Detection & Response Security Engineer, Threat Intelligence
Information security analyst job in Richmond, VA
Meta Security is looking for a threat intelligence investigator with extensive experience in investigating cyber threats with an intelligence-driven approach. You will be proactively responding to a broad set of security threats, as well as tracking actor groups with an interest or capability to target Meta and its employees. You will also be identifying the gaps in current detections and preventions by long-term intelligence tracking and research, and working with cross-functional stakeholders to improve Meta's security posture. You will help the team establish, lead and execute multi-year roadmaps that improve research efficiency and quality across the team, and drive improvements to stakeholder management across a broad range of intelligence requirements.
**Required Skills:**
Detection & Response Security Engineer, Threat Intelligence Responsibilities:
1. Influence and align the team's vision and strategy. Collaboratively prioritize and deliver specific multi-year roadmaps and projects
2. Build, cultivate, and maintain impactful relationships with intelligence stakeholders to identify and facilitate solutions to increase the impact of the team's work
3. Refine operational metrics, key performance indicators, and service level objectives to measure Intelligence research and services
4. Lead cross-functional projects to improve the security posture of Meta's infrastructure, such as red team operations, surface detection coverage expansion and vulnerability management discussions
5. Track threat clusters posing threats to Meta's infrastructure and employees, and identify, develop and implement countermeasures on our corporate network
6. Investigate, mitigate, and forecast emerging technical trends and communicate effectively with actionable suggestions to different types of audiences
7. Work closely with incident responders to provide useful and timely intelligence to enrich ongoing investigations
8. Improve the tooling of threat cluster tracking and intelligence data integration to existing systems
**Minimum Qualifications:**
Minimum Qualifications:
9. 8+ years threat intelligence experience
10. B.S. or M.S. in Computer Science or related field, or equivalent experience
11. Be a technical and process subject matter expert regarding Security Operations and Threat Intelligence services
12. Experience developing and delivering information on threats, incidents and program status for leadership
13. Expertise with campaign tracking techniques and converting tracking results to long term countermeasures
14. Expertise with threat modeling frameworks, such as Diamond Model or/and MITRE ATT&CK framework
15. Experience intelligence-driven hunting to spot suspicious activities in the network and identify potential risks
16. Proven track record of managing and executing on short term and long term projects
17. Ability to work with a team spanning multiple locations/time zones
18. Ability to prioritize and execute tasks with minimal direction or oversight
19. Ability to think critically and qualify assessments with solid communications skills
20. Coding or scripting experience in one or more scripting languages such as Python or PHP
**Preferred Qualifications:**
Preferred Qualifications:
21. Experience recruiting, building, and leading technical teams, including performance management
22. Experience close collaborating with incident responders on incident investigations
23. Experience in threat hunting including leveraging intelligence data to proactively identify and iteratively investigates suspicious behavior across networks and systems
24. Familiarity with malware analysis or network traffic analysis
25. Familiarity with nation-state, sophisticated criminal, or supply chain threats
26. Familiarity with file-based or network-based rules and signatures for detection and tracking of complex threats, such as YARA or Snort
27. Experience in one or more query languages such as SQL
28. Experience authoring production code for threat intelligence tooling
29. Experience conducting large scale data analysis
30. Experience working across the broader security community
**Public Compensation:**
$177,000/year to $251,000/year + bonus + equity + benefits
**Industry:** Internet
**Equal Opportunity:**
Meta is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Meta participates in the E-Verify program in certain locations, as required by law. Please note that Meta may leverage artificial intelligence and machine learning technologies in connection with applications for employment.
Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at accommodations-ext@fb.com.
Senior Analyst, Security Compliance (SOX IT)
Information security analyst job in Richmond, VA
Ready to be pushed beyond what you think you're capable of? At Coinbase, our mission is to increase economic freedom in the world. It's a massive, ambitious opportunity that demands the best of us, every day, as we build the emerging onchain platform - and with it, the future global financial system.
To achieve our mission, we're seeking a very specific candidate. We want someone who is passionate about our mission and who believes in the power of crypto and blockchain technology to update the financial system. We want someone who is eager to leave their mark on the world, who relishes the pressure and privilege of working with high caliber colleagues, and who actively seeks feedback to keep leveling up. We want someone who will run towards, not away from, solving the company's hardest problems.
Our ******************************** is intense and isn't for everyone. But if you want to build the future alongside others who excel in their disciplines and expect the same from you, there's no better place to be.
While many roles at Coinbase are remote-first, we are not remote-only. In-person participation is required throughout the year. Team and company-wide offsites are held multiple times annually to foster collaboration, connection, and alignment. Attendance is expected and fully supported.
Coinbase stores more digital currency than any company in the world, making us a top tier target on the internet. Security is core to our mission and has been a key competitive differentiator for us as we scale worldwide. Essential to scaling is building and running a security compliance program that reflects how we protect the data and assets in our care, to open the doors with customers, regulators, auditors, and other external stakeholders. If you love working with fast moving companies to grow and scale security compliance engines and create positive change across the business, we'd like to speak with you about joining our team. Coinbase is looking for a Security Compliance Senior Analyst to drive the second line of defense IT SOX initiatives and help mature the IT SOX program.
*What you'll be doing (ie. job duties):*
* Lead Security and IT initiatives to support the SOX roadmap and advance program maturity
* Assist with SOX planning activities, including scoping of IT systems and creating training material to owners in preparation for SOX audit
* Lead security control gap assessments over SOX control environment, recommend remediation plans and track through completion
* Assess SOX implications of new products, update relevant controls, and communicate requirements to product organization and other stakeholders
* Provide ongoing reporting to stakeholders and leadership on above responsibilities and communicate progress and escalations management
* Perform SOX audit and control impact analysis as a result of security and technology incidents and partner with owning teams on control uplift activities
* Build close relationships with stakeholder teams including Security, IT, Infrastructure, Engineering, Data, and Finance to advise on SOX requirements and ensure excellence in control ownership
* Create and improve SOX procedural documentation, including process documentation, data flow diagrams, and uplifting templates
* Work closely with internal and external auditors to educate them about a complex technology control environment
* Oversee quality of audit initiatives, identify and analyze process gaps, provide guidance and expertise to team members
* Develop creative solutions to prove risk mitigation and solve for complex audit problems faced by the crypto industry
* Identify opportunities to address systemic program challenges, recommend solutions and drive efficiency through AI and automation
*What we look for in you (ie. job requirements):*
* Minimum of 5+ years of security/IT compliance or equivalent experience
* Strong knowledge and hands-on experience in Internal Controls over Financial Reporting, SOX 404 frameworks, and testing to support compliance
* Prior experience at a big 4 accounting firm
* Experience leading compliance initiatives from start to finish
* Proven understanding and audit experience of cloud technologies, AWS preferred
* Ability to effectively and autonomously accomplish outcomes across cross-functional teams in ambiguous situations with minimal supervision
* Strong oral and written communication skills
* Ability to multitask, direct cross functional work, and hold others accountable to committed deadlines in a fast paced environment
* Ability to communicate with technical / non-technical stakeholders to align on shared outcomes
* Experience in Financial services, Big Tech, or FinTech
*Nice to haves:*
* BA or BS in a technical field or equivalent experience
* Security certifications e.g. CISA, CISSP, CISM or other relevant certifications
* Experience auditing in Crypto space
Position ID: P73675
\#LI-Remote
*Pay Transparency Notice:* Depending on your work location, the target annual salary for this position can range as detailed below. Full time offers from Coinbase also include bonus eligibility + equity eligibility**+ benefits (including medical, dental, vision and 401(k)).
Pay Range:
$167,280-$196,800 USD
Please be advised that each candidate may submit a maximum of four applications within any 30-day period. We encourage you to carefully evaluate how your skills and interests align with Coinbase's roles before applying.
Commitment to Equal Opportunity
Coinbase is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, sex, gender expression or identity, sexual orientation or any other basis protected by applicable law. Coinbase will also consider for employment qualified applicants with criminal histories in a manner consistent with applicable federal, state and local law. For US applicants, you may view the *********************************************** in certain locations, as required by law.
Coinbase is also committed to providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please contact us at accommodations***********************************
*Global Data Privacy Notice for Job Candidates and Applicants*
Depending on your location, the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) may regulate the way we manage the data of job applicants. Our full notice outlining how data will be processed as part of the application procedure for applicable locations is available ********************************************************** By submitting your application, you are agreeing to our use and processing of your data as required.
*AI Disclosure*
For select roles, Coinbase is piloting an AI tool based on machine learning technologies to conduct initial screening interviews to qualified applicants. The tool simulates realistic interview scenarios and engages in dynamic conversation. A human recruiter will review your interview responses, provided in the form of a voice recording and/or transcript, to assess them against the qualifications and characteristics outlined in the job description.
For select roles, Coinbase is also piloting an AI interview intelligence platform to transcribe and summarize interview notes, allowing our interviewers to fully focus on you as the candidate.
*The above pilots are for testing purposes and Coinbase will not use AI to make decisions impacting employment*. To request a reasonable accommodation due to disability, please contact accommodations[at]coinbase.com
Information Security Analyst
Information security analyst job in Richmond, VA
Centurion is seeking a skilled Information Security Analyst to support security and privacy efforts across all programs, projects, IT systems, and applications. This role will work closely with the Information Security Office (ISO), providing expertise in governance, risk, and compliance, while ensuring appropriate security controls are implemented and maintained. The ideal candidate is detail-oriented, collaborative, and experienced in applying security frameworks to real-world business and technology environments.
