us at ******************* and provide your name and contact information.
$112.4k-186.5k yearly Auto-Apply 43d ago
Sr. Security Compliance Analyst
TP-Link Systems 3.9
Information security analyst job in Irvine, CA
Headquartered in the United States, TP-Link Systems Inc. is a leading global provider of networking devices and smart home products. Consistently ranked as the world's top provider of Wi-Fi devices, TP-Link is dedicated to delivering innovative solutions that improve people's lives by offering faster, more reliable connectivity. Serving customers in over 170 countries, we are committed to expanding our global footprint.
At TP-Link Systems Inc., we believe that technology has the power to transform the world for the better. Our mission is to design reliable, high-performance products that connect users worldwide to the limitless possibilities of technology.
We are driven by our core values of professionalism, innovation, excellence, and simplicity. Our goal is to help clients achieve outstanding global performance and to provide consumers with a seamless, effortless technology experience.
TP-Link Systems Inc. is seeking a skilled and proactive Sr. Security Compliance Analyst who will be responsible for developing and overseeing TP-Link's enterprise security governance framework, ensuring compliance with regulatory requirements, industry standards, and internal policies. This individual will collaborate with cross-functional teams to embed security into business operations, manage risk, and enhance security resilience across TP-Link's enterprise ecosystem.
Key Responsibilities:
Security Governance & Policy Development
Develop, implement, and maintain security policies, standards, and guidelines aligned with industry best practices (e.g., NIST, ISO 27001, CIS).
Establish and lead a security governance framework to ensure consistent application of security controls across the enterprise.
Risk Management & Compliance
Identify, assess, and mitigate security risks across TP-Link's global operations.
Ensure compliance with regulatory requirements such as GDPR, CCPA, NIST CSF, and other applicable cybersecurity frameworks.
Oversee security audits, risk assessments, and third-party security evaluations.
Partner with legal, IT, and business leaders to address security compliance gaps.
Third-Party & Supply Chain Security
Develop and enforce security requirements for vendors, suppliers, and third-party partners.
Conduct security assessments of supply chain partners to identify and mitigate potential risks.
Security Awareness & Training
Develop and lead security awareness programs to educate employees on cybersecurity risks and best practices.
Foster a security-first culture across all levels of the organization.
Provide guidance and training on security governance processes for internal stakeholders.
Incident Response & Continuous Improvement
Support security incident response efforts by ensuring governance processes facilitate rapid detection and response.
Lead post-incident analysis to refine security policies and controls.
Monitor emerging threats, regulatory changes, and industry trends to evolve TP-Link's security governance strategies.
Requirements
Qualifications Education:
Bachelor's degree in Computer Science, Cybersecurity, InformationSecurity, or a related field.
Experience:
5+ years of experience in security governance, risk management, or compliance in a global technology or networking company.
Proven track record in developing and implementing security governance frameworks for enterprise security.
Experience managing compliance with industry standards and regulations (ISO 27001, NIST CSF, SOC 2, GDPR, CCPA, etc.).
Hands-on experience with supply chain security, third-party risk management, and vendor security assessments.
Skills:
Deep understanding of security frameworks (ISO 27001, NIST, CIS, SOC 2) and regulatory requirements.
Strong expertise in risk management methodologies, security policy development, and compliance auditing.
Proficient in conducting security assessments, third-party risk evaluations, and internal security reviews.
Ability to communicate complex security concepts to business and technical stakeholders effectively.
Strong leadership skills with experience in cross-functional collaboration and executive reporting.
Benefits
Salary range: $100,000-$150,000
Free snacks and drinks, and provided lunch on Fridays
Fully paid medical, dental, and vision insurance (partial coverage for dependents)
Contributions to 401k funds
Bi-annual reviews, and annual pay increases
Health and wellness benefits, including free gym membership
Quarterly team-building events
At TP-Link Systems Inc., we are continually searching for ambitious individuals who are passionate about their work. We believe that diversity fuels innovation, collaboration, and drives our entrepreneurial spirit. As a global company, we highly value diverse perspectives and are committed to cultivating an environment where all voices are heard, respected, and valued. We are dedicated to providing equal employment opportunities to all employees and applicants, and we prohibit discrimination and harassment of any kind based on race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws. Beyond compliance, we strive to create a supportive and growth-oriented workplace for everyone. If you share our passion and connection to this mission, we welcome you to apply and join us in building a vibrant and inclusive team at TP-Link Systems Inc.
Please, no third-party agency inquiries, and we are unable to offer visa sponsorships at this time.
$100k-150k yearly Auto-Apply 60d+ ago
Director Information Security
Aspire General Insurance Company
Information security analyst job in Rancho Cucamonga, CA
Job DescriptionDescription:
Aspire General Insurance Company and its affiliated general agent, Aspire General Insurance Services, are on a mission to deliver affordable specialty auto coverage to drivers without compromising outstanding service.
Our company values can best be described with ABLE: to always do the right thing, be yourself, learn and evolve, and execute. Join our team where every individual takes pride in driving their role for shared success.
JOB SUMMARY:
Aspire General Insurance, a leader in non-standard auto insurance, is seeking a hands-on and strategic Director of InformationSecurity to develop, implement, and maintain the company's informationsecurity program. This role is responsible for protecting sensitive customer data, ensuring compliance with regulatory standards, and strengthening our overall cyber risk posture in a cloud-native, AI-enabled environment.
Key Responsibilities:
Develop and lead the enterprise-wide informationsecurity strategy, including governance, risk management, threat detection, and incident response.
Manage and mature security operations, vulnerability management, and access controls.
Own compliance with regulatory frameworks (e.g., NAIC Model Law, GLBA, PCI-DSS, SOC 2) relevant to the insurance industry.
Collaborate with IT, legal, and claims teams to embed security into infrastructure, applications, and third-party vendor relationships.
Oversee risk assessments, penetration testing, and security audits; prioritize and remediate findings.
Lead response to security incidents, including detection, containment, communication, and recovery.
Evaluate and implement modern security technologies, particularly in cloud environments (e.g., Azure security tools).
Educate employees on security awareness and develop policies for secure use of systems and data.
Supervise and grow a small but high-performing InfoSec team and contractors.
Requirements:
Qualifications:
8+ years in informationsecurity roles, with at least 3 years in a leadership capacity.
Deep knowledge of cybersecurity principles, risk frameworks, and regulatory requirements.
Experience with cloud security (AWS or Azure), identity and access management (IAM), SIEM tools, endpoint protection, and zero trust architectures.
Track record of managing security programs in regulated industries such as financial services or insurance.
Familiarity with third-party risk management and secure SDLC practices.
Excellent communication and incident-handling skills.
Knowledge of SOC 2, ISO 27001, and/or NIST frameworks.
Bachelor's degree in InformationSecurity, Computer Science, or related field (CISSP, CISM, or similar certification strongly preferred).
Preferred Experience:
Experience working with or securing AI/ML platforms and data pipelines.
Experience with security considerations in insurance claims and policy systems (e.g., PII, policy documents).
Benefits: Medical, Dental, Vision, HSA*, PTO, 401k, Company Observed Holidays
Individuals seeking employment at Aspire General Insurance Services LLC are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation in accordance with federal and state Equal Employment Opportunity/Affirmative Action record keeping, reporting, and other legal requirements.
*Dependent on plan selected
$132k-195k yearly est. 29d ago
Information Security Analyst
Cathay General Bancorp 4.4
Information security analyst job in Rancho Cucamonga, CA
This position is responsible for ensuring that the Bank's Security operations and preventive controls are managed and maintained in accordance with established InformationSecurity policies, standards and procedures, published regulations and industry best practices.
Primarily responsible for the constant review of vendor security controls in comparison with policies and industry frameworks, risk assessments, determination of control gaps and their remediation.
ESSENTIAL FUNCTIONS
Performs vendor security risk assessments to determine inherent risk on proposed projects and assesses vendor security controls to determine residual risk.
Evaluates the potential exposure to application security risks and threats based on industry security frameworks and recommends appropriate mitigation.
Assesses security practices including InformationSecurity governance, Identity and access control, Incident monitoring and response, Vulnerability assessment and Penetration tests, Network Security and Endpoint Security, among others.
Acts as liaison with Third Party Risk Management, Information Technology and business department Relationship Managers related to vendor risk assessments.
Reports informationsecurity risks and follows-up remediations.
Remediates audit and regulatory findings and recommendations related to InformationSecurity and Vendor Risk Management.
QUALIFICATIONS
Education:
College degree in Information Technology or InformationSecurity or equivalent;
Security+, SSCP, CISSP, CISM or similar informationsecurity certifications preferred.
Experience:
Minimum two years of experience in InformationSecurity Risk, InformationSecurity Operations or Security Auditing.
