Information Security Analyst
Information security analyst job in Norwell, MA
INFORMATION Department Security Reports To Information Security Manager Type Full-Time Rate Type Salary Work as part of ESG's Global Information Security Team to maintain the confidentiality, integrity, and availability of enterprise assets. The Security Analyst plays a critical role in supporting the organization's cybersecurity posture by monitoring, analyzing, and responding to security incidents and threats.
This position requires a strong technical foundation, analytical thinking, and understanding of cyber security threats.
Essential Functions
* Analyze security alerts to identify and respond to any security events or incidents.
* Support investigations, reporting and remediation activities of security events and incidents
* Manage, create, and update information security documentation.
* Provide support to ensure information security compliance with industry regulations and data privacy laws.
* Keep up to date with the latest security trends and technologies and recommend improvements to our security posture.
* Research the latest information security threats and vulnerabilities and prepare reports and presentations.
* Conducting vulnerability assessments on systems and applications, to identify and mitigate any security vulnerabilities.
* Participate in both internal and external audits.
* Ability to function in a fast-paced environment and effectively manage multiple tasks simultaneously.
* All other related duties as assigned.
Experience
* Two years' experience as a Security Analyst, or 2 years' experience in a related technical field.
* Knowledge of implementing, supporting, and auditing information security control frameworks such as, NIST, PCI DSS, ISO and SOC.
* Knowledge of security Incident event management and monitoring
* Supporting penetration testing and vulnerability management programs
* Security threat monitoring
* Strong communication skills with the ability to work collaboratively in a global team.
* Detail oriented and ability to focus on granular level compliance and security issues.
Education
Bachelor of Science in Computer Science or related field
Perks
By becoming a team member here at ESG, you'll have access to competitive health, dental, and vision coverage, as well as life insurance, and short term and long-term disability insurance. We value work life balance, and you'll benefit from our open time off and excellent 401K package. We also offer a generous paid parental leave and education assistance program.
Work Environment
This job operates in a hybrid work environment with a preference for being in the office two to three days a week. Full time remote can be considered for the right candidate and fit with the ESG North American operation.
Travel Requirements
Up to 5% travel may be required based on location.
ESG is an equal opportunity employer. Qualified candidates will receive consideration for employment without regard to race, color, religion, national origin, gender, sexual orientation, gender identity or expression, age, mental or physical disability, and genetic information, marital status, citizenship status, military status, protected veteran status or any other category protected by law.
Global Cyber Wordings Analyst
Information security analyst job in Boston, MA
Join our global Cyber team as a Wordings Analyst supporting the Global Cyber Wordings Manager in the strategic development and governance of our Cyber and Tech policy suite, including Liberty Cyber Resolution and Liberty Tech Resolution. This role is a hands-on business enabler: you will help translate complex legal and regulatory requirements into clear, market-ready wordings, maintain our global clause library, support manuscript negotiations, and produce practical tools that empower underwriters and strengthen broker confidence. It's an excellent opportunity for an early-career insurance wordings or legal professional to build expertise in a fast-moving, global specialty line and make a visible impact on growth, innovation, and client experience.
Key responsibilities:
Wording library and drafting support
Maintain and expand the global wording library centered on Liberty Cyber Resolution and Liberty Tech Resolution, including endorsements, exclusions, and guidance notes.
Redline and prepare first drafts of standard clauses and endorsements; ensure consistency with definitions, coverage intent, and plain-language standards.
Track version control, change logs, approvals, and archiving;
Assist with localization for different jurisdictions, coordinating translations and filing documentation with Legal/Compliance.
Commercial enablement
Build practical tools (playbooks, FAQs, objection-handling guides, coverage summaries) to help regional teams position our products and close deals efficiently.
Prepare broker/client comparison decks and battlecards; support pitches, RFP/RFI responses, and manuscript negotiations with clause comparisons and recommended alternatives.
Triage wording queries from regions; track SLAs and referral approvals per the global governance framework.
Partner closely with Underwriting, Product, Global Cyber Engagement, Claims, Legal/Compliance, and regional leaders to deliver accurate, timely support and uphold governance standards.
Regulatory and legal stewardship
Monitor and synthesize global regulatory and market developments (e.g., Lloyd's cyber war/systemic guidance, GDPR, DORA, NIS2, sanctions) into succinct briefs and recommended wording actions.
Maintain audit-ready documentation; assist with regulatory filings or attestations where required.
Claims partnership and feedback loop
Collaborate with Claims to capture lessons from disputes and litigation trends; draft guidance notes and propose clarifications to improve coverage certainty.
Support coverage position letters and documentation packs with research, citations, and clause histories.
Innovation and product development support
Help draft prototype wordings for new propositions
Check alignment between underlying policy wordings and reinsurance treaty/facultative clauses.
Administer wording management tools, ensuring robust version control, approval workflows, and usage analytics.
Build dashboards and trackers for adoption of standard forms, deviation rates, SLA performance, disputes, and audit findings; provide monthly reporting to stakeholders.
Qualifications
Bachelor's degree in business, economics, or other quantitative field. Minimum 3 years, typically 4 years or more of relevant work experience.
2 - 5 years of experience in insurance wordings, legal/paralegal support, underwriting support, or product documentation; cyber specialty experience preferred.
Strong drafting, redlining, and proofreading skills with a plain-language mindset and exceptional attention to detail.
Working knowledge of insurance policy structures, endorsements, exclusions, and coverage interpretation; familiarity with cyber war/systemic language, sanctions, and privacy regulations is advantageous.
Research and synthesis skills to translate complex regulatory/legal topics into practical guidance and actionable updates.
Proficiency with MS Word (advanced track changes/redlining), Excel (trackers and dashboards), PowerPoint (training/pitch materials), and document/enablement tools.
Collaborative, service-oriented approach; comfortable operating in a global matrix and meeting defined SLAs.
Curiosity about cybersecurity risks and the incident response ecosystem; willingness to learn common threat scenarios to inform practical drafting.
About Us
Pay Philosophy: The typical starting salary range for this role is determined by a number of factors including skills, experience, education, certifications and location. The full salary range for this role reflects the competitive labor market value for all employees in these positions across the national market and provides an opportunity to progress as employees grow and develop within the role. Some roles at Liberty Mutual have a corresponding compensation plan which may include commission and/or bonus earnings at rates that vary based on multiple factors set forth in the compensation plan for the role.
At Liberty Mutual, our goal is to create a workplace where everyone feels valued, supported, and can thrive. We build an environment that welcomes a wide range of perspectives and experiences, with inclusion embedded in every aspect of our culture and reflected in everyday interactions. This comes to life through comprehensive benefits, workplace flexibility, professional development opportunities, and a host of opportunities provided through our Employee Resource Groups. Each employee plays a role in creating our inclusive culture, which supports every individual to do their best work. Together, we cultivate a community where everyone can make a meaningful impact for our business, our customers, and the communities we serve.
We value your hard work, integrity and commitment to make things better, and we put people first by offering you benefits that support your life and well-being. To learn more about our benefit offerings please visit: ***********************
Liberty Mutual is an equal opportunity employer. We will not tolerate discrimination on the basis of race, color, national origin, sex, sexual orientation, gender identity, religion, age, disability, veteran's status, pregnancy, genetic information or on any basis prohibited by federal, state or local law.
Fair Chance Notices
California
Los Angeles Incorporated
Los Angeles Unincorporated
Philadelphia
San Francisco
We can recommend jobs specifically for you! Click here to get started.
Auto-ApplySenior Cyber Security Analyst (42466)
Information security analyst job in Smithfield, RI
Senior Cyber Security Analyst is an experienced cyber security individual who maintains the security of an organization's technical environment. They study existing security hardware and software, evaluate new security options and makes recommendations for improvement. Senior Cyber Security Analyst also identifies weak spots in a cyber security system that may be breached and creates procedures to manage threats. Senior Cyber Security Analyst monitors networks for suspicious activity and potential cyber threats. They keep up on threat intelligence, install and maintain security software and encryption. They are responsible for aiding in the planning of security systems, implementing policy and identifying business processes that may violate intended and acceptable use policies. They monitor and remediate vulnerabilities. Senior Cyber Security Analyst works on advanced, complex technical projects or business issues requiring state of the art technical or industry knowledge.
Duties and Responsibilities
Responsibilities include, but are not limited to the following:
* Assist in developing, operating, and evolving Cloud Access Security solutions and capabilities
* Performs system security administration on designated technology platforms, including operating systems, applications and network security devices, in accordance with the defined policies, standards and procedures of the organization, as well as with industry best practices and vendor guidelines
* Performs installation and configuration management of security systems and applications, including policy assessment and compliance tools, network security appliances and host-based security systems
* Performs threat and vulnerability assessments, followed by appropriate remedial action, to ensure that systems are protected from known and potential threats and are free from known vulnerabilities Research, recommend, and implement streamlined automation processes
* Develops and maintains documentation for security systems and procedures
* Conducts network monitoring and intrusion detection analysis using various computer network defense tools, such as intrusion detection/prevention systems, firewalls and host-based security systems
* Provide support to one or more projects simultaneously. Delivers projects on schedule
* Deploys cloud-centric detection to detect threats related to cloud environments and services used by the organization
* Assists and trains junior team members in the use of security tools, the preparation of security reports and the resolution of security issues
* Applies patches where appropriate and, removes or otherwise mitigates known control weaknesses, such as unnecessary services or applications or redundant user accounts, as a means of hardening systems in accordance with security policies and standards Correlates activity across assets (endpoint, network, apps) and environments (on-premises, cloud) to identify patterns of anomalous activity
* Using threat intelligence information research emerging threats and vulnerabilities to aid in the identification of incidents
* Job Knowledge - Remains up-to-date in assigned area of responsibility: possesses skills and knowledge to perform job effectively; efficiently and safely; acquires, understands, and applies technical and professional information and skills; understands and adheres to policies and procedures
* Supports the creation of security incident response, business continuity/disaster recovery plans, including conducting tests, publishing test results and making changes necessary to address deficiencies
* Analyzes problems and alternative solutions and takes appropriate timely action to achieve desired business results. Seeks unique and novel solutions to problems and considers impact of final resolution
* Perform security standards testing against computers before implementation to ensure security
* Provide Key Performance Metrics to our Risk Management team to help coordinate risk tracking.
