About the role
We're looking for a detail oriented, technically skilled engineer to join our Application Security team. This role offers opportunities to influence the group's growth and direction while integrating security within the entire Software Development Life Cycle (SDLC).
SecurityEngineers will collaborate with Product and Engineering teams to embed security into all phases of the SDLC from feature design and implementation to deployment. They also establish and evaluate authentication, authorization, and privacy controls for B2C, B2B and M2M entity types and use cases.
They will identify, prioritize, and remediate vulnerabilities identified via internal and third party penetration testing, Software Composition Analysis (SCA), Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST). They will also deploy, maintain and tune the tools used to perform this testing.
SecurityEngineers serve as subject matter experts on authentication and authorization security, partnering with product and engineering teams to implement security and privacy best practices for healthcare applications.
The ideal candidate will have experience securing, hardening, and identifying vulnerabilities in web applications, RESTful and GraphQL APIs, and mobile applications (iOS and Android) in a cloud hosted microservice environment.
The ideal candidate will also have experience risk assessing the results of automated SCA, SAST and DAST to validate severity before assigning to engineers for remediation.
They may also have experience in securing Generative AI LLM services, including, but not limited to security guardrails to prevent jailbreaks, sensitive information disclosure, data/model poisoning, and safety guardrail verification and testing.
What You'll Accomplish
Implement and maintain automated security scanning tools (SCA, SAST, DAST) and perform manual and AI assisted security assessments including source code review to identify and remediate vulnerabilities in Hinge Health web applications, mobile applications and API endpoints.
Enable the product teams to create secure by design product features and services by working alongside product managers and engineers during the design phase of projects including Generative AI projects.
Assist with third party security assessments and penetration tests of Hinge Health web applications, API endpoints, and mobile applications, including interpretation of results and verification of remediations.
Contribute to the improvement of Software Development Life Cycle management policies, procedures, and standards.
Basic Qualifications
3+ years of experience in application security, product security, or related securityengineering roles
Experience securing web applications, mobile applications (iOS/Android), or API endpoints
Experience with automated security testing, including configuring and automating security scans as part of the CI/CD process, and interpreting the results and working directly with engineers on prioritization and remediation.
Experience in examining source code in multiple languages to evaluate security controls and identifying common coding and design vulnerabilities. Experience with OWASP Top 10 and other common security flaw patterns.
Demonstrated ability to collaborate with engineering and product teams to address security concerns.
Preferred Qualifications
Experience securing applications in Health Care, securing ePHI and HIPAA/HITECH regulations.
Experience with modern authentication and authorization technologies including OAuth 2.0, OIDC, SAML, JWT validation, SSO integrations, MFA/OTP implementations, API tokens, and identity platforms such as Auth0 or Okta. Understanding of session management, refresh tokens, and secure authentication flows for B2C, B2B, and M2M use cases.
Experience assessing the security and safety of Generative AI LLM solutions and in evaluating and implementing solutions for their continuous monitoring
Familiarity with HITRUST CSF and NIST control frameworks.
Experience in Threat Modeling
Experience performing security assessments and secure design of hardware and firmware of medical devices communicating over Bluetooth
Experience with any of the following, deploying web based services on AWS infrastructure, Kubernetes, Typescript, ReactNative, Python, Go, Ruby on Rails, GraphQL, IaC using Terraform.
Incident Handling: Be able to work as a subject matter expert in the security controls, internal communications, and infrastructure of Hinge Health applications during security incidents.
Hinge Health Hybrid Model
We believe that remote work and in-person work have their own advantages and disadvantages, and we want to be able to leverage the best of both worlds. Employees in hybrid roles are required to be in the office 3 days/week. The San Francisco office has a dog-friendly workplace program.
Compensation
This position will have an annual salary, plus equity and benefits. Please note the annual salary range is a guideline, and individual total compensation will vary based on factors such as qualifications, skill level, competencies, and work location. The annual salary range for this position is $192,000 - $230,400.
About Hinge Health
Hinge Health leverages software, including AI, to largely automate care for joint and muscle health, delivering an outstanding member experience, improved member outcomes, and cost reductions for its clients. The company has designed its platform to address a broad spectrum of MSK care-from acute injury, to chronic pain, to post-surgical rehabilitation-and the platform can help to ease members' pain, improve their function, and reduce their need for surgeries, all while driving health equity by allowing members to engage in their exercise therapy sessions from anywhere. The company is headquartered in San Francisco, California.
Learn more at **************************
What You'll Love About Us
Inclusive healthcare and benefits: On top of comprehensive medical, dental, and vision coverage, we offer employees and their family members help with gender-affirming care, tools for family and fertility planning, and travel reimbursements if healthcare isn't available where you live.
Planning for the future: Start saving for the future with our traditional or Roth 401k retirement plan options which include a 2% company match.
Modern life stipends: Manage your own learning and development
Culture & Engagement
Hinge Health is an equal opportunity employer and prohibits discrimination and harassment of any kind. We make employment decisions without regards to race, color, religion, sex, sexual orientation, gender identity, national origin, age, veteran status, disability status, pregnancy, or any other basis protected by federal, state or local law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. We provide reasonable accommodations for candidates with disabilities. If you feel you need assistance or an accommodation due to a disability, let us know by reaching out to your recruiter.
By submitting your application you are acknowledging we are using your personal data as outlined in personnel and candidate privacy policy.
#J-18808-Ljbffr
$192k-230.4k yearly 2d ago
Looking for a job?
Let Zippia find it for you.
Senior Security Engineer II (IAM)
Aledade, Inc. 4.1
Bethesda, MD jobs
As a Senior SecurityEngineer II for Identity and Access Management (IAM) at Aledade, you will play a central role in enhancing the security posture of our enterprise, cloud‑native environments, and applications. We are seeking a dedicated professional with in‑depth knowledge of IAM principles, standards, and best practices to help safeguard our systems and support our security compliance initiatives.
In this role, you will work to design, implement, and maintain robust IAM solutions, managing authentication, authorization, and provisioning across diverse platforms. You will also collaborate closely with various teams to ensure alignment between IAM solutions and organizational security requirements, enabling secure and seamless access across the enterprise and cloud services. Your ability to partner cross‑functionally will be key to driving impactful outcomes and further strengthening our digital landscape.
Primary Duties
Working cross functionally to design, build, and operate solutions that continuously improve and automate our security capabilities
Leveraging data to understand trends, metrics, and opportunities to improve our security posture and then helping execute on those opportunities with stakeholders
Leading and enhancing incident response efforts, spearheading analysis, containment, and mitigation strategies in a cross‑functional environment to ensure effective resolution and remediation of security incidents
Helping craft and refine security documentation pertinent to our Security Program, such as policies, standards, baselines, and standard operating procedures
Mentoring and coaching more junior engineers or analysts
Minimum Qualifications
BS / BTech (or higher) in Computer Science, Information Technology, Cybersecurity or a related field, 8 years security domain experience without degree
6+ years of experience in software or securityengineering within Cloud Native environments
4+ years of experience working with large datasets to identify opportunities for security posture improvements or to detect, investigate and respond to threats
4+ years of experience acting as a trusted advisor in a team setting, solving for short‑term and long‑term business value
4+ years of experience coaching other engineers or analysts
Preferred KSA's
Identity & Access Management
Experience with Identity & Access Management (IaM) systems and practices
In‑depth knowledge of authentication protocols, authorization mechanisms, and directory services
Strong proficiency implementing IAM solutions within very complex environments
Familiarity with regulatory compliance and security standards
Experience generating automated metrics to measure service and program effectiveness and consistency
Strong communication skills, both written and verbal, with the capability to articulate complex security issues to a diverse audience
Automation skills: Powershell, Python, Terraform
Expertise on Okta products - Directory, SSO, MFA, Workflows, ISPM and IGA
Experience with tools in the security stack strongly preferred: Auth0/Entra ID/Ping Identity, Cloud Platforms - AWS/Azure/GCP
Physical Requirements
Sitting for prolonged periods of time. Extensive use of computers and keyboard. Occasional walking and lifting may be required.