Key Responsibilities
Support Information Security and Privacy initiatives across business areas and vendor engagements.
Manage and update information security documentation within a Governance, Risk, and Compliance (GRC) system.
Develop and maintain System Security Plans (SSPs) in collaboration with business stakeholders.
Represent the Information Security Office in PMO-led projects, ensuring proper ISO engagement.
Partner with teams to analyze challenges, propose compliant solutions, and deliver clear communications.
Assist in the creation and maintenance of information security standards, policies, and procedures.
Document security controls, including system diagrams, risk assessments, and control narratives.
Review contracts and vendor documentation to ensure adequate information security protections.
Conduct research on emerging information security and privacy practices to strengthen internal processes.
Required Qualifications
Minimum of 3 years' experience in information security concepts related to governance, risk, and compliance.
Strong knowledge of information security principles, methods, and IT infrastructure management.
Experience with security frameworks (e.g., NIST, ISO 27001, COBIT).
Proven ability to organize work, prioritize tasks, and meet deadlines independently.
Experience drafting policies, standards, and procedures related to Information Security and Privacy.
Ability to interpret technical documentation, flow diagrams, and process maps.
Strong communication skills with the ability to write clearly for varied audiences.
Proficiency in creating diagrams, flowcharts, and spreadsheets.
Understanding of general contract terms and conditions related to information security.
Preferred Qualifications
Bachelor's degree in Computer Science, Information Systems, or related field.
Professional certifications such as CISA, CISSP, or equivalent.
Prior experience in the financial services industry.
Knowledge of cloud and application security controls.
Familiarity with information security regulations such as GLBA, GDPR, PCI, and privacy regulations including GDPR, CCPA, VCDPA.
Why Join Us?
Play a vital role in protecting sensitive information and strengthening enterprise-wide security posture.
Collaborate across teams and gain exposure to a broad range of security and compliance initiatives.
Security Analyst II
Information security analyst job in Richmond, VA
Join the Market Leader in Electric Power Data and Analytics Solutions
The electrical grid is the largest and most complicated machine ever built. Yes Energy's industry-leading electric power trading analytics software provides real-time visibility into the massive amount of data generated by the North American electrical grid daily. Our unique and innovative view of the data informs real-time trading decisions and mid-to-long-term investment decisions that keep utility prices low, support the energy transition, and keep the grid running. It's both challenging work and work with a purpose.
Be a part of our successful, growing business during international transformation.
Position Summary
As a Security Analyst II, you will be helping keep the grid safe and our customers secure. You will be part of our growing Security & Compliance team, building security automations, creating baselines for on-premises and cloud environments, assisting teams with vulnerability scans and management, supporting our compliance team with evidence gathering and audits, and more. This is an opportunity to be part of a small team with increasing importance and responsibility. You will help Yes Energy stay secure into the future.
Position Details
Salary range: 80,000 - 95,000
Location: Yes Energy Core Offices or Remote
Full-time
Reporting to: Senior Manager, IT and Compliance
Travel requirement: up to 15% to Yes Energy's core offices
Primary Responsibilities
Review and triage findings from vulnerability scans, penetration tests, and configuration assessments to identify potential security risks.
Work with DevOps, engineers, and system owners to remediate vulnerabilities across multi-cloud and on-prem assets.
Support secure configuration baselines for AWS, Azure, and Oracle Cloud resources.
Monitor cloud environments for misconfigurations and suspicious activity.
Assist with IAM policy reviews and privilege audits.
Write scripts (Python, PowerShell, or Bash) to automate detection, reporting, or remediation of security issues.
Integrate security tools and data into dashboards or workflow systems (e.g., Jira, SIEM, or ticketing).
Provide technical evidence and control implementation support for SOC 2, ISO 27001, or customer security assessments.
Partner with the compliance team to map technical controls to framework requirements.
Assist with incident triage, response, and root cause analysis.
Support endpoint protection, log monitoring, and threat intelligence initiatives.
Minimum Qualifications
Bachelor's degree in a related field or equivalent related experience
Minimum of two years of experience with security exposure in information security, systems administration, or DevOps.
Proficient in at least one scripting language (Python, PowerShell, or Bash).
Strong understanding of operating systems, networking, and cloud fundamentals.
Knowledge of security frameworks such as NIST
Familiarity with vulnerability management tools (e.g., Tenable, Qualys, Rapid7, AWS Inspector, or Microsoft Defender).
Working knowledge of AWS, Azure, and/or Oracle Cloud security controls and services.
Comfortable working cross-functionally with engineering, IT, and compliance teams.
Knowledge, Skills, and Abilities
Ability to travel up to 15% to assist in team building and planning exercises.
Strong, professional communication skills, both verbal and written, including the skill in articulating and translating technical language to non-technical customers.
Ability to plan for contingencies and anticipate problems.
Ability to ask critical questions to assess needs and requirements
Preferred Qualifications
Experience with SIEM or SOAR platforms (e.g., Splunk, Microsoft Sentinel).
Familiarity with infrastructure such as code (Terraform, CloudFormation).
Exposure to compliance frameworks such as SOC 2, ISO 27001, or NIST 800-53.
Security certifications (Security+, GSEC, AWS Security Specialty, or similar).
Endpoint Security/Patching/Inventory experience
At Yes Energy, we value connecting directly with candidates. We kindly ask that third-party recruiters and agencies not submit resumes, as we are not open to external recruiting partnerships.
ABOUT YES ENERGY
Overview
Yes Energy delivers real-time market data and electric power trading decision solutions. Over 1,000 market participants use Yes Energy solutions daily. The business is a leader in all aspects of information content collection and management, developing and delivering data and market analytics solutions. Since its inception in 2008, Yes Energy has become a trusted and respected supplier of innovative and reliable solutions focused on the needs of power market analysts, traders, and trade managers. Yes Energy has a team of over 350 amazing professionals in Boulder, CO (HQ); Boston, MA; Chicago, IL; Glendora, CA; Richmond, VA; London, United Kingdom; Auckland, New Zealand, Tokyo, Japan; and Bucharest, Romania.
Culture
Yes Energy has been named one of the Best Places to Work in Colorado, and we have the culture to prove it. At Yes Energy, we care about saying “Yes” to customers. We like to listen, learn, and develop our solutions in line with their needs. We think about customers as business partners, and when we help them be more successful … we are more successful, too.
Around the office, our culture is driven by some pretty fundamental values that we're proud of:
We love innovation and solving tough challenges;
We are “high standards people” who combine passion and pride with hard work and rewards of all kinds-- in an ethic that is consistent across the company;
We're team-focused with a flat hierarchy-- we work in small teams on well-defined projects that directly impact the success of the business;
We play to the strengths and experience of each person while each of us also works along a continuum of roles adjacent to our focus area. This presents the challenge of maintaining a broad set of skills as well as an opportunity to learn and contribute in many ways;
We are constantly growing. Professional development happens every day and every year.
Compensation and Benefits
We offer highly competitive salaries and real bonuses that are achievable and that you can impact. Our benefits package is also very competitive, including medical insurance, a 401 (k) Plan with matching, flexible vacation, and flexible work schedules. Yes Energy encourages and funds investment in both formal and informal professional development.
At Yes Energy, we are dedicated to building a diverse, inclusive, and authentic workplace. If you're excited about this role but your experience doesn't perfectly align with every qualification in the job description, we encourage you to apply anyway. You may be just the right candidate for this or other roles.
In accordance with Colorado law, the range provided is Yes Energy's reasonable estimate of the base compensation for this role. The actual amount may be higher or lower based on non-discriminatory factors such as location, experience, knowledge, skills, and abilities.
Yes Energy provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability, or genetics. In addition to federal law requirements, Yes Energy complies with applicable state and local laws governing nondiscrimination in employment in every location where the company has facilities. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.
Auto-ApplySecurity Analyst I
Information security analyst job in Richmond, VA
It's fun to work in a company where people truly BELIEVE in what they're doing!
We're committed to bringing passion and customer focus to the business.
Day Shift - 7.5 Hours (United States of America)
We are seeking a detail-oriented and motivated Cyber Security Analyst (Level 1) to support our healthcare organization's mission of protecting patient data and ensuring compliance with HIPAA and other healthcare regulations. This entry-level role is ideal for individuals passionate about cybersecurity and eager to grow within a healthcare environment.
Key Responsibilities:
Monitor and analyze security alerts from healthcare systems, EHR platforms, and network infrastructure.
Assist in the investigation and documentation of security incidents, including potential HIPAA violations.
Support vulnerability scanning and patch management across clinical and administrative systems.
Help maintain and enforce security policies, procedures, and incident response plans.
Assist in documentation and presentation of findings from notable security investigations, including action items and lessons learned to drive ongoing security improvements.
Act as first point of contact for security tickets and questions
Participate in audits and risk assessments to ensure compliance with healthcare regulations (e.g., HIPAA, HITECH).
Contribute to security awareness training for clinical and non-clinical staff.
Stay informed on emerging threats, especially those targeting healthcare organizations.
Required Qualifications:
Bachelor's degree in Cybersecurity, Information Technology, Health Informatics, or a related field (or equivalent experience).