* Educate internal teams on information security best practices.
* Assist in technical audits of IT Systems and controls.
* Other duties as assigned.
* Corporate Compliance Responsibility - As an essential function, responsible for complying with Neighborhood's Corporate Compliance Program, Standards of Business Conduct, applicable contracts, laws, rules and regulations, policies and procedures as it applies to individual job duties, the department, and the Company. This position must exercise due diligence to prevent, detect and report unlawful and/or unethical conduct by fellow co-workers, professional affiliates and/or agents
Senior Analyst, Security (Onsite)
Information security analyst job in Westford, MA
Country:
United States of America Onsite
U.S. Citizen, U.S. Person, or Immigration Status Requirements:
Active and transferable U.S. government issued security clearance is required prior to start date. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance
Security Clearance:
DoD Clearance: Secret
At RTX, the foundation of everything we do is rooted in our values and a higher calling - to help our nation and allies defend freedoms and deter aggression. We bring the strength of more than 100 years of experience and renowned engineering expertise to meet the needs of today's mission and stay ahead of tomorrow's threat. Our team solves tough, meaningful problems that create a safer, more secure world.
The Senior Analyst, Security will help develop, administer and maintain the program's security policies and procedures in a fast-paced, deadline driven environment to ensure compliance with the 32 CFR Part 117 National Industrial Security Program Operating Manual (NISPOM), Department of Defense Manual (DoDM) 5205.07 series, Intelligence Community Directive (ICD) 705.
**
This position is onsite in Westford, MA **
What YOU will do:
Administering the security procedures (NISPOM, DoDM 5205.07 series, and Intelligence Community Directive (ICD) 705), as they relate to operating in a classified environment for: personnel processing, media control, marking and control of documents / materials, security education, visitor control, destruction of classified,
Request, review and submit investigative Standard From (SF) for background investigations.
Submit and track foreign travel through DISS.
Implement local Standard Operating Procedures (SOP), Operations Security (OPSEC) Plans, and proprietary test plans utilizing risk management principles.
Assist in the security oversight and management to subcontractors and subordinate business units via the DD Form 254 or other contractual methods.
Support the establishment, accreditation, and maintenance of a secure facility in accordance with (IAW) ICD 705.
Establish and oversee specialized procedures for the transmission of classified and/or proprietary material/information.
Conduct and/or participate in internal reviews and/or Government inspections.
Investigate security infractions/violations and prepare reports specifying the potential for loss or compromise and the associated risk to the program(s).
Collaborate and assist the FSO on implementation of Security requirements.
This position may require travel.
Qualifications You Must Have:
Typically requires a University Degree and minimum 2 years of prior relevant experience or an Advanced Degree in a related Experience with any of the following: NISPOM, DoDM 5205.07 series, and/or ICD 705.
Active and transferable U.S. government issued TOP SECRET security clearance is required prior to start date.
U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance.
Qualifications We Prefer
Previous experience as a security professional supporting SAP and/or SCI programs.
Degree major in Business Management, Security and/or Risk Management, Government Policy, Information Management, Criminal Justice, or other related fields of study.
At least 5 years of National Security experience is preferred.
What We Offer:
Some of our competitive benefits packages include:
Medical, dental, and vision insurance.
Three weeks of vacation for newly hired employees.
Generous 401(k) plan that includes employer matching funds and separate. employer retirement contribution, including a Lifetime Income Strategy option.
Tuition reimbursement program.
Student Loan Repayment Program.
Life insurance and disability coverage.
Optional coverages you can buy pet insurance, home and auto insurance, additional life and accident insurance, critical illness insurance, group legal, ID theft protection.
Birth, adoption, parental leave benefits.
Ovia Health, fertility, and family planning.
Adoption Assistance.
Autism Benefit.
Employee Assistance Plan, including up to 10 free counseling sessions.
Healthy You Incentives, wellness rewards program.
Doctor on Demand, virtual doctor visits.
Bright Horizons, child, and elder care services.
Teladoc Medical Experts, second opinion program.
And more!
Learn More & Apply Now!
Do you want to be part of a new, exciting initiative to combine foundational IT with new digital technologies? Our Digital Technology team is driving business efficiencies and a better customer experience by connecting technologies, people, information and processes. From making aircraft more electric, intelligent and integrated to building new software platforms such as Internet of Things, big data, artificial intelligence, and blockchain, there's no better place to be right now than in digital. If you're an agile thinker who enjoys utilizing modern technology to make big improvements, then you're a perfect fit for this team. Join Collins Aerospace to help us revolutionize the aerospace industry today!
WE ARE REDEFINING AEROSPACE.
* Please consider the following role type definitions as you apply for this role.
Onsite: Employees who are working in Onsite roles will work primarily onsite. This includes all production and maintenance employees, as they are essential to the development of our products.
Regardless of your role type, collaboration and innovation are critical to our business and all employees will have access to digital tools so they can work with colleagues around the world - and access to Collins sites when their work requires in-person meetings.
At Collins, the paths we pave together lead to limitless possibilities. And the bonds we form - with our customers and with each other -- propel us all higher, again and again.
Apply now and be part of the team that's redefining aerospace, every day.
The salary range for this role is 66,000 USD - 130,000 USD. The salary range provided is a good faith estimate representative of all experience levels. RTX considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate's work experience, location, education/training, and key skills.Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement.Hired applicants may be eligible for annual short-term and/or long-term incentive compensation programs depending on the level of the position and whether or not it is covered by a collective-bargaining agreement. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company's performance.This role is a U.S.-based role. If the successful candidate resides in a U.S. territory, the appropriate pay structure and benefits will apply.RTX anticipates the application window closing approximately 40 days from the date the notice was posted. However, factors such as candidate flow and business necessity may require RTX to shorten or extend the application window.
RTX is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or veteran status, or any other applicable state or federal protected class. RTX provides affirmative action in employment for qualified Individuals with a Disability and Protected Veterans in compliance with Section 503 of the Rehabilitation Act and the Vietnam Era Veterans' Readjustment Assistance Act.
Privacy Policy and Terms:
Click on this link to read the Policy and Terms
Auto-ApplySenior Security Analyst
Information security analyst job in Boston, MA
We are seeking a detail-oriented and highly skilled Security Analyst to join our team in Boston and shape the future of Cybersecurity. As a Security Analyst at 7AI, you will leverage your expertise of the security landscape to review and analyze AI Agent investigations, ensuring accuracy and completeness, ultimately helping to build our multi-agent platform. You will be integral in building and maintaining the reliability of our AI Agents, working in tandem with Engineering and Product to inform our roadmap as we build. If you want to build the next generation of Cybersecurity and put AI in the hands of defenders, please apply below.
Key Responsibilities:
Review and validate alerts and investigations completed by the AI Agents for accuracy and completeness.
Collaborate with the Engineering and Product teams to provide feedback and assist in optimizing the AI platform.
Develop internal playbooks, standard operating procedures and tools that will guide the AI Agents to perform quality investigations.
Stay current with emerging cybersecurity trends, vulnerabilities, and new attack techniques, especially the field of AI-driven attacks.
Investigate flagged security incidents, analyzing potential threats and confirming the findings generated by AI.
Recommend mitigation strategies and remediation steps to train the AI to reduce the threat surface.
Correlate findings from multiple sources, including network logs, endpoint data, and threat intelligence, to validate AI-generated reports.
Assist with ongoing threat monitoring, triage, and prioritization of security incidents.
Required Qualifications:
4+ years of experience in a Security Analyst or similar role within the cybersecurity field.
Hands-on experience with incident response for Cloud and Identity alerts, and at least two of Email, EDR, Threat Intel and Networking alerts.
Strong understanding of security monitoring tools and techniques (SIEM, IDS/IPS, IDP, etc.).
Experience analyzing and investigating security alerts from multiple sources, including intrusion detection systems, network monitoring tools, and endpoint protection platforms.
Familiarity with the latest cybersecurity threats, attack vectors, and vulnerabilities.
Strong analytical and problem-solving skills, with the ability to verify AI-driven analysis and make independent security decisions.
Scripting experience with languages such as Python
Data querying experience with SIEM technologies (SPL, KQL, FQL, SQL, etc).
Auto-ApplySenior Security Compliance Analyst
Information security analyst job in Boston, MA
Job Description
At OneStudyTeam (a Reify Health company), we specialize in speeding up clinical trials and increasing the chance of new therapies being approved with the ultimate goal of improving patient outcomes. Our cloud-based platform, StudyTeam, brings research site workflows online and enables sites, sponsors, and other key stakeholders to work together more effectively. StudyTeam is trusted by the largest global biopharmaceutical companies, used in over 6,000 research sites, and is available in over 100 countries. Join us in our mission to advance clinical research and improve patient care.
One mission. One team. That's OneStudyTeam.
We are seeking a Senior Security Compliance Analyst with expertise in Governance, Risk, and Compliance (GRC) to support and enhance our security and compliance programs within the healthcare industry. This role is critical in ensuring adherence to industry regulations, responding to customer audits, and maintaining compliance with ISO 27001, HIPAA, and other security frameworks.
The ideal candidate will be a detail-oriented compliance expert who can navigate complex regulatory environments, assist with internal/external audits, and drive continuous improvement in security governance. The ideal candidate must be able to operate independently while delivering on the following duties.
What You'll Be Working On:
Lead and support customer security audits, responding to security questionnaires and demonstrating compliance with security frameworks.
Prepare, coordinate, and manage ISO 27001 audits, including evidence collection, control implementation, and auditor engagement.
Ensure ongoing compliance with HIPAA, NIST CSF, and other regulatory requirements applicable to healthcare data security.
Develop and maintain policies, procedures, and security documentation to meet regulatory and contractual obligations.
Perform gap analyses and risk assessments to identify and remediate compliance risks.