Who We Are
Aledade, a public benefit corporation, exists to empower the most transformational part of our health care landscape - independent primary care. We were founded in 2014, and since then, we've become the largest network of independent primary care in the country - helping practices, health centers and clinics deliver better care to their patients and thrive in value‑based care. Additionally, by creating value‐based contracts across a wide variety of health plans, we aim to flip the script on the traditional fee‑for‑service model. Our work strengthens continuity of care, aligns incentives and ensures primary care physicians are paid for what they do best - keeping patients healthy. If you want to help create a health care system that is good for patients, good for practices and good for society - and if you're eager to join a collaborative, inclusive, and remote‑first culture - you've come to the right place.
What Does This Mean for You?
At Aledade, you will be part of a creative culture that is driven by a passion for tackling complex issues with respect, open‑mindedness and a desire to learn. You will collaborate with team members who bring a wide range of experiences, interests, backgrounds, beliefs and achievements to their work - and who are all united by a shared passion for public health and a commitment to the Aledade mission.
Benefits
Flexible work schedules and the ability to work remotely are available for many roles
Health, dental and vision insurance paid up to 80% for employees, dependents and domestic partners
Robust time‑off plan (21 days of PTO in your first year)
Two paid volunteer days and 11 paid holidays
12 weeks paid parental leave for all new parents
Six weeks paid sabbatical after six years of service
Educational Assistant Program and Clinical Employee Reimbursement Program
401(k) with up to 4% match
Stock options
And much more!
Equal Employment Opportunity Statement
At Aledade, we don't just accept differences, we celebrate them! We strive to attract, develop and retain highly qualified individuals representing the diverse communities where we live and work. Aledade is committed to creating a diverse environment and is proud to be an equal opportunity employer. Employment policies and decisions at Aledade are based on merit, qualifications, performance and business needs. All qualified candidates will receive consideration for employment without regard to age, race, color, national origin, gender (including pregnancy, childbirth or medical conditions related to pregnancy or childbirth), gender identity or expression, religion, physical or mental disability, medical condition, legally protected genetic information, marital status, veteran status, or sexual orientation.
Privacy Policy
By applying for this job, you agree to Aledade's Applicant Privacy Policy available at *************************************************
#J-18808-Ljbffr
$102k-141k yearly est. 4d ago
Senior Security Engineer I
Aledade 4.1
Bethesda, MD jobs
As a Senior SecurityEngineer I at Aledade, you will play a central role in enhancing the security posture of our enterprise, cloud-native environments, and applications. We are seeking a dedicated professional with in-depth knowledge of security principles, standards, and best practices to help safeguard our systems and support our security compliance initiatives.
In this role, you will work to design, implement, and maintain robust security solutions across diverse platforms and technologies. You will collaborate closely with various teams to ensure alignment between security solutions and organizational requirements, enabling secure operations across the enterprise. Your ability to partner cross-functionally will be key to driving impactful security outcomes and strengthening our digital landscape.
Your expertise will be crucial as we continue to mature our security capabilities and maintain our commitment to protecting critical systems and data.
Primary Duties
Working cross-functionally to design, build, and operate solutions that improve and mature our security capabilities
Leveraging data to understand trends, metrics, and opportunities to improve our security posture, researching options, and then making recommendations as options to secure those opportunities with stakeholders
Leading and enhancing incident / issues response efforts, spearheading analysis, containment, and mitigation strategies in a cross-functional environment to ensure effective resolution and remediation of security incidents / issues
Helping craft and refine security documentation pertinent to our Security Program, such as policies, standards, baselines, and standard operating procedures
Minimum Qualifications
BS / BTech (or higher) in Computer Science, Information Technology, Cybersecurity or a related field, 6 years security domain experience without degree.
4+ years combined experience as a securityengineer in an enterprise environment (preferably cloud) across multiple disciplines.
3+ years of relevant work experience in security posture management.
2+ years of experience acting as a trusted technical decision-maker in a team setting, solving for short-term and long term business value.
Preferred KSA's
Prior experience working in the healthcare industry with health-tech systems, like Electronic Health Records, Clinical data, etc.
Experience in scripting languages such as Python and Bash is required.
Experience with Cloud Native Software Development environments and practices with a focus on multi-cloud deployments in AWS, Azure and/or GCP is required.
Prior experience with a focus on tooling, automation, and distributed systems development is preferred.
Experience with continuous integration tools (e.g. Cloud formation, Code deploy, Jenkins, CircleCI, Codefresh, Github Actions etc.).
Experience with configuration management platforms (e.g. Ansible, Chef, Salt).
Hands-on experience using Terraform, Python and/or other orchestration platforms at scale.
Familiarity with Agile and waterfall development methodologies.
Familiarity with automated testing methodologies, and continuous integration concepts.
Experience in creating, deploying, maintaining, and troubleshooting Docker images.
Experience in scoping, deploying, maintaining and troubleshooting Kubernetes clusters.
Experience with deploying policies with AWS Control tower, Azure Security hub, Google Resource Manager etc.
Experience generating automated metrics to measure service and program effectiveness and consistency
Strong communication skills, both written and verbal, with the capability to articulate complex technical issues to a diverse audience
Physical Requirements
Sitting for prolonged periods of time. Extensive use of computers and keyboard. Occasional walking and lifting may be required.
Who We Are:
Aledade, a public benefit corporation, exists to empower the most transformational part of our health care landscape - independent primary care. We were founded in 2014, and since then, we've become the largest network of independent primary care in the country - helping practices, health centers and clinics deliver better care to their patients and thrive in value-based care. Additionally, by creating value-based contracts across a wide variety of health plans, we aim to flip the script on the traditional fee-for-service model. Our work strengthens continuity of care, aligns incentives and ensures primary care physicians are paid for what they do best - keeping patients healthy. If you want to help create a health care system that is good for patients, good for practices and good for society - and if you're eager to join a collaborative, inclusive and remote-first culture - you've come to the right place.
What Does This Mean for You?
At Aledade, you will be part of a creative culture that is driven by a passion for tackling complex issues with respect, open-mindedness and a desire to learn. You will collaborate with team members who bring a wide range of experiences, interests, backgrounds, beliefs and achievements to their work - and who are all united by a shared passion for public health and a commitment to the Aledade mission.
