Information Systems Security Officer (ISSO) III
Information security analyst job in Ogden, UT
Full Part/Time: Full time Type of Requisition: Regular Clearance Level Must Currently Possess: Top Secret/SCI Clearance Level Must Be Able to Obtain: Top Secret SCI + Polygraph Public Trust/Other Required:
None
Job Family:
Cyber and IT Risk Management
Job Qualifications:
Skills:
Information Security, Information Security Management, Information System Security
Certifications:
None
Experience:
5 + years of related experience
US Citizenship Required:
Yes
Job Description:
The Information Systems Security Officer (ISSO) II is responsible for ensuring the appropriate operational security posture is maintained for an information system and as such, works in close collaboration with the ISSM and ISO. The position shall have the detailed knowledge and expertise required to manage the security aspects of an information system and, in many organizations, is assigned responsibility for the day-to-day security operations of a system.
This will include physical and environmental protection, personnel security, incident handling, and security training and awareness. It will be required to work in close coordination with the ISSM and ISO in monitoring the information system(s) and its environment of operation to include developing and updating the authorization documentation, implementing configuration management across authorization boundaries. This will include assessing the security impact of those changes and making recommendation to the ISSM. The primary function is working within Special Access Programs (SAPs) supporting Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense (OSD) and Military Compartments efforts. The position will provide "day-to-day" support for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities.
Performance shall include:
* Assist the ISSM in meeting their duties and responsibilities.
* Prepare, review, and update authorization packages.
* Ensure approved procedures are in place for clearing, sanitizing, and destroying various types of hardware and media.
* Notify ISSM when changes occur that might affect the authorization determination of the information system(s).
* Conduct periodic reviews of information systems to ensure compliance with the security authorization package.
* Coordinate any changes or modifications to hardware, software, or firmware of a system with the ISSM and AO/DAO prior to the change.
* Monitor system recovery processes to ensure security features and procedures are properly restored and functioning correctly.
* Ensure all IS security-related documentation is current and accessible to properly authorized individuals.
* Ensure audit records are collected, reviewed, and documented (to include any anomalies)
* Attend required technical and security training (e.g., operating system, networking, security management) relative to assigned duties.
* Execute the cyber security portion of the self-inspection, to include security coordination and review of all system assessment plans.
* Identify cyber security vulnerabilities and assist with the implementation of the countermeasures for them.
* Prepare reports on the status of security safeguards applied to computer systems.
* Perform ISSO duties in support of in-house and external customers.
* Conduct continuous monitoring activities for authorization boundaries under your preview.
* Assist Department of Defense, National Agency and Contractor organizations with the development of assessment and authorization (A&A) efforts.
Experience:
* 5+ years related experience.
* 2+ years SAP experience required.
* Prior performance in roles such as System, Network Administrator or ISSO.
Education:
* Bachelor's degree OR Associate's degree in a related area + 2 years' experience OR equivalent experience (4 years)
Certifications:
* IAT Level II ( Security+ CE, CCNA Security, etc) or IAM Level II - within 6 months of hire
Clearance Required to Start:
* TS/SCI required
* Must be able to Attain - TS/SCI with CI Polygraph
#AirforceSAPOpportunities
The likely salary range for this position is $96,034 - $125,465. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
Scheduled Weekly Hours:
40
Travel Required:
10-25%
Telecommuting Options:
Onsite
Work Location:
USA UT Ogden
Additional Work Locations:
Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.
We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.
Join our Talent Community to stay up to date on our career opportunities and events at
gdit.com/tc.
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
Sentinel - Systems Security Engineer - 16416
Information security analyst job in Roy, UT
RELOCATION ASSISTANCE: Relocation assistance may be available CLEARANCE TYPE: SecretTRAVEL: Yes, 10% of the TimeDescriptionAt Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work - and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history.
Join Northrop Grumman on our continued mission to push the boundaries of possible across land, sea, air, space, and cyberspace. Enjoy a culture where your voice is valued and start contributing to our team of passionate professionals providing real-life solutions to our world's biggest challenges. We take pride in creating purposeful work and allowing our employees to grow and achieve their goals every day by Defining Possible. With our competitive pay and comprehensive benefits, we have the right opportunities to fit your life and launch your career today.
Northrop Grumman Defense Systems is seeking a Systems Security Engineer, (Level 2), that will support the Sentinel (GBSD) program performing Hardware Assurance.
This position will be located in Roy, UT and will support the Ground Based Strategic Deterrent (GBSD) program.
The Mission Defense Team (MDT) is seeking a highly motivated and qualified system engineer to serve as a Hardware Assurance Engineer, Level 2. You will be responsible for assessing and prioritizing a broad spectrum of hardware security threats. Key protection activities will involve vendor research, hardware assurance, program protection, counterfeit prevention, and supply chain security.
Additional Responsibilities include:
Assessment and analysis of threats, vulnerabilities, and risk for identified mission-critical functions and critical components
Support courses of action based on knowledge and experience, initiative, guidance, and established regulations and policies
Research, analyze data, and derive facts per identified vulnerabilities
Participate in a variety of working groups and customer meetings; ensure communication of risk environment with stakeholders
Contributes to program plans, goals, objectives, and milestones to for Hardware Assurance
Review technical security assessments of SSE environments to identify points of vulnerability, non-compliance with established standards and regulations and recommended mitigation strategies
Execute completion Statement of Work requirements, Program Milestone Exit Criteria, and program maturity commitments
Ensure the architecture and design of systems are functional and secure; support the design, development, implementation, and integration of security systems and system components
Self-starters compelled to take action in the workplace without requiring prompting from supervisors
Support MDT with other duties as assigned
In addition to technical skills, you will be a self-starter with strong time management skills. Your organizational skills and ability to anticipate future challenges will serve you well
Basic Qualifications
Must be a US Citizen with an active DoD Secret Clearance, at time of application, current and within scope, with an investigation date within the last 6 years
Must have the ability to obtain and maintain Special Access Program (SAP) approval within a reasonable period of time, as determined by the company to meet its business need
Requires a bachelor's degree in a STEM (Science, Technology, Engineering or Mathematics) discipline from an accredited university and 2 years of related experience; or a master's degree with 1 year
Minimum 2 years of applying and understanding Systems Security Engineering principles applicable to US Government Defense Programs
Minimum 2 years in showing the ability to communicate effectively and clearly present technical approaches and findings
Experience in any of the full product life cycles of: ASIC Design, FPGA Design
Experience in HDL (VHDL/Verilog), implementing designs using RTL
Ability to show self as team player, able to multi-task, able to generate quality work products independently, able to make excellent judgement and show interpersonal skills
Preferred Qualifications
Degree in Aerospace Engineering, Systems Engineering, Mechanical Engineering, Software Engineering, or similar
ICBM Experience
Experience developing Systems Security Engineering requirements for hardware and software assurance
Evaluating program processes and compliance strategies for large, complex multi-site programs
Demonstrated experience and familiarity with vulnerability management
Experience with Model-based Systems Engineering (MBSE) concepts and tools
A solid understanding of Program Protection applicable to US Government Defense Programs and applied knowledge in the application of SSE principles across a broad spectrum of security measures (Cybersecurity, Counterfeit Awareness, Anti-Tamper, HW/SW Assurance, OPSEC, etc.) to protect critical program information (CPI)
Top Secret clearance
Position Benefits
As a full-time employee of Northrop Grumman, you are eligible for our robust benefits package including:
Medical, Dental & Vision coverage
401k
Educational Assistance
Life Insurance
Employee Assistance Programs & Work/Life Solutions
Paid Time Off
Health & Wellness Resources
Employee Discounts
******************************************************************
This position's standard work schedule is a 9/80. The 9/80 schedule allows employees who work a nine-hour day Monday through Thursday to take every other Friday off.
This role may offer a competitive relocation assistance package.
#Sentinelsystems
Primary Level Salary Range: $77,200.00 - $115,800.00The above salary range represents a general guideline; however, Northrop Grumman considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills and current market conditions.Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. Annual bonuses are designed to reward individual contributions as well as allow employees to share in company results. Employees in Vice President or Director positions may be eligible for Long Term Incentives. In addition, Northrop Grumman provides a variety of benefits including health insurance coverage, life and disability insurance, savings plan, Company paid holidays and paid time off (PTO) for vacation and/or personal business.The application period for the job is estimated to be 20 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates.Northrop Grumman is an Equal Opportunity Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. For our complete EEO and pay transparency statement, please visit *********************************** U.S. Citizenship is required for all positions with a government clearance and certain other restricted positions.
Auto-ApplyInformation Security and Compliance Analyst
Information security analyst job in Pleasant Grove, UT
Job DescriptionAt Veracity, we aim to be a different kind of insurance partner - one that is free from outside investors, venture capital, or the pressures of a corporate parent. Ours is a culture of empowerment - one that believes in effort, results, and accountability. We believe that transparency fosters trust, trust fosters growth, and that growth drives innovation. Our commitment to rigorous evaluation and relentless execution lead to rapid evolution.
We answer only to the small business owners we serve, and this independence allows us to stay focused on what matters most: helping their businesses thrive by providing expert guidance and best-in-class insurance policies.
We're growing fast and want you to be a part of it!
We're seeking a talented, detail-oriented Information Security and Compliance Analyst to join our team. Reporting to the Technical Operations and Information Security Manager, this role is responsible for supporting the organization's cybersecurity posture by maintaining and enhancing security policies, controls, and monitoring systems, and ensuring compliance with frameworks such as SOC 2 and PCI DSS to protect company and client data.