Basic understanding of healthcare IT systems and regulatory requirements (HIPAA, HITECH).
Familiarity with security tools such as SIEM, antivirus, firewalls, and endpoint protection.
Strong analytical and problem-solving skills.
Excellent communication skills and ability to work in a team-oriented environment.
Preferred Qualifications:
Internship or experience in a healthcare IT or cybersecurity role.
Certifications such as CompTIA Security+, HCISPP, or equivalent.
Knowledge of EHR systems (e.g., Epic, Cerner) and medical device security is a plus.
Work Environment:
May involve hybrid or on-site work depending on facility needs.
Participation in on-call rotation or after-hours incident response may be required
Participation in on-call rotation or after-hours incident response may be required
Salary Range: $65,000 - $80,000
Employment Non-Discrimination: Richmond University Medical Center is committed to equality of opportunity in all aspects of employment and provides full and equal employment opportunities to all employees and potential employees without regard to race, color, national origin, religion, gender identity, sex, sexual orientation, pregnancy, childbirth and related medical conditions and needs including lactation accommodations, physical or mental disability, age, immigration or citizenship status, veteran or active military status, genetic information, or any other legally protected status.
If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us!
Auto-ApplyIT Security Analyst 3
Information security analyst job in Richmond, VA
Job DescriptionRole : IT Security Analyst 3 Interview Mode: Web Cam Interview Only The Virginia Department of Transportation is seeking to fill the Information Technology (IT) Security Analyst position. This position reports to the Deputy Information Security Officer in the Office of Information Security located in Richmond, Virginia.
The IT Security Analyst supports the VDOT Information Security mission by implementing results-oriented strategic approaches, plans, programs, and procedures. This position helps to ensure that Commonwealth of Virginia Information Security Policies and Standards are followed by the Agency. The broad areas of responsibility for this position include; identity and access management, IT risk management, business continuity and IT disaster recovery planning, security awareness education and training, security vulnerability management, Artifical Intelligence compliance and security incident management.
Responsibilities:
Documents processes and script narratives/executive summaries.
Create Business focused documentation for circulation among readers with various technical understanding.
Share insight of Security Architecture and IT Governance approaches and implementation methodologies
Research and provide written guidance on alignment with security policies/standards.
Perform tasks related to Security Compliance and Control Evaluation, Risk analysis, and exception documentation.
Collaborate with Business areas and cross- functional Enterprise Architects to fully understand business needs and provide strategic consultation on data security and risk-averse implementation.
Partner with architects, other technical team members and to develop roadmaps and strategies to support agency KPIs
Design/Implement Enterprise Security/technology Patterns
Consult with teams as needed on initiatives and provide tactical direction as well as provide architecture considerations on legacy solutions
Research and share finding of architecture governance, controls, and peer review processed with regards to platform technology, security, and cloud.
Qualifications:
Comprehensive knowledge of Information Security principles; including information security trends, emerging technologies, best-practices, controls, models, architecture, etc.
Practical experience with identity and access management, IT risk management, business continuity and IT disaster recovery planning, security awareness education and training, security vulnerability management, and security incident management.
Familiarity with the Commonwealth of Virginia's Information Security Standards and/or the National Institute of Standards and Technology Publication 800-53.
Able to communicate effectively in writing and orally, exercise judgment, interpret laws and policies, and maintain effective working relationships with a wide variety of individuals in both the public and private sectors
Experience in monitoring IT environments for compliance with information security architecture policies and standards.
Substantial technical experience in 2 or more: Cloud-based technologies, Artificial Intelligence, Machine Learning, Identity & Access Management, Vulnerability Management, firewalls, computer forensic techniques, databases, collaboration tools, web & mail services.
Ability to provide input and security direction for future designs, information security capabilities, and strategic technology alternatives.
Excellent written and oral communication and presentation skills (possessing the ability to breakdown complex technical terms into everyday language).
Demonstrated ability to work with broad cross-section of personal including all levels of management and external entities such as VITA consultants and service providers to explain and security measures and collaborate and disseminate security related information in partnership with the Office of Information Security.
Work experience in a fast-paced environment and acquire new skills/knowledge to meet customer needs.
Thorough understanding of customers priorities and the business criticality of platforms, applications and services.
Powered by JazzHR
gh J6cBtwVo
IT Procurement Analyst
Information security analyst job in Richmond, VA
Ask ITC Inc. which is backed by a $500 million Microtek group company, provides an industry leading blend of technology, business consulting, and outsourcing services.
Ask IT is a minority-owed enterprise; it has been founded on providing the highest quality possible and on the devotion to customer satisfaction.
Job Description
Daily responsibility for supporting the Procurement / Finance team
To support IT division by overseeing an Outlook Mailbox routing for purchasing IT Goods and Services as well as Sharepoint. Daily accounting, and accounts payable activities. Performs adminstrative duties to support the division. Process invoices, procurement and reconciles vendor inquiries, request quotes for purchases of consumables for VDOT. Interprets and applies policies and interprets and develops procedures and processes in this area.
Oversees a wide range of administrative and technical functions necessary for effective office management. Independently performs all administrative and fiscal tasks with accuracy. Tasks include accounts payable and receivable, and procurement. Routinely responds to a variety of requests from agency management, external organizations, consultants and the general public.
Identify the technology business needs and technology products, services or solution that will best fulfill those needs while determining cost containment.
IT procurement liaison who works with VITA and NG, understanding technology in order to discuss contracts, licenses agreements, maintenance agreements and contracts.
Qualifications
Skilled functionality with SharePoint.
Skilled in the functionality of financial systems, Microsoft Office Suites, and other automated equipment and tools.
Skilled in English grammar with the ability to communicate effectively.
Considerable experience records management, governmental accounting, and financial management.
Additional Information
All your information will be kept confidential according to EEO guidelines.
IT Governance Analyst 2
Information security analyst job in Richmond, VA
Interview Mode: Web Cam Interview Only Need resume by July 25 The client is seeking a team member to function as a Governance Analyst. The IT Governance practice at VDOT is focused on process improvement, standardization, reporting and risk minimization. It's responsible for ensuring compliance. The Analyst will review processes & develop documentation to support Governance initiatives.
The Analyst will also assist in issue resolution, operationalizing Governance practices, creating and socializing IT Governance artifacts (such as IT audit responses, control processes etc.) This position will also assist in extending the scope of ITD Governance, Security Architecture and Process Improvement.
Responsibilities:
The IT Governance Analyst is responsible for providing support to IT services, and will align IT investments with enterprise business goals, as well as Bureau and Agency guidance.
Develop, update and maintain IT governance documents including IIMS, policies and guidelines.
Translate complex technical and compliance concept into clear, understandable documentation
Support technical writing and review for the division's flagship governance documents and policies.
Oversee the IT audit inquiry process by coordinating with internal auditors and customers to relay evidence of compliance to agency standards.
Oversee the IT audit remediation process by coordinating with developers, engineers, and IT Leadership to rectify points of non-compliance to agency standards.
Coordinate requirements submission and execution requirements for the Audit Kanban, ensuring an accurate level of detail and defined scope.
Provide input into the augmentation of a governance model for ITD's critical processes.
Qualifications:
Demonstrated knowledge or experience in process modeling with Microsoft Visio.
Experience with drafting policy, technical briefings, business or executive-centered presentations, and reports
Knowledge an Agile Project Management environment preferred.
Knowledge of general IT Audit and Compliance response processes
Understanding of IT Governance best practices, tools, with willingness to learn Commonwealth or Agency Implementation
Ability to work independently, creatively, and analytically in a fast-paced, team environment.
Attention to detail, strong listening skills, and good verbal and written communications are required.
Skill
Required / Desired
Amount
Experience
Knowledge and application of IT Governance and Compliance standards
Required
7
Years
Experience in Technical Writing, editing skills and policy documentation
Required
7
Years
Experience in Process Modeling
Required
7
Years
Power BI Experience
Required
3
Years
Experience in business writing and presenting
Required
7
Years
Microsoft Visio, Planner and SharePoint Online experience
Required
7
Years
Jr. Cyber Security Engineer
Information security analyst job in Ashland, VA
This position description is subject to change at any time as needed to meet the requirements of the program or company. Working across the globe, V2X builds smart solutions designed to integrate physical and digital infrastructure from base to battlefield. We bring 120 years of successful mission support to improve security, streamline logistics, and enhance readiness. Aligned around a shared purpose, our $3.9B company and 16,000 people work alongside our clients, here and abroad, to tackle their most complex challenges with integrity, respect, responsibility, and professionalism.
As a Cyber Security Engineer with Air Force Golf Enterprise Solution (AFGES), you will be responsible for the Risk Management Framework (RMF) activities at 51 separate locations. This role executes the day-to-day activities planning, implementing and executing overall RMF activities. The Cyber Security Engineer will interact with government leads, subcontractors / vendors, and network administrators.
#clearance
Responsibilities
Major Job Activities:
+ This Jr. Cyber Security Engineer role works closely with a Sr. Cyber Security Engineer and Cyber Security Engineer.
+ Assists in the planning, execution, mitigation and reporting of Security Technical Implementation Guide (STIG) and Security Requirements Guides (SRG).
+ Ongoing Vulnerability Monitoring and scanning.
+ Set up, operate and maintain a test lab.
+ Test patches, upgrades and changes before implementing to field.