In addition to time off to support work-life balance and enjoyment, we offer the following comprehensive benefits package designed for the overall well-being of our team members:
Flexible work schedules and the ability to work remotely are available for many roles
Health, dental and vision insurance paid up to 80% for employees, dependents and domestic partners
Robust time-off plan (21 days of PTO in your first year)
Two paid volunteer days and 11 paid holidays
12 weeks paid parental leave for all new parents
Six weeks paid sabbatical after six years of service
Educational Assistant Program and Clinical Employee Reimbursement Program
401(k) with up to 4% match
Stock options
And much more!
At Aledade, we don't just accept differences, we celebrate them! We strive to attract, develop and retain highly qualified individuals representing the diverse communities where we live and work. Aledade is committed to creating a diverse environment and is proud to be an equal opportunity employer. Employment policies and decisions at Aledade are based on merit, qualifications, performance and business needs. All qualified candidates will receive consideration for employment without regard to age, race, color, national origin, gender (including pregnancy, childbirth or medical conditions related to pregnancy or childbirth), gender identity or expression, religion, physical or mental disability, medical condition, legally protected genetic information, marital status, veteran status, or sexual orientation.
Privacy Policy: By applying for this job, you agree to Aledade's Applicant Privacy Policy available at *************************************************
#J-18808-Ljbffr
A prominent financial institution in Denver seeks a cybersecurity expert to join their Malware Defense Team. The role involves analyzing malware, tracking campaigns, and creating tools to assist in analysis. Ideal candidates will have strong experience in malware analysis, threat detection tools, and team collaboration. This position offers a competitive salary range of $95,700 to $144,900 annually, with industry-leading benefits and a commitment to professional growth.
#J-18808-Ljbffr
$95.7k-144.9k yearly 5d ago
Malware Defense Malware Analyst
Stryker Corporation 4.7
Denver, CO jobs
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day. Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates' physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve. Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations. At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us! Bank of America is one of the world's leading financial institutions, serving over 66 million consumers and small businesses. Company success is only possible with a strong cyber defense, which enables Bank of America to safely conduct global operations across the United States and in approximately 35 countries. Our primary goal is to safeguard not only the company, but our clients and their trust. The Malware Defense Team is looking for top talent who would like to join one of the most advanced cybersecurity teams in the world.
Responsibilities
In-depth analysis of malware, including authoring analysis reports.
Tracking malware campaigns, malicious actors, and related infrastructure.
Creation of tools and scripts to assist in the analysis of malware analysis.
Field escalations of potentially malicious files and websites from teams within Malware Defense.
Required Qualifications
Strong direct experience of analyzing malware.
Intermediate to advanced malware analysis skills.
Experience creating innovative ways to track progression of malware families, infrastructure, and campaigns conducted by e-crime, and cyber espionage actors.
Experience creating tools and scripts to accelerate malware and threat analysis.
Background in network traffic analysis - WireShark, Fiddler, proxy logs, etc.
Experience analyzing malicious web content such as ClickFix, ClearFake, SocGholish, etc.
Experience authoring YARA, Suricata, and EKFiddle detection rules.
Experience with penetration testing and/or adversary emulation is a plus.
Able to work independently on tasks, but also work well within a team environment.
Desired Qualifications
Experience analyzing malware targeting Linux, Android, and IOT platforms.
Skills
Cyber Security
Data Privacy and Protection
Problem Solving
Process Management
Threat Analysis
Business Acumen
Data and Trend Analysis
Interpret Relevant Laws, Rules, and Regulations
Risk Analytics
Stakeholder Management
Access and Identity Management
Data Governance
Encryption
Information Systems Management
Technology System Assessment
Shift
1st shift (United States of America)
Hours Per Week
40
Pay Transparency details
US - CO - Denver - 1144 15th St - Denver Gis (CO9926), US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842), US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540)
Pay and benefits information
Pay range: $95,700.00 - $144,900.00 annualized salary, offers to be determined based on experience, education and skill set.
Discretionary incentive eligible: This role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.
Benefits
This role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.
#J-18808-Ljbffr
$95.7k-144.9k yearly 5d ago
Senior Cloud Security Engineer: Incident Response & IAM
Aledade 4.1
Bethesda, MD jobs
A healthcare technology firm located in Maryland is seeking a Senior SecurityEngineer I to enhance security capabilities within cloud-native environments. The candidate will design and implement security solutions, lead incident response efforts, and collaborate with various teams to strengthen security posture. Applicants should have a degree in Computer Science or related field, extensive experience in securityengineering, and proficiency in scripting languages like Python and Bash. This role offers a supportive workplace that values diversity and innovation.
#J-18808-Ljbffr
$102k-141k yearly est. 1d ago
Senior Security Engineer - Endpoint Defense
Persona 4.3
San Francisco, CA jobs
A forward-thinking technology company in San Francisco seeks a skilled individual to lead their corporate security efforts. In this full-time role, you'll enhance security practices, develop innovative defense strategies, and protect the organization's operations from evolving threats. The ideal candidate has over 3 years of experience in IT security, particularly in endpoint security solutions. The company offers competitive medical, dental, and mental health benefits along with an engaging workplace culture.
#J-18808-Ljbffr
$135k-181k yearly est. 4d ago
Senior Security Engineer, Corporate Security San Francisco
Persona 4.3
San Francisco, CA jobs
Persona is the configurable identity platform built for businesses in a digital-first world. Verifying individuals and organizations is harder - but more important - than ever, with AI enabling fraudsters to launch sophisticated accounts at scale and regulations evolving rapidly.
We've built Persona to support practically every use case and industry - that's why we're able to serve a wide range of leading companies. For example, Instacart relies on Persona to verify shoppers who onboard onto their platform before delivering groceries to your doorstep. Meanwhile, OpenAI relies on Persona to keep bad actors out, protecting one of the world's most powerful AI platforms from large-scale abuse in a time when AI is reshaping the way we work and live.
We're growing rapidly and looking for exceptional people to join us!
About the Role
Persona's Security Team is looking for someone to lead our corporate security efforts. You'll play a pivotal role in fortifying our defenses against evolving threats. Your mission is to protect fellow Personerds and the systems we use to do our work. You'll have the opportunity to employ cutting-edge technologies, innovative strategies, and your expertise to thwart potential attacks before they disrupt our operations.
This is a full-time position based in our headquarters in downtown San Francisco. Our in-office days are Tuesday - Thursday, with the option to work from home on Monday and Friday.
What you'll do at Persona
Develop, enhance, and implement endpoint detection and response rules and tooling for endpoint devices
Collaborate cross-functionally with our TechOps Team in implementing security best practices for SaaS and endpoint environments and support security initiatives like 2-factor authentication, automated encryption of client devices, DLP, etc.
Build tools and processes for automating security controls and monitoring at scale
Support security initiatives across the organization and harden our corporate infrastructure against attack
Recommend endpoint and SaaS mitigations and controls based on generated telemetry
Provide recommendations and support for insider threat programs
Participate in the on-call rotation for the Security Team
What you'll bring to Persona
3+ years of experience in IT security or building endpoint security solutions, including experience supporting mac OS devices
Experience with planning and executing endpoint hardening initiatives
Experience with mobile device management (MDM) and endpoint detection and response (EDR) tools and technologies
Experience with data loss prevention (DLP) and insider threat concepts and mitigations
Experience with email security concepts and protecting a workforce against phishing
Ability to explain security topics clearly to non-technical business representatives
Ability to write code in Ruby, Python, or similar scripting languages, as well as SQL queries
Full-time Employee Benefits and Perks
For full-time employees (excluding internship and contractor opportunities), Persona offers a wide range of benefits, including medical, dental, and vision, 3% 401(k) contribution, unlimited PTO, quarterly mental health days, family planning benefits, professional development stipend, wellness benefits, among others. While we believe competitive compensation and benefits are a critical aspect of you deciding to join us, we do hope you consider why our core values and culture are right for you. If you'd like to better understand what it's like working at Persona, feel free to check out our reviews on Glassdoor.