Key Responsibilities
Strengthen the organization's cybersecurity posture by implementing, maintaining, and improving security policies, standards, and technical controls
Monitor security tools and system activity to identify, investigate, and escalate potential threats or vulnerabilities
Support vulnerability management, including performing scans, tracking remediation, and validating fixes
Maintain accurate, audit-ready documentation and coordinate evidence collection for SOC 2, PCI DSS, and other compliance frameworks
Support incident response processes, including triage, documentation, and post-incident follow-up
Assist with user access reviews, control testing, risk assessments, and security awareness efforts
Collaborate with IT, Engineering, and Compliance teams on secure configurations, remediation plans, and cross-functional security initiatives
Participate in routine policy, procedure, and control reviews to ensure alignment with regulatory requirements and security best practices
Maintain detailed logs and reports of security activities, metrics, and compliance obligations
Identify opportunities to strengthen controls, streamline processes, and enhance overall security program maturity
Required to perform other duties as requested, directed, or assigned
Requirements and Qualifications
Bachelor's degree in information systems, IT, Cybersecurity, or a related field
2-3 years of experience in security compliance, auditing, or governance (SOC 2 experience preferred)
Strong integrity, attention to detail, and accountability in handling sensitive or regulated information
Proactive problem-solving skills with the ability to anticipate and address risks effectively
Strong collaboration and communication skills with experience working across technical and compliance teams
Ability to remain composed and effective under pressure, including during audits and security incident
Perks
Health, dental, and vision plans
Amazing work-life balance with 4 weeks of Paid Time Off
10 Paid Company Holidays with 2 floating holidays
401K Programs with employer match
Personal assistance programs for support in a healthy personal and work life
Why Veracity?
Here at Veracity, you'll be part of a team of trailblazers and visionaries. We're not just revolutionizing the way people “do” insurance; we are creating a whole new paradigm. Here, you will experience a vibrant and inclusive workplace where your ideas matter! With us, you have a chance to:
Engage in groundbreaking projects that are reshaping the insurance landscape
Collaborate with a group of dedicated, like-minded professionals
Experience a culture that prioritizes growth and development
Compensation Range: $75k/yr - $85k/yr
We are proud to be an equal-opportunity employer. We are committed to providing equal opportunities to all qualified applicants, regardless of race, color, religion, sex, national origin, disability, or any other legally protected characteristics.
If you need accommodation, please let us know during the interview process.
Powered by JazzHR
tg FX77drAm
Sr. Security Analyst
Information security analyst job in South Jordan, UT
Job Description
Lightspeed is a leading provider of cloud-based software for dealerships and Original Equipment Manufacturers (OEMs), serving the Powersport, Marine, RV, Trailer, Outdoor Power Equipment, and Golf Cart industries. Lightspeed's Dealer Management Solution (DMS) enables dealerships to optimize their end-to-end business operations, including sales, parts, service, rentals, accounting, and Customer Relationship Management (CRM). When implemented into their daily operations, Lightspeed helps dealers increase their profitability by selling more units, service, and parts, all while creating a more streamlined experience for customers. For nearly 40 years, Lightspeed has been empowering 4,500+ dealers across North America with the tools and technology they need to manage their dealerships.
The Senior Security Analyst is responsible for team lead activities, such as monitoring, analyzing, and responding to security incidents across enterprise systems, cloud environments, and networks. This role ensures the confidentiality, integrity, and availability of organizational information through proactive detection, incident response, and continuous improvement. The ideal candidate will have a strong technical background in leading threat analysis, SIEM integration and management, vulnerability management, and incident handling.
What you'll do:
Monitor and investigate security alerts and events across SIEM, EDR, and network systems.
Conduct root cause analysis and coordinate remediation of security incidents.
Lead vulnerability assessments and ensure timely patching and mitigation.
Develop and maintain incident response playbooks and escalation procedures.
Collaborate with IT, DevOps, and Development teams to strengthen overall security posture.
Lead proactive threat hunting and continuous tuning of detection mechanisms.
Support internal and external audits (e.g., SOC 2) and risk assessments by providing evidence and guidance.
Perform firewall management, including rule changes, troubleshooting, and SOP development for hybrid cloud/on-prem environments.
Lead to red/blue team exercises and implement findings to improve defenses.
Coordinate and assist with enterprise pen-tests, risk assessments, and compliance initiatives.
Serve as a lead security advisor to business and technical teams, providing guidance on secure design, risk mitigation, and compliance using industry frameworks and best practices.
What you should have:
Qualifications:
Bachelor's degree in Cybersecurity, Information Technology, or a related field, or equivalent experience.
8+ years of experience in information security, incident response, or SOC operations.
Proven hands-on experience with SIEM tools (Splunk, Sentinel, QRadar, etc.) and EDR/XDR platforms (CrowdStrike, Darktrace, Microsoft Defender).
Strong experience securing and monitoring cloud environments (AWS, Azure).
Deep knowledge of security frameworks (NIST CSF, ISO 27001, SOC 2).
Advanced scripting and automation proficiency (Python, PowerShell, Terraform).
Excellent analytical, problem-solving, and communication skills.
Preferred Qualifications:
Relevant certifications such as AWS Security, CISSP, GCIH, GCIA, GPEN, GWAPT preferred.
Experience integrating AI and automation into security operations workflows.
Hands-on experience performing dynamic application security testing and red team exercises across endpoint and cloud environments.
Expert-level networking and firewall expertise with platforms such as Palo Alto, Cisco, or Checkpoint.
Master's degree in Cybersecurity, Information Technology, or a related field.
Inclusion and Diversity at Lightspeed:
At Lightspeed, we celebrate the uniqueness of every individual and encourage diverse perspectives. We believe that inclusion drives innovation and fosters meaningful connections. We are committed to building an environment where everyone feels valued and empowered to make an impact.
Equal Employment Opportunity Statement:
Lightspeed is an Equal Opportunity Employer and is dedicated to building a diverse and inclusive workforce. All qualified applicants will be considered for employment without regard to race, color, creed, ancestry, national origin, gender, sexual orientation, gender identity, gender expression, marital status, religion, age, disability, veteran status, or any other protected category.
Important Note:
Applicants must be authorized to work in the U.S.
Ready to apply?
Take the next step in your career-apply today and join a team where your skills will make an impact!
Data Security Analyst - C78843 7.5 Salt Lake City, Utah
Information security analyst job in Salt Lake City, UT
We are looking for a Data Security Analyst for our long-term multiyear project out of Salt Lake City, Utah. Build software libraries and services to provide secure-by-default services to software engineering teams, including authentication systems, secure service architectures, endpoint control solutions, and cloud controls
· Partner with colleagues from across engineering and risk to ensure an outstanding developer experience that satisfies the firm's security needs
· Collaborate on feature design and problem solving
· Help to provide frictionless integration with the firm's runtime, deployment and SDLC technologies
· Manage the full lifecycle of software components, from requirements through design, testing, development, release and demise
· Help to communicate and promote best practices for security engineering across the firm
· Engage in production troubleshooting
Basic Qualifications
· A strong grounding in security concepts, including secure coding practices, trusted computing and principles of authentication and authorization
· A good understanding of public key and symmetric key cryptography
· The ability to reason about performance, security, and process interactions in complex distributed systems
· Proficiency in designing, developing and testing cross-platform software in one or more of Java, Golang or C#; open to using multiple languages
· Experience developing, deploying and supporting software across the full Continuous Delivery life-cycle
· The ability to understand and effectively debug both new and existing software
· Experience meeting demands for high availability, low latency and scale
· The ability to communicate technical concepts effectively, both in writing and orally, as well as the interpersonal skills required to collaborate effectively with colleagues across diverse engineering teams
Preferred Qualifications
· An understanding of regulated environments, e.g. financial services
· Experience building services using public cloud providers such as AWS, Azure or GCP
· Experience with threat modeling and risk assessment
· Experience of practical security engineering in a Linux and/or Windows environment
· Familiarity with service mesh concepts and service-oriented architectures
· Familiarity with data protection principles and solutions
· Experience with deploying software to containerized environments - Kubernetes/Docker
· Experience monitoring, measuring, auditing and supporting software
· Scripting skills using Python, PowerShell or bash
· Experience with Terraform or similar infrastructure-as-code platforms, as a user and/or as a service provider
Sr. Cyber Security Engineer
Information security analyst job in Ogden, UT
* Telework Type: Full-Time Office/Project Extraordinary teams building inspiring projects: Since 1898, we have helped customers complete more than 25,000 projects in 160 countries on all seven continents that have created jobs, grown economies, improved the resiliency of the world's infrastructure, increased access to energy, resources, and vital services, and made the world a safer, cleaner place.
Differentiated by the quality of our people and our relentless drive to deliver the most successful outcomes, we align our capabilities to our customers' objectives to create a lasting positive impact. We serve the Infrastructure; Nuclear, Security & Environmental; Energy; Mining & Metals, and the Manufacturing and Technology markets. Our services span from initial planning and investment, through start-up and operations.
Core to Bechtel is our Vision, Values and Commitments. They are what we believe, what customers can expect, and how we deliver. Learn more about our extraordinary teams building inspiring projects in our Impact Report.
Project Overview:
Bechtel is the Engineering, Procurement, and Construction (EPC) partner on the Northrop Grumman team to deliver the Sentinel Program, which is modernizing the ground-based leg of the U.S. nuclear deterrent triad, including intercontinental ballistic missile (ICBM) systems and launch infrastructure. Bechtel's scope of service in Sentinel's current Engineering & Manufacturing Development phase focuses on the ground infrastructure component of the program.
A major contractor for the United States and allied governments, Bechtel has handled such efforts as chemical weapons demilitarization projects, missile-defense, infrastructure, base operations, procurement and project management, and restoration and recovery spanning half a century. We use our expertise to help our customers securely and effectively transform mission delivery.