Manage and improve security governance frameworks, ensuring alignment with industry best practices and business objectives.
Conduct third-party vendor risk assessments, ensuring compliance with security policies and contractual obligations.
Monitor security controls, ensuring effectiveness and continuous improvement in alignment with security frameworks.
Support security awareness training initiatives, ensuring employees understand compliance responsibilities.
Stay current on ISO 27001, HIPAA, NIST 800-53, and other relevant standards, translating them into actionable security controls.
Assist in defining security metrics and reporting on compliance status and risk posture to leadership.
Work closely with legal, security, IT, and business teams to align compliance requirements with security operations.
What You'll Bring to OneStudyTeam:
Bachelor's degree in Information Security, Computer Science, Risk Management, or related field (or equivalent experience).
8+ years of progressive experience in GRC, compliance, or security audit roles.
Experience in healthcare or regulated industries strongly preferred.
Certifications strongly preferred: ISO 27001 Lead Auditor/Implementer, CISSP, CISM, CISA, HITRUST CCSFP, CRISC.
Experience leading ISO 27001, SOC2, or HITRUST audits, including ISMS implementation and external audit coordination.
Strong understanding of NIST CSF, SOC 2, GDPR, and other security frameworks.
Hands-on experience with customer security audits, including responding to security questionnaires and managing security assessments.
Ability to perform risk assessments, policy reviews, and compliance gap analyses.
Strong written and verbal communication skills, with the ability to explain technical concepts to non-technical stakeholders.
Detail-oriented with excellent organizational and project management skills.
Ability to work independently and collaboratively in a remote environment.
Familiarity with GRC tools (e.g., OneTrust, LogicGate, Archer, Vanta, Drata) is a plus.
We value diversity and believe the unique contributions each of us brings drives our success. We do not discriminate on the basis of race, sex, religion, color, national origin, gender identity, age, marital status, veteran status, or disability status.
Note: OneStudyTeam is unable to sponsor work visas at this time. If you are a non-U.S. resident applicant, please note that OneStudyTeam works with a Professional Employer Organization.
As a condition of employment, you will abide by all organizational security and privacy policies.
This organization participates in E-Verify (E-Verify's Right to Work guidance can be found here).
Information Systems Security Officer (ISSO) III
Information security analyst job in Bedford, MA
Type of Requisition:
Regular
Clearance Level Must Currently Possess:
Top Secret/SCI
Clearance Level Must Be Able to Obtain:
Top Secret SCI + Polygraph
Public Trust/Other Required:
None
Job Family:
Cyber and IT Risk Management
Job Qualifications:
Skills:
Information Security, Information Security Management, Information System Security
Certifications:
Cisco Certified Network Associate (CCNA) Security - Cisco - Cisco, GSEC: GIAC Security Essentials Certification - Global Information Assurance Certification (GIAC) - Global Information Assurance Certification (GIAC)
Experience:
5 + years of related experience
US Citizenship Required:
Yes
Job Description:
The Information Systems Security Officer (ISSO) III is responsible for ensuring the appropriate operational security posture is maintained for an information system and as such, works in close collaboration with the ISSM and ISO. The position shall have the detailed knowledge and expertise required to manage the security aspects of an information system and, in many organizations, is assigned responsibility for the day-to-day security operations of a system.
This will include physical and environmental protection, personnel security, incident handling, and security training and awareness. It will be required to work in close coordination with the ISSM and ISO in monitoring the information system(s) and its environment of operation to include developing and updating the authorization documentation, implementing configuration management across authorization boundaries.
This will include assessing the security impact of those changes and making recommendation to the ISSM. The primary function is working within Special Access Programs (SAPs) supporting Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense (OSD) and Military Compartments efforts. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities.
Performance shall include:
Assist the ISSM in meeting their duties and responsibilities.
Prepare, review, and update authorization packages.
Ensure approved procedures are in place for clearing, sanitizing, and destroying various types of hardware and media.
Notify ISSM when changes occur that might affect the authorization determination of the information system(s).
Conduct periodic reviews of information systems to ensure compliance with the security authorization package.
Coordinate any changes or modifications to hardware, software, or firmware of a system with the ISSM and AO/DAO prior to the change.
Monitor system recovery processes to ensure security features and procedures are properly restored and functioning correctly.
Ensure all IS security-related documentation is current and accessible to properly authorized individuals.
Ensure audit records are collected, reviewed, and documented (to include any anomalies)
Attend required technical and security training (e.g., operating system, networking, security management) relative to assigned duties.
Execute the cyber security portion of the self-inspection, to include security coordination and review of all system assessment plans.
Identify cyber security vulnerabilities and assist with the implementation of the countermeasures for them.
Prepare reports on the status of security safeguards applied to computer systems.
Perform ISSO duties in support of in-house and external customers.
Conduct continuous monitoring activities for authorization boundaries under your preview.
Assist Department of Defense, National Agency and Contractor organizations with the development of assessment and authorization (A&A) efforts.
Experience:
5+ years related experience, especially in developing RMF packages or bodies of evidence.
2+ years SAP experience required.
Prior performance in roles such as System, Network Administrator or ISSO.
Education:
Bachelor's degree in a related area or equivalent experience (4 years)
Certifications:
IAT Level II ( Security+ CE, CCNA Security, etc) or IAM Level II.
Clearance Required to Start:
TS/SCI required.
Must be able to Attain - TS/SCI with CI Polygraph
#AirforceSAPOpportunities #ISSO III
The likely salary range for this position is $98,345 - $133,055. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
Scheduled Weekly Hours:
40
Travel Required:
10-25%
Telecommuting Options:
Onsite
Work Location:
USA MA Bedford
Additional Work Locations:
Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.Join our Talent Community to stay up to date on our career opportunities and events at
gdit.com/tc.
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
Auto-ApplyInformation Systems Security Officer (ISSO)
Information security analyst job in Boston, MA
ISSO Employment Type: Full-Time, Experienced Department: Information Technology CGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment documentation to support Dept. of Commerce systems and efforts to achieve their Authorization to Operate (ATO). This position is located at the client site in the Herbert Hoover building in Washington, DC. The scope of this position includes full life-cycle Assessment and Authorization (A&A) management through all 6 Steps of the RMF process in support of the Government ISSM.In this role, you'll conduct security assessment, and information system security oversight activities in accordance with NIST 800.53 that support systems from the perspective RMF requirements.
CGS brings motivated, highly skilled, and creative people together to solve the government's most dynamic problems with cutting-edge technology. To carry out our mission, we are seeking candidates who are excited to contribute to government innovation, appreciate collaboration, and can anticipate the needs of others. Here at CGS, we offer an environment in which our employees feel supported, and we encourage professional growth through various learning opportunities.
Skills and attributes for success:
* Review systems to identify potential security weaknesses and recommend improvements to amend vulnerabilities, implement changes, and document upgrades.
* Maintain responsibility for managing cybersecurity risk from an organizational perspective.
* Identify organizational risks, prioritize those risks, and maintain a risk registry for escalating and presenting those risks to senior leadership.
* Provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies.
* Providing configuration management (CM) recommendations for information system security software, hardware, and firmware and coordinating changes and modifications with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO).
* Maintain vulnerability scanning tool compliance, such as HBSS or ACAS, and patch management, such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance with all applicable directives, manage system changes, and assess the security impact of those changes.
* Support security authorization activities, including transitioning from the legacy Information Assurance Certification and Accreditation Process (DIACAP) to compliance with the DoC RMF.
* Provide subject matter expertise for cyber security and trusted system technology.
* Apply advanced technical knowledge and analysis of specialized functional areas in task requirements to develop solutions to complex problems.
* Research, write, review, disposition feedback, and finalize recommendations regarding cyber security policy, assessment and authorization assessments (A&As), security test and evaluation reports, and security engineering practices and processes.
* Conduct research and write risk assessment reports to include risk thresholds, evaluation, and scoring.
* Support analysis of the findings and provide expert technical guidance for mitigation strategies, including implementation advice on the cyber security risk findings, and other complex problems.
Qualifications:
* Bachelor's Degree.
* A minimum of five (5) years experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development, including generating security documentation for requirements, security control assessment, STIG and IAVA compliance, Standard Operating Procedures, test results, etc.
* eMASS experience.
* Professional security certification such as: CCNA Security, CySA+, GICSP, GSEC, CompTIA Security+ CE, SSCP, or higher.
* Strong desktop publishing skills using Microsoft Word and Excel.
* Experience with industry writing styles such as grammar, sentence form, and structure.
* Ability to multi-task in a deadline-oriented environment.
Ideally, you will also have:
* CISSP, CASP, or a similar certificate is preferred.
* Master's Degree in Cybersecurity or related field.
* Strong initiative, detail orientation, organizational skills, and aptitude for analytical thinking.
* Demonstrated ability to work well independently and as a part of a team.
* Excellent work ethic and a high commitment to quality.
Our Commitment:
Contact Government Services (CGS) strives to simplify and enhance government bureaucracy through the optimization of human, technical, and financial resources. We combine cutting-edge technology with world-class personnel to deliver customized solutions that fit our client's specific needs. We are committed to solving the most challenging and dynamic problems.
For the past seven years, we've been growing our government contracting portfolio, and along the way, we've created valuable partnerships by demonstrating a commitment to honesty, professionalism, and quality work.
Here at CGS we value honesty through hard work and self-awareness, professionalism in all we do, and to deliver the best quality to our consumers mending those relations for years to come.
We care about our employees. Therefore, we offer a comprehensive benefits package.
Health, Dental, and Vision
Life Insurance
401k
Flexible Spending Account (Health, Dependent Care, and Commuter)
Paid Time Off and Observance of State/Federal Holidays
Contact Government Services, LLC is an Equal Opportunity Employer. Applicants will be considered without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Join our team and become part of government innovation!