Proven experience on third-party risk management and vendor security assessments.
Working knowledge of security practices such as Endpoint Security, Network Security, Security Operations and Security Governance required.
Experience working with Vendor Risk Management (VRM) applications preferred.
Skills/Ability:
Proven ability to initiate and manage projects.
Excellent communication and problem-solving skills.
Strong inter-personal communication and collaboration skills.
Self-starter, highly motivated, and able to work with general supervision.
OTHER DETAILS
$28.84 - $33.65 / hour
Pay determined based on job-related knowledge, skills, experience, and location.
This position may be eligible for a discretionary bonus.
$28.8-33.7 hourly 10d ago
Senior Security Engineer
Goodleap 4.6
Information security analyst job in Irvine, CA
GoodLeap is a technology company delivering best-in-class financing and software products for sustainable solutions, from solar panels and batteries to energy-efficient HVAC, heat pumps, roofing, windows, and more. Over 1 million homeowners have benefited from our simple, fast, and frictionless technology that makes the adoption of these products more affordable, accessible, and easier to understand. Thousands of professionals deploying home efficiency and solar solutions rely on GoodLeap's proprietary, AI-powered applications and developer tools to drive more transparent customer communication, deeper business intelligence, and streamlined payment and operations. Our platform has led to more than $30 billion in financing for sustainable solutions since 2018.
GoodLeap is also proud to support our award-winning nonprofit, GivePower, which is building and deploying life-saving water and clean electricity systems, changing the lives of more than 1.6 million people across Africa, Asia, and South America.
Position Summary
The GoodLeap security team is responsible for both business enablement and safeguarding the organization's information assets; it is involved in virtually all aspects of the business, from product safety and resilience, to building security paved roads, customer, partner, and regulatory trust, managing technology governance and compliance, and ensuring the privacy, and safety of GoodLeap's customers, partners, and employees information.
The senior security engineer role provides a unique opportunity to shape the security and resilience of GoodLeap corporate systems, services, and operational processes. In this role, you will work closely with product, engineering, IT, and business teams within GoodLeap, acting as the key individual with both the authority and responsibility to ensure the safety and resilience of enterprise systems, products, and services.
Your oversight will encompass:
* Enterprise systems:Identifying potential misuse and abuse cases, proposing solutions to address these scenarios, and identifying product features, configuration settings, and/or mitigating or compensating controls to meet resilience requirements.
* Build-time controls: Managing applications/products security controls and activities during development.
* Runtime controls: Overseeing security measures at runtime, from prevention to detection and response.
Additionally, you will be involved with aspects of internally built products and represent all areas of security, spanning governance, risk, and compliance (GRC) to security monitoring, for a number of departments/teams. You will also have the authority and ability to involve other security team members as needed.
While you will take on multiple responsibilities-from advisor to builder and beyond-your primary focus will be designing and building security patterns and practices for services and processes, and fostering strong relationships with product, business, and engineering.
Essential Job Duties & Responsibilities
* Lead, participate in, and contribute to partnerships between security, IT, General & Administrative teams, engineering, product, and operations teams to build, orchestrate, and automate security controls and services in GoodLeap enterprise systems, products, services, and operational processes.
* Identify potential misuse and abuse cases in enterprise systems, propose solutions to address these scenarios, and identify product features, configuration settings, and/or mitigating or compensating controls to meet resilience requirements.
* Support or develop components of the security analytics platform.
* Contribute to investigations, threat hunting, and incident response activities in a supporting role.
* Collaborate with the monitoring and response team to create playbooks for specific incident response scenarios related to the products and services you oversee. These investigations, incidents, and playbooks may address security, fraud, privacy, resilience, and related concerns.
* Support the security operations team with the vulnerability management lifecycle for products and services under your purview.
* Ensure technical alignment for the products and services you oversee with team initiatives, including GRC, security operations, and monitoring and response activities.
Required Skills, Knowledge & Abilities
* Strong communicator with the ability to lead technical architecture discussions, drive technical decisions, and effectively communicate with non-technical audiences.
* Expertise in agile product lifecycles. Ideally, you have experience in a product manager or engineering manager role and understand how SaaS products (B2B, B2B2C, and B2C) are built, including roadmap planning and feature and defect prioritization.
* Experience with threat modeling methodologies, with the ability to create efficient and scalable approaches to conducting such assessments.
* Familiarity with AWS services, including KMS, SST, Container Registry, ELBs, Lambda, API Gateway, CloudTrail, and IAM (knowledge of GCP and/or Azure is a plus).
* Proven ability to establish credibility and build trust with business, engineers, and operational staff; confident yet humble.
* Hands-on experience with managing security for core enterprise systems, e.g., ERP, HCM, Salesforce, etc.
* Strong understanding of both human and non-human identity management and common enterprise and consumer authentication standards and use cases.
* Practical experience with CI/CD pipelines and DevOps tools, including Infrastructure-as-Code (IaC) tools like Terraform, Pulumi, or CDK; GitHub and GitHub Actions; artifact management; and secrets management tools like Doppler and HashiCorp Vault.
* Passionate about learning new technologies. While you're not expected to know everything, you should demonstrate a willingness and ability to learn as needed.
* Prior experience interfacing and supporting with G&A teams, internal product teams, and other cross-functional areas.
* Proficiency in writing automation scripts in multiple languages, with prior experience automating security processes in cloud or SaaS environments.
* Experience engaging with vendors in design partnerships.
* Experience overseeing vulnerability and threat management at the platform and application levels.
* Familiarity with penetration testing and red team exercises, including manual verification, exploitation, and lateral movement.
* Ability to balance a high-level view of security strategy with attention to detail, ensuring thorough and effective execution.
$146,000 - $170,000 a year
In addition to the above salary, this role may be eligible for a bonus.
Additional Information Regarding Job Duties and s:
Job duties include additional responsibilities as assigned by one's supervisor or other managers related to the position/department. This job description is meant to describe the general nature and level of work being performed; it is not intended to be construed as an exhaustive list of all responsibilities, duties and other skills required for the position. The Company reserves the right at any time with or without notice to alter or change job responsibilities, reassign or transfer job position or assign additional job responsibilities, subject to applicable law. The Company shall provide reasonable accommodations of known disabilities to enable a qualified applicant or employee to apply for employment, perform the essential functions of the job, or enjoy the benefits and privileges of employment as required by the law.
If you are an extraordinary professional who thrives in a collaborative work culture and values a rewarding career, then we want to work with you! Apply today!
We are committed to protecting your privacy. To learn more about how we collect, use, and safeguard your personal information during the application process, please review our Employment Privacy Policy and Recruiting Policy on AI.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
$146k-170k yearly 60d+ ago
Systems Security Engineer II - P2 (Onsite-Fullerton, CA)
RTX Corporation
Information security analyst job in Fullerton, CA
**Country:** United States of America ** Onsite **U.S. Citizen, U.S. Person, or Immigration Status Requirements:** Active and transferable U.S. government issued security clearance is required prior to start date.
U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance
**Security Clearance:**
Secret - Current
At Raytheon, the foundation of everything we do is rooted in our values and a higher calling - to help our nation and allies defend freedoms and deter aggression. We bring the strength of more than 100 years of experience and renowned engineering expertise to meet the needs of today's mission and stay ahead of tomorrow's threat. Our team solves tough, meaningful problems that create a safer, more secure world.
Raytheon is seeking a well-qualified **Systems Security Engineer II (P2)** to join our Systems Security Engineering (SSE) team in developing solutions to protect the Warfighter's technology advantage. Systems Security Engineering creates holistic security solutions leveraging Cyber Security, Software Assurance and Supply Chain Risk Management to support Program Protection Implementation on embedded weapons systems. Join our highly visible team and perform technically challenging assignments, which will directly contribute to protecting our nation and our Warfighters. This is an onsite position at Raytheon in Fullerton, CA.