#J-18808-Ljbffr
$135k-181k yearly est. 4d ago
Senior Security Engineer, Product San Francisco
Persona 4.3
San Francisco, CA jobs
Persona is the configurable identity platform built for businesses in a digital-first world.
Verifying individuals and organizations is harder - but more important - than ever, with AI enabling fraudsters to launch sophisticated accounts at scale and regulations evolving rapidly.
We've built Persona to support practically every use case and industry - that's why we're able to serve a wide range of leading companies. For example, Instacart relies on Persona to verify shoppers who onboard onto their platform before delivering groceries to your doorstep. Meanwhile, OpenAI relies on Persona to keep bad actors out, protecting one of the world's most powerful AI platforms from large-scale abuse in a time when AI is reshaping the way we work and live.
We're growing rapidly and looking for exceptional people to join us!
About the Role
We're building something special here at Persona, and our Security Team is a big part of that. Our team is made up of veterans from industry leaders like Square and Dropbox, and we're looking for someone to join us in shipping innovative products quickly and securely.
Your job? Work with our engineering teams to make sure we're delivering rock-solid security for our customers and users. As we grow fast (and we mean fast), you'll be key in managing the risks that come with that speed. We're not just looking for someone to play defense - we want you to think ahead and outsmart the bad guys before they even know what hit them. You'll get to work with the latest tech and come up with clever ways to keep our systems locked down tight.
What you'll do at Persona
Collaborate cross-functionally with our product teams to understand, manage, and mitigate the security risks associated with their work, while supporting their ability to ship quickly
Build tools and processes for automating product security controls and monitoring at scale
Support product security initiatives across our fast-growing engineering team
Participate in the on-call rotation for the Security Team
What you'll bring to Persona
Communication and Collaboration skills. Ability to explain security topics clearly to non-technical business representatives. Drive to enable other engineers to ship securely.
Bias toward shipping. Improving our product quickly and continually is one of Persona's greatest strengths. You should be excited about finding ways to integrate security into our product delivery processes without slowing things down.
Proactive approach to solving problems. We're looking for someone that can tell us how to solve our problems, not someone who waits to be told how to solve problems.
Passion for security. You should be excited about keeping your skills and knowledge sharp, and sharing that with your peers and the rest of the company.
Experience. 2+ years of software engineering, 2+ years of product security at a fast-moving technology company.
Nice to have
Experience securing a large Ruby on Rails application.
Full-time Employee Benefits and Perks
For full-time employees (excluding internship and contractor opportunities), Persona offers a wide range of benefits, including medical, dental, and vision, 3% 401(k) contribution, unlimited PTO, quarterly mental health days, family planning benefits, professional development stipend, wellness benefits, among others. While we believe competitive compensation and benefits is a critical aspect of you deciding to join us, we do hope you consider why our core values and culture are right for you. If you'd like to better understand what it's like working at Persona, feel free to check out our reviews on Glassdoor.
#J-18808-Ljbffr
$135k-181k yearly est. 4d ago
Senior Security Engineer - Ship Securely at Speed
Persona 4.3
San Francisco, CA jobs
A leading identity platform in San Francisco seeks a SecurityEngineer to enhance product security while supporting the fast-paced delivery processes of engineering teams. The candidate will collaborate cross-functionally to manage risks, build security automation tools, and participate in on-call rotations. Required skills include communication, collaboration, and a passion for security, with 2+ years in software engineering and product security at a tech company. This full-time role offers competitive benefits and emphasizes a culture of proactive problem-solving.
#J-18808-Ljbffr
$135k-181k yearly est. 4d ago
Mid-Level Systems Engineer
Leidos 4.7
Bethesda, MD jobs
Leidos National Security Sector combines technology-enabled services and mission software capabilities in the areas of cyber, logistics, security operations, and decision analytics to support our defense and intel customers' mission to defend against evolving threats around the world. Our team's focus is to ensure our customers have the right tools, technologies, and tactics to keep pace with an ever-evolving security landscape and succeed in their pursuit to protect people and critical assets.
The Intelligence Production Solutions Division (IPSD), part of the Decision Advantage Solutions Business Area, is currently seeking a Mid-Level Systems Engineer for the Chinook Program. As part of a highly skilled team, you will play a critical role in delivering geospatial intelligence (GEOINT) capabilities through innovative systems engineering practices, directly supporting the Customer's mission to provide timely, relevant, and accurate intelligence to national decision-makers and warfighters.
Position may be performed in the following locations below. Please note Gaithersburg, MD is the program's primary work location.
Gaithersburg, MD
Alexandria, VA
Chantilly, VA
Aurora, CO
St. Louis, MO
Tucson, AZ
Clearance Level Required:
Top Secret with SCI eligibility and able to obtain a Polygraph.
Primary Responsibilities:
Support system architecture design, requirements development, integration planning, and configuration management.
Provide engineering expertise for mission systems across the full system lifecycle from concept through deployment and sustainment.
Collaborate with stakeholders across the Customer's and contractor teams to ensure interoperability, scalability, and mission alignment.
Evaluate and recommend tools, techniques, and processes for system development and integration.
Develop and maintain technical documentation, including system interface control documents (ICDs), and engineering reports.
Participate in technical reviews, readiness assessments, and milestone events.
Conduct analysis of system performance and provide recommendations for optimization.
Basic Qualifications:
US citizenship is required per contract.
Bachelor's degree in Systems Engineering, Computer Science, or related field and 4-8 years of prior relevant experience or Master's with 2-6 years of prior relevant experience.
Strong understanding of systems engineering principles, including requirements management, integration & test, and configuration control.
Familiarity with Model-Based Systems Engineering (MBSE) tools and methodologies (e.g., Cameo, Sysml).
Experience working in a DoD or Intelligence Community (IC) environment.
Proficiency with Atlassian tools (JIRA, Confluence), Microsoft Office Suite, and collaboration platforms.
Excellent written and verbal communication skills.
Preferred Qualifications:
Systems Engineering Professional (SEP), INCOSE, CISSP, Security+ certification, or similar credentials.
Experience supporting the Customer's programs or working with the GEOINT lifecycle.
Knowledge of cloud-based architectures (AWS, C2S) and DevSecOps environments.
Familiarity with Agile and SAFe methodologies.
Experience supporting GEOINT missions.
At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail.
Original Posting:
November 21, 2025
For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:
$87,100.00 - $157,450.00
The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
About Leidos
Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit ***************
Pay and Benefits
Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at ************************************
Securing Your Data
Beware of fake employment opportunities using Leidos' name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system - never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at *****************************.
If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission.
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.