+ Respond to system update and patching failures.
+ Oversite of 51 existing remote field networks.
+ Interaction with Golf Club Management Software vendor.
+ Create and update all RMF related documentation (ex. Topology, Network Component Inventory, Various plans to include Plan of Action and Milestones (POAM)).
+ Contribute to Program Management Plan and Program reporting as needed.
+ Work non-business hours when required to avoid disrupting operations.
Material & Equipment Directly Used:
+ Proficient with MS Office Suite (Excel, Word, PowerPoint).
+ Proficient with MS Project
Working Environment:
Office environment with potential to support CONUS and OCONUS locations.
Physical Activities:
Must be able to lift / carry 50 lbs.
Qualifications
Education / Certifications:
+ Technical BA / BS Degree
+ IAT Level II related certifications (or higher):
+ CompTIA Security+ CE
+ Cisco Certified CyberOps Associate
+ CySA
+ + GSEC
+ SSCP
Experience:
+ Four (4) years of related experience with a BA / BS degree.
Clearance Requirement:
+ Candidates must possess or be able to obtain a favorable IT-I, IT-II, or IT-III Public Trust Clearance.
Skills & Technology Used:
+ Experience with multiple disciplines across computing environment:
+ System Administration (Windows Endpoints and Windows Servers)
+ Networking/VPN
+ Code Development
+ Compute Infrastructure Setup
+ Remote Maintenance
+ Experience with DoD RMF process, eMASS, and attaining system ATOs.
+ Familiarity of system artifacts required for ATO packages.
+ Configuration and use of ACAS, STIGs, SCAP, ENS / ESS, MS Defender.
+ Scripting and process automation.
+ Proficient with MS Office Suite (Excel, Word, PowerPoint); proficient with MS Project.
+ Preferred - Experience with Beyond Trust access security software application.
At V2X, we are deeply committed to both equal employment opportunity, including protection for Veterans and individuals with disabilities, and fostering an inclusive and diverse workplace. We ensure all individuals are treated with fairness, respect, and dignity, recognizing the strength that comes from a workforce rich in diverse experiences, perspectives, and skills. This commitment, aligned with our core Vision and Values of Integrity, Respect, and Responsibility, allows us to leverage differences, encourage innovation, and expand our success in the global marketplace, ultimately enabling us to best serve our clients.
Engineer, Information Security and Risk
Information security analyst job in Richmond, VA
Cardinal Health, Inc. (NYSE: CAH) is a global healthcare services and products company. We provide customized solutions for hospitals, healthcare systems, pharmacies, ambulatory surgery centers, clinical laboratories, physician offices and patients in the home. We are a distributor of pharmaceuticals and specialty products; a global manufacturer and distributor of medical and laboratory products; an operator of nuclear pharmacies and manufacturing facilities; and a provider of performance and data solutions. Working to be healthcare's most trusted partner, our customer-centric focus drives continuous improvement and leads to innovative solutions that improve the lives of people every day. With approximately 50,000 employees worldwide, Cardinal Health ranks among the top fifteen in the Fortune 500.
**_Department Overview:_**
**Information Technology** oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value.
**Information Security and Risk** develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure, or destruction. This job family develops system back-up and disaster recovery plans, conducts incident responses, threat management, vulnerability scanning, virus management and intrusion detection as well as completes risk assessments.
We are seeking a highly skilled and experienced Identity and Access Management (IAM) Engineer to join our team. In this pivotal role, you will be instrumental in designing, implementing, and managing IAM solutions that secure our enterprise applications and facilitate the secure, efficient, and seamless integration of identity and access systems in context of our rapid growth through Mergers and Acquisitions. You will ensure robust access controls, streamline user experiences, and maintain operational continuity across our diverse IT landscape. The ideal candidate will have deep technical expertise in modern IAM principles, protocols and products along with strong management and communication skills.
**Responsibilities:**
+ **Application Integration Leadership:** Lead the integration of various enterprise applications (SaaS, on-premise, custom-built) with our core IAM infrastructure, ensuring secure authentication, authorization, and user provisioning/de-provisioning.
+ **M&A Integration Strategy & Execution:** Lead the planning, design, and execution of IAM integration strategies for M&A activities, ensuring alignment with overall business and security objectives. This includes assessing the IAM landscapes of merging entities to identify challenges and solutions.
+ **Identity System Merging & Consolidation:** Manage the complex process of merging disparate identity providers, user directories (e.g., Active Directory, Azure AD, LDAP), and access management systems from acquired companies into the existing infrastructure.
+ **User Lifecycle Management:** Streamline and automate user provisioning, de-provisioning, and periodic access reviews for employees, contractors, and partners across all integrated systems, ensuring smooth onboarding and offboarding during M&A transitions.
+ **Solution Design & Implementation:** Design, implement, and maintain IAM solutions including Single Sign-On (SSO), Multi-Factor Authentication (MFA), Privileged Access Management (PAM), and Role-Based Access Control (RBAC) frameworks.
+ **Security & Compliance:** Ensure IAM systems and processes comply with regulatory requirements (e.g., GDPR, HIPAA, SOX) and internal security policies, providing auditable records of access activities. Protect against data breaches by ensuring only authorized personnel can access sensitive information.
+ **Technical Troubleshooting & Support:** Troubleshoot, identify, and resolve technical identity and access management-related issues, providing expert support to internal teams and end-users during and after integration.
+ **Collaboration & Communication:** Coordinate cross-functional teams, including Information Security, IT Operations, HR, and Application Development, to ensure effective IAM implementation and seamless integration with business processes. Communicate complex security concepts to technical and non-technical stakeholders.
+ **Documentation & Best Practices:** Develop, review, and maintain comprehensive technical documentation, including architecture diagrams, configuration guides, and operational procedures. Stay up-to-date with IAM best practices, regulatory requirements, and security trends.
**Qualifications:**
+ **Education:** Bachelor's degree in Computer Science, Information Technology, Information Security, or a related field, or equivalent practical experience.
+ **Experience:** 5+ years of progressive experience as an IAM Engineer, designing and implementing enterprise scale solutions with significant experience in supporting M&A integration projects preferred.
+ **Technical Expertise:**
+ Proficiency in directory services (e.g., Active Directory, Azure AD, LDAP).
+ Extensive knowledge and experience with authentication standards and technologies such as SSO (SAML, OAuth, OpenID Connect), MFA, and privileged access management (PAM).
+ Hands-on experience with leading IAM platforms (e.g., Okta, Microsoft Azure AD, CyberArk, ForgeRock, Ping Identity, SailPoint).
+ Experience with scripting languages (e.g., PowerShell, Python) for automation and integration.
+ Strong understanding of security principles, risk management, and access control models (e.g., RBAC).
+ Understanding of DevOps practices.
+ Familiarity with Zero Trust architecture principles.
+ Familiarity with AI/ML concepts and their practical application in security and risk management, especially in IAM context.
+ **M&A Specific Skills:** Proven track record of managing complex integration projects, including assessing existing IAM capabilities, workflow, systems, and processes of acquired entities. Ability to navigate the complexities of integrating diverse identity infrastructures.
+ Strong communication and interpersonal skills to collaborate effectively with various teams and stakeholders.
+ Detail-oriented mindset to ensure precise access control configurations and compliance.
+ Excellent problem-solving and analytical abilities to troubleshoot access issues and design solutions for unique business requirements
+ Must be a self-starter who takes full ownership of projects from inception to completion , holding oneself accountable for the security and operation integrity of IAM platform.
+ Ability to manage multiple priorities and meet tight deadlines in a fast-paced M&A environment.
+ Adaptability to stay ahead of evolving IAM technologies and security threats.
**Anticipated salary range:** $94,900 - $135,600
**Bonus eligible:** No
**Benefits:** Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
+ Medical, dental and vision coverage
+ Paid time off plan
+ Health savings account (HSA)
+ 401k savings plan
+ Access to wages before pay day with my FlexPay
+ Flexible spending accounts (FSAs)
+ Short- and long-term disability coverage
+ Work-Life resources
+ Paid parental leave
+ Healthy lifestyle programs
**Application window anticipated to close:** 12/20/2025 *if interested in opportunity, please submit application as soon as possible.
The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.
_Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply._
_Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal_ _Opportunity/Affirmative_ _Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law._
_To read and review this privacy notice click_ here (***************************************************************************************************************************
IT Product and Financial Analyst
Information security analyst job in Laurel, VA
ON SITE: 3 days a week required Responsibilities:
Conduct detailed financial analysis and forecasting for security products and services within the agency.
Develop and maintain budgeting models to support product and service funding requests, execution, and cost management.
Collaborate with cross-functional teams including IT security, procurement, and compliance to align financial strategies with agency goals
Monitor and report on financial performance against approved budgets, identifying risks and opportunities.
Support procurement and contract negotiations with vendors from a financial perspective.
Analyze life cycle costs and support cost-benefit evaluations for new security initiatives and technology acquisitions.
Assist in evaluating the financial viability of new security products or enhancements
Provide clear, concise financial reports and briefings for senior leadership and oversight bodies.
Support continuous improvement of financial processes and systems related to security program funding and expenditure tracking.