**What You Will Do**
+ Lead the patch team, ensuring on-time delivery of patches to our customer
+ Perform analysis on cybersecurity collected data and test results
+ Validate secure configuration of routers, switches, firewalls, servers, operating systems, applications, and other assets, using DoD approved scanning and assessment tools such as Nessus, STIG, Evaluate STIG, and/or RADIX
+ Create and maintain Linux Bash and Python scripts
+ Create patch artifacts such as patch media and information assurance posture reports
**Qualifications You Must Have**
+ Typically requires a Bachelor's Degree in Science, Technology, Engineering or Mathematics (STEM) and 2 years of prior relevant experience
+ Active and transferable U.S. government issued DoD Secret security clearance is required prior to start date. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance
+ Experience in System Security Engineering, computer technology reverse engineering, cybersecurity or embedded security
**Qualifications We Prefer**
+ Experience with scrum planning and scrum tools such as Jira
+ Experience in the SSE implementation throughout the entire life cycle
+ Experience contributing to a team environment for the purpose of developing creative solutions to technical problems
+ Cyber Certifications in accordance with DoDD 8570/DoDD 8140 such as CISSP, GSLC, CEH
+ Experience supporting the development of Risk Management Framework (RMF) documents and controls validation testing for Authority to Operate (ATO) accreditations
+ Candidate must exhibit an exceptional degree of ingenuity, creativity and resourcefulness
+ Excellent communication, technical writing, oral presentation and interpersonal skills
**What We Offer**
+ Our values drive our actions, behaviors, and performance with a vision for a safer, more connected world. At RTX we value: Trust, Respect, Accountability, Collaboration, and Innovation
+ Relocation Eligible - Relocation assistance is available
**_As part of our commitment to maintaining a secure hiring process, candidates may be asked to attend select steps of the interview process in-person at one of our office locations, regardless of whether the role is designated as on-site, hybrid or remote._**
The salary range for this role is 72,000 USD - 144,000 USD. The salary range provided is a good faith estimate representative of all experience levels.
RTX considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate's work experience, location, education/training, and key skills.
Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement.
Hired applicants may be eligible for annual short-term and/or long-term incentive compensation programs depending on the level of the position and whether or not it is covered by a collective-bargaining agreement. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company's performance.
This role is a U.S.-based role. If the successful candidate resides in a U.S. territory, the appropriate pay structure and benefits will apply.
RTX anticipates the application window closing approximately 40 days from the date the notice was posted. However, factors such as candidate flow and business necessity may require RTX to shorten or extend the application window.
_RTX is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or veteran status, or any other applicable state or federal protected class. RTX provides affirmative action in employment for qualified Individuals with a Disability and Protected Veterans in compliance with Section 503 of the Rehabilitation Act and the Vietnam Era Veterans' Readjustment Assistance Act._
**Privacy Policy and Terms:**
Click on this link (******************************************************** to read the Policy and Terms
Raytheon Technologies is An Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age or any other federally protected class.
$96k-139k yearly est. 56d ago
Systems Security Engineer II - P2 (Onsite-Fullerton, CA)
RTX
Information security analyst job in Fullerton, CA
Country:
United States of America Onsite
U.S. Citizen, U.S. Person, or Immigration Status Requirements:
Active and transferable U.S. government issued security clearance is required prior to start date. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance
Security Clearance:
Secret - Current
At Raytheon, the foundation of everything we do is rooted in our values and a higher calling - to help our nation and allies defend freedoms and deter aggression. We bring the strength of more than 100 years of experience and renowned engineering expertise to meet the needs of today's mission and stay ahead of tomorrow's threat. Our team solves tough, meaningful problems that create a safer, more secure world.
Raytheon is seeking a well-qualified Systems Security Engineer II (P2) to join our Systems Security Engineering (SSE) team in developing solutions to protect the Warfighter's technology advantage. Systems Security Engineering creates holistic security solutions leveraging Cyber Security, Software Assurance and Supply Chain Risk Management to support Program Protection Implementation on embedded weapons systems. Join our highly visible team and perform technically challenging assignments, which will directly contribute to protecting our nation and our Warfighters. This is an onsite position at Raytheon in Fullerton, CA.
What You Will Do
Lead the patch team, ensuring on-time delivery of patches to our customer
Perform analysis on cybersecurity collected data and test results
Validate secure configuration of routers, switches, firewalls, servers, operating systems, applications, and other assets, using DoD approved scanning and assessment tools such as Nessus, STIG, Evaluate STIG, and/or RADIX
Create and maintain Linux Bash and Python scripts
Create patch artifacts such as patch media and information assurance posture reports
Qualifications You Must Have
Typically requires a Bachelor's Degree in Science, Technology, Engineering or Mathematics (STEM) and 2 years of prior relevant experience
Active and transferable U.S. government issued DoD Secret security clearance is required prior to start date. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance
Experience in System Security Engineering, computer technology reverse engineering, cybersecurity or embedded security
Qualifications We Prefer
Experience with scrum planning and scrum tools such as Jira
Experience in the SSE implementation throughout the entire life cycle
Experience contributing to a team environment for the purpose of developing creative solutions to technical problems
Cyber Certifications in accordance with DoDD 8570/DoDD 8140 such as CISSP, GSLC, CEH
Experience supporting the development of Risk Management Framework (RMF) documents and controls validation testing for Authority to Operate (ATO) accreditations
Candidate must exhibit an exceptional degree of ingenuity, creativity and resourcefulness
Excellent communication, technical writing, oral presentation and interpersonal skills
What We Offer
Our values drive our actions, behaviors, and performance with a vision for a safer, more connected world. At RTX we value: Trust, Respect, Accountability, Collaboration, and Innovation
Relocation Eligible - Relocation assistance is available
As part of our commitment to maintaining a secure hiring process, candidates may be asked to attend select steps of the interview process in-person at one of our office locations, regardless of whether the role is designated as on-site, hybrid or remote.
The salary range for this role is 72,000 USD - 144,000 USD. The salary range provided is a good faith estimate representative of all experience levels. RTX considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate's work experience, location, education/training, and key skills.Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement.Hired applicants may be eligible for annual short-term and/or long-term incentive compensation programs depending on the level of the position and whether or not it is covered by a collective-bargaining agreement. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company's performance.This role is a U.S.-based role. If the successful candidate resides in a U.S. territory, the appropriate pay structure and benefits will apply.RTX anticipates the application window closing approximately 40 days from the date the notice was posted. However, factors such as candidate flow and business necessity may require RTX to shorten or extend the application window.
RTX is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or veteran status, or any other applicable state or federal protected class. RTX provides affirmative action in employment for qualified Individuals with a Disability and Protected Veterans in compliance with Section 503 of the Rehabilitation Act and the Vietnam Era Veterans' Readjustment Assistance Act.
Privacy Policy and Terms:
Click on this link to read the Policy and Terms
$96k-139k yearly est. Auto-Apply 56d ago
IT Security Analyst II
Monster 4.7
Information security analyst job in Corona, CA
Energy:
Forget about blending in. That's not our style. We're the risk-takers, the trailblazers, the game-changers. We're not perfect, and we don't pretend to be. We're raw, unfiltered, and a bit unconventional. But our drive is unrivaled, just like our athletes. The power is in your hands to define what success looks like and where you want to take your career. It's not just about what we do, but about who we become along the way. We are much more than a brand here. We are a way of life, a mindset. Join us.
A day in the life:
Rev up your career as an IT SecurityAnalyst II at Monster Energy, where you'll be on the frontlines of cyber defense! Your mission? Identify, track, and analyze cyber threats with the precision of a racing champion. Harness your technical and analytical skills to decode threat tactics, techniques, and procedures (TTPs), assessing impacts like a pro and effectively communicating your findings to management and stakeholders. Master the MITRE ATT&CK framework and stay ahead of the curve, adapting to the ever-evolving cyber landscape. Keep a keen eye on security tools like MS Defender, Red Canary, and BlueVoyant, tackling tickets, and neutralizing any threats that dare to challenge MEC. Get ready to protect and serve with Monster Energy's unstoppable spirit!
The impact you'll make:
Threat Identification and Tracking potential threats such as malware or hacking attempts
Vulnerability Response Management using ServiceNow, MS Defender, Tenable.io
Participate in MDR/EDR actionable events and fine tuning alerts from 3rd party monitoring such as Red Canary and Blue Voyant
Work with the team and with 3rd parties to update and maintain rules associated with securing endpoints and identities
Ensure up-to-date documentation surrounding cyber security awareness, training, security events, incidents and all reported issues
Who you are:
Key Competencies:
Oral and written communication skills
Learning skills
Customer service orientated
Problem analysis
Problem-solving
Adaptability
Planning and organizing
Attention to detail
Ability to multi-task and work in a fast paced environment
Preferred Requirements:
Bachelor's Degree in IT Cyber Security or related field
Experience with MS Windows 11, MS Office suite to include Word, Excel, and Powerpoint
Minimum 1 year of experience in MS Office Suite
Between 3-5 years of experience in Industry standards such as NIST
Monster Energy provides a competitive total compensation. This position has an estimated annual salary of $78,750 - $105,000. The actual pay may vary depending on your skills, qualifications, experience, and work location.
$78.8k-105k yearly 60d+ ago
Information Systems Security Officer
CSA Global 4.3
Information security analyst job in Westminster, CA
Full-time Description
For nearly 50 years, CSA has delivered integrated technology and operational support services to meet the defense and federal sector's most complex enterprise needs. Working from operations centers and shipyards to training sites and program offices, CSA deploys experienced teams, innovative tools, and proven processes to advance federal missions.