#J-18808-Ljbffr
$87.1k-157.5k yearly 1d ago
Mid-Level Systems Engineer
Leidos 4.7
Saint Louis, MO jobs
Leidos National Security Sector combines technology-enabled services and mission software capabilities in the areas of cyber, logistics, security operations, and decision analytics to support our defense and intel customers' mission to defend against evolving threats around the world. Our team's focus is to ensure our customers have the right tools, technologies, and tactics to keep pace with an ever-evolving security landscape and succeed in their pursuit to protect people and critical assets.
The Intelligence Production Solutions Division (IPSD), part of the Decision Advantage Solutions Business Area, is currently seeking a Mid-Level Systems Engineer for the Chinook Program. As part of a highly skilled team, you will play a critical role in delivering geospatial intelligence (GEOINT) capabilities through innovative systems engineering practices, directly supporting the Customer's mission to provide timely, relevant, and accurate intelligence to national decision-makers and warfighters.
Position may be performed in the following locations below. Please note Gaithersburg, MD is the program's primary work location.
Gaithersburg, MD
Alexandria, VA
Chantilly, VA
Aurora, CO
St. Louis, MO
Tucson, AZ
Clearance Level Required:
Top Secret with SCI eligibility and able to obtain a Polygraph.
Primary Responsibilities:
Support system architecture design, requirements development, integration planning, and configuration management.
Provide engineering expertise for mission systems across the full system lifecycle from concept through deployment and sustainment.
Collaborate with stakeholders across the Customer's and contractor teams to ensure interoperability, scalability, and mission alignment.
Evaluate and recommend tools, techniques, and processes for system development and integration.
Develop and maintain technical documentation, including system interface control documents (ICDs), and engineering reports.
Participate in technical reviews, readiness assessments, and milestone events.
Conduct analysis of system performance and provide recommendations for optimization.
Basic Qualifications:
US citizenship is required per contract.
Bachelor's degree in Systems Engineering, Computer Science, or related field and 4-8 years of prior relevant experience or Master's with 2-6 years of prior relevant experience.
Strong understanding of systems engineering principles, including requirements management, integration & test, and configuration control.
Familiarity with Model-Based Systems Engineering (MBSE) tools and methodologies (e.g., Cameo, Sysml).
Experience working in a DoD or Intelligence Community (IC) environment.
Proficiency with Atlassian tools (JIRA, Confluence), Microsoft Office Suite, and collaboration platforms.
Excellent written and verbal communication skills.
Preferred Qualifications:
Systems Engineering Professional (SEP), INCOSE, CISSP, Security+ certification, or similar credentials.
Experience supporting the Customer's programs or working with the GEOINT lifecycle.
Knowledge of cloud-based architectures (AWS, C2S) and DevSecOps environments.
Familiarity with Agile and SAFe methodologies.
Experience supporting GEOINT missions.
At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail.
Original Posting:
November 21, 2025
For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:
$87,100.00 - $157,450.00
The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
About Leidos
Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit ***************
Pay and Benefits
Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at ************************************
Securing Your Data
Beware of fake employment opportunities using Leidos' name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system - never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at *****************************.
If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission.
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.
#J-18808-Ljbffr
$87.1k-157.5k yearly 1d ago
System Engineer I
El Camino Health 4.4
San Francisco, CA jobs
System Engineer I page is loaded## System Engineer Iremote type: Hybridlocations: San Francisco, CAtime type: Full timeposted on: Posted 3 Days Agojob requisition id: JR747**Career-defining. Life-changing.**At iRhythm, you'll have the opportunity to grow your skills and your career while impacting the lives of people around the world. iRhythm is shaping a future where everyone, everywhere can access the best possible cardiac health solutions. Every day, we collaborate, create, and constantly reimagine what's possible. We think big and move fast, driven by our commitment to put patients first and improve lives. We need builders like you. Curious and innovative problem solvers looking for the chance to meaningfully shape the future of cardiac health, our company, and your career**About This Role:**As a System Engineer I in iRhythm's Product Development - System Engineering Group, you will contribute to the development and improvement of innovative testing solutions that enhance our products and manufacturing processes. This entry-level position provides an excellent opportunity to grow within the MedTech and wearable device industry, collaborating with cross-functional teams including Design, Firmware, Software, Electrical, and Mechanical Engineering.You will work closely with R&D, product development, and manufacturing teams to design, refine, and support test fixtures and tools for iRhythm's products. This role offers hands-on experience, exposure to multiple engineering disciplines, and a collaborative environment that supports career development.Key Responsibilities* Support the design, development, and validation of test systems for iRhythm's medical devices.* Collaborate cross-functionally with design, software, firmware, and manufacturing teams to enhance testing efficiency and reliability.* Assist in creating and maintaining technical documentation including test plans, system requirements, and test reports.* Contribute to root cause analysis and troubleshooting activities for test and system-level issues.* Participate in continuous improvement initiatives to optimize test processes and tools.* Ensure work complies with quality system and regulatory requirements relevant to medical device development.Required Qualifications* Bachelor's degree in Electrical, Biomedical, or a related engineering discipline (Master's degree preferred).* Familiarity with bench-top lab equipment (e.g., power supplies, DMMs, oscilloscopes).* Ability to read and interpret circuit schematics and PCB layouts.* Basic programming or scripting skills in Python or C#.* Strong written and verbal communication skills for documentation and cross-functional collaboration.* Attention to detail with the ability to follow procedures while contributing innovative ideas.Preferred Qualifications* Experience automating test processes or procedures.* Understanding of statistical analysis and deriving test limits using GR&R or similar methods.* Exposure to electromechanical devices and/or medical device testing.* Familiarity with manufacturing processes or collaboration with manufacturing teams.* Experience with engineering documentation (Test Plans, Requirements, Validation Reports).Work Arrangement* Hybrid role - requires a minimum of 50% in-office presence at our San Francisco office.**Location:**San FranciscoActual compensation may vary depending on job-related factors including knowledge, skills, experience, and work location.**Estimated Pay Range**$83,200.00 - $104,000.00As a part of our core values, we ensure an inclusive workforce. We welcome and celebrate people of all backgrounds, experiences, skills, and perspectives. iRhythm Technologies, Inc. is an Equal Opportunity Employer. We will consider for employment all qualified applicants with arrest and conviction records in accordance with all applicable laws.iRhythm provides reasonable accommodations for qualified individuals with disabilities in job application procedures, including those who may have any difficulty using our online system. If you need such an accommodation, you may contact us at ***********************About iRhythm Technologies** iRhythm is a leading digital healthcare company that creates trusted solutions that detect, predict, and prevent disease. Combining wearable biosensors and cloud-based data analytics with powerful proprietary algorithms, iRhythm distills data from millions of heartbeats into clinically actionable information. Through a relentless focus on patient care, iRhythm's vision is to deliver better data, better insights, and better health for all.**Make iRhythm your path forward. Zio, the heart monitor that changed the game.**There have been instances where individuals not associated with iRhythm have impersonated iRhythm employees pretending to be involved in the iRhythm recruiting process, or created postings for positions that do not exist. Please note that all open positions will always be shown here on the iRhythm Careers page, and all communications regarding the application, interview and hiring process will come from a @irhythmtech.com email address. Please check any communications to be sure they come directly from @irhythmtech.com email address. If you believe you have been the victim of an imposter or want to confirm that the person you are communicating with is legitimate, please contact *********************. Written offers of employment will be extended in a formal offer letter from an @irhythmtech.com email address **ONLY**.For more information, see and At iRhythm, you'll have the opportunity to grow your skills and your career while impacting the lives of people around the world. Together, we are reimagining the way cardiac arrhythmias are diagnosed. We need curious problem solvers like you. With opportunities remotely, at our office, in manufacturing, and in locations across the globe, this is your chance to meaningfully shape the future of cardiac health, our company, and your career.**Driven By Purpose** - Cardiac health touches the lives of people all around us. Providing life-changing healthcare solutions that impact patients around the world drives us to bring our best every single day.**Growth Means Opportunity** - We are growing rapidly. And with that growth comes a wealth of opportunities to learn and advance at iRhythm. The potential to deepen your impact, seek new opportunities, and advance your career is yours to pursue.**Build the Future** - We are a boundary-pushing organization that values innovative thinking and impacts healthcare at a global level. The expectation is to think big and build the future you see for iRhythm, our patients, and yourself.### Get In TouchIntroduce yourself to our recruiters and we'll get in touch if there's a role that seems like a good match.