Job Type: Contract
Experience:
BS/MS degree in Computer Science, Engineering or a related: 4 years (Preferred)
financial modeling, budgeting, cost analysis,forecasting.: 2 years (Preferred)
analytical, organizational, and communication skills.: 2 years (Preferred)
Ability to manage multiple priorities and deliver results: 2 years (Preferred)
Familiarity with State Government budgeting process.: 2 years (Preferred)
Understand technologies as it relates to product and cost: 2 years (Preferred)
financial management systems and tools (Microsoft Office): 2 years (Preferred)
IT Security Analyst 4
Information security analyst job in Richmond, VA
Number of positions: 1
Length: 12Months +
Work Address: Richmond, VA
Immediate Interviews In Person Interview
IT Security Analyst 4
Hybrid (ONSITE Required: 2-3 days/week)
Document and address organization\'s information security, cybersecurity architecture, and systems security engineering requirements throughout the acquisition life cycle.
3 days - on site -2 days - remote
Notes from the manager:
For this position we are really looking for someone who is strong in Security Operations (Vulnerability Management, Penetration Testing, Incident Response, Identity Access Management, etc.). A few of the candidates were strong in Risk Management (Risk Assessment, Data Classification, Audits, etc.) but we already have those skills on our team. The remaining candidates mostly struggled to answer basic technical questions relating to security and seemed to mostly come from more IT Operations backgrounds. We are looking for an experienced person as this is not an entry level opening.
General things to consider when screening:
1. Experience with vulnerability management is key for this position.
2. Experience with application penetration is key for this position.
3. Experience with Dev SecOps/Secure Software Development Lifecycle (Secure SDLC/SSDLC)/Secure by Design is key for this position.
4. Scripting and automation experience is highly desired for this position.
5. Interpersonal skills and being able to talk with and manage stakeholders are key for this position.
Analyze the security impact of application, configuration, and infrastructure changes to ensure compliance with the security standard as part of the change management lifecycle.
Assess the configurations of applications, servers, and network devices for compliance with the security standard.
Analyze and document how the implementation of new system or new interfaces between systems impacts the security posture of the current environment.
Assess and document the security impact and risks of newly discovered vulnerabilities in the environment.
Coordinate resolution of application and infrastructure security vulnerabilities with System Owners, IT, and vendors. Track resolution of vulnerabilities and provide regular updates to management.
Coordinate resolution of endpoint security vulnerabilities with users and provide regular updates to management.
Respond to, and investigate, security incidents and provide thorough post-event analyses.
Perform internal application penetration testing, document findings, and recommend improvements to improve the organizations security posture.
Complete annual password security audits and coordinate completion of agency wide user access audits in compliance with the security standard.
Determine the protection needs (i.e., security controls) for the information system(s) and network(s) and document appropriately.
Create and maintain desk procedures and process documentation for all responsibilities.
Required/Desired Skills
Candidates must have ALL the Required skills in order to be considered for the position. Desired or Highly Desired skills are a PLUS but may NOT be required.
Skill Matrix (Please fill the last two columns of this matrix)
Experience with Business workflow processes
Required / Desired
Amount
of Experience
Years of Experience
Last Used
NIST 800-53 rev 5 and/or Criminal Justice Information System (CJIS) specifications for an information security management system.
Required
5
Years
Software development lifecycle, vulnerability management processes, role-based authentication methodologies, etc.
Required
5
Years
Familiarity with programming languages such as Python, Java, JavaScript, C++, C#, SQL, HTML, CSS, and/or COBOL.
Required
5
Years
Expertise in using automated vulnerability scanners like Nessus, Qualys, Retina, and/or Tenable.
Required
5
Years
Familiarity with web application security testing tools like Burp Suite, Fortify, and/or AppScan.
Required
5
Years
Basic scripting skills (e.g. WDL, VBScript, JavaScript, PowerShell, Python) for automation
Required
5
Years
IT security or risk assessment certifications are advantageous (CISM, CCSP, CISSP, CEH, CompTIA Pentest+ and/or CompTIA Security+)
Required
5
Years
Security Engineer
Information security analyst job in Richmond, VA
What part will you play? If you're looking for a place where you can make a meaningful difference, you've found it. The work we do at Markel gives people the confidence to move forward and seize opportunities, and you'll find your fit amongst our global community of optimists and problem-solvers. We're always pushing each other to go further because we believe that when we realize our potential, we can help others reach theirs.
Join us and play your part in something special!
Looking for a role that will have a meaningful impact on Security Engineering?
We are looking for an individual to reduce enterprise risk through the secure design, implementation and administration of cybersecurity tools and helping to enhance department strategies to protect our customers, data, and associates.
What part will you play? If you're looking for a place where you can make a meaningful difference, you've found it. The work we do at Markel gives people the confidence to move forward and seize opportunities, and you'll find your fit amongst our global community of optimists and problem-solvers. We're always pushing each other to go further because we believe that when we realize our potential, we can help others reach theirs.
Join us and play your part in something special!
The opportunity:
We are seeking a Security Engineer to join our dynamic team, where you'll play a pivotal role in fortifying our company's internal network against unauthorized access and cyber threats.
As a Security Engineer, you'll be at the forefront of our cybersecurity efforts, designing and implementing cutting-edge security strategies. You will have the chance to collaborate with a team of skilled security specialists to devise and execute robust architecture solutions that protect our digital assets. Your expertise will not only help mitigate potential damages during current attacks but also proactively identify and resolve hardware or software vulnerabilities before they become threats.
In this role, you'll leverage your deep understanding of various hardware and software technologies, along with the Enterprise Security Framework, to drive innovative design solutions and provide strategic recommendations. Your insights and contributions will be crucial in shaping the security posture of our organization, ensuring that we stay ahead of evolving cyber risks.
What you'll be doing:
* Architect & Implement: Design and deploy cloud security architectures meeting business, security, and compliance needs.
* Configuration Management: Secure cloud-based tools and mobile technology, ensuring safe access solutions.
* Security Environments: Create and maintain testing environments for security solutions.
* Risk Mitigation: Innovate security measures across on-premise and cloud environments.
* Network Security Oversight: Manage cloud network security, including firewall approvals.
* Automation & Scripting: Develop automation scripts for security needs.
* Incident Response: Lead and strategize responses to cyber threats.
* Secure Access Solutions: Implement secure authentication, authorization, and encryption strategies.
* Cyber Threat Awareness: Stay updated on security trends and threats.
* Change Management: Oversee security aspects of cloud changes and software deployments.
* Policy Documentation: Document and enforce security policies and procedures.
* Skill Development: Update and share technical knowledge on data protection.
* Metrics & Reporting: Generate Cloud Security status metrics.
* Mentorship & Leadership: Guide and mentor junior team members.
* Operational Support: Maintain security tools and systems.
* Compliance: Ensure compliance with regulations (NY State, PCI, GDPR, NIST).
* Project Support: Evaluate and implement new security technologies.
* Technical Resource: Serve as an expert for other departments.
* Communication: Convey security issues and solutions clearly.
* Additional Duties: Participate in incident response, change management, and system maintenance.
Our must-haves:
* 3+ years related work experience & industry certification in cyber security.
* Bachelor's degree in Computer Science or Engineering with a focus on Cyber Security, Digital Forensics or related work experience/certification.
* Security+ or similar industry approved certifications.
Other certifications that are a plus:
* ITIL, preferred
* Certified Cloud Security Professional - ISC2 .org (CCSP)
* Certified Information Systems Security Professional (CISSP)
* Certificate of Cloud Security Knowledge - CSA (CCSK)
* Information Systems Security Engineering Professional (ISSEP)
* Microsoft Certified: Azure Fundamentals (MCAF)
* Microsoft Certified Azure Administrator Associate (MCAAA)
* Microsoft Certified: Azure Security Engineer Associate (MCASEA)
#LI-Hybrid
#DEIB
US Work Authorization
US Work Authorization required. Markel does not provide visa sponsorship for this position, now or in the future.
Pay information:
Who we are:
Markel Group (NYSE - MKL) a fortune 500 company with over 60 offices in 20+ countries, is a holding company for insurance, reinsurance, specialist advisory and investment operations around the world.
We're all about people | We win together | We strive for better
We enjoy the everyday | We think further
What's in it for you:
In keeping with the values of the Markel Style, we strive to support our employees in living their lives to the fullest at home and at work.
* We offer competitive benefit programs that help meet our diverse and changing environment as well as support our employees' needs at all stages of life.
* All full-time employees have the option to select from multiple health, dental and vision insurance plan options and optional life, disability, and AD&D insurance.
* We also offer a 401(k) with employer match contributions, an Employee Stock Purchase Plan, PTO, corporate holidays and floating holidays, parental leave.
Are you ready to play your part?
Choose 'Apply Now' to fill out our short application, so that we can find out more about you.
Caution: Employment scams
Markel is aware of employment-related scams where scammers will impersonate recruiters by sending fake job offers to those actively seeking employment in order to steal personal information. Frequently, the scammer will reach out to individuals who have posted their resume online. These "job offers" include convincing offer letters and frequently ask for confidential personal information. Therefore, for your safety, please note that:
* All legitimate job postings with Markel will be posted on Markel Careers. No other URL should be trusted for job postings.
* All legitimate communications with Markel recruiters will come from Markel.com email addresses.
We would also ask that you please report any job employment scams related to Markel to ***********************.