For more information on the Sentinel program: ******************************************
Job Summary:
In this role, you will participate in conducting field investigations and planning specifications for operational technology (OT) cyber design for large projects. You will contribute in the design, development, and implementation of control system components, and security controls and enhancements. Your expertise will help ensure a highly available and secure environment that meets standards and government cyber security mandates.
This position is for a Senior Operational Technology (OT) Cyber Engineer to coordinate the development and delivery of engineering products which meet cybersecurity requirements and controls. The Senior OT Cyber Engineer will serve as a working-level interface with the Partner's Cybersecurity Program, Project Cybersecurity Subject Matter Experts (SMEs), and Engineering in the design engineering process; coordinating activities and deliverables with multiple functions and disciplines as well as with internal and external stakeholders as required. The individual is required to have a good knowledge of Bechtel and industry's OT/ICS governance frameworks, practices, and policies. Additionally, the ideal candidate must have excellent communication skills (both oral and written), strong organizational and teamwork skills, proven problem-solving abilities, can-do attitude, and the desire to innovate designs.#LI-TN1
Major Responsibilities:
* Responsible for executing OT Cyber engineering work assignments concerned with specialized unique engineering requirements in a DoD NIST SP 800-37/800-53/800-82 framework.
* Exploration of subject area, definition of scope, and may involve development of novel concepts, approaches, and solutions.
* Interfacing, collaborating, and coordinating with other engineering disciplines, client, stakeholders, and suppliers in the design and verification of the system and facility OT cybersecurity requirements.
* Developing key systems engineering documents with a broad knowledge of industry and regulatory standards, and design criteria pertinent to engineering and construction.
* Developing key design engineering documents, such as proposals, conceptual studies, designs, and reports; in the design and modification of OT and controls systems components; utilizing relevant Engineering Department Procedures (EDPs), design standards and guides, and Bechtel Standard Application Programs (BSAPs).
* Evaluates, selects, and applies standard OT Cyber engineering methods, techniques, procedures, and criteria, using independent judgment in making adaptations and modifications.
* Interpretation of cybersecurity requirements and implementation, evaluation, and verification of the requirements in engineered systems.
* Supports the implementation of necessary security controls and enhancements on the control systems, as well as reviewing and evaluating cybersecurity implementation as part of a NIST RMF compliance program.
* Coordinates OT Cyber engineering efforts in assigned areas with specialty groups, engineering disciplines, the client, vendor, contractors, construction and other functional groups.
* Provides technical assistance to other OT Cyber personnel and interacts with project functions, the customer, and regulatory agency personnel in the resolution of complex regulatory issues and industry codes and standards.
* Provides assistance to project and construction management in identifying and complying with project OT Cyber requirements and in addressing issues as they arise during project execution.
* Works closely with other cybersecurity professionals to achieve a common goal.
* Ensures a highly available and secure environment that meets the government mandated cyber security requirements in accordance with appropriate standards.
Education and Experience Requirements:
BS from a US accredited institution in Cybersecurity, Operational Technology, Information Technology, Computer Science, Mechanical, Electrical, Chemical, Control Systems or related discipline, with at least 8-10 years of relevant experience.
Required Knowledge and Skills:
Basic Qualifications:
* US citizenship is required per contract requirement.
* Possess or ability to obtain and maintain an active Secret/TS security clearance. Meets Department of Defense Directive (DoDD) 8570 IA Technical/Management Level 2 Requirements, such as Security+ CE, CISSP, CGRC/CAP, CCNA (or ability to obtain within 6 months)·
* Must be able to complete and pass a pre-employment drug screen and background check which includes verification of employment and education.
Minimum Qualifications:
* Proficiency in one or more cybersecurity program standards. (i.e., NIST SP 800-37, SP 800-53, SP 800-82; CNSSI 1253; ISA/IEC 62443; NRC RG 5.71, NEI 08-09)
* Knowledge of industry and regulatory guides, codes, and standards.
* Experience with cybersecurity / security controls requirements and design specification, risk-based assessment, and implementation.
* Experience with industry standard cybersecurity solutions, configurations, and practices, to include operating systems, directory services, policy, logging/telemetry, networking/telecommunications, and vulnerability management.
* Experience working with various vendors control system software (e.g., Schneider, ABB, Emerson, Honeywell, Siemens, Allen Bradley)
* Experience supporting OT/ICS design engineering, startup, and operations.
* Experience with OT/ICS systems communication protocols, architecture concepts, configurations, and standards.
* Experience with Systems Engineering concepts and practices.
* Necessary skills to present technical subjects with competence and confidence.
* Excellent oral and written communication, planning, and organizational skills.
* Ability to articulate ideas and write clear and concise reports.
* Ability to execute work independently.
* Ability to collaborate and maintain solid working relationships with peers internal and external to the project and the NS&E organization.
* Communication and interpersonal skills that enables both independent and/or team approach to assigned technical work tasks.
Preferred Qualifications:
* Proficiency with cybersecurity concepts and principles, operating systems, TCP/IP networking & security, and virtual environments.
* Proficiency in preparing detailed OT cybersecurity specifications, data sheets, and requisitions for digital equipment derived from OT cybersecurity codes and standards.
* Experience reviewing and preparing Building Management System (BMS) or ICS/SCADA Cybersecurity engineering products such as plan, studies, vendor documentation, requirements, technical specifications, drawings, network design, and risk-based assessments.
* ISA/IEC 62443 Cybersecurity Expert, GISCP, CISSP, Security+ CE certification
* Professional Engineer License
Total Rewards/Benefits:
For decades, Bechtel has worked to inspire the next generation of employees and beyond! Because our teams face some of the world's toughest challenges, we offer robust benefits to ensure our people thrive. Whether it is advancing careers, delivering programs to enhance our culture, or providing time to recharge, Bechtel has the benefits to build a legacy of sustainable growth. Learn more at Bechtel Total Rewards
Diverse teams build the extraordinary:
As a global company, Bechtel has long been home to a vibrant multitude of nationalities, cultures, ethnicities, and life experiences. This diversity has made us a more trusted partner, more effective problem solvers and innovators, and a more attractive destination for leading talent.
We are committed to being a company where every colleague feels that they belong-where colleagues feel part of "One Team," respected and rewarded for what they bring, supported in pursuing their goals, invested in our values and purpose, and treated equitably. Click here to learn more about the people who power our legacy.
Bechtel is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity and expression, age, national origin, disability, citizenship status (except as authorized by law), protected veteran status, genetic information, and any other characteristic protected by federal, state or local law. Applicants with a disability, who require a reasonable accommodation for any part of the application or hiring process, may e-mail their request to ********************
Cloud Cyber Security Engineer
Information security analyst job in Ogden, UT
T-Rex Solutions is seeking a qualified Cyber Security Engineer to support of a secure DOD customer located in Ogden, UT. The overall program that this role supports aims to modernize legacy network infrastructure and migrate services into a new AWS Cloud Environment. For any candidates not already local to the Ogden, UT area, T-Rex is offering a relocation support package to assist with moving costs.
Responsibilities:
Implement and manage Secure Cloud Computing Architecture (SCCA) controls, including Virtual Data Center Security Stack (VDSS) and Boundary Cloud Access Point (BCAP).
Work with DoD teams to ensure cloud environments are compliant with DoD security frameworks, including NIST, STIGs, and FedRAMP+.
Manage and enforce Trusted Cloud Credential Management (TCCM) practices for secure identity access and cloud credential management.
Configure and maintain cloud security services for monitoring, alerting, and logging using tools like SolarWinds, ELK, and native CSP security features.
Support cloud onboarding and migration, ensuring security best practices are adhered to during the transition.
Collaborate with cross-functional teams to ensure Zero Trust principles are implemented effectively in the cloud environment.
Assist in preparing and maintaining documentation for ATO processes, including mapping inherited controls and contributing to eMASS submissions.
Provide guidance on cloud security best practices and mentor junior team members in cloud security management.
Requirements:
Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field (or equivalent experience).
CompTIA Security+
7+ years of experience in cloud security with hands-on experience in at least one CSP (OCI, Azure, or AWS).
Experience in implementing and managing security controls in cloud environments, including identity and access management (IAM), logging, and monitoring.
Experience with security incident management, vulnerability assessments, and cloud compliance processes.
Strong troubleshooting and problem-solving skills in cloud environments.
Solid understanding of DoD cloud security requirements, including NIST 800-53, STIGs, and FedRAMP+.
Proficiency with automation tools such as Terraform, Ansible, and PowerShell for managing cloud configuration.
Ability to obtain a DOD Secret clearance
Desired:
Secret Clearance or higher desired.
DoD-approved cloud security certifications (e.g., AWS Certified Security Specialty, Microsoft Certified: Azure Security Engineer) preferred.
T-Rex Overview
Established in 1999, T-Rex Solutions, LLC is a proven mid-tier business providing data-centric mission services to the Federal government as it increasingly tries to secure and leverage the power of data. We design, integrate, secure, and deploy advanced technical solutions for our customers so they can efficiently fulfill their critical objectives. T-Rex offers both IT and professional services to numerous Federal agencies and is a leader in providing high quality and innovative solutions in the areas of Cloud and Infrastructure Services, Cyber Security, and Big Data Engineering.
T-Rex is constantly seeking qualified people to join our growing team. We have built a broad client base through our devotion to delivering quality products and customer service, and to do that we need quality individuals. But more than that, we at T-Rex are committed to creating a culture that supports the development of every employee's personal and professional lives. T-Rex has made a commitment to maintain the status of an industry leader in compensation packages and benefits which includes competitive salaries, performance bonuses, training and educational reimbursement, Transamerica 401(k) and Cigna healthcare benefits.