Client Solution Architects (CSA) is currently seeking an Information Systems Security Officer to support a program at Grafenwoehr, Germany.
Works with System Administrators (SA), Command Information System Security Manager (ISSM), other Information System Security Officers (ISSOs), multiple Branch Heads, multiple Program Managers (PMs) and a project strategist in support of the completion of a mixture of Certification and Accreditation (C&A) boundaries consolidated into overarching master boundaries in support of information assurance policy and regulations. In addition to C&A package development, the individual will be responsible for the day-to-day operations as an ISSO.
How Role will make an impact:
Develop and maintain an organizational or system-level cybersecurity program that includes cybersecurity architecture, requirements, objectives and policies, cybersecurity personnel, and cybersecurity processes and procedures.
Provide support to the System Owner and the ISSM for maintaining the appropriate operational IA posture for a system, program, or enclave.
Provide support to the customer on all matters involving the security of their information systems.
Assist with the management of all security aspects of the information system and as assigned performs day-to-day security operations of the system.
Assist in the development of the system security policy and ensures compliance with that policy on a routine basis.
Prepare, validate, and maintain security documentation including, but not limited to: system security plan (SSP), risk assessment (RA), contingency plan (CP), privacy impact assessment (PIA), eAuthentication assessment, FIPS categorization.
Provide configuration management for security-relevant information system software, hardware, and firmware, controlling changes to the system and assessing the security impact of those changes.
Identify and mitigate security business and system risks.
Identify and manage POA&Ms through remediation as well as develop corrective action plans for each POA&M.
Maintain a repository for all organizational or system-level cybersecurity-related documentation such as RMF processes within eMASS or other automated process.
Maintain Defense Information Technology Portfolio Registry (DITPR) for client systems and software.
Ensure implementation of Information System (IS) security measures and procedures, including reporting incidents to the Command Information System Security Manger (ISSM) and appropriate reporting chains as well as coordinating system-level responses to unauthorized disclosures in accordance with DoDM 5200.01 Vol 3 for classified information or DoDM 5200.01 Vol 4 for CUI, respectively.
Implement and enforce all DoD IS and Platform Information Technology (PIT) system cybersecurity policies and procedures, as defined by cybersecurity-related documentation.
Ensure that all users have the requisite security clearances and access authorization, and are aware of their cybersecurity responsibilities for DoD IS and PIT systems under their purview before being granted access to those systems.
In coordination with the ISSM, initiate protective or corrective measures when a cybersecurity incident or vulnerability is discovered.
Establish a process for authorized users to report all cybersecurity-related events and potential threats and vulnerabilities to the ISSO.
Ensure that all DoD IS cybersecurity-related documentation is current and accessible to properly authorized individuals.
Ensures proper Configuration Management procedures are followed. Prior to implementation and contingent upon necessary approval with the ISSM.
Initiates requests for temporary and permanent exception, deviations, or waivers to IA requirements such as Plan of Action and Milestones (POA&Ms).
Ensures IA and IA-enabled software, hardware and firmware comply with appropriate security configuration guides.
Provide status updates of assigned duties to the appropriate agency heads as defined in their respective Service Level Agreement (SLA).
Respond to all applicable data calls, CTO's, FRAGO's, IAVA's ,etc within the requested timeframe.
Attend all Cybersecurity Workforce Meetings when requested.
Perform as needed system administration on JLCCTC or other simulations or interface systems as needed.
Perform as needed technical operations, setup and tear down of servers, systems and integration tools; maintaining RMF compliance; providing input to exercise design and technical planning products.
Support as needed other set-up, transition, and break down for all training and training support activities pertaining to this task order.
Participate in individual training, seminars, conferences, exercise/experiment planning events, site surveys, and exercise and training events and supports the planning and preparation processes and product development as needed.
Requirements
What you'll need to join our award-winning team:
Clearance: Must possess and maintain an active U.S. Top Secret/SCI security clearance with the ability to pass a CI/Polygraph exam
Education: A bachelor's degree plus 3 years of recent related experience OR an associate's degree plus 7 years of recent related experience OR a major certification plus 7 years of recent related experience OR 11 years of recent related experience.
DoD Approved 8570 Baseline Certification for a minimum of IAM Level II.
Five (5) years' experience within the past 10 years, in planning simulation exercise architectures, supervising implementation of communication systems, and integration of Army Mission Command Systems in support of distributed exercises.
Five (5) years' experience in information technology management
What Sets you apart:
A working knowledge of RMF and the security authorization processes and procedures.
Knowledge of NIST Special Publications and their counterparts, especially SP800- 37, SP800-53, ICD 503, and CNSS 1253.
Ability to communicate clearly and present information to the customer in a format they can understand.
Experience in several of the following areas: knowledge of current security tools, hardware and software security implementation; different communication protocols; and encryption techniques/tools.
Familiarity with commercial security products, security authorization techniques, security incident management, and PKI and authorization services.
Must be able to prioritize tasks, deliver solutions on time and be a team player with the ability to work independently and proactively while being flexible and prioritizing competing priorities, often under time constraints.
Have strong analysis, oral and written communication, and change management skills with ability to plan, organize, prioritize, track, manage, and learn new skills.
It is preferred that a candidate have at least one year of experience under the DoD Information Assurance Certification and Accreditation Process (DIACAP) and/or Risk Management Framework (RMF) accreditation process and has a familiarity with Enterprise Mission Assurance Support Service (eMASS).
Technical familiarity with Windows 7 Enterprise/Windows 10 Professional, Windows Server 2012, and Red Hat Linux.
Experience with providing IA or IT support to a US Army client desirable, but not required.
Proficiency with using the Internet and with Microsoft Office products including e-mail, Word, Excel, Access and Project is required.
Outstanding work ethic and personal integrity.
Superior analytical and problem-solving skills.
Ability to document and update processes.
Ability to perform tasks under deadlines.
Ability to work with senior Government and Industry leaders.
Possess a very high degree of attention to detail.
Capable of working at a computer terminal for extended periods.
Ability to work 12-hour shifts, day or night, for consecutive days up to 4 weeks. • Outstanding interpersonal and written communication skills.
$78k-109k yearly est. 60d+ ago
Systems Security Engineer II
Cambro Manufacturing 4.4
Information security analyst job in Huntington Beach, CA
The System Security Engineer Level II is required to be a highly skilled and hands-on security engineer, and will be responsible for helping to maintain and expand the infrastructure of the entire Cambro network, ensuring that they are protected from cyber threats and attacks, ensuring compliance, and responding to incidents. In this role, the responsibility is to manage, monitor, and maintain our Network IT infrastructure from CVEs, cyber threats, manage and implement device firmware and software updates. Also, the role is required to assist in projects and initiatives to support, upgrade, and maintain our technical environment to improve network security. The role requirement is to be proficient with cybersecurity frameworks including NIS, ISO27001/27002, CIS, HIPAA, CCPA/CPRA and GDPR. The role requires to have a multi-disciplined background including experience with Cybersecurity Operations, firewalls, IDS/IPS, switches, VLANs, routing protocols, IPsec, VPN tunnels, multi factor authentication and e-mail security. In addition, they must have a solid understanding of virtualized servers, Windows workstations and services. This role is required to have the network monitoring skills and technologies for detecting unusual activity, investigate security breaches and lead incidence response.
ESSENTIAL JOB FUNCTIONS
• Monitor network traffic for anomalies, investigate alerts and respond to security incidents.
• Conduct regular vulnerability scans, risk assessments, patch management and mitigation across network devices.
• Ensure adherence to cybersecurity frameworks including NIS, ISO27001/27002, CIS, HIPAA, CCPA/CPRA and GDPR.
• Able to proactively scan servers and network devices for vulnerable ports and protocols and rogue devices.
• Manage our firewall environment with the ability to create route policies and apply cybersecurity recommendations
• Install and configure Network Equipment (Switches, Firewalls, and other networking hardware)
• Perform (Layer 2) switch administration and configuration on Cisco/Ruckus switches. Including configuring LAGs, interfaces, creating trunks, creating, and managing segmented VLANs.
• Possess a solid understanding of Windows Server services and roles including installation and configuration
• Create certificates for network devices and servers that have a web management capability
• A strong understanding of Windows Active Directory and can design, implement, and configure and troubleshoot Active Directory issues
• Create, Manage and Deploy Group Policy Objects (GPO's) to deploy applications and implement security including windows firewalls
• Effectively use PowerShell to automate and standardize administrative tasks
• Capable of installing a Linux VM and execute basic Linux commands and managing Linux appliances
• Manage our virtualized server environment managing, creating VM's and patching the VMware environment.