Explore additional job opportunities with CGS on our Job Board:
*************************************
For more information about CGS please visit: ************************** or contact:
Email: [email protected]
#CJ
$92,213.33 - $125,146.66 a year
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Director, Information Security
Information security analyst job in Boston, MA
At DraftKings, AI is becoming an integral part of both our present and future, powering how work gets done today, guiding smarter decisions, and sparking bold ideas. It's transforming how we enhance customer experiences, streamline operations, and unlock new possibilities. Our teams are energized by innovation and readily embrace emerging technology. We're not waiting for the future to arrive. We're shaping it, one bold step at a time. To those who see AI as a driver of progress, come build the future together.
The Crown Is Yours
As a Director, Information Security, you'll lead our Security Engineering and Security Operations teams to shape how we defend our platforms at scale. You'll build modern security programs grounded in automation, AI, and pragmatic risk management. You'll drive strategy, deliver key capabilities, and evolve our approach to detection, response, and resilience. This is a hands-on leadership role where you'll empower technical leaders, elevate team performance, and partner closely with Engineering, Legal, IT, and Information Security leadership.
What You'll Do
Lead a high-performing team of managers and senior individual contributors; foster growth through coaching, clarity, and development planning.
Provide strategic direction and mentorship to the broader InfoSec team through skip levels, feedback loops, and leadership modeling.
Define and communicate KPIs to drive the program, looking across operational impact as well as technical indicators of risk and drift toward failure.
Partner with InfoSec leadership on roadmap planning, prioritization, risk management, and capability development across detection, response, engineering, and investigations.
Advance our adoption of AI and automation to drive quantifiable impact across security functions, both in new capabilities and latency.
Collaborate with Legal, Compliance, and Audit to meet regulatory and customer expectations.
What You'll Bring
At least 10 years of progressive experience in security, including 5+ years in leadership roles with a strong emphasis on both proactive security engineering and reactive security operations.
Strong technical foundation in modern enterprise and cloud environments, including what we secure (AWS, GCP, Kubernetes, datacenters, IoT) and what we secure it with (SIEM, EDR, CSPM, SAST/DAST, IAM, forensics).
Familiarity with industry-standard risk and compliance frameworks (NIST CSF, ISO 27001, SOC 2, SLSA) and how to operationalize them in modern, tech-forward environments.
Experience in fast-paced, high-growth companies in enterprise tech, SaaS, gaming, or other technical consumer industries like online video gaming.
Executive-level communication skills, including the ability to deliver clear, timely, and actionable updates to both technical stakeholders and executive leadership.
Join Our Team
We're a publicly traded (NASDAQ: DKNG) technology company headquartered in Boston. As a regulated gaming company, you may be required to obtain a gaming license issued by the appropriate state agency as a condition of employment. Don't worry, we'll guide you through the process if this is relevant to your role.
The US base salary range for this full-time position is 216,000.00 USD - 270,000.00 USD, plus bonus, equity, and benefits as applicable. Our ranges are determined by role, level, and location. The compensation information displayed on each job posting reflects the range for new hire pay rates for the position across all US locations. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific pay range and how that was determined during the hiring process. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Auto-ApplySenior Information Security Engineer
Information security analyst job in Boston, MA
At WHOOP, we're on a mission to unlock human performance. WHOOP empowers members to perform at a higher level through a deeper understanding of their bodies and daily lives. WHOOP is seeking a Senior Information Security Engineer to serve as a technical leader in our Security team reporting to our Information Security Manager. In this role, you will drive the deployment and continuous enhancement of controls that protect millions of users' biometric and health data, build scalable defenses across our infrastructure and applications, and lead incident response efforts with visibility across the business. This is an opportunity to have direct impact at scale, working alongside engineers, product teams, and executives to drive forward-looking security strategies. RESPONSIBILITIES:
Implement and enhance security controls by leading the deployment, integration, and tuning of solutions such as CNAPP, SIEM, CASB, EDR, DLP, and MDM to maximize effectiveness.
Support security design decisions by providing subject matter expertise on cloud and SaaS security best practices while influencing architecture led by the Security Architect role.
Lead incident response and investigations by guiding containment, remediation, root cause analysis, and post-incident improvements.
Strengthen application security by overseeing secure development practices and managing SAST, SCA, and DAST tooling.
Advance identity and access management by supporting IAM policy enforcement, SSO, MFA, SCIM, RBAC, and user lifecycle governance.
Secure AI systems and integrations by assessing and protecting embedded APIs and organizational AI tool usage to ensure resilience, privacy, and compliance.
Collaborate cross-functionally by working with Engineering, IT, and GRC teams to embed security into systems and workflows.
Mentor and influence by providing technical guidance, reviewing work, and promoting security-first thinking across the organization.
Stay ahead of threats and regulations by tracking emerging risks, technologies, and compliance requirements to inform forward-looking strategies.
Participate in and help improve the on-call rotation by providing guidance, escalation support, and driving improvements in response processes.
QUALIFICATIONS:
Bachelor's degree in Computer Science, Information Security, or a related technical field and/or advanced certifications (CISSP, CISM, AWS Security Specialty, SANS, etc.).
8+ years of hands-on experience in Information Security, IT Security, or a related role, including at least 2 years in a senior or lead capacity.
Proven track record implementing and managing advanced security technologies (e.g., CASB, CNAPP, CSPM, SIEM, SOAR, DLP, SWG).
Experience securing AI/ML systems or APIs, including governance of third-party AI integrations and organizational use of AI tools.
Strong understanding of modern cloud security architecture (AWS, Azure, GCP) and experience performing threat modeling and risk assessments on cloud-based systems.
Hands-on experience with application security tooling (SAST, SCA, DAST) and embedding secure development practices.
Demonstrated leadership in security incident response, investigations, and root cause analysis.
Effective communicator with the ability to influence stakeholders and explain security concepts to technical and non-technical audiences.
Strong project management skills and the ability to drive initiatives to completion in a fast-paced environment.
Experience mentoring engineers and setting operational standards.
Familiarity with compliance and risk frameworks relevant to health and AI (SOC 2, ISO 27001, PCI, GDPR, FTC guidance, HIPAA-adjacent state laws) is a plus.
Interested in the role, but don't meet every qualification? We encourage you to still apply! At WHOOP, we believe there is much more to a candidate than what is written on paper, and we value character as much as experience. As we continue to build a diverse and inclusive environment, we encourage anyone who is interested in this role to apply.
WHOOP is an Equal Opportunity Employer and participates in E-verify to determine employment eligibility. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
The WHOOP compensation philosophy is designed to attract, motivate, and retain exceptional talent by offering competitive base salaries, meaningful equity, and consistent pay practices that reflect our mission and core values.
At WHOOP, we view total compensation as the combination of base salary, equity, and benefits, with equity serving as a key differentiator that aligns our employees with the long-term success of the company and allows every member of our corporate team to own part of WHOOP and share in the company's long-term growth and success.
The U.S. base salary range for this full-time position is $150,000 - $190,000. Salary ranges are determined by role, level, and location. Within each range, individual pay is based on factors such as job-related skills, experience, performance, and relevant education or training. In addition to the base salary, the successful candidate will also receive benefits and a generous equity package.
These ranges may be modified in the future to reflect evolving market conditions and organizational needs. While most offers will typically fall toward the starting point of the range, total compensation will depend on the candidate's specific qualifications, expertise, and alignment with the role's requirements.
Learn more about WHOOP.
Auto-ApplyInformation Security Manager
Information security analyst job in Boston, MA
Are you a Cybersecurity compliance expert ready to take the lead in a dynamic, high-impact role? Join a globally recognized firm where you'll play a key role in shaping and strengthening our cybersecurity strategy. This is your chance to make a difference in a fast-paced, professional environment that values innovation, collaboration, and technical excellence.
Why You'll Love This Role:
Drive Security Initiatives - Lead firmwide cybersecurity programs, ensuring compliance with ISO 27001 and other industry standards.
Be a Decision-Maker - Approve security risks, implement best practices, and enhance policies to safeguard critical systems.
Third-Party & Risk Management - Oversee vendor risk assessments, vulnerability management, and client security audits.
Lead & Mentor - Supervise a Compliance Analyst and provide strategic guidance across teams.
Innovate & Protect - Collaborate with IT leadership to integrate cutting-edge security solutions into firm operations.
What You Bring to the Table:
5+ years of cybersecurity experience in a complex IT environment.
Strong knowledge of security frameworks (ISO 27001, NIST, etc.).
Hands-on experience with security tools, compliance audits, and risk assessments.
Leadership experience with a passion for mentoring and developing security professionals.
Bachelor's degree in Cyber Security, Computer Science, or a related field. Security certifications (CISSP, CRISC, etc.) strongly preferred.
Offer includes:
Competitive salary: $145,000 - $170,000
Hybrid work environment
Excellent benefits package
A culture of excellence, diversity, and professional growth
Ready to step into a leadership role where your expertise will make a real impact? Apply today and be a key player in securing the future of a top international firm.
Apply to this post or email your resume directly to Dan Gilliam, email: ****************************
Tags: Cybersecurity, IT, ISO, Compliance, Security Manager
Easy ApplySenior Information System Security Officer (ISSO) - Woburn, MA
Information security analyst job in Woburn, MA
Country: United States of America Onsite U.S. Citizen, U.S. Person, or Immigration Status Requirements: Active and transferable U.S. government issued security clearance is required prior to start date. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance
Security Clearance:
Secret - Current
At Raytheon, the foundation of everything we do is rooted in our values and a higher calling - to help our nation and allies defend freedoms and deter aggression. We bring the strength of more than 100 years of experience and renowned engineering expertise to meet the needs of today's mission and stay ahead of tomorrow's threat. Our team solves tough, meaningful problems that create a safer, more secure world.
Our cybersecurity team is seeking a Senior Information Systems Security Officer (ISSO) to support our team 100% onsite at our facility in Woburn, Massachusetts. The successful candidate will interface with the Information Systems Security Manager (ISSM) to ensure adherence with NIST Special Publications, customer directives, and company policies as applicable all NISPOM Chapter 8, DAAPM, JSIG policies.
What You Will Do
* Assessing and monitoring system compliance, auditing, security plan development and delivering information systems security education and awareness.