T-Rex is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, sex (including pregnancy and sexual orientation), parental status, national origin, age, disability, family medical history or genetic information, political affiliation, military service, or other non-merit based factors.
In compliance with pay transparency guidelines, the annual base salary range for this position is $125,000 - $150,000. Please note that the salary information is a general guideline only. T-Rex considers factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience, education/training, key skills, internal peer equity, as well as market and business considerations when extending an offer.
T-Rex offers a diverse and collaborative work environment, exciting opportunities for professional growth, and generous benefits, including: PTO available to use immediately upon joining (prorated based on start date), paid parental leave, individual and family health, vision, and dental benefits, annual budget for training, professional development and tuition reimbursement, and a 401(k) plan with company match fully vested after 60 days of employment among other benefits.
Auto-ApplyInformation Security Analysts
Information security analyst job in Salt Lake City, UT
Information Security Analysts The incumbent will play a critical role in safeguarding regulated data across the enterprise by monitoring and analyzing the organization's data security posture. This position focuses on configuring Data Security Posture Management ( DSPM ) settings and policies, interpreting results, creating reports, identifying risks, and ensuring compliance. The analyst will take a risk-based approach to assess and remediate issues related to unauthorized storage or transmission of regulated data across cloud and on-premise environments. Learn more about the great benefits of working for University of Utah: benefits.utah.edu The department may choose to hire at any of the below job levels and associated pay rates based on their business need and budget.
Responsibilities
Data Security Monitoring -Review and analyze DSPM tool outputs to identify misconfigurations, unauthorized data flows, and storage of regulated data in non-approved locations. -Monitor the movement of sensitive data across cloud and on-prem systems, ensuring compliance with internal policies and regulatory requirements. Risk Assessment & Governance -Apply a risk-based methodology to prioritize remediation efforts. -Maintain applicable risk register entries and document findings for governance reporting. Collaboration -Partner with the Enterprise Security team to validate technical controls. -Work closely with the Chief Data Officer and Privacy Office to align DSPM findings with data governance and privacy requirements. Compliance & Policy Alignment -Ensure adherence to frameworks such as NIST CSF , CIS 18, and other applicable regulations (e.g., HIPAA , FERPA , etc. etc.). -Support audits and compliance reviews by providing DSPM -related evidence. Reporting & Communication -Prepare dashboards and reports for leadership summarizing DSPM findings, trends, and risk posture. -Communicate actionable insights to stakeholders in clear, business-focused language.
Minimum Qualifications
EQUIVALENCY STATEMENT : 1 year of higher education can be substituted for 1 year of directly related work experience (Example: bachelor's degree = 4 years of directly related work experience). Department may hire employee at one of the following job levels: Information Security Analyst, III : Requires a bachelor's (or equivalency) + 6 years or a master's (or equivalency) + 4 years of directly related work experience. Information Security Analyst, IV: Requires a bachelor's (or equivalency) + 8 years or a master's (or equivalency) + 6 years of directly related work experience. Information Security Analyst, V: Requires a bachelor's (or equivalency) + 10 years or a master's (or equivalency) + 8 years of directly related work experience.
Network Security Analyst
Information security analyst job in Lehi, UT
Mindlance is a national recruiting company which partners with many of the leading employers in the Life Sciences, IT, and Financial Services sectors, feel free to check us out at ************************* Job Description Job Title: Network Security Analyst
Duration: 6 Months
Location: Lehi, UT
Required:
• Minimum 3+ years exp.
• Experience with implementing policy on firewalls (Juniper & Palo alto experience preferred)
• Review requests for new firewall policy
• Understanding of IP stack
• Ability to prioritize work and meet defined SLAs
• Good communication skills - both verbal and written
Additional Information
Thanks & Regards,
______________________________________________________________________________________________________
Vikram Bhalla | Team-Recruitment | Mindlance, Inc. | Office: **************
Google Cloud Security Architect
Information security analyst job in Salt Lake City, UT
Who You'll Work With As a modern technology company, our Slalom Technologists are disrupting the market and bringing to life the art of the possible for our clients. We have passion for building strategies, solutions, and creative products to help our clients solve their most complex and interesting business problems. We surround our technologists with interesting challenges, innovative minds, and emerging technologies.
Join the Slalom Cloud Team -a team of trailblazers ensuring we achieve our strategic goals through innovation and investment in the future. You'll collaborate with local market teams, niche experts, and global partners to drive cloud solution sales and empower clients on their cloud transformation journey. As a key member of Slalom's Google Cloud Center of Excellence, you'll leverage our award-winning partnerships and multidisciplinary teams to deliver business value and technical excellence for high-impact security and infrastructure solutions.
What You'll Do
* Stay current with security trends, technologies, and best practices around Google Cloud solutions, leveraging tools like Cloud IAM, Cloud Security Command Center, BeyondCorp, and Cloud Armor.
* Define and guide transformational security strategies for Google Cloud environments, ensuring alignment with Google's Zero Trust and BeyondCorp principles.
* Translate complex regulatory requirements (e.g., GDPR, SOC 2, HIPAA) and technology standards into actionable functional and technical requirements for cloud and hybrid environments, ensuring security and compliance.
* Lead teams through various phases of gap analyses, including security assessments, remediation planning, roadmap development, and implementation of remediation actions using Google Cloud-native tools.
* Deliver on the vision, architecture, execution, and quality assurance of security projects on Google Cloud, driving initiatives that secure enterprise workloads and data.
* Guide stakeholders and senior leaders on aligning security solutions with broader business goals, ensuring the architecture follows Google Cloud's security best practices and roadmap.
* Establish security architecture patterns based on Google Cloud security frameworks and industry standards to meet the unique needs of enterprise clients.
* Collaborate with other Google Cloud architects and security teams to continuously improve security knowledge assets and best practices, ensuring the most effective security solutions for clients.
* Design and architect solutions to secure Generative AI models and applications against adversarial attacks, prompt injection, and their potential misuse for malicious cyber activities.
What You'll Bring
* Proven experience with Google Cloud security architecture, with hands-on experience in tools like Cloud IAM, VPC Service Controls, Cloud DLP, and Cloud Armor.
* Strong background in defining and implementing Zero Trust and BeyondCorp security models within Google Cloud environments.
* Familiarity or direct experience with Identity and Access Management (IAM), Data Protection, Vulnerability Management, and Cloud Security solutions in Google Cloud.
* Extensive experience with security design patterns specific to Google Cloud, as well as hybrid and multi-cloud security architecture.
* Experience in security and risk advisory consulting, particularly related to cloud security transformations.
* Ability to lead the development and implementation of cloud security roadmaps aligned with business goals and compliance needs.
* Familiarity with Google Cloud's Artificial Intelligence (AI) capabilities (e.g., Vertex AI, Generative AI services, Model Armor) including their applications, associated security risks (e.g., prompt injection, data poisoning, privacy concerns), and proven strategies for implementing security controls, governance, and responsible AI practices.
* Relevant certifications are strongly desired but not required, including (but not limited to):
* GCP Professional Security Engineer
* GCP Professional Cloud Architect
* CISSP
* Security+
About Us
Slalom is a fiercely human business and technology consulting company that leads with outcomes to bring more value, in all ways, always. From strategy through delivery, our agile teams across 52 offices in 12 countries collaborate with clients to bring powerful customer experiences, innovative ways of working, and new products and services to life. We are trusted by leaders across the Global 1000, many successful enterprise and mid-market companies, and 500+ public sector organizations to improve operations, drive growth, and create value. At Slalom, we believe that together, we can move faster, dream bigger, and build better tomorrows for all.
Compensation and Benefits
Slalom prides itself on helping team members thrive in their work and life. As a result, Slalom is proud to invest in benefits that include meaningful time off and paid holidays, parental leave, 401(k) with a match, a range of choices for highly subsidized health, dental, & vision coverage, adoption and fertility assistance, and short/long-term disability. We also offer yearly $350 reimbursement account for any well-being-related expenses, as well as discounted home, auto, and pet insurance.
Slalom is committed to fair and equitable compensation practices.
Slalom is committed to fair and equitable compensation practices. For this role, we are targeting the following levels and salary ranges:
East Bay, San Francisco, Silicon Valley:
* Senior Consultant: $131,000-$196,500
San Diego, Los Angeles, Orange County, Seattle, Houston, New Jersey, New York City, Westchester, Boston, Washington DC:
* Senior Consultant: $120,000-$180,000
All other locations:
* Senior Consultant: $110,000-$165,000
In addition, individuals may be eligible for an annual discretionary bonus. Actual compensation will depend upon an individual's skills, experience, qualifications, location, and other relevant factors. The salary pay range is subject to change and may be modified at any time.
EEO and Accommodations
Slalom is an equal opportunity employer and is committed to inclusion, diversity, and equity in the workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veterans' status, or any other characteristic protected by federal, state, or local laws. Slalom will also consider qualified applications with criminal histories, consistent with legal requirements. Slalom welcomes and encourages applications from individuals with disabilities. Reasonable accommodations are available for candidates during all aspects of the selection process. Please advise the talent acquisition team if you require accommodations during the interview process.
Information Assurance (IA) System Security Engineer (ISSE) I
Information security analyst job in Ogden, UT
Type of Requisition:
Regular
Clearance Level Must Currently Possess:
Top Secret/SCI
Clearance Level Must Be Able to Obtain:
Top Secret SCI + Polygraph
Public Trust/Other Required:
None
Job Family:
Cyber and IT Risk Management
Job Qualifications:
Skills:
Computer Security, Information Assurance, Information System Security
Certifications:
None
Experience:
10 + years of related experience
US Citizenship Required:
Yes
Job Description:
The Information System Security Engineer (ISSE) is primarily responsible for conducting information system security engineering activities with a focus on lifecycle of current systems and future requirement scoping. The position will collect and process the captured information security requirements and ensures that the requirements are effectively integrated into information systems through purposeful security architecting, design, development, and configuration. The position is an integral part of the development team designing and developing organizational information systems or upgrading legacy systems. The ISSE employs best practices when implementing security requirements within an information system including software engineering methodologies, system/security engineering principles, secure design, secure architecture, and secure coding techniques. This position's main function is working within Special Access Programs (SAPs) supporting Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense (OSD) and Military Compartments efforts. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities.