#J-18808-Ljbffr
$83.2k-104k yearly 4d ago
Security Engineer - Application & AI Security (REMOTE)
Enablecomp 3.7
Franklin, TN jobs
EnableComp provides Specialty Revenue Cycle Management solutions for healthcare organizations, leveraging over 24 years of industry-leading expertise and its unified
E360 RCM
™ intelligent automation platform to improve financial sustainability for hospitals, health systems, and ambulatory surgery centers (ASCs) nationwide. Powered by proprietary algorithms, iterative intelligence from 10M+ processed claims, and expert human-in-the-loop integration, EnableComp provides solutions across the revenue lifecycle for Veterans Administration, Workers' Compensation, Motor Vehicle Accidents, and Out-of-State Medicaid claims as well as denials for all payer classes. By partnering with clients to supercharge the reimbursement process, EnableComp removes the burden of payment from patients and provider organizations while enabling accelerated cash, higher and more accurate yield, clean AR management, reduced denials, and data-rich performance management. EnableComp is a multi-year recipient the Top Workplaces award and was recognized as Black Book's #1 Specialty Revenue Cycle Management Solution provider in 2024 and is among the top one percent of companies to make the Inc. 5000 list of the fastest-growing private companies in the United States for the last eleven years.
Position Summary
The SecurityEngineer (Application & AI Security) will serve as the technical implementation bridge between our security policy team and development operations. The SecurityEngineer will be embedded with development teams, writing code, configuring systems, and directly implementing security controls across applications, databases, and AI systems during a major Agentic AI platform transformation.Key Responsibilities
Bridge security policy and technical execution by translating organizational security requirements into practical, deployable solutions across applications, data environments, and AI systems.
Design, build, and deploy security controls across web applications, data pipelines, APIs, and Agentic AI systems to ensure confidentiality, integrity, and availability.
Implement secure-by-design practices throughout the software development lifecycle, including code-level remediations, configuration hardening, and secure infrastructure deployment.
Develop automation scripts and infrastructure-as-code to integrate security into CI/CD pipelines, enabling continuous compliance, secrets management, vulnerability scanning, and environment hardening.
Implement and operationalize AI-specific security frameworks by building guardrails for agentic models, securing data flows, and integrating AI security tooling into development workflows.
Perform hands-on technical security assessments, including penetration testing, threat modeling, and code reviews, and directly remediate identified vulnerabilities.
Collaborate with cloud and DevOps teams to deploy monitoring and detection controls and ensure secure configuration baselines across environments.
Provide practical security guidance and training to developers and engineers during architecture reviews, sprint planning, and project delivery.
Continuously evaluate and improve the organization's security posture through testing, feedback loops, and adoption of emerging best practices for AI and distributed systems.
Document security architectures, configurations, and implementation patterns to support ongoing operations, compliance, and knowledge sharing.
Other duties as required
Requirements & Qualifications
Bachelor's degree in Computer Science, Information Security, Engineering, or a related technical field required
3+ years in hands-on application security, DevSecOps, or securityengineering roles.
Proven experience building and configuring secure CI/CD pipelines (Jenkins, GitLab CI, GitHub Actions, Azure DevOps).
Equivalent combination of education and experience will be considered.
Deep proficiency with cloud security in AWS, Azure, or GCP environments.
Strong implementation experience with infrastructure as code (Terraform, CloudFormation) and container security (Docker, Kubernetes).
Strong scripting and automation skills (Python, Bash, PowerShell) for security tooling.
Versatility across web/API security, data pipeline security, microservices, and database security.
Understanding of security frameworks (NIST, ISO 27001, SOC 2) and compliance requirements (GDPR, HIPAA, PCI-DSS).
Hands-on experience deploying and configuring security scanning tools (SAST, DAST, SCA).
Excellent communication skills-ability to translate security requirements into working technical implementations.
Experience working embedded within cross-functional development teams.
Proven track record of hands-on problem-solving in fast-paced development environments.
Regular and predictable attendance.
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. Reasonable accommodations may be made to enable qualified individuals with disabilities to perform the essential functions
Special Considerations & Prerequisites
Practices and adheres to EnableComp's Core Values, Vision and Mission.
Hands-on experience with AI/ML security, model security, and data governance
Technical knowledge of LLM security, prompt injection prevention, and AI agent safety
Security certifications (CISSP, CEH, OSCP, CSSLP, or cloud security certifications)
Strong coding background in Python, Go, or similar languages.
Background in software development or engineering transitioning to security.
Direct experience implementing secrets management solutions (HashiCorp Vault, AWS Secrets Manager).
Practical experience with zero trust architecture implementation.
Familiarity with data security, ETL processes, and data warehouse security.
Experience with microservices architectures and distributed systems security.
EnableComp is an Equal Opportunity Employer M/F/D/V. All applicants will be considered for this position based upon experience and knowledge, without regard to race, color, religion, national origin, sexual orientation, ancestry, marital, disabled or veteran status. We are committed to creating and maintaining a workforce environment that is free from any form of discrimination or harassment.
EnableComp recruits, develops and retains the industry's top talent. As the employer of choice in the complex claims industry, EnableComp takes pride in our continuous commitment to building and maintaining a culture centered around fostering the professional growth and development of our people. We believe that investing in our employees is the key to our success, and we are dedicated to providing them with the tools, resources, and support they need to thrive and grow their career here. At EnableComp, we are committed to living up to our core values each and every day, and we believe that this commitment is what sets us apart from other companies. If you are looking for a company that values its employees and is dedicated to helping them achieve their full potential, then EnableComp is the place for you.
Don't just take our word for it! Hear what our people are saying:
“I love my job because everyone shares the same vision and is determined and dedicated. People care about you as a person and your professional growth. There is a genuine spirit of cooperation and shared goals all revolving around helping each other.”
- Revenue Specialist
“I enjoy working for EnableComp because of the Core Values we believe in. EnableComp stands true to these values from empowering employees to ecstatic clients. This company is family oriented and flexible, along with understanding the balance of work, life, and fun.”