* Investigating information system security violations and help prepare reports specifying corrective and preventative actions.
* Reviewing and approving (within authority) configuration management requests.
* Conducting technical and administrative assessments.
* Integrating new cybersecurity processes, procedures, and tools.
* Support the creation, review and update of cybersecurity documentation and other technical writing.
Qualifications You Must Have
* Typically requires a University Degree or equivalent experience and minimum 5 years prior relevant experience, or an Advanced Degree in a related field and minimum 3 years' experience.
* Current IAM Level I certification (Security+ or other).
* Relevant Experience Considered in any combination:
* Cybersecurity, systems security or hardening
* Information Technology
* Compliance-based auditing using the Risk Management Framework (RMF), DCSA Assessment and Authorization Process Manual (DAAPM), Joint SAP Implementation Guide (JSIG), National Industrial Security Program Operating Manual (NISPOM), and/or non-defense regulations such as FAA, Payment Card Industry (PCI), ISO 9001 Quality Management standards, or HIPPA
* Experience working with and/or supporting computer technologies (such as: databases, operating systems, computer network hardware, software programs, hardware troubleshooting or electronics)
* Physical security/security, policework/criminal justice, investigations, or Border Patrol
* Project or program management, office management, senior administration, or account management
Qualifications We Prefer
* Experience working in DoD classified operating and/or laboratory environments.
* Experience with various information system security tools that address vulnerability analysis and mitigation. These may include Splunk, Forcepoint, Ivanti, Tenable, ACAS, HBSS, etc.
* Familiarity with implementation of Government directives and policies derived from NIST, CNSSI, DoD, or other Government Regulatory compliance standards within a professional industry.
* Experience in the execution of the Assessment & Authorization processes, as defined within the Risk Managed Framework (RMF).
* Experience providing technical security consultation for complex, cross-domain, heterogeneous classified networked environments in collaboration with internal/external Customers, Information Technology (IT).
* Familiarity with large multi-facility networks including various complex components, including Windows and Linux environments.
* Experience interpreting, implementing, and assessing DISA STIGs.
* Familiarity with the execution and management of cyber incident response; preservation, containment, and eradication.
What We Offer
Our values drive our actions, behaviors, and performance with a vision for a safer, more connected world. At RTX we value: Trust, Respect, Accountability, Collaboration, and Innovation.
Relocation Non-Eligible - Relocation assistance not available
Please consider the following role type definition as you apply for this role:
* Onsite: Employees who are working in Onsite roles will work primarily onsite. This includes all production and maintenance employees, as they are essential to the development of our products.
We are RTX
#LI-Onsite
As part of our commitment to maintaining a secure hiring process, candidates may be asked to attend select steps of the interview process in-person at one of our office locations, regardless of whether the role is designated as on-site, hybrid or remote.
The salary range for this role is 82,000 USD - 164,000 USD. The salary range provided is a good faith estimate representative of all experience levels. RTX considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate's work experience, location, education/training, and key skills.
Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement.
Hired applicants may be eligible for annual short-term and/or long-term incentive compensation programs depending on the level of the position and whether or not it is covered by a collective-bargaining agreement. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company's performance.
This role is a U.S.-based role. If the successful candidate resides in a U.S. territory, the appropriate pay structure and benefits will apply.
RTX anticipates the application window closing approximately 40 days from the date the notice was posted. However, factors such as candidate flow and business necessity may require RTX to shorten or extend the application window.
RTX is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or veteran status, or any other applicable state or federal protected class. RTX provides affirmative action in employment for qualified Individuals with a Disability and Protected Veterans in compliance with Section 503 of the Rehabilitation Act and the Vietnam Era Veterans' Readjustment Assistance Act.
Privacy Policy and Terms:
Click on this link to read the Policy and Terms
Auto-ApplyIdentity and Access Management (IAM) Security Administration Senior Specialist (Mainframe / Oracle exp highly desired)acle exp highly desired)
Information security analyst job in Boston, MA
Boston, Massachusetts;Washington, District of Columbia **To proceed with your application, you must be at least 18 years of age.** Acknowledge Refer a friend **To proceed with your application, you must be at least 18 years of age.** Acknowledge (*******************************************************************************************************************************************************************
**Job Description:**
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates' physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
**LOB Overview:**
+ Global Information Security (GIS) is responsible for protecting bank information systems, confidential and proprietary data, and customer information. GIS develops the bank's Information Security strategy and policy, manages the Information Security program, identifies, and addresses vulnerabilities and operates global security operations centers that monitor, detect, and respond to cybersecurity incidents. Within GIS, Identity and Access Management (IAM) is a security discipline that enables the right individuals to access the right resources at the right times and in the right context. IAM addresses the mission-critical need to ensure appropriate access to the resources across increasingly heterogeneous technology environments, and to meet increasingly rigorous compliance requirements.
**Role Description:**
+ We are seeking a highly experienced and technically proficient **Senior Identity and Access Management (IAM) Specialist** to lead access provisioning initiatives across a complex enterprise environment. This role is critical to ensuring secure, compliant, and efficient access to systems and data, with a strong emphasis on enforcing **least privileged access** principles that eliminate excessive permissioning.
+ The ideal candidate will bring deep expertise in IAM technologies and platforms-including **Active Directory** , **Microsoft Azure, Amazon Web Services (AWS),** and **Mainframe** , **Oracle** , **SQL** , and various file and storage collaboration systems, password secure controls including keys and tokens -and will be responsible for designing and implementing scalable access provisioning solutions to integrate IAM processes across cloud services. This is a hands-on technical leadership role that requires strategic thinking, cross-functional collaboration, and a commitment to continuous improvements in identity governance and access platforms and controls.
**Responsibilities:**
+ Lead the design, implementation, and ongoing management of **access provisioning solutions** across enterprise platforms, ensuring alignment with security policies and regulatory requirements.
+ Serve as the subject matter expert for **Active Directory** , **Microsoft Azure, Amazon Web Services (AWS),** and **Mainframe** , **Oracle and SQL databases** , **file systems** , and **enterprise storage** , with a focus on enforcing **least privileged access** .
+ Develop and maintain **access control policies** , **group structures** , and **role-based access models** to support scalable and secure provisioning.
+ Collaborate with application owners, infrastructure teams, and business stakeholders to define and implement **access requirements** for new and existing systems.
+ Drive automation initiatives to streamline **provisioning and de-provisioning workflows** , integrating with identity governance platforms and HR systems and IAM controls.
+ Conduct periodic **access reviews** , **entitlement audits** , and **certification campaigns** to ensure compliance and identify access anomalies.
+ Investigate and remediate access-related incidents, working closely with cybersecurity and risk teams to address vulnerabilities and improve controls.
+ Provide technical leadership and mentorship to junior IAM team members, fostering a culture of security-first thinking and operational excellence.
+ Stay current with emerging IAM technologies, regulatory changes, and industry best practices to continuously enhance the access provisioning program.
+ Prepare and present metrics, reports, and recommendations to senior leadership and audit teams regarding access provisioning effectiveness and risk posture.
**Required Qualifications:**
+ **10+ years of progressive experience** in Identity and Access Management, with a strong focus on access provisioning across enterprise environments.
+ Deep technical expertise in **Active Directory** , **Microsoft Azure AWS, Mainframe** , **Oracle Database** , **SQL Server** , **Windows and Unix file systems** , and **enterprise storage platforms** .
+ Proven ability to design, implement, and manage access provisioning solutions that enforce **least privileged access** and align with regulatory and internal compliance requirements.
+ Strong understanding of **IAM governance frameworks** , platforms ( **e.g., SailPoint, Saviynt** ) **role-based access control (RBAC)** , **group policy management** , and **privileged access management (PAM)** tools, **CyberArk, Hashi Corp and Beyond Trust.**
+ Experience with **automated provisioning/de-provisioning workflows** , including integration with HR systems to demonstrated proficiency in scripting and automation (e.g., PowerShell, Python) to support scalable access provisioning and audit processes.
+ Familiarity with **cloud infrastructure security** and access controls in hybrid environments, particularly within **Microsoft Azure AWS** and **Oracle Cloud** .
+ Ability to conduct **access reviews** , **entitlement audits** , and **risk assessments** to identify and remediate access-related vulnerabilities.
+ Excellent analytical, problem-solving, and communication skills, with the ability to collaborate across technical and business teams.
**Shift:**
1st shift (United States of America)
**Hours Per Week:**
40
Bank of America and its affiliates consider for employment and hire qualified candidates without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote the concept of equal employment opportunity, in accordance with all applicable federal, state, provincial and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our teammates.
View your **"Know your Rights (************************************************************************************** "** poster.
**View the LA County Fair Chance Ordinance (************************************************************************************************** .**
Bank of America aims to create a workplace free from the dangers and resulting consequences of illegal and illicit drug use and alcohol abuse. Our Drug-Free Workplace and Alcohol Policy ("Policy") establishes requirements to prevent the presence or use of illegal or illicit drugs or unauthorized alcohol on Bank of America premises and to provide a safe work environment.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations. Should you be offered a role with Bank of America, your hiring manager will provide you with information on the in-office expectations associated with your role. These expectations are subject to change at any time and at the sole discretion of the Company. To the extent you have a disability or sincerely held religious belief for which you believe you need a reasonable accommodation from this requirement, you must seek an accommodation through the Bank's required accommodation request process before your first day of work.
This communication provides information about certain Bank of America benefits. Receipt of this document does not automatically entitle you to benefits offered by Bank of America. Every effort has been made to ensure the accuracy of this communication. However, if there are discrepancies between this communication and the official plan documents, the plan documents will always govern. Bank of America retains the discretion to interpret the terms or language used in any of its communications according to the provisions contained in the plan documents. Bank of America also reserves the right to amend or terminate any benefit plan in its sole discretion at any time for any reason.
Physical Security Systems Engineer
Information security analyst job in Wilmington, MA
Join Allied Universal Technology Services, a global leader in transforming the security industry. We integrate advanced technology - video surveillance, electronic access control, alarm monitoring and augmented solutions with physical security to help people feel safe. Whether you're an installation technician, service technician, engineer, or project manager, you'll discover rewarding opportunities to grow your career as part of a valued team.