Markel is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of any protected characteristic. This includes race; color; sex; religion; creed; national origin or place of birth; ancestry; age; disability; affectional or sexual orientation; gender expression or identity; genetic information, sickle cell trait, or atypical hereditary cellular or blood trait; refusal to submit to genetic tests or make genetic test results available; medical condition; citizenship status; pregnancy, childbirth, or related medical conditions; marital status, civil union status, domestic partnership status, familial status, or family responsibilities; military or veteran status, including unfavorable discharge from military service; personal appearance, height, or weight; matriculation or political affiliation; expunged juvenile records; arrest and court records where prohibited by applicable law; status as a victim of domestic or sexual violence; public assistance status; order of protection status; status as a smoker or nonsmoker; membership or activity in local commissions; the use or nonuse of lawful products off employer premises during non-work hours; declining to attend meetings or participate in communications about religious or political matters; or any other classification protected by applicable law.
Should you require any accommodation through the application process, please send an e-mail to the ***********************.
No agencies please.
Auto-ApplySecurity Engineer II
Information security analyst job in Richmond, VA
Trustmark's mission is to improve wellbeing - for everyone. It is a mission grounded in a belief in equality and born from our caring culture. It is a culture we can only realize by building trust. Trust established by ensuring associates feel respected, valued and heard. At Trustmark, you'll work collaboratively to transform lives and help people, communities and businesses thrive. Flourish in a culture of diversity and inclusion where appreciation, mutual respect and trust are constants, not just for our customers but for ourselves. At Trustmark, we have a commitment to welcoming people, no matter their background, identity or experience, to a workplace where they feel safe being their whole, authentic selves. A workplace made up of diverse, empowered individuals that allows ideas to thrive and enables us to bring the best to our colleagues, clients and communities.
We are seeking a highly skilled Cyber Security Engineer to join our team and play a pivotal role in safeguarding our organization's digital assets. The ideal candidate will possess a deep understanding of cybersecurity principles, a strong technical background, and a passion for protecting sensitive information.
You will be responsible for engineering, implementing and monitoring security measures for the protection of Trustmark's computer systems, networks and information. The role helps identify and define system security requirements as well as develop detailed cyber security designs.
**Responsibilities:**
+ Design, implement, and maintain security architectures, systems, and solutions to protect critical infrastructure and data.
+ Conduct vulnerability assessments and penetration testing to identify and mitigate risks.
+ Develop and implement security policies, standards, and procedures.
+ Monitor security systems and respond to incidents promptly and effectively.
+ Stay up-to-date with the latest cybersecurity threats and trends.
+ Collaborate with cross-functional teams to ensure security is integrated into all aspects of the business.
+ Provide technical guidance and support to internal stakeholders.
**Qualifications:**
+ Bachelor's degree in Computer Science, Information Technology, or a related field or
+ 3-5 Years of network engineering or cyber engineering experience
+ Strong understanding of cybersecurity frameworks and standards (e.g., NIST, ISO 27001).
+ Proficiency in network security, systems security, application security, and data security.
+ Hands-on experience with security tools and technologies (e.g., firewalls, intrusion detection systems, encryption, SIEM).
+ Excellent problem-solving and analytical skills.
+ Strong communication and interpersonal skills.
+ Ability to work independently and as part of a team.
**Preferred Qualifications:**
+ Certifications such as CISSP, CISA, or CEH.
+ Experience with cloud security (e.g., AWS, Azure, GCP).
+ Knowledge of scripting and programming languages (e.g., Python, PowerShell).
Brand: Trustmark
Come join a team at Trustmark that will not only utilize your current skills but will enhance them as well. Trustmark benefits include health/dental/vision, life insurance, FSA and HSA, 401(k) plan, Employee Assistant Program, Back-up Care for Children, Adults and Elders and many health and wellness initiatives. We also offer a Wellness program that enables employees to participate in health initiatives to reduce their insurance premiums.
**For the fourth consecutive year we were selected as a Top Workplace by the Chicago Tribune.** The award is based exclusively on Trustmark associate responses to an anonymous survey. The survey measured 15 key drivers of engaged cultures that are critical to the success of an organization.
All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, sex, sexual orientation, sexual identity, age, veteran or disability.
Join a passionate and purpose-driven team of colleagues who contribute to Trustmark's mission of helping people increase wellbeing through better health and greater financial security. At Trustmark, you'll work collaboratively to transform lives and help people, communities and businesses thrive. Flourish in a culture where appreciation, mutual respect and trust are constants, not just for our customers but for ourselves.
Introduce yourself to our recruiters and we'll get in touch if there's a role that seems like a good match.
When you join Trustmark, you become part of an organization that makes a positive difference in people's lives. You will play a vital role in delivering on our mission of helping people increase wellbeing through better health and greater financial security. Our customers tell us they simply appreciate the personal attention and knowledgeable service. Others tell us we've changed their lives.
At Trustmark, you'll be part of a close-knit team. You'll enjoy abundant opportunities to grow your career. That's why so many of our associates stay at Trustmark and thrive. Trustmark benefits from more than 100 years of experience but pairs that rich history with a palpable sense of optimism, growth and excitement for what's ahead - and beyond. This is a place where associates bring their whole selves to work each day. A place where you can be yourself. Whatever your beyond is, you can achieve it at Trustmark.
Product Security Engineer, Instagram
Information security analyst job in Richmond, VA
The Instagram Security Ecosystems team is seeking a product-focused security engineer interesting in enabling Instagram product teams to develop features with a focus on security and user safety. You will be relied upon to directly work with Instagram engineers, hardening both product features and our protective frameworks that make life harder for bad actors on the Instagram platform.
**Required Skills:**
Product Security Engineer, Instagram Responsibilities:
1. Threat Modeling and Security Architecture: Work directly with product managers and technical leads on threat models and security architecture for novel Instagram features or products
2. Security Reviews: Perform manual design and implementation reviews of web, mobile, and native code
3. Developer Guidance: Provide guidance and education to developers that help prevent the authoring of vulnerabilities
4. Automated Analysis and Secure Frameworks: Work with other security teams to improve Instagram's static and dynamic analysis and frameworks to scale coverage
5. Bug Bounty: Help provide technical guidance to our world class bug bounty program and independent security researchers
6. Industry Impact: Push the industry forward through conference talks and open source projects to contribute broadly to security for the world
**Minimum Qualifications:**
Minimum Qualifications:
7. B.S. or M.S. in Computer Science, Cybersecurity, or related field, or equivalent experience
8. 8+ years of experience finding vulnerabilities in interpreted languages (Python, PHP)
9. Extensive, proven experience in threat modeling and secure systems design
10. Experience with exploiting common security vulnerabilities
**Preferred Qualifications:**
Preferred Qualifications:
11. Product software engineering or product management experience
12. Experience in security consulting or other leadership-facing security advisory roles
13. Familiarity with cybersecurity investigations, abuse operations, and/or security incident response
14. Contributions to the security community (public research, blogging, presentations, bug bounty, etc.)
**Public Compensation:**
$177,000/year to $251,000/year + bonus + equity + benefits
**Industry:** Internet
**Equal Opportunity:**
Meta is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Meta participates in the E-Verify program in certain locations, as required by law. Please note that Meta may leverage artificial intelligence and machine learning technologies in connection with applications for employment.
Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at accommodations-ext@fb.com.
IT Purchasing Analyst
Information security analyst job in Richmond, VA
Job Description Role : IT Purchasing Analyst Interview Mode: In Person Only The Virginia State Police (VSP), Criminal Justice Information Services (CJIS) Division, is looking for an information technology (IT) purchasing analyst to support of IT projects. The incumbent will perform procurement tasks such as working with suppliers to obtain quotes, enter requisitions in the state procurement system (eVA), track requisition processing to ensure timely completion, propose and process contract amendments, assist with enforcement of vendor contract terms, review and recommend approval/denial of invoices, and evaluate VITA expenses to identify and record expenses related to IT projects. In addition, updates project budgets and grants, and coordinates activities with the VSP Procurement Office, VSP IT Division and VSP grant managers. Provides VSP management with reports that describe current procurement activities, invoices and bills processed, and budget and grant balances. Full-time onsite at VSP headquarters, North Chesterfield, Virginia.
Candidates must have 2+years of IT procurement experience, able to learn Commonwealth of Virginia, VITA and VSP procurement policies and systems (e.g. eVA). In addition, candidates:
* Must have very good skills in operating computers and using MS Office (Word, Excel, PowerPoint);
* Be able to plan, organize and manage multiple tasks simultaneously;
* Have strong communication skills (orally and in writing, in English).
Candidates should highlight experience procuring high value procurements with an emphasis on information technology (IT) procurements. Candidates should highlight procurement experience and certifications. For example, experience with public procurement, contracting laws and state regulations; experience with technology related procurements, service contracts, business writing, and fiscal procedures; certification as a Virginia Contracting Officer (VCO); certification as a Certified Public Purchasing Officer (CPPO), and/or Certified Professional Public Buyer (CPPB); experience in the procurement of wide variety of goods and services within state government
Powered by JazzHR
J3bBwWqEBi
Engineer, Information Security and Risk
Information security analyst job in Richmond, VA
Cardinal Health, Inc. (NYSE: CAH) is a global healthcare services and products company. We provide customized solutions for hospitals, healthcare systems, pharmacies, ambulatory surgery centers, clinical laboratories, physician offices and patients in the home. We are a distributor of pharmaceuticals and specialty products; a global manufacturer and distributor of medical and laboratory products; an operator of nuclear pharmacies and manufacturing facilities; and a provider of performance and data solutions. Working to be healthcare's most trusted partner, our customer-centric focus drives continuous improvement and leads to innovative solutions that improve the lives of people every day. With approximately 50,000 employees worldwide, Cardinal Health ranks among the top fifteen in the Fortune 500.