• Strong understanding of Virtual Switches, Port Groups (Distributed and Standard)
• Manage the Active Backup for Business on Synology and other advanced Synology administration features
• Maintain and monitor Backup solutions.
• Manage our users email accounts using the cloud service M365 from Microsoft
• Responsible for creating and maintaining server and network documentation to include tasks and procedures
• Proactively monitor our network using a variety of tools to help identify potential network and server issues
• Assist in patching our entire infrastructure when needed using a variety of tools
• Maintains strong technical abilities, knowledge of new and changing technologies
• Prepare for emergencies by creating and/or updating action plans
• Jumping into time-sensitive projects wherever needed
• Showing flexibility and a willingness to learn
• Maintain healthy communication with IT Staff, IT Customers and Vendors
• Actively participate in IT Infrastructure and Operations projects, managing, completing, communicating, and fully documenting assigned tasks and deliverables.
• Maintain reliable and consistent attendance, including being punctual, and dependable in order to meet the needs of the department and the organization.
• Execute each essential duty satisfactorily to perform job successfully.
• Follows all safety procedures required in work area, wears PPE as needed, attends all safety meetings, and reports safety issues regarding equipment or unsafe/hazardous conditions.
• Performs effectively as a team member, able to work well with others, open to receiving and give feedback, and treats everyone with respect.
• Takes ownership of own work and behavior, accepts accountability for own actions, encourages solutions, and communicates status of work/projects.
• Follow all department quality standards/criteria. Raise concerns and issues to immediate manager.
• Able to understand and demonstrate Cambro company culture, display company core values (Safety, Quality, Respect, and Service).
• Understands department's key performance indicators and contributes to achieve these goals both individually and as a team.
• Maintains reliable and consistent attendance, including being punctual, dependable, and flexible to potential schedule changes to meet the needs of the department and the organization.
• Executes each essential duty satisfactorily to perform job successfully.
• Follows all safety procedures required in work area, wears PPE as needed, attends all safety meetings, and reports safety issues regarding equipment or unsafe/hazardous conditions.
• Performs effectively as a team member, able to work well with others, open to receive and give feedback, and treats everyone with respect.
• Takes ownership of own work and behavior, accepts accountability for own actions, encourages solutions, and communicates status of work/projects.
• Follows all department quality standards/criteria. Raises concerns and issues to management.
• Understands department's key performance indicators (KPIs) and contributes to achieve these goals both individually and as a team.
• Other duties as needed or required.
ADDITIONAL RESPONSIBILITIES
• Ability to be on call 24 hours a day, 7 days a week for global operations, by periodically providing off-hours, evening, and weekend support to accommodate maintenance windows and issue resolution
• Occasional travel to various Cambro locations domestically and internationally as required (15%)
• May occasionally guide less experienced associates to help with technical projects
• Some travel may be required.
REQUIRED QUALIFICATIONS
The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
• Bachelor's degree (B.A.) from a four-year accredited college or university.
• 5-10 years of experience in IT security, network, administration, and support roles.
• Ability to interpret a variety of instructions furnished in written, oral, diagram, or schedule form.
• Ability to adapt and adjust plans to meet changing needs.
• Proficient in Microsoft Office Suite
• Experience with Fortinet solutions, EDR, email security solutions
• Solid knowledge of cybersecurity frameworks including NIS, ISO27001/27002, CIS, HIPAA, CCPA/CPRA and GDPR.
• Solid working knowledge of Layer 2 (VLANs, Inter-VLANs, VTP Domains, bridge groups, MVRP, ACL's) technologies and network segmentation.
• Strong knowledge of DNS records including reverse zones and maintaining DNS records
• Strong DHCP Knowledge to include DHCP Fail over and able to configure DCHP relay on Switches
• Solid understanding of routing protocols, static routes and ARP cache
• Proficient in creating and implementing certificates on layer 2 devices (Switches, Firewalls, Linux Appliances)
• Strong troubleshooting skills and possess the ability to find security and network issues in a timely manner
• Strong Windows administration skills including Active Directory/GPO's and security policies
• Solid working knowledge of Virtualization, such as VMware ESXi servers and vCenter 7.x
• Solid working knowledge of Veeam/Bacula/Exagrid backup software to manage backup and restore procedures
• Must be able to follow instructions and procedures and ask questions if something is unclear
• Excellent documentation skills including ability to create network drawings
• Self-motivated and energetic with the ability to manage time efficiently without supervision and to work effectively under pressure
• Strong customer service and communication skills
• Excellent organizational skills and strong sense of urgency
• Familiarity with various network types including LANs, WANs, SDWAN, WLANs, SANs, and VoIP networks
• Great accuracy and attention to detail
PREFERRED QUALIFICATIONS
• Experience in Business Continuity and disaster recovery is a plus
• Knowledge of Ruckus Access Points and Switches
• Knowledge of IBMi
PHYSICAL DEMANDS
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Sitting, walking, standing, bending at the neck, bending at the waist, squatting, climbing, kneeling, crawling, twisting at the neck and waist, repetitive use of hands, simple grasping, power grasping, fine manipulation, pushing and pulling, reaching above and below the shoulder, carrying/lifting up to 50 lbs.
Driving cars and other IT equipment
Working around equipment and machinery
Exposure to excessive noise
Exposure to dust, gas, fumes or chemicals
Working at heights
Use of special visual or auditory protective equipment
Walking on uneven ground
PPE Requirements
Safety glasses
Steel-toe slip-resistant shoes - When in production area
Hearing protection (e.g. ear plugs, ear muffs) - When in production area
Face covering (mask) in accordance with company policy.
Hardhat/bump camp
IT Application
COMPENSATION RANGE:
$97,000- $120,000
Salary may vary based on experience.
CAMBRO is proud to be an equal-opportunity workplace. All qualified applicants will receive consideration for employment without regard to and will not be discriminated against based upon race, color, religion, national origin, gender, sexual orientation, gender identity, age, physical or mental disability, genetic information, military or veteran status, or other characteristics protected by law.
$97k-120k yearly Auto-Apply 44d ago
Controls Security & Fire System Engineer III
Johnson Controls Holding Company, Inc. 4.4
Information security analyst job in Huntington Beach, CA
What you do
Be responsible for Pre Sales Support & End User Support for, but not limited to the design, configuration, and operation of complete building low voltage systems, including fire, security, and other low voltage control sub-systems (i.e. lighting, nurse call, data networks, etc.) to meet the intent of the project requirements.
Accountable to field teams for quality, timeliness and efficiency of designs.
Develops complex software programs, commissions and troubleshooting to ensure proper operations of the building control system.
Provides detailed information and submittals to communicate design and operation to customers, consultants, Johnson Controls field installation team and subcontractors.
How will you do it - Sales Support and End User Support
· Possible job walks with the Sales Team on the initial design phase
· Designs and configures are technically complex building control systems as defined by the contract documents.
· Creates flow diagrams, sequence of operations, bill of material, network layouts and electrical schematics as required.
· Develop and tests software programs necessary to operate the system per the project requirements' intent.
· Coordinates the creation of necessary drawings and equipment schedules for submittals and installation.
· Assists in the loading and commissioning of all system and network-level controllers as required.
· Assists in validation of complete system functionality and troubleshoots problems with subcontractors and other trades to ensure proper operation.
· Provides field change information to the project team for the creation of as-built drawings and software.
· Keeps management and JCI contractor or customer informed of job progress and issues.
· Assists in performing site-specific training for owner/operator on the total building control system.
· Participates in release meeting with the project field team.
· Performs value engineering to provide cost effective results while maintaining customer satisfaction.
· Adheres to safety standards.
· High degree of employee and subcontractor safety.
What we look for
Required Qualifications
· Minimum of seven years of experience, or an associate degree in a related technical field with seven years of relevant work experience required.
· Demonstrated knowledge of the construction, mechanical, electrical, or HVAC service industry.
· Demonstrated knowledge of mechanical drawings, electrical wiring diagrams, control theory, automatic temperature controls, building automation systems and other building subsystems.
· Demonstrated experience in the integration of low voltage building sub-systems using various industry protocols (i.e. LON, BACnet, etc.).
· Ability to relate technical knowledge to a non-technical audience.
· Demonstrated advanced computer skills required, particularly computer-related drafting tools, such as Visio.
Preferred Qualifications
· Bachelor's degree in engineering with a minimum of five years of experience, or an associate degree in a related technical field with seven years of relevant work experience required.
· Understanding of IP networking for building automation systems.