Performance shall include:
Perform oversight of the development, implementation and evaluation of information system security program policy; special emphasis placed upon integration of existing SAP network infrastructures
Perform analysis of network security, based upon the Risk Management Framework (RMF) with emphasize on Joint Special Access Program Implementation Guide (JSIG) authorization process
Provides expert support, research and analysis of exceptionally complex problems, and processes relating to them
Serves as technical expert to the Cybersecurity Assessment Program providing technical direction, interpretation and alternatives to complex problems
Thinks independently and demonstrates exceptional written and oral communications skills. Applies advanced technical principles, theories, and concepts
Contributes to the development of new principles, concepts, and methodologies.
Works on unusually complex technical problems and provides highly innovative and ingenious solutions
Recommends cybersecurity software tools and assists in the development of software tool requirements and selection criteria to include the development of product specific STIGs from applicable DISA SRGs
Leads technical teams in implementation of predetermined long- range goals and objectives
Support customer and SAP community IA working groups, participate in SSE IPT reviews
Provides expert level consultation and technical services on all aspects of Information Security
Review ISSE related designs and provides security compliance recommendations
Develop and provide IA risk management recommendations to the customer
Assist with development and maintenance of the Program Protection Plan
Assist with site activation activities and design reviews
Interface and support the System Engineer (SE) on system security design, interoperability, and basic engineering endeavors implementing cybersecurity policy, system security engineering processes, and basic system engineering (SE) processes
Represent the customer in various ISSE related working groups, advisory groups, and advisory council meetings
Assist team to design, integrate, and implement JSIG/RMF Continuous Monitoring tools and processes
Perform security assessments of servers/network devices/security appliances
Develop improvements to security assessments with regard to accuracy and efficiency
Integrate ancillary monitoring tools/capabilities with the enterprise security information and event management (SIEM) and create/tailor complex event alarms/rules and summary reports
Write and execute cybersecurity test procedures for validation of control compliance
Monitor/analyze output of cybersecurity related tools for reportable security incidents and residual risk
Analyze technical risk of emerging cybersecurity tools and processes
Work as part of a security incident response team as needed
Build operational Operations and Maintenance (O&M) checklists to maintain the service (daily, weekly, monthly, yearly O&M checklists); build Tactics, Techniques and Processes (TTPs) and Standard Operating Processes (SOPs) associated with service checklists
Integrate/Develop new techniques to improve Confidentiality, Integrity, and Availability for networks/systems operating at various classification levels
Advanced technical competency in one or more of the following supported platforms: Microsoft Windows Server, Active Directory, Red Hat Enterprise Linux servers, MS Hyper- V/VMWare/ESx/Xen Hypervisors, Enterprise networking/firewalls/intrusion detection/prevention systems, forensic analysis/vulnerability assessment, Group Policy management and configuration, Scripting, BMC Footprints, WSUS, Lumension, Bitlocker, SQL Server 2012, TomCat, IIS, Windows Server 2012r2/2016, Win 10, Red Hat 6.5, Microsoft Office
Maintain relationship with System Engineer (SE). SSE is responsible for system security design, interoperability and basic engineering endeavors with a firm grasp of cybersecurity policy, system security engineering processes and system engineering processes
Experience:
10+ years related experience
SAP experience desired
Education:
Bachelor's degree in related discipline OR Associate's degree in a related area + 2 years' experience OR equivalent experience (4 years)
Certifications:
IAM Level III or IAAE I - within 6 months of hire
Clearance Required to Start:
TS/SCI required
Must be able to Attain - TS/SCI with CI Polygraph
#AirforceSAPOpportunities
The likely salary range for this position is $141,355 - $191,245. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
Scheduled Weekly Hours:
40
Travel Required:
10-25%
Telecommuting Options:
Onsite
Work Location:
USA UT Ogden
Additional Work Locations:
Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.Join our Talent Community to stay up to date on our career opportunities and events at
gdit.com/tc.
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
Auto-ApplyInformation Systems Security Officer
Information security analyst job in Clearfield, UT
**MANTECH** seeks a motivated, career and customer-oriented **Information Systems Security Officer (ISSO)** to join our Air Force / Space team at **Hill AFB** . The ISSO's primary function is to support the United States Air Force's 53rd Wing Technical Support Services (53rd WTSS) contract.
**Responsibilities include, but are not limited to:**
+ Perform ISSO duties in support of in-house and external customers
+ Notify ISSM when changes occur that might affect the authorization determination of the information system(s)
+ Conduct periodic reviews of information systems to ensure compliance with the security authorization package
+ Coordinate any changes or modifications to hardware, software, or firmware of a system with the ISSM and AO/DAO prior to the change
+ Ensure all IS security-related documentation is current and accessible to properly authorized individuals
+ Execute the cyber security portion of the self-inspection, to include provide security coordination and review of all system assessment plans
+ Identify cyber security vulnerabilities and assist with the implementation of the countermeasures for them
+ Conduct security impact analysis activities and provide to the ISSM on all configuration management changes to the authorization boundaries
**Minimum Qualifications:**
+ Bachelor's degree in related discipline from an accredited college or university. 2 additional years of experience may be substituted for a degree.
+ 4+ years direct/related experience
+ Active / valid DoD 8570.01-M IAT-II certification
+ Experience with DoD/USAF information security policy background with practical / hands-on experience applying RMF processes and principles.
+ Experience developing and/or contributing to an RMF body of evidence composition, applicable artifacts, and associated control families.
**Clearance Requirements:**
+ Active Top Secret Clearance
+ Must be able to obtain and maintain a DoD TS/SCI-eligible clearance (i.e. DCID 6/4 eligibility)
+ Eligibility for access to Special Access Program Information
+ Willingness to submit to a Polygraph.
**Physical Requirements:**
+ Must be able to remain in a stationary position 50%
+ Needs to occasionally move about inside the office to access file cabinets, office machinery, etc.
+ Constantly operates a computer and other office productivity machinery, such as a calculator, copy machine and computer printer.
+ Frequently communicates with co-workers, management and customers, which may involve delivering presentations. Must be able to exchange accurate information in these situations
MANTECH International Corporation considers all qualified applicants for employment without regard to disability or veteran status or any other status protected under any federal, state, or local law or regulation.
If you need a reasonable accommodation to apply for a position with MANTECH, please email us at ******************* and provide your name and contact information.
Senior Security Engineer
Information security analyst job in Lehi, UT
Our Company Changing the world through digital experiences is what Adobe's all about. We give everyone-from emerging artists to global brands-everything they need to design and deliver exceptional digital experiences! We're passionate about empowering people to create beautiful and powerful images, videos, and apps, and transform how companies interact with customers across every screen.
We're on a mission to hire the very best and are committed to creating exceptional employee experiences where everyone is respected and has access to equal opportunity. We realize that new ideas can come from everywhere in the organization, and we know the next big idea could be yours!
Position summary:
The Senior Security Engineer position will be part of the Enterprise Security organization consisting of IAM professionals across several technologies. This specific position will have a specialized role in directory services and SaaS applications! It will focus on large implementations of Entra ID with integrations with other directories, IDPs, applications, and automated workflows. We give technical direction, administer tools, and provide support for various security technologies. We participate in driving Enterprise Security projects that use our cloud directory services for various internal and external Adobe services. We work with other specialists, architects, security teams, and software engineer teams across Adobe and collectively provide services, guidance, and strategies that protect services and data as well as adhere to various global government regulations. You will work with business customers, management teams, infrastructure teams, development teams, project managers, and other security teams to help implement the vision, structure, standards, and plan solutions that support the future architecture.
At Adobe, you will be immersed in an exceptional work environment that is recognized throughout the world on Best Companies lists! You will also be surrounded by colleagues who are committed to helping each other grow through our Check-In approach where ongoing feedback flows freely.
If you're looking to make an impact, Adobe is the place for you. Discover what our employees are saying about their career experiences on the Adobe Life blog and explore the meaningful benefits we offer.
Adobe is an equal opportunity employer. We welcome and encourage diversity in the workplace regardless of race, gender, religion, age, sexual orientation, gender identity, disability or veteran status.
Primary Responsibilities May Include, but Are Not Limited To:
* Managing deep and complex directory architectures and services span directories, IDPs, and federated environments.
* Providing guidance and architecting solutions for directory service strategies across a variety of internal customers at Adobe.
* We help test, implement, and support secure services used by end-users, devices, and application workflows to all of Adobe.
* We engineer secure identity solutions for on-premises and cloud environments.
* We are a team of Security Engineers that handle incoming requests, respond to issues, solve reported problems, and develop solutions.
* We meet with teams to get business requirements, understand workflows, and devise solutions.
* We help assess SaaS implementations for identity integrations and general security.
* We generate useful metrics to help make decisions, identify issues, and manage our sevices.
Requirements:
* Possess a Bachelor's or advanced degree in MIS, Computer Science, Cybersecurity, or Engineering OR 10+ years in IT or Cybersecurity
* Comfortable working on and leading different projects with many teams at one time
* In-depth understanding of Windows, Mac and UNIX/Linux based systems, permissions, and interoperability.
* Strong knowledge of machine to machine and application to machine connections using MFA, certificates, tokens, and other methods.
* Strong understanding of the identity lifecycle, secure by design, least privileged and zero trust.