**_Department Overview:_**
**Information Technology** oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value.
**Information Security and Risk** develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure, or destruction. This job family develops system back-up and disaster recovery plans, conducts incident responses, threat management, vulnerability scanning, virus management and intrusion detection as well as completes risk assessments.
**Responsibilities:**
+ **M&A Integration Execution:** Collaborate and engage with IAM Lead and other business partners on planning, design, and execution of IAM integration strategies for M&A activities, ensuring alignment with overall business and security objectives. This includes assessing the IAM landscapes of merging entities to identify challenges and solutions.
+ **Design and Implement Sailpoint IIQ Solutions:** Configure and customize Sailpoint IIQ components (Lifecycel Manager, Compliance Manager etc). Also develop workflows, rules, and connectors for identity governance.
+ **Application integration with Sailpoint IIQ:** Integrate Sailpoint IIQ with enterprise applications, directories and cloud platforms in addition to developing and maintaining connectros for provisioning and de-provisioning.
+ **Sailpoint IIQ Development and Scripting:** Write and maintain BeanShell scripts, Java code and XML configurations, develop customer Sailpoint tasks and workflows.
+ **Identity System Merging & Consolidation:** Manage the complex process of merging disparate identity providers, user directories (e.g., Active Directory, Azure AD, LDAP), and access management systems from acquired companies into the existing infrastructure.
+ **User Lifecycle Management:** Streamline and automate user provisioning, de-provisioning, and periodic access reviews for employees, contractors, and partners across all integrated systems, ensuring smooth onboarding and offboarding during M&A transitions.
+ **Security & Compliance:** Ensure IAM systems and processes comply with regulatory requirements (e.g., GDPR, HIPAA, SOX) and internal security policies, providing auditable records of access activities. Protect against data breaches by ensuring only authorized personnel can access sensitive information.
+ **Technical Troubleshooting & Support:** Troubleshoot, identify, and resolve technical identity and access management-related issues, providing expert support to internal teams and end-users during and after integration.
+ **Collaboration & Communication:** Coordinate cross-functional teams, including Information Security, IT Operations, HR, and Application Development, to ensure effective IAM implementation and seamless integration with business processes. Communicate complex security concepts to technical and non-technical stakeholders.
+ **Documentation & Best Practices:** Develop, review, and maintain comprehensive technical documentation, including architecture diagrams, configuration guides, and operational procedures. Stay up-to-date with IAM best practices, regulatory requirements, and security trends.
**Qualifications**
+ Experience with SailPoint IdentityIQ (IIQ) is a must
+ Experience with SailPoint IIQ Integrations (Workday, Active Directory/LDAP, Webservices, SCIM, JDBC, SAP)
+ Experience implementing Life Cycle Manager (LCM) Configuration workflow tasks that model business functions, including Lifecycle Requests (Role or Entitlement), Lifecycle Events (Joiner, Mover, or Leaver), and LCM Workflow Details (Workflows and Subprocesses)
+ Solid understanding of the SailPoint object model, rules, and policies
+ Experience with both lifecycle manager (LCM) and compliance manager (CM) modules
+ Knowledge of Active Directory, LDAP, Workday, and cloud platforms (GCP, MS Entra ID) is required
+ Proven track record of successful IAM implementations including large scale enterprise deployments.
+ Experience working within regulatory standards and requirements such as, SOX, HIPAA, GDPR etc. is desired.
**Anticipated salary range:** $94,900 - $135,600
**Bonus eligible:** No
**Benefits:** Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
+ Medical, dental and vision coverage
+ Paid time off plan
+ Health savings account (HSA)
+ 401k savings plan
+ Access to wages before pay day with my FlexPay
+ Flexible spending accounts (FSAs)
+ Short- and long-term disability coverage
+ Work-Life resources
+ Paid parental leave
+ Healthy lifestyle programs
**Application window anticipated to close:** 12/20/2025 *if interested in opportunity, please submit application as soon as possible.
The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.
_Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply._
_Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal_ _Opportunity/Affirmative_ _Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law._
_To read and review this privacy notice click_ here (***************************************************************************************************************************
Security Engineer
Information security analyst job in Richmond, VA
What part will you play? If you're looking for a place where you can make a meaningful difference, you've found it.
The work we do at Markel gives people the confidence to move forward and seize opportunities, and you'll find your fit amongst our global community of optimists and problem-solvers. We're always pushing each other to go further because we believe that when we realize our potential, we can help others reach theirs. Join us and play your part in something special! Looking for a role that will have a meaningful impact on Security Engineering?
We are looking for an individual to reduce enterprise risk through the secure design, implementation and administration of cybersecurity tools and helping to enhance department strategies to protect our customers, data, and associates.
What part will you play? If you're looking for a place where you can make a meaningful difference, you've found it. The work we do at Markel gives people the confidence to move forward and seize opportunities, and you'll find your fit amongst our global community of optimists and problem-solvers. We're always pushing each other to go further because we believe that when we realize our potential, we can help others reach theirs.
Join us and play your part in something special!
The opportunity:
We are seeking a Security Engineer to join our dynamic team, where you'll play a pivotal role in fortifying our company's internal network against unauthorized access and cyber threats.
As a Security Engineer, you'll be at the forefront of our cybersecurity efforts, designing and implementing cutting-edge security strategies. You will have the chance to collaborate with a team of skilled security specialists to devise and execute robust architecture solutions that protect our digital assets. Your expertise will not only help mitigate potential damages during current attacks but also proactively identify and resolve hardware or software vulnerabilities before they become threats.
In this role, you'll leverage your deep understanding of various hardware and software technologies, along with the Enterprise Security Framework, to drive innovative design solutions and provide strategic recommendations. Your insights and contributions will be crucial in shaping the security posture of our organization, ensuring that we stay ahead of evolving cyber risks.
What you'll be doing:
Architect & Implement: Design and deploy cloud security architectures meeting business, security, and compliance needs.
Configuration Management: Secure cloud-based tools and mobile technology, ensuring safe access solutions.
Security Environments: Create and maintain testing environments for security solutions.
Risk Mitigation: Innovate security measures across on-premise and cloud environments.
Network Security Oversight: Manage cloud network security, including firewall approvals.
Automation & Scripting: Develop automation scripts for security needs.
Incident Response: Lead and strategize responses to cyber threats.
Secure Access Solutions: Implement secure authentication, authorization, and encryption strategies.
Cyber Threat Awareness: Stay updated on security trends and threats.
Change Management: Oversee security aspects of cloud changes and software deployments.
Policy Documentation: Document and enforce security policies and procedures.
Skill Development: Update and share technical knowledge on data protection.
Metrics & Reporting: Generate Cloud Security status metrics.
Mentorship & Leadership: Guide and mentor junior team members.
Operational Support: Maintain security tools and systems.
Compliance: Ensure compliance with regulations (NY State, PCI, GDPR, NIST).
Project Support: Evaluate and implement new security technologies.
Technical Resource: Serve as an expert for other departments.
Communication: Convey security issues and solutions clearly.
Additional Duties: Participate in incident response, change management, and system maintenance.
Our must-haves:
3+ years related work experience & industry certification in cyber security.
Bachelor's degree in Computer Science or Engineering with a focus on Cyber Security, Digital Forensics or related work experience/certification.
Security+ or similar industry approved certifications.
Other certifications that are a plus:
ITIL, preferred
Certified Cloud Security Professional - ISC2 .org (CCSP)
Certified Information Systems Security Professional (CISSP)
Certificate of Cloud Security Knowledge - CSA (CCSK)
Information Systems Security Engineering Professional (ISSEP)
Microsoft Certified: Azure Fundamentals (MCAF)
Microsoft Certified Azure Administrator Associate (MCAAA)
Microsoft Certified: Azure Security Engineer Associate (MCASEA)
#LI-Hybrid
#DEIB
US Work Authorization
US Work Authorization required. Markel does not provide visa sponsorship for this position, now or in the future.
Pay information:
Who we are:
Markel Group (NYSE - MKL) a fortune 500 company with over 60 offices in 20+ countries, is a holding company for insurance, reinsurance, specialist advisory and investment operations around the world.
We're all about people | We win together | We strive for better
We enjoy the everyday | We think further
What's in it for you:
In keeping with the values of the Markel Style, we strive to support our employees in living their lives to the fullest at home and at work.
We offer competitive benefit programs that help meet our diverse and changing environment as well as support our employees' needs at all stages of life.
All full-time employees have the option to select from multiple health, dental and vision insurance plan options and optional life, disability, and AD&D insurance.
We also offer a 401(k) with employer match contributions, an Employee Stock Purchase Plan, PTO, corporate holidays and floating holidays, parental leave.
Are you ready to play your part?
Choose ‘Apply Now' to fill out our short application, so that we can find out more about you.