· Understanding of Tridium/Niagara Framework
HIRING SALARY RANGE: $100K to $125K (Salary to be determined by the education, experience, knowledge, skills, and abilities of the applicant, internal equity, location and alignment with market data.) This role offers a competitive Bonus plan that will take into account individual, group, and corporate performance. This position includes a competitive benefits package. For details, please visit the About Us tab on the Johnson Controls Careers site at *****************************************
Johnson Controls International plc. is an equal employment opportunity and affirmative action employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, protected veteran status, genetic information, sexual orientation, gender identity, status as a qualified individual with a disability or any other characteristic protected by law. To view more information about your equal opportunity and non-discrimination rights as a candidate, visit EEO is the Law. If you are an individual with a disability and you require an accommodation during the application process, please visit here.
$100k-125k yearly Auto-Apply 44d ago
Oracle Cloud IT Functional Analyst II - Fusion OM
Niagara Water 4.5
Information security analyst job in Diamond Bar, CA
Information security analyst job in San Jacinto, CA
ON-SITE ROLE
The InformationSecurity Manager's role is to lead and oversee the organization's centralized informationsecurity program serving both Tribal Administration and Soboba Casino Resort operations. This includes establishing enterprise-wide security policies and standards, coordinating risk management and incident response efforts, and ensuring security controls align with business, regulatory, and operational requirements. The Manager partners with IT leadership, department heads, and external stakeholders to assess risk, guide security priorities, and provide consistent security governance across the organization.
Duties/Responsibilities
Lead and oversee the organization's centralized informationsecurity program across Tribal Administration and Casino operations.
Develop, maintain, and enforce enterprise-wide informationsecurity policies, standards, and procedures.
Establish security governance, risk management processes, and exception handling frameworks.
Establish and oversee formal risk acceptance, exception, and compensating control processes in coordination with IT leadership and executive management.
Oversee security incident response coordination, escalation, and communication with leadership and stakeholders.
Provide oversight of vulnerability management, audit activities, and remediation prioritization.
Coordinate disaster recovery and business continuity security requirements in partnership with IT and business teams.
Serve as the primary point of contact for security-related audits, assessments, and regulatory reviews.
Engage with vendors, service providers, and partners on security requirements and risk management.
Provide leadership, guidance, and mentorship to informationsecurity staff.
Assess enterprise security risks and provide regular reporting to IT leadership and executive management.
Guide security strategy, roadmap planning, and prioritization aligned with business objectives.
Establish and maintain a risk-based approach to informationsecurity prioritization and decision making.
Oversee third-party and vendor security risk management activities.
Ensure security incidents are reviewed for root cause analysis and lessons learned.
Develop and report security metrics, risk summaries, and program status to leadership, including key performance indicators (KPIs) and key risk indicators (KRIs).
Participate in continuous improvement of the informationsecurity program based on evolving threats, technologies, and organizational needs.
Promote security awareness and best practices across the organization, including implementation of comprehensive training programs and phishing simulations.
Provide input into the design and architecture of new systems to ensure secure implementation and alignment with enterprise security standards.
Establish and maintain threat intelligence capabilities to proactively identify and respond to emerging threats.
Lead data protection initiatives, including compliance with applicable privacy regulations (e.g., GDPR, CCPA), and oversee data classification and handling policies.
Oversee security for cloud-based services and emerging technologies, ensuring secure adoption and integration.
Support and promote diversity, equity, and inclusion within the IT and security teams.
Perform special projects and other responsibilities, tasks, or duties as requested.
Education / Qualifications
Must be at least 21 years of age.
High School Diploma or GED equivalent, required.
Bachelor's in computer science or related field, or equivalent work experience, required.
Industry-recognized informationsecurity certification(s) required or preferred, with expectation to obtain additional certifications as part of ongoing professional development, such as:
Security+, SSCP, or equivalent (required)
CISSP or CISM (preferred)
Other relevant security certifications (e.g., CRISC, GIAC) are a plus
Minimum of five (5) years of progressive experience in informationsecurity, including hands-on involvement in security operations, risk assessment, incident response, vulnerability management, and policy or security control development, preferred.
Any combination of education, experience, and training that provides the required knowledge, skills, and abilities.
Must have excellent verbal and written communication skills to promote a positive and professional image.
Broad hands-on knowledge of firewalls, intrusion detection systems, anti-virus software, data encryption, and other industry-standard techniques and practices, preferred.
In-depth technical knowledge of enterprise network, endpoint, and platform operating systems within heterogeneous environments, preferred.
Working technical knowledge of enterprise operating systems and platforms across Windows and Linux-based environments, preferred.
Strong knowledge of TCP/IP and network administration/protocols, preferred.
Hands-on experience with devices such as hubs, switches, and routers, preferred.
Knowledge of data privacy and data protection practices, along with familiarity with informationsecurity frameworks and best practices such as NIST, CIS, and ISO standards, preferred.
Must be able to provide evidence of eligibility to work in the United States of America.
Certificates, licenses, and registration
Ability to obtain and maintain a valid Soboba Tribal Gaming Commission license.
Required to submit to and obtain negative results on all drug and/or alcohol testing.
Soboba Casino Resort Benefits
Full-time team members are eligible to participate in a variety of group health and wellness benefits upon timely submission of appropriate enrollment forms. Coverage effective dates vary by plan and additional information will be provided to you during New Hire Orientation. Benefit offerings may change from time-to-time, but presently, Soboba Casino resort offers the following:
401k Plan
Basic Life Insurance (employer paid) with the option to purchase Supplemental Life Insurance
Medical available to employees at a significantly reduced cost. Dental & Vision paid for the employee.
Employee Assistance Program
Wellness Program (Annual Health Fair, Wellness Education, and Incentive Programs)
Paid Time Off
Soboba Casino Resort Team Member Recognition including, but not limited to:
Reward and Recognition Program (Quarterly, and Annually)
Team member Incentives
Discounted Team member meal
$126k-155k yearly est. Auto-Apply 6d ago
IT Analyst
Firstservice Corporation 3.9
Information security analyst job in Irvine, CA
The IT Systems Specialist position actively supports FirstService Residential philosophies and culture to staff, clients, and the community, enhancing the brand's image, reputation, differentiation, and professionalism. As an IT Specialist, the primary functions include supporting end-user technology and maintaining 100% availability of all IT related systems and software to provide Regional Offices and On-Site Locations with a competitive advantage, improved profitability, and exceptional customer service.
Compensation: $26-$30hr
FirstService Residential will compensate the successful candidate in accordance with the posted range. The salary or wage paid to the successful candidate will be commensurate with experience, education, and specific job responsibilities. For positions designated at a client's property, the salary or wage will also be premised upon the client's directive. The base pay range is subject to change and may be modified in the future.
Job Responsibilities:
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. Due to the nature of this role and technology these responsibilities may change over time.
* Manage internal and external client relationships and expectations during escalated issue processes.
* Effectively communicate pertinent information to the team, associates, and leadership as needed.
* Document all work performed in ServiceDesk in a timely, accurate, and detailed manner, with follow-up to resolution.
* Provide professional, courteous, and timely support and service to users/customers.
* Occasionally travel to other offices and site locations as needed.
* Active Directory - Manage user's accounts, permissions, reset passwords. Create and disable accounts.
* Support Office 365 and Office applications (Outlook, Word, Excel).
* Manage the maintenance of all hardware (desktops, laptops, printers, and peripherals) and software.
* Be familiar with Citrix desktops and applications.
* Use remote support tools (GoToAssist, ManageEngine) to troubleshoot and resolve issues.
* Conduct user training sessions on an as-needed basis
Skills & Qualifications:
* Valid State Driver's License and mandated vehicle insurance.
* Proficient in English; bilingual skills are helpful.
* Expert level with Microsoft Windows 10/11. Proficient in Active Directory, Citrix, Office 365, and Microsoft applications.
* Basic understanding of networks and troubleshooting
* Strong customer orientation.
* Excellent interpersonal and communication skills
Education & Experience:
* Experience in IT (1-3 years).
* Combination of associate's degree and/or IT-related certifications (Microsoft, CompTIA) in a related field is desirable.
Physical Requirements & Working Environment:
The physical demands described here are representative of those that must be met by an associate to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
* Must be able to sit for extended periods of time.
* Must be able to stand for extended periods of time.
* Must be able to communicate both on the phone and in person with our clients in order to resolve issues and manage the business.
* Must have finger dexterity for typing/using a keyboard.
* Must be mobile enough to move around both the office in order to make copies, send mail and faxes and to walk around the property. This could include lengthy walks on uneven areas.
* Talking and hearing occur continuously in the process of communicating with guests, supervisors, and other associates.
Hours over and above normal office hours will occur, including evenings, holidays, and some weekends. Schedule is subject to change based on business needs.
Tools & Equipment Used:
* Must have access to and consistent use of a vehicle for transportation to client sites and local offices.
* Computer and peripherals, standard and customized software applications and tools, and usual office equipment.