- Supervisor, Operations
$82k-110k yearly est. Auto-Apply 60d+ ago
IT Network & Security Analyst II
Faith Regional Health Services 4.7
Norfolk, NE jobs
Work Status Details: Full Time | 80.00 Hours Every Two Weeks Exempt from Overtime: Exempt Shift Details: Evening and weekend work will be required as needed for projects. Department: Information Technology | Reports To: Manager-IT Infrastructure & Telecommunications
The mission of Faith Regional Health Services is to serve Christ by providing all people with exemplary medical services in an environment of love and care.
Summary:
Supports and maintains the network infrastructure and implements projects related to network security, hardware, and software. Responsible for ensuring a secure computing environment throughout the organization. Lead implementation of security services, appliances, systems, policies, and procedures for protecting information assets from threats, both external and internal. Provide advanced skills in identifying and eliminating security risks, threats, and vulnerabilities.
This position may be performed on-site, hybrid, or remotely with the following guidelines:
* The employee must reside in Nebraska.
* Successfully completes a 90-day on-site introductory period starting on day 1.
* If fully remote, may be required to come on-site up to 20%.
* Adherence to all other organizational remote work requirements and policies.
The listing of job duties contained in this job description is not all inclusive. Duties may be added or subtracted at any time due to the needs of the organization.
Responsibilities:
Essential Job Duties and Responsibilities:
1. Assist with the design, implementation, and maintenance of complex secure network technologies, including firewalls, switches, load balancers, and wireless systems. Act as a subject matter expert for existing network devices and services, ensuring the environment remains secure and efficient.
2. Maintain accurate inventory records and problem logs for all network equipment. Keep detailed network diagrams up to date. Evaluate, test, and implement hardware changes to enhance network functionality, ensuring seamless user experience after all upgrades.
3. Apply advanced problem-solving skills to quickly resolve network and security issues reported by users or automated systems. Maintain an in-depth knowledge of industry-standard networking and security concepts and technologies.
4. Provide primary support for core network protocols such as IP, TCP, Spanning Tree, OSPF, BGP, VRRP, and ARP, as well as application-level interactions (e.g., HTTP, SSL).
5. Assist in the design, implementation, and maintenance of complex system infrastructures. This includes implementing, testing, and supporting both hardware and software systems to ensure operational stability.
6. Collaborate with information security teams and external vendors to proactively identify, assess, monitor, and report on security incidents and cyber risks. Analyze data from security platforms, monitor intrusion detection reports and security logs daily, and stay informed on current cyber threats and vulnerabilities. Document and respond to potential security breaches following established organizational procedures.
7. Provide day-to-day operational support to protect information systems from unauthorized access. Interface with users to understand and address their security needs while ensuring they adhere to security protocols. Implement policies and procedures that comply with industry best practices and frameworks like HIPAA, PCI, ISO, SANS Top 20, and DISA STIG.
8. Demonstrate knowledge of network security technologies such as IDS/IPS, DLP, and PKI. Stay current with evolving security trends, risks, and technologies through ongoing research, and keep up to date on testing tools and techniques.
9. Prepare for, conduct, and remediate the results of internal and external audits, security/risk assessments, and vulnerability scans of the enterprise environment.
10. Provide exceptional customer service when troubleshooting and interacting with employees, physicians, and clinicians. Assist with vendor and application security evaluations and support the organization's security awareness training programs.
Hours will be dependent on patient census and workload. Ability and willingness to work a flexible schedule, to include after-hours and weekends as necessary.
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Other information:
Job Requirements:
The requirements listed below must be representative of the knowledge, skills, minimum education, training, licensure, experience, and/or ability required.
EDUCATION (Minimum Requirements for Position):
Associate's Degree required.
Bachelor's Degree preferred.
CERTIFICATES, LICENSES, REGISTRATIONS:
Current, valid driver's license issued in the state of legal residence required.
Operate FRHS owned vehicles required.
IT Certification in IT Security preferred.
Previous Experience Requirements:
EXPERIENCE:
2 years of previous experience in IT Networking or Security field preferred.
Combination of 6 years of education and experience in position field preferred.
Skills/Knowledge Requirements:
SKILLS (If Applicable):
Language Skills - Ability to read, write, speak, and understand the English language required.
KNOWLEDGE (If Applicable):
Network protocols: IP, TCP, Spanning Tree, OSPF, BGP, VRRP, ARP and applications interaction at the network layer (e.g. HTTP, SSL, TCP, etc.) required.
Industry-standard networking/security concepts and technologies required.
Industry best practices and compliance frameworks, including HIPAA, PCI, ISO, HITECH, SANS Top 20 preferred.
Network security technologies, e.g. IDS/IPS, DLP, PKI, SSL, certificates, etc. required.
Network devices and services, i.e. firewalls, switches, load balancers, remote access/VPN, DNS, wireless, etc. required.
Other Certifications/Requirements:
Your own personal smart phone (Faith Regional mobile apps, as well as consent to receive messages by SMS/MMS on personal phone, may be necessary to perform the functions of this position) required.
Faith Regional Health Services is an equal opportunity employer that is committed to diversity and inclusion in the workplace. We prohibit discrimination and harassment of any kind based on race, color, sex, religion, sexual orientation, national origin, disability, genetic information, pregnancy, or any other protected characteristic as outlined by federal, state, or local laws.
$65k-84k yearly est. 6d ago
Information Security Business Analyst II
Massachusetts Eye and Ear Infirmary 4.4
Somerville, MA jobs
Site: Mass General Brigham Incorporated
Mass General Brigham relies on a wide range of professionals, including doctors, nurses, business people, tech experts, researchers, and systems analysts to advance our mission. As a not-for-profit, we support patient care, research, teaching, and community service, striving to provide exceptional care. We believe that high-performing teams drive groundbreaking medical discoveries and invite all applicants to join us and experience what it means to be part of Mass General Brigham.
Job Summary
Summary
The Information Security Analyst II independently operates existing processes to operate security controls within their domain. They will identify improvements in these processes, and may be tasked with executing those improvements.
The Information Security Analyst II works across multiple teams within MGB Digital, and participates in broader projects to drive improvements in the MGB information security posture. They leverage critical thinking and problem-solving skills in their day to day work, and may mentor more junior team members.
The Information Security Analyst II will support the cybersecurity program management team with operations, including process improvement, resource management, and performance tracking. The role will focus on building ongoing collaboration and standardization across Digital Information Security (DIS) to help assure that the program matures and improves from year to year. Focused areas of support will include overall program goals tracking against Digital's goals, strategic planning and performance measurement.
Essential Functions
-Independently operates existing processes and proactively identifies and optimizes improvement in existing processes. May individually drive improvements in these processes.
-May mentor junior team members, sharing knowledge and best practices.
-Works across multiple teams to drive security improvements for MGB.
-Participates in project-level efforts to improve cybersecurity capabilities.
-Works independently to stay abreast of changes in domain, suggesting relevant improvements to MGB cybersecurity posture.