* An in-depth knowledge and understanding of managing and securing cloud directories (e.g. Entra ID/AWS/Okta) and integrating with traditional directories (e.g. Active Directory/389DS/ LDAP based directories).
* Proficient in written and verbal communications, skilled at working alongside differing viewpoints to accomplish shared objectives.
* Able to work independently and as a team member.
* Capable of conveying technical concepts to diverse audiences including non-technical users, architects, and senior leadership.
* Professional written, verbal, and presentation communication skills to engage with senior leadership.
* A deep understanding of Cloud Directories, especially Entra ID, and how to secure it, use conditional access policies, and apply/create automation.
* Ability to teach and mentor others while fostering a collaborative environment.
* Can model leadership behavior and help to grow other's leadership behavior.
Preferred:
* Understanding of Desktop operating systems including Windows, Linux, and Mac
* Experience or knowledge of Public Key Infrastructure
* Strong abilities in programming/scripting languages for automating repeatable tasks like Python, PowerShell, etc.
* Experience and/or Knowledge of dashboarding and log correlation engines such as Grafana, Telegraph, Splunk, etc.
* Experience with SaaS Security Posture Management technologies.
* Experience with developing PowerBI dashboards.
The Person Should:
* Have strong social skills, ability to "win people over" and be a great teammate.
* Be able to communicate, influence and mentor across business and executive leadership as well as partners while being able to explain the benefits for their teams.
* Be neutral toward technology, vendor and product choices; more interested in results than in personal preferences.
* Have the ability to think creatively and to solve complex tasks and problems with minimal direction.
Our compensation reflects the cost of labor across several U.S. geographic markets, and we pay differently based on those defined markets. The U.S. pay range for this position is $160,900 -- $297,400 annually. Pay within this range varies by work location and may also depend on job-related knowledge, skills, and experience. Your recruiter can share more about the specific salary range for the job location during the hiring process.
At Adobe, for sales roles starting salaries are expressed as total target compensation (TTC = base + commission), and short-term incentives are in the form of sales commission plans. Non-sales roles starting salaries are expressed as base salary and short-term incentives are in the form of the Annual Incentive Plan (AIP).
In addition, certain roles may be eligible for long-term incentives in the form of a new hire equity award.
State-Specific Notices:
California:
Fair Chance Ordinances
Adobe will consider qualified applicants with arrest or conviction records for employment in accordance with state and local laws and "fair chance" ordinances.
Colorado:
Application Window Notice
Nov 10 2025 12:00 AM
If this role is open to hiring in Colorado (as listed on the job posting), the application window will remain open until at least the date and time stated above in Pacific Time, in compliance with Colorado pay transparency regulations. If this role does not have Colorado listed as a hiring location, no specific application window applies, and the posting may close at any time based on hiring needs.
Massachusetts:
Massachusetts Legal Notice
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Adobe is proud to be an Equal Employment Opportunity employer. We do not discriminate based on gender, race or color, ethnicity or national origin, age, disability, religion, sexual orientation, gender identity or expression, veteran status, or any other applicable characteristics protected by law. Learn more.
Adobe aims to make Adobe.com accessible to any and all users. If you have a disability or special need that requires accommodation to navigate our website or complete the application process, email accommodations@adobe.com or call **************.
Engineer, Information Security and Risk
Information security analyst job in Boise, ID
Cardinal Health, Inc. (NYSE: CAH) is a global healthcare services and products company. We provide customized solutions for hospitals, healthcare systems, pharmacies, ambulatory surgery centers, clinical laboratories, physician offices and patients in the home. We are a distributor of pharmaceuticals and specialty products; a global manufacturer and distributor of medical and laboratory products; an operator of nuclear pharmacies and manufacturing facilities; and a provider of performance and data solutions. Working to be healthcare's most trusted partner, our customer-centric focus drives continuous improvement and leads to innovative solutions that improve the lives of people every day. With approximately 50,000 employees worldwide, Cardinal Health ranks among the top fifteen in the Fortune 500.
**_Department Overview:_**
**Information Technology** oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value.
**Information Security and Risk** develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure, or destruction. This job family develops system back-up and disaster recovery plans, conducts incident responses, threat management, vulnerability scanning, virus management and intrusion detection as well as completes risk assessments.
Lead IAM work for new customer onboardings and migrations. Collaborate with CAH Account Management, Application Teams, and Customers to design, implement, and test federated SSO solution based on customer login requirements. Provide technical guidance and act as primary point of contact for business partners and customer related to IAM work for onboarding. Additional responsibilities include supporting application integrations and enhancing SSO self service application onboarding.
**Responsibilities:**
+ **Customer Onboarding IAM Efforts - Strategy & Execution :** Lead the planning, design, and execution for Customer Onboarding via federated SSO, ensuring alignment with overall business and security objectives. This includes assessing multiple Cardinal Health e-commerce applications, understanding login requirements for new/existing customers, designing, testing and implementing solutions etc to ensure top notch user login experience and enhancing Cardinal Health's security posture.
+ **Collaboration & Communication:** Coordinate cross-functional teams, including Customer Business and IT teams, Cardinal Health's Account Management/Sales and Application teams, Information Security and others to ensure effective IAM implementation and seamless integration with business processes. Communicate complex security concepts to technical and non-technical internal and external stakeholders.
+ **Application Integration Leadership:** Lead the integration of various enterprise applications (SaaS, on-premise, custom-built) with our core IAM infrastructure, ensuring secure authentication, authorization, and user provisioning/de-provisioning.
+ **User Lifecycle Management:** Streamline and automate user provisioning, de-provisioning, and periodic access reviews for employees, contractors, and partners across all integrated systems, ensuring smooth onboarding and offboarding during M&A transitions.
+ **Solution Design & Implementation:** Design, implement, and maintain IAM solutions including Single Sign-On (SSO), Multi-Factor Authentication (MFA), and Role-Based Access Control (RBAC) frameworks.
+ **Technical Troubleshooting & Support:** Troubleshoot, identify, and resolve technical identity and access management-related issues, providing expert support to internal teams and end-users during and after integration.
+ **Documentation & Best Practices:** Develop, review, and maintain comprehensive technical documentation, including architecture diagrams, configuration guides, and operational procedures. Stay up-to-date with IAM best practices, regulatory requirements, and security trends.
**Qualifications:**
+ **Education:** Bachelor's degree in Computer Science, Information Technology, Information Security, or a related field, or equivalent practical experience.
+ **Experience:** 5+ years of progressive experience as an IAM Engineer, designing and implementing enterprise scale solutions with significant experience in supporting M&A integration projects preferred.
+ **Technical Expertise:**
+ Extensive knowledge and experience with authentication standards and technologies such as SSO (SAML, OAuth, OpenID Connect), MFA
+ Proficiency in directory services (e.g., Active Directory, Azure AD, LDAP).
+ Hands-on experience with leading IAM platforms (e.g., Okta, Microsoft Azure AD, CyberArk, ForgeRock, Ping Identity, SailPoint).
+ Strong understanding of security principles, risk management, and access control models (e.g., RBAC).
+ Familiarity with Zero Trust architecture principles.
+ Familiarity with AI/ML concepts and their practical application in security and risk management, especially in IAM context.
+ Strong communication and interpersonal skills to collaborate effectively with various teams and stakeholders.
+ Detail-oriented mindset to ensure precise access control configurations and compliance.
+ Excellent problem-solving and analytical abilities to troubleshoot access issues and design solutions for unique business requirements
+ Must be a self-starter who takes full ownership of projects from inception to completion , holding oneself accountable for the security and operation integrity of IAM platform.
+ Ability to manage multiple priorities and meet tight deadlines in a fast-paced M&A environment.
**Anticipated salary range:** $94,900 - $135,600
**Bonus eligible:** No
**Benefits:** Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
+ Medical, dental and vision coverage
+ Paid time off plan
+ Health savings account (HSA)
+ 401k savings plan
+ Access to wages before pay day with my FlexPay
+ Flexible spending accounts (FSAs)
+ Short- and long-term disability coverage
+ Work-Life resources
+ Paid parental leave
+ Healthy lifestyle programs
**Application window anticipated to close:** 12/20/2025 *if interested in opportunity, please submit application as soon as possible.
The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.
_Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply._
_Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal_ _Opportunity/Affirmative_ _Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law._
_To read and review this privacy notice click_ here (***************************************************************************************************************************
Senior Security Engineer
Information security analyst job in Lehi, UT
About GoodLeap:GoodLeap is a technology company delivering best-in-class financing and software products for sustainable solutions, from solar panels and batteries to energy-efficient HVAC, heat pumps, roofing, windows, and more. Over 1 million homeowners have benefited from our simple, fast, and frictionless technology that makes the adoption of these products more affordable, accessible, and easier to understand. Thousands of professionals deploying home efficiency and solar solutions rely on GoodLeap's proprietary, AI-powered applications and developer tools to drive more transparent customer communication, deeper business intelligence, and streamlined payment and operations. Our platform has led to more than $30 billion in financing for sustainable solutions since 2018. GoodLeap is also proud to support our award-winning nonprofit, GivePower, which is building and deploying life-saving water and clean electricity systems, changing the lives of more than 1.6 million people across Africa, Asia, and South America.
Position Summary The GoodLeap security team is responsible for both business enablement and safeguarding the organization's information assets; it is involved in virtually all aspects of the business, from product safety and resilience, to building security paved roads, customer, partner, and regulatory trust, managing technology governance and compliance, and ensuring the privacy, and safety of GoodLeap's customers, partners, and employees information.
The senior security engineer role provides a unique opportunity to shape the security and resilience of GoodLeap corporate systems, services, and operational processes. In this role, you will work closely with product, engineering, IT, and business teams within GoodLeap, acting as the key individual with both the authority and responsibility to ensure the safety and resilience of enterprise systems, products, and services.