Caution: Employment scams
Markel is aware of employment-related scams where scammers will impersonate recruiters by sending fake job offers to those actively seeking employment in order to steal personal information. Frequently, the scammer will reach out to individuals who have posted their resume online. These "job offers" include convincing offer letters and frequently ask for confidential personal information. Therefore, for your safety, please note that:
All legitimate job postings with Markel will be posted on Markel Careers. No other URL should be trusted for job postings.
All legitimate communications with Markel recruiters will come from Markel.com email addresses.
We would also ask that you please report any job employment scams related to Markel to ***********************.
Markel is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of any protected characteristic. This includes race; color; sex; religion; creed; national origin or place of birth; ancestry; age; disability; affectional or sexual orientation; gender expression or identity; genetic information, sickle cell trait, or atypical hereditary cellular or blood trait; refusal to submit to genetic tests or make genetic test results available; medical condition; citizenship status; pregnancy, childbirth, or related medical conditions; marital status, civil union status, domestic partnership status, familial status, or family responsibilities; military or veteran status, including unfavorable discharge from military service; personal appearance, height, or weight; matriculation or political affiliation; expunged juvenile records; arrest and court records where prohibited by applicable law; status as a victim of domestic or sexual violence; public assistance status; order of protection status; status as a smoker or nonsmoker; membership or activity in local commissions; the use or nonuse of lawful products off employer premises during non-work hours; declining to attend meetings or participate in communications about religious or political matters; or any other classification protected by applicable law.
Should you require any accommodation through the application process, please send an e-mail to the ***********************.
No agencies please.
Auto-ApplyCybersecurity Engineer/Azure Sr Security Engg
Information security analyst job in Richmond, VA
Number of positions: 1
Length: 12Months +
Work Address: Richmond, VA 23219
Immediate interviews Web Cam Interview
Elect - Cybersecurity Engineer
Is Remote.
Seeking an Azure Senior Security Engineer (Cybersecurity Engineer 3) with minimum 5 years experience to work with an existing software development team.
You will be working with our more established contractors and staff to focus on several web and Windows applications used both by internal staff and constituents of the Commonwealth of Virginia. The candidate will need expertise in all aspects of IT security and cloud security and experience working in an Agile/Scrum development environment interacting with technical and non-technical stakeholders.
Candidate will need to have extensive knowledge of cybersecurity practices, industry security standards, and regulatory standards. A bachelors degree and/or applicable recognized industry certifications are strongly desired and will help you stand out in this position.
using mobile and responsive design practices, so a familiarity with these methodologies would be a plus.
Required/Desired Skills
Candidates must have ALL the Required skills in order to be considered for the position. Desired or Highly Desired skills are a PLUS but may NOT be required.
Skill Matrix (Please fill the last two columns of this matrix)
Experience with Business workflow processes
Required / Desired
Amount
of Experience
Years of Experience
Last Used
5+ years in IT security or cloud security roles required.
Required
5
Years
3+ years of hands-on experience securing Azure environments
Required
3
Years
Bachelors degree in Computer Science, Cybersecurity, or related field or equivalent work experience required.
Required
5
Years
Relevant certifications (MS Certified Cybersecurity Architect Expert, Azure Security Engineer Associate (SC-300), CompTIA Security+, CISSP, CISM
Highly desired
5
Years
Experience with Azure Security Services (Azure Defender, MS Sentinel, Azure Key Vault, Azure Policy and Blueprints, Azure Security Center) required.
Required
5
Years
Experience with Azure Active Directory (AAD), including conditional access, MFA, and identity protection required.
Required
5
Years
Extensive knowledge of PIM and RBAC required
Required
5
Years
Experience with NSGs, ASGs, VPN, ExpressRoute, and hybrid connectivity security required
Required
5
Years
Ability to implement and moitor compliance with regulatory standards such as NIST, ISO 27001, GDPR, etc. is required
Required
5
Years
Extensive knowledge of threat modeling and vulnerability management, SIEM/SOAR tuning and response workflows, and security alert triage and forensics
Required
5
Years
Ability to perform scripting and automation using PowerShell, Bicep, ARM templates, or Terraform
Required
5
Years
Ability to perform perform integration with CI/CD pipelines for secure deployments (GitHub Actions, Azure DevOps)
Required
5
Years
Ability to create and deliver security architecture reports and documentation
Required
5
Years
Experience in risk assessment and mitigation strategies
Required
5
Years
Engineer, Information Security and Risk
Information security analyst job in Richmond, VA
Cardinal Health, Inc. (NYSE: CAH) is a global healthcare services and products company. We provide customized solutions for hospitals, healthcare systems, pharmacies, ambulatory surgery centers, clinical laboratories, physician offices and patients in the home. We are a distributor of pharmaceuticals and specialty products; a global manufacturer and distributor of medical and laboratory products; an operator of nuclear pharmacies and manufacturing facilities; and a provider of performance and data solutions. Working to be healthcare's most trusted partner, our customer-centric focus drives continuous improvement and leads to innovative solutions that improve the lives of people every day. With approximately 50,000 employees worldwide, Cardinal Health ranks among the top fifteen in the Fortune 500.
**_Department Overview:_**
**Information Technology** oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value.
**Information Security and Risk** develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure, or destruction. This job family develops system back-up and disaster recovery plans, conducts incident responses, threat management, vulnerability scanning, virus management and intrusion detection as well as completes risk assessments.
Lead IAM work for new customer onboardings and migrations. Collaborate with CAH Account Management, Application Teams, and Customers to design, implement, and test federated SSO solution based on customer login requirements. Provide technical guidance and act as primary point of contact for business partners and customer related to IAM work for onboarding. Additional responsibilities include supporting application integrations and enhancing SSO self service application onboarding.
**Responsibilities:**
+ **Customer Onboarding IAM Efforts - Strategy & Execution :** Lead the planning, design, and execution for Customer Onboarding via federated SSO, ensuring alignment with overall business and security objectives. This includes assessing multiple Cardinal Health e-commerce applications, understanding login requirements for new/existing customers, designing, testing and implementing solutions etc to ensure top notch user login experience and enhancing Cardinal Health's security posture.
+ **Collaboration & Communication:** Coordinate cross-functional teams, including Customer Business and IT teams, Cardinal Health's Account Management/Sales and Application teams, Information Security and others to ensure effective IAM implementation and seamless integration with business processes. Communicate complex security concepts to technical and non-technical internal and external stakeholders.
+ **Application Integration Leadership:** Lead the integration of various enterprise applications (SaaS, on-premise, custom-built) with our core IAM infrastructure, ensuring secure authentication, authorization, and user provisioning/de-provisioning.
+ **User Lifecycle Management:** Streamline and automate user provisioning, de-provisioning, and periodic access reviews for employees, contractors, and partners across all integrated systems, ensuring smooth onboarding and offboarding during M&A transitions.
+ **Solution Design & Implementation:** Design, implement, and maintain IAM solutions including Single Sign-On (SSO), Multi-Factor Authentication (MFA), and Role-Based Access Control (RBAC) frameworks.
+ **Technical Troubleshooting & Support:** Troubleshoot, identify, and resolve technical identity and access management-related issues, providing expert support to internal teams and end-users during and after integration.
+ **Documentation & Best Practices:** Develop, review, and maintain comprehensive technical documentation, including architecture diagrams, configuration guides, and operational procedures. Stay up-to-date with IAM best practices, regulatory requirements, and security trends.
**Qualifications:**
+ **Education:** Bachelor's degree in Computer Science, Information Technology, Information Security, or a related field, or equivalent practical experience.
+ **Experience:** 5+ years of progressive experience as an IAM Engineer, designing and implementing enterprise scale solutions with significant experience in supporting M&A integration projects preferred.
+ **Technical Expertise:**
+ Extensive knowledge and experience with authentication standards and technologies such as SSO (SAML, OAuth, OpenID Connect), MFA
+ Proficiency in directory services (e.g., Active Directory, Azure AD, LDAP).
+ Hands-on experience with leading IAM platforms (e.g., Okta, Microsoft Azure AD, CyberArk, ForgeRock, Ping Identity, SailPoint).
+ Strong understanding of security principles, risk management, and access control models (e.g., RBAC).
+ Familiarity with Zero Trust architecture principles.
+ Familiarity with AI/ML concepts and their practical application in security and risk management, especially in IAM context.
+ Strong communication and interpersonal skills to collaborate effectively with various teams and stakeholders.
+ Detail-oriented mindset to ensure precise access control configurations and compliance.
+ Excellent problem-solving and analytical abilities to troubleshoot access issues and design solutions for unique business requirements
+ Must be a self-starter who takes full ownership of projects from inception to completion , holding oneself accountable for the security and operation integrity of IAM platform.
+ Ability to manage multiple priorities and meet tight deadlines in a fast-paced M&A environment.
**Anticipated salary range:** $94,900 - $135,600
**Bonus eligible:** No
**Benefits:** Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
+ Medical, dental and vision coverage
+ Paid time off plan
+ Health savings account (HSA)
+ 401k savings plan
+ Access to wages before pay day with my FlexPay
+ Flexible spending accounts (FSAs)
+ Short- and long-term disability coverage
+ Work-Life resources
+ Paid parental leave
+ Healthy lifestyle programs
**Application window anticipated to close:** 12/20/2025 *if interested in opportunity, please submit application as soon as possible.
The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.
_Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply._
_Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal_ _Opportunity/Affirmative_ _Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law._
_To read and review this privacy notice click_ here (***************************************************************************************************************************