Travel:
* Must be able to travel locally to client sites in the field (Southern California)
What We Offer:
* Medical, dental, and vision plans (full time and part time 30+ hours)
* Part time 20+ hours qualify for dental and vision
* 401K match
* Time off including vacation, sick, and company paid holidays
* Pet insurance available
* Tuition reimbursement
* Legal services
* Free emotional wellbeing and daily life assistance support for all associates
* Domestic partner coverage
* Health savings account
* Flexible spending account
About Us:
FirstService Residential transforms the property management landscape by providing professional association management services to over 9,000 residential communities across the United States and Canada.
Our dedication to associate satisfaction and growth is recognized by our Great Place to Work certification, exemplifying our commitment to fostering a positive and inclusive workplace culture. Our 19,000 associates can count on competitive salaries, top-tier medical, dental, and retirement benefits, career training, and support for continued professional development.
Disclaimer:
The above information in this description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of employees assigned to this job. This is not an all-inclusive job description; therefore, management has the right to assign or reassign schedules, duties, and responsibilities to this job at any time.
FirstService Residential is an equal opportunity employer committed to a diverse and inclusive workforce. Applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy), age, sexual orientation, national origin, marital status, parental status, ancestry, disability, gender identity, veteran status, genetic information, other distinguishing characteristics of diversity and inclusion, or any other protected status.
Qualified applicants with arrest and/or conviction records will be considered for employment in a manner consistent with federal and state laws. All offers of employment with FirstService Residential are contingent upon a satisfactory background check.
$26-30 hourly 2d ago
Information Security Analyst 1 (On-site Rancho Cucamonga, CA)
Arrowhead Credit Union 3.6
Information security analyst job in Rancho Cucamonga, CA
Are you passionate about administrating and enforcing solutions that safeguard data? Are your interested in serving your fellow team and the community? If so, we want to talk to you - we are currently looking for Service Superstars to join our Team! An InformationSecurityAnalyst 1 takes a lead role in the research, design, and implementation of all informationsecurity related hardware or software; including operating systems and communications products, coordinating implementations with third party vendors and supporting representatives as needed. This role also serves as a liaison between vendors and other departments on informationsecurity related projects.
Duties and Essential Functions:
Service
* Personally, provides exceptional member service; uses Service Standards in every work-related interaction.
* Ensures that exceptional member service is being provided to members and team members, at all times.
* Serves as a strong example of leadership in work ethic, professionalism, and conduct.
* Promotes a harmonious work environment that motivates others towards team participation, goal setting/accomplishment, and personal development.
Daily Operations
* Assists in the management of multiple informationsecurity systems, ensuring proper integration of the components with computer systems, network equipment and other devices.
* Assists in research of data security needs and requirements for current and future systems.
* Performs regular vulnerability analysis for intentional and unintentional systems misuse and identifies appropriate counter measures.
* Takes a supporting role in the management of the Credit Union's informationsecurity program including establishing, implementing and monitoring of informationsecurity, incident response procedures and policies, system configuration standards and ongoing risk assessments.
* Assists the credit union management team with the creation, modification, and implementation of InformationSecurity policies and standards.
* Performs routine audits of security databases including Active Directory, Anti-Virus, Data Loss Prevention (DLP), Group Policy, Remote Authentication Dial-In User Service (RADIUS), and regularly reviews other security logging systems. Designs and/or implements changes to these systems in response to any discovered vulnerabilities.
* Performs regular audits of credit union procedures including new hire/transfer/separation process, configuration checklists, firewall changes, Uniform Resource Locator (URL)/Spam filter changes, DLP changes, file permission changes, inventory changes, equipment changes, and system health checks.
* Takes a supporting role in the management of Credit Union patch management, anti-virus, Spam filtering, DLP, URL filtering, and intrusion prevention systems.
* Assists with the development and implementation of active directory group policy objects with an emphasis on enhancing computer systems security.
* Manages the creation, deletion, or alteration of systems access for Credit Union team members. Makes key decisions on whether to honor system access requests and responds appropriately.
* Takes a supporting role in the research, design, and implementation of all informationsecurity related hardware or software including operating systems and communications products; assists with coordination of implementations with third party vendors and supports representatives as needed; serves as a liaison between vendors and other departments on informationsecurity related projects.
* Conducts various training and instruction programs for credit union team members on the secure use of e-mail and the internet as well as operating systems, networking, computer applications and databases.
* Assists in the evaluation of new projects and proposes systems for security risks and makes recommendations for implementation to management.
* Takes supporting role in analyzing, planning and implementing projects including software, in-house development, hardware, and networks to provide new products and services to members of the credit union and to improve the effectiveness of member data security. Performs capacity planning and tuning of informationsecurity systems to assure maximum availability and optimal utilization; directs/assists with hardware and software upgrades as needed.
* Develops project scope and timeline documents for individual projects per Information Systems (IS) Department standards.
* Stays current with evolving trends in informationsecurity related hardware, applications, development, and the internet.
* Provides guidance and assistance on technical skills to other IS staff.
* Provides regular documentation and reports on the progress of informationsecurity initiatives as well as provides suggestions or plans to further improve the credit union's security efforts.
* Other duties as deemed necessary and assigned by Supervisor to achieve the goals of the department and the Credit Union.
Benefits Include: (not a complete list)
Wellbeing
* Weekly pay
* 401K Retirement Savings Plan with company match
* Paid time off accrual begins upon hire, 15 paid vacation days, 11 paid holidays
* Paid sick leave
* Company-provided life insurance at twice your annual salary
* Financial Education Programs
* DoorDash DashPass
Health
* Medical, Dental, and Vision Insurance for part-time and full-time employees
* Modern Health
* Care.com subscription
* Teladoc
Career Development
* Career development opportunities
* Team members are eligible to apply for assistance with educational expenses through ArrowHeart's scholarship program.
To learn more about Arrowhead Credit Union and our service culture, visit our Career page, and our ArrowHeart Foundation.
The pay range for this position is listed below.
Starting pay for successful applicants is generally within the minimum to midpoint of the pay range. Our consideration for pay is designed to support career growth and development over time. Offers extended depend on a variety of job-related factors, including but not limited to individual experience, knowledge, training, education, geographic location, market demands, and internal equity.
Pay range:
Minimum: $35.11/hourly| Midpoint: $43.89/hourly | Maximum: $52.67/hourly
$35.1-52.7 hourly 13d ago
Sr. Security Compliance Analyst
TP-Link Corp 3.9
Information security analyst job in Irvine, CA
Headquartered in the United States, TP-Link Systems Inc. is a leading global provider of networking devices and smart home products. Consistently ranked as the world's top provider of Wi-Fi devices, TP-Link is dedicated to delivering innovative solutions that improve people's lives by offering faster, more reliable connectivity. Serving customers in over 170 countries, we are committed to expanding our global footprint.
At TP-Link Systems Inc., we believe that technology has the power to transform the world for the better. Our mission is to design reliable, high-performance products that connect users worldwide to the limitless possibilities of technology.
We are driven by our core values of professionalism, innovation, excellence, and simplicity. Our goal is to help clients achieve outstanding global performance and to provide consumers with a seamless, effortless technology experience.
TP-Link Systems Inc. is seeking a skilled and proactive Sr. Security Compliance Analyst who will be responsible for developing and overseeing TP-Link's enterprise security governance framework, ensuring compliance with regulatory requirements, industry standards, and internal policies. This individual will collaborate with cross-functional teams to embed security into business operations, manage risk, and enhance security resilience across TP-Link's enterprise ecosystem.
Key Responsibilities:
Security Governance & Policy Development
* Develop, implement, and maintain security policies, standards, and guidelines aligned with industry best practices (e.g., NIST, ISO 27001, CIS).
* Establish and lead a security governance framework to ensure consistent application of security controls across the enterprise.
Risk Management & Compliance
* Identify, assess, and mitigate security risks across TP-Link's global operations.
* Ensure compliance with regulatory requirements such as GDPR, CCPA, NIST CSF, and other applicable cybersecurity frameworks.
* Oversee security audits, risk assessments, and third-party security evaluations.
* Partner with legal, IT, and business leaders to address security compliance gaps.
Third-Party & Supply Chain Security
* Develop and enforce security requirements for vendors, suppliers, and third-party partners.
* Conduct security assessments of supply chain partners to identify and mitigate potential risks.
Security Awareness & Training
* Develop and lead security awareness programs to educate employees on cybersecurity risks and best practices.
* Foster a security-first culture across all levels of the organization.
* Provide guidance and training on security governance processes for internal stakeholders.
Incident Response & Continuous Improvement
* Support security incident response efforts by ensuring governance processes facilitate rapid detection and response.
* Lead post-incident analysis to refine security policies and controls.
* Monitor emerging threats, regulatory changes, and industry trends to evolve TP-Link's security governance strategies.