Your oversight will encompass: - Enterprise systems:Identifying potential misuse and abuse cases, proposing solutions to address these scenarios, and identifying product features, configuration settings, and/or mitigating or compensating controls to meet resilience requirements. - Build-time controls: Managing applications/products security controls and activities during development. - Runtime controls: Overseeing security measures at runtime, from prevention to detection and response.
Additionally, you will be involved with aspects of internally built products and represent all areas of security, spanning governance, risk, and compliance (GRC) to security monitoring, for a number of departments/teams. You will also have the authority and ability to involve other security team members as needed.
While you will take on multiple responsibilities-from advisor to builder and beyond-your primary focus will be designing and building security patterns and practices for services and processes, and fostering strong relationships with product, business, and engineering. Essential Job Duties & Responsibilities
Lead, participate in, and contribute to partnerships between security, IT, General & Administrative teams, engineering, product, and operations teams to build, orchestrate, and automate security controls and services in GoodLeap enterprise systems, products, services, and operational processes.
Identify potential misuse and abuse cases in enterprise systems, propose solutions to address these scenarios, and identify product features, configuration settings, and/or mitigating or compensating controls to meet resilience requirements.
Support or develop components of the security analytics platform.
Contribute to investigations, threat hunting, and incident response activities in a supporting role.
Collaborate with the monitoring and response team to create playbooks for specific incident response scenarios related to the products and services you oversee. These investigations, incidents, and playbooks may address security, fraud, privacy, resilience, and related concerns.
Support the security operations team with the vulnerability management lifecycle for products and services under your purview.
Ensure technical alignment for the products and services you oversee with team initiatives, including GRC, security operations, and monitoring and response activities.
Required Skills, Knowledge & Abilities
Strong communicator with the ability to lead technical architecture discussions, drive technical decisions, and effectively communicate with non-technical audiences.
Expertise in agile product lifecycles. Ideally, you have experience in a product manager or engineering manager role and understand how SaaS products (B2B, B2B2C, and B2C) are built, including roadmap planning and feature and defect prioritization.
Experience with threat modeling methodologies, with the ability to create efficient and scalable approaches to conducting such assessments.
Familiarity with AWS services, including KMS, SST, Container Registry, ELBs, Lambda, API Gateway, CloudTrail, and IAM (knowledge of GCP and/or Azure is a plus).
Proven ability to establish credibility and build trust with business, engineers, and operational staff; confident yet humble.
Hands-on experience with managing security for core enterprise systems, e.g., ERP, HCM, Salesforce, etc.
Strong understanding of both human and non-human identity management and common enterprise and consumer authentication standards and use cases.
Practical experience with CI/CD pipelines and DevOps tools, including Infrastructure-as-Code (IaC) tools like Terraform, Pulumi, or CDK; GitHub and GitHub Actions; artifact management; and secrets management tools like Doppler and HashiCorp Vault.
Passionate about learning new technologies. While you're not expected to know everything, you should demonstrate a willingness and ability to learn as needed.
Prior experience interfacing and supporting with G&A teams, internal product teams, and other cross-functional areas.
Proficiency in writing automation scripts in multiple languages, with prior experience automating security processes in cloud or SaaS environments.
Experience engaging with vendors in design partnerships.
Experience overseeing vulnerability and threat management at the platform and application levels.
Familiarity with penetration testing and red team exercises, including manual verification, exploitation, and lateral movement.
Ability to balance a high-level view of security strategy with attention to detail, ensuring thorough and effective execution.
Additional Information Regarding Job Duties and s:
Job duties include additional responsibilities as assigned by one's supervisor or other managers related to the position/department. This job description is meant to describe the general nature and level of work being performed; it is not intended to be construed as an exhaustive list of all responsibilities, duties and other skills required for the position. The Company reserves the right at any time with or without notice to alter or change job responsibilities, reassign or transfer job position or assign additional job responsibilities, subject to applicable law. The Company shall provide reasonable accommodations of known disabilities to enable a qualified applicant or employee to apply for employment, perform the essential functions of the job, or enjoy the benefits and privileges of employment as required by the law.
If you are an extraordinary professional who thrives in a collaborative work culture and values a rewarding career, then we want to work with you! Apply today!
We are committed to protecting your privacy. To learn more about how we collect, use, and safeguard your personal information during the application process, please review our Employment Privacy Policy and Recruiting Policy on AI.
Auto-ApplyInformation Security Engineer
Information security analyst job in Cheyenne, WY
ANB Bank has financial strength embodied in $3 billion in assets and is a true community bank with an unwavering commitment to excellence. The bank helps each of its communities prosper through investment, sponsorship, philanthropy, and employee volunteerism. It is a passion ANB has for banking that makes a difference.
ANB Bank hires individuals who provide excellent customer service and build meaningful relationships with our customers and within our communities. ANB is committed to rewarding our team members who strengthen our company and culture. ANB offers competitive compensation and a comprehensive benefits package for this position.
Hiring Pay Range: $27.00 - $35.50 per hour
This position may be eligible to receive an additional $1.00 per hour is approved for the Spanish Communication Assistant ProgramThe hiring pay range for this position is commensurate with the level of relevant experience and education.
Health & Wellness Benefits (Subject to Eligibility Requirements)
Minimum 4 Weeks of Paid Time Off (PTO)11 Paid HolidaysMedical, Dental, and Vision InsuranceHealth Savings (HSA), Flexible Spending (FSA), and dependent care spending accounts Company provided Live, AD&D, and Disability Insurance with supplementation options 401(k) plan with discretionary company match and profit sharing Discretionary annual bonus and employee referral incentives Employee Assistance Program (EAP) Tuition Reimbursement ProgramSpanish Communication Assistant Program IncentiveEmployee Banking Products
Summary
* Responsible for implementation and administration of corporate Information Security Systems as listed below.
Essential Duties and Responsibilities
* Manage Corporate Information Security Systems as follows:
* Manage user accounts across multiple solutions.
* Engineer, design and installation of intrusion detection/prevention, firewall and other information security solutions.
* Manage and maintain log analysis systems, respond to alerts, and generate reports.
* Monitor and maintain security setting implementations to enhance security posture without affecting system availability.
* Manage and maintain patching solutions and generate reports.
* Manage digital evidence collection solution, ensuring proper chain of custody.
* Monitor and respond to alerts from various security solutions.
* Manage VPN solution and generate reports.
* Continuously monitor and evaluate results from vulnerability management solution and generate reports.
* Audit software solutions to ensure compliance with Company policies.
* Engineer, design, implement and support TCP/IP subnets.
* Provide direct technical assistance and support to internal teams as necessary.
* Monitor, maintain and control network efficiency using appropriate tools.
* Maintain network server applications specific to the Internet, E-Mail and remote access.
* Assist in the support of communications devices, such as Routers, switches, etc.
* Recommend ways to improve efficiency of Information Security operations.
* Ensuring management is made aware of critical events and situations within the department.
* Accept phone calls and solve problems after hours during rotating on-call schedule.
* Maintains a current knowledge and consistent compliance with Bank Secrecy Act (BSA) requirements, as well as knowledge and consistent compliance with other banking regulations and Bank policies and procedures related to the position.
* Delivers quality of service as defined by department standards.
* Maintains confidentiality as defined by department standards.
* Supports the company's Mission, Vision, and Values.
* Other duties may be assigned.
Education and/or Experience
* Five years of related experience and/or training.
* Preferred college degree in related field; or equivalent combination of education and experience.
* Other qualifications include:
* In-depth knowledge of networking and security concepts;
* Experience with patching solution;
* Experience managing anti-virus solution;
* Experience with intrusion detection and prevention systems;
* Experience with Microsoft Active Directory;
* Experience managing VPN solution;
* Experience managing vulnerability management platform;
* Experience showing progressive technical knowledge and understanding.
* Performs several, if not all, of the above duties with moderate direction and supervision.
* Several Industry standard Information Security advanced certifications (GSEC, CISSP, etc) in good standing and appropriate training and experience required.
Work Schedule: Monday - Friday, 8:00am - 5:00pm
Equal Opportunity Employer / Affirmative Action / Minorities / Female / Disability / Veteran
ANB Bank is committed to providing Equal Opportunity in Employment. The Bank is continually trying to improve recruitment, employment, development, and promotional opportunities for its employees. Our selection decisions are based on job-related factors and not on the basis of age, race, sex, color, religion, national origin, disability, sexual orientation, veteran status, pregnancy, marital status, genetic information, gender identity, or any other status protected by federal, state, or local law.
ANB Bank complies with the Equal Pay for Equal Work Act. ANB Bank requests that Applicant not disclose its wage history to ANB Bank. If ANB Bank for any reason comes into possession of Applicant's wage rate history, ANB Bank will not rely on it in determining a wage rate. ANB Bank requests that Applicant not provide information on age, date of birth, or graduation date from any academic institution, including on resumes.
Anticipated Date of Application Window Closure: 01/03/2026 (or until filled)
IT&S Analyst
Information security analyst job in Lander, WY
At ScionHealth, we empower our caregivers to do what they do best. We value every voice by caring deeply for every patient and each other. We show courage by running toward the challenge and we lean into new ideas by embracing curiosity and question asking. Together, we create our culture by living our values in our day-to-day interactions with our patients and teammates.
Job Summary
* The IT Analyst I provides entry-level technical support for users, systems, and network-related issues. This role is responsible for resolving helpdesk tickets, assisting with PC and printer setup, supporting basic application functions, and escalating complex issues as needed. The Analyst I is a key member of the front-line support team and contributes to documentation and user training.