Apply today and be phenomenal-build a meaningful career while protecting what matters most through innovative security technology.
Job Description
Allied Universal is looking to hire a Solution Engineer. The Solution Engineer creates all post-sale security systems design, engineering, value engineering, and documentation. The position is part of the Solutions Engineering department, which is responsible for translating, expanding, finalizing, and documenting pre-sales proposals and technical designs produced by Sales and Solutions Architecture in pre-sale systems architecting and quoting. This position works closely with Sales, Solutions Architecture, Operations, and external customers as required.
The primary work products for the Solution Engineer are security system and construction technical drawings, including custom installation drawings and instructions, network design diagrams, riser diagrams, typical installation diagrams, point-to-point system schedules, door hardware schedules, document redlining, functional narratives describing systems operations, and as-built documentation.
RESPONSIBILITIES:
Creates and updates comprehensive post-sale engineering packages illustrating device locations, IDF/MDF room layouts, SOC/GSOC layouts, console designs, installation diagrams, riser diagrams, network designs, etc.
Creates and updates performance-based and product-based specifications
Creates and updates pre-fabrication submittal packages as specified by architects and engineers for their approval prior to installation
Develops and maintains as-built record documentation over the life cycle of various projects and follow-on MAC work
Utilizes and contributes to a comprehensive library of standard post-sale engineering documents, templates, and standards, as well as project-specific and customer-specific submittals
Ensures effective value engineering by assuring technical compliance while at the same time reducing Allied Universal Technology Services costs whenever possible
Reviews AUTS proposals both pre-sale and post-sale to scrutinize selected products for applicability and specification compliance
Collaborates with AUTS's product suppliers to ensure the desired functionality of selected products.
Consistently applies AUTS's standards for installation
Contributes to AUTS internal guidelines for Solutions Engineering engagement and post-sale systems engineering
QUALIFICATIONS (MUST HAVES):
A minimum of five (5) years of experience in electronic security systems design / engineering
In-depth knowledge of security system design best practices and product applicability, including products like:
Video surveillance and related technologies (Analog, IP, Codecs, VMS)
Access control and related technologies (card access, biometrics, PIV, FIPS-201, HSPD-12, various processor panels, electric locking hardware, etc.)
Physical intrusion detection (Bosch, DMP, etc.)
Software House, Lenel, Amag, Brivo, Genetec, and Avigilon systems architectures
Computer software skills to include: AutoCAD and associated rendering applications, MS Office, Acrobat Writer, and Visio
Ability to read and understand complex architectural and engineering drawings
Working knowledge of AC and DC circuitry, voltage drop calculations, and wire sizing
Ability to collaborate with diverse teams of technical designers and engineers
Ability to simultaneously work on multiple large, complex projects
Good written and verbal communication skills
Strong analytical decision-making capabilities
Self-motivated with the ability to influence others
PREFERRED QUALIFICATION (NICE TO HAVES):
Manufacture certifications
PMP/PSP certifications
A bachelor's or associate's degree in electrical engineering or equivalent is considered a plus
Ability to plan, size, and design enterprise-class IT network and storage solutions, including products like:
Virtualization technologies such as VMware vSphere and View
Data-center networking technologies such as Cisco Nexus
Storage Area Network technologies such as NetApp or EMC
Load balancing / firewalling technologies such as Cisco ACE or Cisco ASA
Data-center protocols such as Fibre Channel, NFS, IP, iSCSI, DCE
Physical Security Information Management (PSIM)
BENEFITS:
Salary: $80,000 - 115,000 / annually
Medical, dental, vision, basic life, AD&D, and disability insurance
Enrollment in our company's 401 (k) or Supplemental Income Plan, subject to eligibility requirements
Eight paid holidays annually, five sick days, and four personal days
Vacation time offered at an accrual rate of 3.08 hours biweekly. Unused vacation is only paid out where required by law.
#LI-EL1
Closing
Allied Universal is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race/ethnicity, age, color, religion, sex, sexual orientation, gender identity, national origin, genetic information, disability, protected veteran status or relationship/association with a protected veteran, or any other basis or characteristic protected by law. For more information: ***********
If you have difficulty using the online system and require an alternate method to apply or require an accommodation, please contact our local Human Resources department. To find an office near you, please visit: ***********/offices.
Requisition ID 2025-1495451
Auto-ApplyPhysical Security Systems Engineer
Information security analyst job in Wilmington, MA
Overview
Join Allied Universal Technology Services, a global leader in transforming the security industry. We integrate advanced technology - video surveillance, electronic access control, alarm monitoring and augmented solutions with physical security to help people feel safe. Whether you're an installation technician, service technician, engineer, or project manager, you'll discover rewarding opportunities to grow your career as part of a valued team.
Apply today and be phenomenal-build a meaningful career while protecting what matters most through innovative security technology.
Job Description
Allied Universal is looking to hire a Solution Engineer. The Solution Engineer creates all post-sale security systems design, engineering, value engineering, and documentation. The position is part of the Solutions Engineering department, which is responsible for translating, expanding, finalizing, and documenting pre-sales proposals and technical designs produced by Sales and Solutions Architecture in pre-sale systems architecting and quoting. This position works closely with Sales, Solutions Architecture, Operations, and external customers as required.
The primary work products for the Solution Engineer are security system and construction technical drawings, including custom installation drawings and instructions, network design diagrams, riser diagrams, typical installation diagrams, point-to-point system schedules, door hardware schedules, document redlining, functional narratives describing systems operations, and as-built documentation.
RESPONSIBILITIES:
Creates and updates comprehensive post-sale engineering packages illustrating device locations, IDF/MDF room layouts, SOC/GSOC layouts, console designs, installation diagrams, riser diagrams, network designs, etc.
Creates and updates performance-based and product-based specifications
Creates and updates pre-fabrication submittal packages as specified by architects and engineers for their approval prior to installation
Develops and maintains as-built record documentation over the life cycle of various projects and follow-on MAC work
Utilizes and contributes to a comprehensive library of standard post-sale engineering documents, templates, and standards, as well as project-specific and customer-specific submittals
Ensures effective value engineering by assuring technical compliance while at the same time reducing Allied Universal Technology Services costs whenever possible
Reviews AUTS proposals both pre-sale and post-sale to scrutinize selected products for applicability and specification compliance
Collaborates with AUTS's product suppliers to ensure the desired functionality of selected products.
Consistently applies AUTS's standards for installation
Contributes to AUTS internal guidelines for Solutions Engineering engagement and post-sale systems engineering
QUALIFICATIONS (MUST HAVES):
A minimum of five (5) years of experience in electronic security systems design / engineering
In-depth knowledge of security system design best practices and product applicability, including products like:
Video surveillance and related technologies (Analog, IP, Codecs, VMS)
Access control and related technologies (card access, biometrics, PIV, FIPS-201, HSPD-12, various processor panels, electric locking hardware, etc.)
Physical intrusion detection (Bosch, DMP, etc.)
Software House, Lenel, Amag, Brivo, Genetec, and Avigilon systems architectures
Computer software skills to include: AutoCAD and associated rendering applications, MS Office, Acrobat Writer, and Visio
Ability to read and understand complex architectural and engineering drawings
Working knowledge of AC and DC circuitry, voltage drop calculations, and wire sizing
Ability to collaborate with diverse teams of technical designers and engineers
Ability to simultaneously work on multiple large, complex projects
Good written and verbal communication skills
Strong analytical decision-making capabilities
Self-motivated with the ability to influence others
PREFERRED QUALIFICATION (NICE TO HAVES):
Manufacture certifications
PMP/PSP certifications
A bachelor's or associate's degree in electrical engineering or equivalent is considered a plus
Ability to plan, size, and design enterprise-class IT network and storage solutions, including products like:
Virtualization technologies such as VMware vSphere and View
Data-center networking technologies such as Cisco Nexus
Storage Area Network technologies such as NetApp or EMC
Load balancing / firewalling technologies such as Cisco ACE or Cisco ASA
Data-center protocols such as Fibre Channel, NFS, IP, iSCSI, DCE
Physical Security Information Management (PSIM)
BENEFITS:
Salary: $80,000 - 115,000 / annually
Medical, dental, vision, basic life, AD&D, and disability insurance
Enrollment in our company's 401 (k) or Supplemental Income Plan, subject to eligibility requirements
Eight paid holidays annually, five sick days, and four personal days
Vacation time offered at an accrual rate of 3.08 hours biweekly. Unused vacation is only paid out where required by law.
#LI-EL1
Closing
Allied Universal is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race/ethnicity, age, color, religion, sex, sexual orientation, gender identity, national origin, genetic information, disability, protected veteran status or relationship/association with a protected veteran, or any other basis or characteristic protected by law. For more information: ***********
If you have difficulty using the online system and require an alternate method to apply or require an accommodation, please contact our local Human Resources department. To find an office near you, please visit: ***********/offices.
Requisition ID
2025-1495451
Manager, Information Security
Information security analyst job in Boston, MA
New England College of Optometry seeks an entry level Information Security Manager to develop, implement, and oversee a robust information security strategy and program. This critical role involves establishing and enforcing policies, procedures, and technologies to protect the confidentiality, integrity, and availability of institutional and student data. The Information Security Manager will be responsible for risk assessment, incident response, security operations, and ensuring compliance with all relevant regulations and standards. This role requires strong leadership, technical expertise, and excellent communication skills to collaborate effectively across the institution.
Responsibilities
* Develop, implement, and oversee a robust information security strategy and program in alignment with institutional goals and industry best practices.
* Establish and maintain institutional information security policies, standards, and guidelines, ensuring they are regularly reviewed, updated, and communicated.
* Manage security operations, including monitoring, detection, prevention, response, and analysis of security threats and vulnerabilities.
* Lead and coordinate the information security incident response team, managing security breaches & ensuring timely and effective resolution and post-incident analysis.