$111k-150k yearly est. 15d ago
Senior Security Engineer
Goodleap 4.6
Information security analyst job in Irvine, CA
About GoodLeap:GoodLeap is a technology company delivering best-in-class financing and software products for sustainable solutions, from solar panels and batteries to energy-efficient HVAC, heat pumps, roofing, windows, and more. Over 1 million homeowners have benefited from our simple, fast, and frictionless technology that makes the adoption of these products more affordable, accessible, and easier to understand. Thousands of professionals deploying home efficiency and solar solutions rely on GoodLeap's proprietary, AI-powered applications and developer tools to drive more transparent customer communication, deeper business intelligence, and streamlined payment and operations. Our platform has led to more than $30 billion in financing for sustainable solutions since 2018. GoodLeap is also proud to support our award-winning nonprofit, GivePower, which is building and deploying life-saving water and clean electricity systems, changing the lives of more than 1.6 million people across Africa, Asia, and South America.
Position Summary The GoodLeap security team is responsible for both business enablement and safeguarding the organization's information assets; it is involved in virtually all aspects of the business, from product safety and resilience, to building security paved roads, customer, partner, and regulatory trust, managing technology governance and compliance, and ensuring the privacy, and safety of GoodLeap's customers, partners, and employees information.
The senior security engineer role provides a unique opportunity to shape the security and resilience of GoodLeap corporate systems, services, and operational processes. In this role, you will work closely with product, engineering, IT, and business teams within GoodLeap, acting as the key individual with both the authority and responsibility to ensure the safety and resilience of enterprise systems, products, and services.
Your oversight will encompass: - Enterprise systems:Identifying potential misuse and abuse cases, proposing solutions to address these scenarios, and identifying product features, configuration settings, and/or mitigating or compensating controls to meet resilience requirements. - Build-time controls: Managing applications/products security controls and activities during development. - Runtime controls: Overseeing security measures at runtime, from prevention to detection and response.
Additionally, you will be involved with aspects of internally built products and represent all areas of security, spanning governance, risk, and compliance (GRC) to security monitoring, for a number of departments/teams. You will also have the authority and ability to involve other security team members as needed.
While you will take on multiple responsibilities-from advisor to builder and beyond-your primary focus will be designing and building security patterns and practices for services and processes, and fostering strong relationships with product, business, and engineering. Essential Job Duties & Responsibilities
Lead, participate in, and contribute to partnerships between security, IT, General & Administrative teams, engineering, product, and operations teams to build, orchestrate, and automate security controls and services in GoodLeap enterprise systems, products, services, and operational processes.
Identify potential misuse and abuse cases in enterprise systems, propose solutions to address these scenarios, and identify product features, configuration settings, and/or mitigating or compensating controls to meet resilience requirements.
Support or develop components of the security analytics platform.
Contribute to investigations, threat hunting, and incident response activities in a supporting role.
Collaborate with the monitoring and response team to create playbooks for specific incident response scenarios related to the products and services you oversee. These investigations, incidents, and playbooks may address security, fraud, privacy, resilience, and related concerns.
Support the security operations team with the vulnerability management lifecycle for products and services under your purview.
Ensure technical alignment for the products and services you oversee with team initiatives, including GRC, security operations, and monitoring and response activities.
Required Skills, Knowledge & Abilities
Strong communicator with the ability to lead technical architecture discussions, drive technical decisions, and effectively communicate with non-technical audiences.
Expertise in agile product lifecycles. Ideally, you have experience in a product manager or engineering manager role and understand how SaaS products (B2B, B2B2C, and B2C) are built, including roadmap planning and feature and defect prioritization.
Experience with threat modeling methodologies, with the ability to create efficient and scalable approaches to conducting such assessments.
Familiarity with AWS services, including KMS, SST, Container Registry, ELBs, Lambda, API Gateway, CloudTrail, and IAM (knowledge of GCP and/or Azure is a plus).
Proven ability to establish credibility and build trust with business, engineers, and operational staff; confident yet humble.
Hands-on experience with managing security for core enterprise systems, e.g., ERP, HCM, Salesforce, etc.
Strong understanding of both human and non-human identity management and common enterprise and consumer authentication standards and use cases.
Practical experience with CI/CD pipelines and DevOps tools, including Infrastructure-as-Code (IaC) tools like Terraform, Pulumi, or CDK; GitHub and GitHub Actions; artifact management; and secrets management tools like Doppler and HashiCorp Vault.
Passionate about learning new technologies. While you're not expected to know everything, you should demonstrate a willingness and ability to learn as needed.
Prior experience interfacing and supporting with G&A teams, internal product teams, and other cross-functional areas.
Proficiency in writing automation scripts in multiple languages, with prior experience automating security processes in cloud or SaaS environments.
Experience engaging with vendors in design partnerships.
Experience overseeing vulnerability and threat management at the platform and application levels.
Familiarity with penetration testing and red team exercises, including manual verification, exploitation, and lateral movement.
Ability to balance a high-level view of security strategy with attention to detail, ensuring thorough and effective execution.
Additional Information Regarding Job Duties and s:
Job duties include additional responsibilities as assigned by one's supervisor or other managers related to the position/department. This job description is meant to describe the general nature and level of work being performed; it is not intended to be construed as an exhaustive list of all responsibilities, duties and other skills required for the position. The Company reserves the right at any time with or without notice to alter or change job responsibilities, reassign or transfer job position or assign additional job responsibilities, subject to applicable law. The Company shall provide reasonable accommodations of known disabilities to enable a qualified applicant or employee to apply for employment, perform the essential functions of the job, or enjoy the benefits and privileges of employment as required by the law.
If you are an extraordinary professional who thrives in a collaborative work culture and values a rewarding career, then we want to work with you! Apply today!
We are committed to protecting your privacy. To learn more about how we collect, use, and safeguard your personal information during the application process, please review our Employment Privacy Policy and Recruiting Policy on AI.
$114k-145k yearly est. Auto-Apply 60d+ ago
Information Systems Security Officer
Mantech 4.5
Information security analyst job in Camp Pendleton South, CA
**MANTECH** seeks a motivated, career and customer-oriented **Information Systems Security Officer** with strengths in Information Systems Security to join our team at Marine Corps Base **Camp Pendleton California.** This position will assist Marine Corps Warfighting Laboratory (MCWL) prepare for and maintain the IT infrastructure, IT capabilities and Audio-Visual capabilities to support emerging ICD 705 Sensitive Compartmentalized Information Facilities (SCIFs) and Special Access Control Facilities (SAPFs) through planning, activation and operations.
**Responsibilities include but are not limited to:**
+ Experience in network design, network monitoring, systems development, and knowledge of Information Assurance (IA) policies, directives, and best practices across DoD and Marine Corps.
+ Knowledge and experience with organizations within the Marine Corps responsible for facilitating network approvals and connections.
+ Work with various Marine Corps, Navy, Joint, and other services to coordinate installs supporting Initial Operating Capability (IOC) and Final Operating Capability (FOC).
+ Ability to communicate and provide effective staff coordination across government, Marine Corps, and contractor organizations.
+ Support the facility Site Security Manager (SSM)/Special Security Representative (SSR) and Information Systems Security Manager (ISSM) to oversee the secure installations and operations of systems across multiple security domains and in accordance with policies, directives, and best practices.
+ Establishes and satisfies complex system-wide informationsecurity requirements based upon the analysis of user, policy, regulatory, and resource demands. Supports Marine Corps and other customers at the highest levels in the development and implementation of doctrine and policies.
**Minimum Qualifications:**
+ Bachelor's degree and at least 10 years' experience planning and/or operating IT infrastructure within ICD 705 facilities.
+ Experience with network security aspects of installations and operations.
**Preferred Qualifications:**
+ Experience with MS Word, MS Power Point
**Clearance Requirements** **_:_**
+ Candidate must have a current/active Top Secret clearance with the ability to obtain and maintain a TS/SCI clearance prior to starting this position.
**Physical Requirements:**
+ Ability to maintain construction security oversight in outdoor environment; walk (with personal protective equipment) to inspect and document delivery of components and assembly/construction of structure.
MANTECH International Corporation considers all qualified applicants for employment without regard to disability or veteran status or any other status protected under any federal, state, or local law or regulation.
If you need a reasonable accommodation to apply for a position with MANTECH, please email us at ******************* and provide your name and contact information.
$67k-94k yearly est. 47d ago
Learn more about information security analyst jobs
How much does an information security analyst earn in Moreno Valley, CA?
The average information security analyst in Moreno Valley, CA earns between $75,000 and $155,000 annually. This compares to the national average information security analyst range of $71,000 to $135,000.
Average information security analyst salary in Moreno Valley, CA