Essential Functions
* Responds to helpdesk tickets and user inquiries, resolving issues related to hardware, software, printers, and login credentials
* Assists with computer imaging, deployment, and setup for new hires or replacements
* Provides basic troubleshooting and support for Microsoft Office and other enterprise software
* Escalates unresolved technical problems to IT Analyst II or III
* Maintains inventory logs for hardware and software
* Participates in user orientation and basic IT training
* Maintains documentation for routine IT procedures and knowledgebase updates
Knowledge/Skills/Abilities/Expectations
* Basic understanding of Microsoft Windows, Office, and networked systems
* Excellent customer service and problem-solving skills
* Ability to manage time, prioritize tasks, and communicate effectively
Qualifications
Education
* High school diploma or GED required
* Associate's degree in Information Technology or related field preferred
Licenses/Certifications
* None Required
Experience
* 1-2 years of experience in a helpdesk or IT support role
Sr. Security Analyst
Information security analyst job in South Jordan, UT
Lightspeed is a leading provider of cloud-based software for dealerships and Original Equipment Manufacturers (OEMs), serving the Powersport, Marine, RV, Trailer, Outdoor Power Equipment, and Golf Cart industries. Lightspeed's Dealer Management Solution (DMS) enables dealerships to optimize their end-to-end business operations, including sales, parts, service, rentals, accounting, and Customer Relationship Management (CRM). When implemented into their daily operations, Lightspeed helps dealers increase their profitability by selling more units, service, and parts, all while creating a more streamlined experience for customers. For nearly 40 years, Lightspeed has been empowering 4,500+ dealers across North America with the tools and technology they need to manage their dealerships.
The Senior Security Analyst is responsible for team lead activities, such as monitoring, analyzing, and responding to security incidents across enterprise systems, cloud environments, and networks. This role ensures the confidentiality, integrity, and availability of organizational information through proactive detection, incident response, and continuous improvement. The ideal candidate will have a strong technical background in leading threat analysis, SIEM integration and management, vulnerability management, and incident handling.
What you'll do:
Monitor and investigate security alerts and events across SIEM, EDR, and network systems.
Conduct root cause analysis and coordinate remediation of security incidents.
Lead vulnerability assessments and ensure timely patching and mitigation.
Develop and maintain incident response playbooks and escalation procedures.
Collaborate with IT, DevOps, and Development teams to strengthen overall security posture.
Lead proactive threat hunting and continuous tuning of detection mechanisms.
Support internal and external audits (e.g., SOC 2) and risk assessments by providing evidence and guidance.
Perform firewall management, including rule changes, troubleshooting, and SOP development for hybrid cloud/on-prem environments.
Lead to red/blue team exercises and implement findings to improve defenses.
Coordinate and assist with enterprise pen-tests, risk assessments, and compliance initiatives.
Serve as a lead security advisor to business and technical teams, providing guidance on secure design, risk mitigation, and compliance using industry frameworks and best practices.
What you should have:
Qualifications:
Bachelor's degree in Cybersecurity, Information Technology, or a related field, or equivalent experience.
8+ years of experience in information security, incident response, or SOC operations.
Proven hands-on experience with SIEM tools (Splunk, Sentinel, QRadar, etc.) and EDR/XDR platforms (CrowdStrike, Darktrace, Microsoft Defender).
Strong experience securing and monitoring cloud environments (AWS, Azure).
Deep knowledge of security frameworks (NIST CSF, ISO 27001, SOC 2).
Advanced scripting and automation proficiency (Python, PowerShell, Terraform).
Excellent analytical, problem-solving, and communication skills.
Preferred Qualifications:
Relevant certifications such as AWS Security, CISSP, GCIH, GCIA, GPEN, GWAPT preferred.
Experience integrating AI and automation into security operations workflows.
Hands-on experience performing dynamic application security testing and red team exercises across endpoint and cloud environments.
Expert-level networking and firewall expertise with platforms such as Palo Alto, Cisco, or Checkpoint.
Master's degree in Cybersecurity, Information Technology, or a related field.
Inclusion and Diversity at Lightspeed:
At Lightspeed, we celebrate the uniqueness of every individual and encourage diverse perspectives. We believe that inclusion drives innovation and fosters meaningful connections. We are committed to building an environment where everyone feels valued and empowered to make an impact.
Equal Employment Opportunity Statement:
Lightspeed is an Equal Opportunity Employer and is dedicated to building a diverse and inclusive workforce. All qualified applicants will be considered for employment without regard to race, color, creed, ancestry, national origin, gender, sexual orientation, gender identity, gender expression, marital status, religion, age, disability, veteran status, or any other protected category.
Important Note:
Applicants must be authorized to work in the U.S.
Ready to apply?
Take the next step in your career-apply today and join a team where your skills will make an impact!
Auto-ApplyData Security Analyst Sr
Information security analyst job in Salt Lake City, UT
The Data Security Analyst Senior position in the Information Security Office ( ISO ) is responsible for leading and supporting security initiatives which mitigate risk and ensure data integrity at the University of Utah and University Health Care. This includes providing security guidance and technical risk assessments of new or ongoing projects, responding to, and analyzing security incidents, and implementing new security technologies or processes. This is a highly collaborative position which requires strong analytical and communication skills.
Responsibilities
· Communicate security risks, incidents, and mitigation strategies to senior management and relevant stakeholders. · Collaborate with IT teams, system administrators, and network security analysts to ensure cohesive security strategy and technical implementations. · Collaborate in the development of action plans to improve security posture. · Assist the University in meeting compliance obligations regarding information security. · Contribute to incident response procedures and play a key role in incident response activities and help develop strategies to prevent future occurrences. · Analyze digital evidence from endpoints, servers, and cloud environments to identify the root cause of breaches, malware infections, or other security issues. · Provide security evaluation and guidance regarding new technologies or processes. · Assist in legal discovery and evidence acquisition and preservation. · Support and configure security safeguards in major cloud platforms. · Participate in security assessments of departments and colleges. · Evaluate, select, implement, and maintain endpoint security solutions such as endpoint detection and response ( EDR ). This will include working with portions of the Microsoft Extended Detection and Response suite. · Support the Security Operations Center ( SOC ) leverage technology and data to accomplish their responsibilities. · Stay up-to-date and informed about emerging threats, vulnerabilities, and security solutions through research and industry publications. This job description is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to the job. Work Environment and Level of Frequency typically required Nearly Continuously: Office environment. Physical Requirements and Level of Frequency that may be required Nearly Continuously: Sitting, hearing, listening, talking. Often: Repetitive hand motion (such as typing), walking. Seldom: Bending, reaching overhead.
Minimum Qualifications
Requires a bachelor's degree in area of specialty, or equivalency (one year of education can be substituted for two years of related work experience); and 2-4 years of experience in the field or in a related area. Applicants must demonstrate the potential ability to perform the essential functions of the job as outlined in the position description.
Information Systems Security Officer
Information security analyst job in Clearfield, UT
General information Requisition # R64695 Posting Date 12/10/2025 Security Clearance Required Top Secret Remote Type Onsite Time Type Full time Description & Requirements Shape the future of defense with MANTECH! Join a team dedicated to safeguarding our nation through advanced tech and innovative solutions. Since 1968, we've been a trusted partner to the Department of Defense, delivering cutting-edge projects that make a real impact. Dive into exciting opportunities in Cybersecurity, IT, Data Analytics and more. Propel your career forward and be part of something extraordinary. Your journey starts now-protect and innovate with MANTECH!
MANTECH seeks a motivated, career and customer-oriented Information Systems Security Officer (ISSO) to join our Air Force / Space team at Hill AFB.
The ISSO's primary function is to support the United States Air Force's 53rd Wing Technical Support Services (53rd WTSS) contract.
Responsibilities include, but are not limited to:
* Perform ISSO duties in support of in-house and external customers
* Notify ISSM when changes occur that might affect the authorization determination of the information system(s)
* Conduct periodic reviews of information systems to ensure compliance with the security authorization package
* Coordinate any changes or modifications to hardware, software, or firmware of a system with the ISSM and AO/DAO prior to the change
* Ensure all IS security-related documentation is current and accessible to properly authorized individuals
* Execute the cyber security portion of the self-inspection, to include provide security coordination and review of all system assessment plans
* Identify cyber security vulnerabilities and assist with the implementation of the countermeasures for them
* Conduct security impact analysis activities and provide to the ISSM on all configuration management changes to the authorization boundaries
Minimum Qualifications:
* Bachelor's degree in related discipline from an accredited college or university. 2 additional years of experience may be substituted for a degree.
* 4+ years direct/related experience
* Active / valid DoD 8570.01-M IAT-II certification
* Experience with DoD/USAF information security policy background with practical / hands-on experience applying RMF processes and principles.
* Experience developing and/or contributing to an RMF body of evidence composition, applicable artifacts, and associated control families.
Clearance Requirements:
* Active Top Secret Clearance
* Must be able to obtain and maintain a DoD TS/SCI-eligible clearance (i.e. DCID 6/4 eligibility)
* Eligibility for access to Special Access Program Information
* Willingness to submit to a Polygraph.
Physical Requirements:
* Must be able to remain in a stationary position 50%
* Needs to occasionally move about inside the office to access file cabinets, office machinery, etc.
* Constantly operates a computer and other office productivity machinery, such as a calculator, copy machine and computer printer.
* Frequently communicates with co-workers, management and customers, which may involve delivering presentations. Must be able to exchange accurate information in these situations
MANTECH International Corporation considers all qualified applicants for employment without regard to disability or veteran status or any other status protected under any federal, state, or local law or regulation.
If you need a reasonable accommodation to apply for a position with MANTECH, please email us at ******************* and provide your name and contact information.
Auto-Apply