* Conduct regular risk assessments and penetration testing to identify and mitigate potential security vulnerabilities across systems, networks, and applications.
* Ensure compliance with national and international regulatory frameworks (e.g., FERPA, HIPAA, ISO 27001, SOC 2) relevant to the organization.
* Oversee security awareness training programs for all employees to promote a culture of security consciousness.
* Manage the security budget and evaluate, select, and implement appropriate security tools and technologies.
* Report on the status of the security program, vulnerabilities, and incidents to executive leadership.
* Work on "special projects" as assigned by the Chief Information Officer.
* Other duties as assigned.
Requirements
* Experience in designing, implementing, and managing enterprise-level information security programs and strategy.
* Technical knowledge of network security, application security, cloud security (e.g., AWS, Azure, GCP), and endpoint protection technologies.
* Understanding of risk management methodologies and security frameworks (e.g., ISO 27001, NIST, CIS Controls).
* Experience leading security incident response and forensic analysis.
* Strong communication and interpersonal skills, with the ability to explain complex security issues to technical and non-technical audiences.
* Knowledge of networking principles, including wireless networking.
* Excellent written and verbal communication skills, professional appearance, punctuality and a sense of urgency.
* Experience working with Active Directory and Google Cloud Platform.
* Ability and willingness to learn new technologies.
Preferred Background/Skills
* Professional certifications such as CISSP, CISM, or relevant SANS certifications.
* Experience with Governance, Risk, and Compliance (GRC) tools and processes.
* Exceptional organizational skills, with the ability to prioritize projects and tasks.
* Familiarity with scripting languages (e.g., Python, PowerShell) for security automation.
* Ability to write reports and document steps for knowledge sharing.
* Ability to work efficiently and independently with minimal supervision.
* Excellent customer service and communications skills.
Education
* Bachelor's degree in Computer Science, Information Technology, Information Security, or a related technical field.
Experience
* A minimum of 2 years of progressive experience in the field of information security.
NECO is an Equal Opportunity employer and encourages all qualified candidates to apply.
New England College of Optometry offers a robust benefits program including:
* 3 plan options for BCBS medical coverage (employer subsidized at 75% or greater)
* Mental Health and Wellness benefits
* BCBS Dental
* Discounted vision services
* 13 paid holidays and generous paid time off for sick, vacation, and personal days
* Employer-paid life insurance, and short-term and long-term disability
* Voluntary Insurance: life, critical illness, hospital indemnity, accident,
* Voluntary Benefits: employee discounts and pet insurance
* 9% employer contribution to a 403(b) retirement plan after 1 year of service with no vesting schedule or match requirement
* Qualified Public Service Loan Forgiveness Employer
Manager, Information Security
Information security analyst job in Boston, MA
Full-time Description
New England College of Optometry seeks an entry level Information Security Manager to develop, implement, and oversee a robust information security strategy and program. This critical role involves establishing and enforcing policies, procedures, and technologies to protect the confidentiality, integrity, and availability of institutional and student data. The Information Security Manager will be responsible for risk assessment, incident response, security operations, and ensuring compliance with all relevant regulations and standards. This role requires strong leadership, technical expertise, and excellent communication skills to collaborate effectively across the institution.
Responsibilities
Develop, implement, and oversee a robust information security strategy and program in alignment with institutional goals and industry best practices.
Establish and maintain institutional information security policies, standards, and guidelines, ensuring they are regularly reviewed, updated, and communicated.
Manage security operations, including monitoring, detection, prevention, response, and analysis of security threats and vulnerabilities.
Lead and coordinate the information security incident response team, managing security breaches & ensuring timely and effective resolution and post-incident analysis.
Conduct regular risk assessments and penetration testing to identify and mitigate potential security vulnerabilities across systems, networks, and applications.
Ensure compliance with national and international regulatory frameworks (e.g., FERPA, HIPAA, ISO 27001, SOC 2) relevant to the organization.
Oversee security awareness training programs for all employees to promote a culture of security consciousness.
Manage the security budget and evaluate, select, and implement appropriate security tools and technologies.
Report on the status of the security program, vulnerabilities, and incidents to executive leadership.
Work on "special projects" as assigned by the Chief Information Officer.
Other duties as assigned.
Requirements
Experience in designing, implementing, and managing enterprise-level information security programs and strategy.
Technical knowledge of network security, application security, cloud security (e.g., AWS, Azure, GCP), and endpoint protection technologies.
Understanding of risk management methodologies and security frameworks (e.g., ISO 27001, NIST, CIS Controls).
Experience leading security incident response and forensic analysis.
Strong communication and interpersonal skills, with the ability to explain complex security issues to technical and non-technical audiences.
Knowledge of networking principles, including wireless networking.
Excellent written and verbal communication skills, professional appearance, punctuality and a sense of urgency.
Experience working with Active Directory and Google Cloud Platform.
Ability and willingness to learn new technologies.
Preferred Background/Skills
Professional certifications such as CISSP, CISM, or relevant SANS certifications.
Experience with Governance, Risk, and Compliance (GRC) tools and processes.
Exceptional organizational skills, with the ability to prioritize projects and tasks.
Familiarity with scripting languages (e.g., Python, PowerShell) for security automation.
Ability to write reports and document steps for knowledge sharing.
Ability to work efficiently and independently with minimal supervision.
Excellent customer service and communications skills.
Education
Bachelor's degree in Computer Science, Information Technology, Information Security, or a related technical field.
Experience
A minimum of 2 years of progressive experience in the field of information security.
NECO is an Equal Opportunity employer and encourages all qualified candidates to apply.
New England College of Optometry offers a robust benefits program including:
3 plan options for BCBS medical coverage (employer subsidized at 75% or greater)
Mental Health and Wellness benefits
BCBS Dental
Discounted vision services
13 paid holidays and generous paid time off for sick, vacation, and personal days
Employer-paid life insurance, and short-term and long-term disability
Voluntary Insurance: life, critical illness, hospital indemnity, accident,
Voluntary Benefits: employee discounts and pet insurance
9% employer contribution to a 403(b) retirement plan after 1 year of service with no vesting schedule or match requirement
Qualified Public Service Loan Forgiveness Employer
Senior Information Systems Security Officer (ISSO) - Marlborough, MA
Information security analyst job in Marlborough, MA
Country:
United States of America Onsite
U.S. Citizen, U.S. Person, or Immigration Status Requirements:
Active and transferable U.S. government issued security clearance is required prior to start date. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance
Security Clearance:
DoD Clearance: SecretAt Raytheon, the foundation of everything we do is rooted in our values and a higher calling - to help our nation and allies defend freedoms and deter aggression. We bring the strength of more than 100 years of experience and renowned engineering expertise to meet the needs of today's mission and stay ahead of tomorrow's threat. Our team solves tough, meaningful problems that create a safer, more secure world.
Our cybersecurity team is seeking a Senior Information Systems Security Officer (ISSO) to support our team 100% onsite at our facility in Marlborough, Massachusetts. The successful candidate will interface with the Information Systems Security Manager (ISSM) to ensure adherence with NIST Special Publications, customer directives, and company policies as applicable all NISPOM Chapter 8, DAAPM, JSIG policies.
What You Will Do
Assessing and monitoring system compliance, auditing, security plan development and delivering information systems security education and awareness.
Investigating information system security violations and help prepare reports specifying corrective and preventative actions.
Reviewing and approving (within authority) configuration management requests.
Conducting technical and administrative assessments.
Integrating new cybersecurity processes, procedures, and tools.
Support the creation, review and update of cybersecurity documentation and other technical writing.
Qualifications You Must Have
Typically requires a University Degree or equivalent experience and minimum 5 years prior relevant experience, or an Advanced Degree in a related field and minimum 3 years' experience.
Current IAM Level I certification (Security+ or other).
Relevant Experience Considered in any combination:
Cybersecurity, systems security or hardening
Information Technology
Compliance-based auditing using the Risk Management Framework (RMF), DCSA Assessment and Authorization Process Manual (DAAPM), Joint SAP Implementation Guide (JSIG), National Industrial Security Program Operating Manual (NISPOM), and/or non-defense regulations such as FAA, Payment Card Industry (PCI), ISO 9001 Quality Management standards, or HIPPA
Experience working with and/or supporting computer technologies (such as: databases, operating systems, computer network hardware, software programs, hardware troubleshooting or electronics)
Physical security/security, policework/criminal justice, investigations, or Border Patrol
Project or program management, office management, senior administration, or account management
Qualifications We Prefer
Experience working in DoD classified operating and/or laboratory environments.
Experience with various information system security tools that address vulnerability analysis and mitigation. These may include Splunk, Forcepoint, Ivanti, Tenable, ACAS, HBSS, etc.
Familiarity with implementation of Government directives and policies derived from NIST, CNSSI, DoD, or other Government Regulatory compliance standards within a professional industry.
Experience in the execution of the Assessment & Authorization processes, as defined within the Risk Managed Framework (RMF).
Experience providing technical security consultation for complex, cross-domain, heterogeneous classified networked environments in collaboration with internal/external Customers, Information Technology (IT).
Familiarity with large multi-facility networks including various complex components, including Windows and Linux environments.
Experience interpreting, implementing, and assessing DISA STIGs.
Familiarity with the execution and management of cyber incident response; preservation, containment, and eradication.
What We Offer
Our values drive our actions, behaviors, and performance with a vision for a safer, more connected world. At RTX we value: Trust, Respect, Accountability, Collaboration, and Innovation.
Relocation Non-Eligible - Relocation assistance not available
Please consider the following role type definition as you apply for this role:
Onsite: Employees who are working in Onsite roles will work primarily onsite. This includes all production and maintenance employees, as they are essential to the development of our products.
We are RTX
#LI-Onsite
As part of our commitment to maintaining a secure hiring process, candidates may be asked to attend select steps of the interview process in-person at one of our office locations, regardless of whether the role is designated as on-site, hybrid or remote.
The salary range for this role is 82,000 USD - 164,000 USD. The salary range provided is a good faith estimate representative of all experience levels. RTX considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate's work experience, location, education/training, and key skills.Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement.Hired applicants may be eligible for annual short-term and/or long-term incentive compensation programs depending on the level of the position and whether or not it is covered by a collective-bargaining agreement. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company's performance.This role is a U.S.-based role. If the successful candidate resides in a U.S. territory, the appropriate pay structure and benefits will apply.RTX anticipates the application window closing approximately 40 days from the date the notice was posted. However, factors such as candidate flow and business necessity may require RTX to shorten or extend the application window.
RTX is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or veteran status, or any other applicable state or federal protected class. RTX provides affirmative action in employment for qualified Individuals with a Disability and Protected Veterans in compliance with Section 503 of the Rehabilitation Act and the Vietnam Era Veterans' Readjustment Assistance Act.
Privacy Policy and Terms:
Click on this link to read the Policy and Terms
Auto-ApplyInformation Systems Security Officer (ISSO)
Information security analyst job in Boston, MA
ISSOEmployment Type: Full-Time, Experienced Department: Information Technology CGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment documentation to support Dept. of Commerce systems and efforts to achieve their Authorization to Operate (ATO). This position is located at the client site in the Herbert Hoover building in Washington, DC. The scope of this position includes full life-cycle Assessment and Authorization (A&A) management through all 6 Steps of the RMF process in support of the Government ISSM.In this role, you'll conduct security assessment, and information system security oversight activities in accordance with NIST 800.53 that support systems from the perspective RMF requirements.
CGS brings motivated, highly skilled, and creative people together to solve the government's most dynamic problems with cutting-edge technology. To carry out our mission, we are seeking candidates who are excited to contribute to government innovation, appreciate collaboration, and can anticipate the needs of others. Here at CGS, we offer an environment in which our employees feel supported, and we encourage professional growth through various learning opportunities.
Skills and attributes for success:- Review systems to identify potential security weaknesses and recommend improvements to amend vulnerabilities, implement changes, and document upgrades. - Maintain responsibility for managing cybersecurity risk from an organizational perspective. - Identify organizational risks, prioritize those risks, and maintain a risk registry for escalating and presenting those risks to senior leadership.- Provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies.- Providing configuration management (CM) recommendations for information system security software, hardware, and firmware and coordinating changes and modifications with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO).- Maintain vulnerability scanning tool compliance, such as HBSS or ACAS, and patch management, such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance with all applicable directives, manage system changes, and assess the security impact of those changes.- Support security authorization activities, including transitioning from the legacy Information Assurance Certification and Accreditation Process (DIACAP) to compliance with the DoC RMF.- Provide subject matter expertise for cyber security and trusted system technology. - Apply advanced technical knowledge and analysis of specialized functional areas in task requirements to develop solutions to complex problems.- Research, write, review, disposition feedback, and finalize recommendations regarding cyber security policy, assessment and authorization assessments (A&As), security test and evaluation reports, and security engineering practices and processes. - Conduct research and write risk assessment reports to include risk thresholds, evaluation, and scoring.- Support analysis of the findings and provide expert technical guidance for mitigation strategies, including implementation advice on the cyber security risk findings, and other complex problems.
Qualifications:- Bachelor's Degree.- A minimum of five (5) years experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development, including generating security documentation for requirements, security control assessment, STIG and IAVA compliance, Standard Operating Procedures, test results, etc.- eMASS experience.- Professional security certification such as: CCNA Security, CySA+, GICSP, GSEC, CompTIA Security+ CE, SSCP, or higher.- Strong desktop publishing skills using Microsoft Word and Excel.- Experience with industry writing styles such as grammar, sentence form, and structure.- Ability to multi-task in a deadline-oriented environment.
Ideally, you will also have:- CISSP, CASP, or a similar certificate is preferred.- Master's Degree in Cybersecurity or related field.- Strong initiative, detail orientation, organizational skills, and aptitude for analytical thinking.- Demonstrated ability to work well independently and as a part of a team.- Excellent work ethic and a high commitment to quality.
Our Commitment:Contact Government Services (CGS) strives to simplify and enhance government bureaucracy through the optimization of human, technical, and financial resources. We combine cutting-edge technology with world-class personnel to deliver customized solutions that fit our client's specific needs. We are committed to solving the most challenging and dynamic problems.
For the past seven years, we've been growing our government contracting portfolio, and along the way, we've created valuable partnerships by demonstrating a commitment to honesty, professionalism, and quality work.
Here at CGS we value honesty through hard work and self-awareness, professionalism in all we do, and to deliver the best quality to our consumers mending those relations for years to come.
We care about our employees. Therefore, we offer a comprehensive benefits package.Health, Dental, and VisionLife Insurance 401k Flexible Spending Account (Health, Dependent Care, and Commuter) Paid Time Off and Observance of State/Federal Holidays
Contact Government Services, LLC is an Equal Opportunity Employer. Applicants will be considered without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Join our team and become part of government innovation!Explore additional job opportunities with CGS on our Job Board:**************************************** more information about CGS please visit: ************************** or contact:Email: *******************
#CJ
Auto-ApplySenior Information System Security Officer (ISSO) - Woburn, MA
Information security analyst job in Woburn, MA
**Country:** United States of America ** Onsite **U.S. Citizen, U.S. Person, or Immigration Status Requirements:** Active and transferable U.S. government issued security clearance is required prior to start date.
U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance
**Security Clearance:**
Secret - Current
At Raytheon, the foundation of everything we do is rooted in our values and a higher calling - to help our nation and allies defend freedoms and deter aggression. We bring the strength of more than 100 years of experience and renowned engineering expertise to meet the needs of today's mission and stay ahead of tomorrow's threat. Our team solves tough, meaningful problems that create a safer, more secure world.
Our cybersecurity team is seeking a **Senior Information Systems Security Officer (ISSO)** to support our team **100% onsite** at our facility in **Woburn, Massachusetts.** The successful candidate will interface with the Information Systems Security Manager (ISSM) to ensure adherence with NIST Special Publications, customer directives, and company policies as applicable all NISPOM Chapter 8, DAAPM, JSIG policies.
**What You Will Do**
+ Assessing and monitoring system compliance, auditing, security plan development and delivering information systems security education and awareness.
+ Investigating information system security violations and help prepare reports specifying corrective and preventative actions.
+ Reviewing and approving (within authority) configuration management requests.
+ Conducting technical and administrative assessments.
+ Integrating new cybersecurity processes, procedures, and tools.
+ Support the creation, review and update of cybersecurity documentation and other technical writing.
**Qualifications You Must Have**
+ Typically requires a University Degree or equivalent experience and minimum 5 years prior relevant experience, or an Advanced Degree in a related field and minimum 3 years' experience.
+ Current IAM Level I certification (Security+ or other).
+ Relevant Experience Considered in any combination:
+ Cybersecurity, systems security or hardening
+ Information Technology
+ Compliance-based auditing using the Risk Management Framework (RMF), DCSA Assessment and Authorization Process Manual (DAAPM), Joint SAP Implementation Guide (JSIG), National Industrial Security Program Operating Manual (NISPOM), and/or non-defense regulations such as FAA, Payment Card Industry (PCI), ISO 9001 Quality Management standards, or HIPPA
+ Experience working with and/or supporting computer technologies (such as: databases, operating systems, computer network hardware, software programs, hardware troubleshooting or electronics)
+ Physical security/security, policework/criminal justice, investigations, or Border Patrol
+ Project or program management, office management, senior administration, or account management
**Qualifications We Prefer**
+ Experience working in DoD classified operating and/or laboratory environments.
+ Experience with various information system security tools that address vulnerability analysis and mitigation. These may include Splunk, Forcepoint, Ivanti, Tenable, ACAS, HBSS, etc.
+ Familiarity with implementation of Government directives and policies derived from NIST, CNSSI, DoD, or other Government Regulatory compliance standards within a professional industry.
+ Experience in the execution of the Assessment & Authorization processes, as defined within the Risk Managed Framework (RMF).
+ Experience providing technical security consultation for complex, cross-domain, heterogeneous classified networked environments in collaboration with internal/external Customers, Information Technology (IT).
+ Familiarity with large multi-facility networks including various complex components, including Windows and Linux environments.
+ Experience interpreting, implementing, and assessing DISA STIGs.
+ Familiarity with the execution and management of cyber incident response; preservation, containment, and eradication.
**What We Offer**
Our values drive our actions, behaviors, and performance with a vision for a safer, more connected world. At RTX we value: Trust, Respect, Accountability, Collaboration, and Innovation.
Relocation Non-Eligible - Relocation assistance not available
**Please consider the following role type definition as you apply for this role:**
+ Onsite: Employees who are working in Onsite roles will work primarily onsite. This includes all production and maintenance employees, as they are essential to the development of our products.
We are RTX (****************************************
\#LI-Onsite
**_As part of our commitment to maintaining a secure hiring process, candidates may be asked to attend select steps of the interview process in-person at one of our office locations, regardless of whether the role is designated as on-site, hybrid or remote._**
The salary range for this role is 82,000 USD - 164,000 USD. The salary range provided is a good faith estimate representative of all experience levels.
RTX considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate's work experience, location, education/training, and key skills.
Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement.
Hired applicants may be eligible for annual short-term and/or long-term incentive compensation programs depending on the level of the position and whether or not it is covered by a collective-bargaining agreement. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company's performance.
This role is a U.S.-based role. If the successful candidate resides in a U.S. territory, the appropriate pay structure and benefits will apply.
RTX anticipates the application window closing approximately 40 days from the date the notice was posted. However, factors such as candidate flow and business necessity may require RTX to shorten or extend the application window.
_RTX is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or veteran status, or any other applicable state or federal protected class. RTX provides affirmative action in employment for qualified Individuals with a Disability and Protected Veterans in compliance with Section 503 of the Rehabilitation Act and the Vietnam Era Veterans' Readjustment Assistance Act._
**Privacy Policy and Terms:**
Click on this link (******************************************************** to read the Policy and Terms
Raytheon Technologies is An Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age or any other federally protected class.