Qualifications
Education Associate's Degree Related Field of Study required or Bachelor's Degree Related Field of Study required Can this role accept experience in lieu of a degree? Yes Licenses and Credentials Experience Relevant experience 2-3 years required Knowledge, Skills and Abilities - Strong understanding of cybersecurity concepts within their domain. - High proficiency with the tools and solutions supported by the team. - Solid understanding of technology and design principles. - Strong problem-solving skills and analytical thinking to identify solutions to complex problems, and to optimize existing solutions. - An ability to work on several tasks simultaneously and pay attention to sources of information from inside and outside one's network within an organization. - Excellent prioritization capabilities, with an aptitude for breaking down work into manageable parts, effectively assessing the priority and time required to complete each part. - Excellent communication and teamwork skills to share knowledge, present ideas, and lead discussions.
Additional Job Details (if applicable)
M-F Eastern Business Hours required
Hybrid onsite Flexible working model required weekly includes onsite in office (number of days weekly can vary, must be flexible for business needs)
1-2 onsite days per week
Remote working days require stable, secure, quiet, compliant working station
Remote Type
Hybrid
Work Location
399 Revolution Drive
Scheduled Weekly Hours
40
Employee Type
Regular
Work Shift
Day (United States of America)
Pay Range
$73,798.40 - $107,400.80/Annual
Grade
6
At Mass General Brigham, we believe in recognizing and rewarding the unique value each team member brings to our organization. Our approach to determining base pay is comprehensive, and any offer extended will take into account your skills, relevant experience if applicable, education, certifications and other essential factors. The base pay information provided offers an estimate based on the minimum job qualifications; however, it does not encompass all elements contributing to your total compensation package. In addition to competitive base pay, we offer comprehensive benefits, career advancement opportunities, differentials, premiums and bonuses as applicable and recognition programs designed to celebrate your contributions and support your professional growth. We invite you to apply, and our Talent Acquisition team will provide an overview of your potential compensation and benefits package.
EEO Statement:
0100 Mass General Brigham Incorporated is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religious creed, national origin, sex, age, gender identity, disability, sexual orientation, military service, genetic information, and/or other status protected under law. We will ensure that all individuals with a disability are provided a reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. To ensure reasonable accommodation for individuals protected by Section 503 of the Rehabilitation Act of 1973, the Vietnam Veteran's Readjustment Act of 1974, and Title I of the Americans with Disabilities Act of 1990, applicants who require accommodation in the job application process may contact Human Resources at **************.
Mass General Brigham Competency Framework
At Mass General Brigham, our competency framework defines what effective leadership “looks like” by specifying which behaviors are most critical for successful performance at each job level. The framework is comprised of ten competencies (half People-Focused, half Performance-Focused) and are defined by observable and measurable skills and behaviors that contribute to workplace effectiveness and career success. These competencies are used to evaluate performance, make hiring decisions, identify development needs, mobilize employees across our system, and establish a strong talent pipeline.
$73.8k-107.4k yearly Auto-Apply 9d ago
Application Security Engineer
Alignment Healthcare 4.7
Orange, CA jobs
Alignment Health is breaking the mold in conventional health care, committed to serving seniors and those who need it most: the chronically ill and frail. It takes an entire team of passionate and caring people, united in our mission to put the senior first. We have built a team of talented and experienced people who are passionate about transforming the lives of the seniors we serve. In this fast-growing company, you will find ample room for growth and innovation alongside the Alignment Health community. Working at Alignment Health provides an opportunity to do work that really matters, not only changing lives but saving them. Together.
This position is responsible for identifying, analyzing, and helping with remediate security vulnerabilities within our applications. This role requires a strong understanding of application security principles, hands-on experience with various security testing methodologies, and excellent communication skills to collaborate effectively with development teams and other stakeholders.
Job Responsibilities:
Conduct static application security testing (SAST), dynamic application security testing (DAST), and interactive application security testing (IAST) on a continuous basis.
Identify, triage, and validate security vulnerabilities using both automated tools and manual review.
Work closely with software development and DevOps teams to provide clear, actionable guidance on how to fix vulnerabilities and implement secure coding practices.
Help integrate security controls and checks into the software development lifecycle (SDLC) and CI/CD pipelines.
Drive and support application security reviews and threat modeling.
Manage and configure a suite of application security tools, ensuring their effective use and reporting.
Stay up-to-date with the latest security threats, trends, and technologies, and conduct research on new vulnerabilities and attack vectors.
Contribute to the creation and maintenance of application security policies, standards, and procedures to guide development teams and ensure compliance.
Develop and deliver security awareness and secure coding training to engineering teams.
Support and lead third-party penetration testing.
Job Requirements:
Experience:
Required:
5-7+ years of progressive experience in information security, with a strong focus on application security testing and vulnerability management.
Proven track record of working directly with developers and engineering teams to identify and remediate security vulnerabilities in a fast-paced environment.
Experience in a large-scale enterprise environment with complex application portfolios.
Preferred:
Experience in healthcare or another highly regulated field.
Education:
Required:
Bachelor's degree or equivalent work experience in Computer Science, Information Security, or a related technical discipline.
Preferred:
Relevant professional certifications such as Offensive Security Certified Professional (OSCP), GIAC Web Application Penetration Tester (GWAPT), or Certified Secure Software Lifecycle Professional (CSSLP) are highly desirable.
ISC2 Certified Information Systems Security Professional (CISSP)
Specialized Skills:
Required:
Experience with general threat hunting techniques and tools.
Experience with one or more programming languages (i.e., C#, Scala, Python).
Essential Physical Functions:
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
1. While performing the duties of this job, the employee is regularly required to talk or hear. The employee regularly is required to stand, walk, sit, use hand to finger, handle or feel objects, tools, or controls; and reach with hands and arms.
2. The employee frequently lifts and/or moves up to 10 pounds. Specific vision abilities required by this job include close vision and the ability to adjust focus.
Pay Range: $113,332.00 - $169,999.00
Pay range may be based on a number of factors including market location, education, responsibilities, experience, etc.
Alignment Health is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, age, protected veteran status, gender identity, or sexual orientation.
*DISCLAIMER: Please beware of recruitment phishing scams affecting Alignment Health and other employers where individuals receive fraudulent employment-related offers in exchange for money or other sensitive personal information. Please be advised that Alignment Health and its subsidiaries will never ask you for a credit card, send you a check, or ask you for any type of payment as part of consideration for employment with our company. If you feel that you have been the victim of a scam such as this, please report the incident to the Federal Trade Commission at ******************************* If you would like to verify the legitimacy of an email sent by or on behalf of Alignment Health's talent acquisition team, please email ******************.
$113.3k-170k yearly Auto-Apply 60d+ ago
Associate Information Security Analyst
Martin's Point Health Care 3.8
Portland, ME jobs
Join Martin's Point Health Care - an innovative, not-for-profit health care organization offering care and coverage to the people of Maine and beyond. As a joined force of "people caring for people," Martin's Point employees are on a mission to transform our health care system while creating a healthier community. Martin's Point employees enjoy an organizational culture of trust and respect, where our values - taking care of ourselves and others, continuous learning, helping each other, and having fun - are brought to life every day. Join us and find out for yourself why Martin's Point has been certified as a "Great Place to Work" since 2015.
Position Summary
The Associate Information Security Analyst will be a contributor to security policies, monitoring and analyzing traffic and logs, and assisting in protecting the organization's IT systems and software from malicious activity and technology breaches. With general guidance and coaching, participates in security risk assessments, performing and analyzing vulnerability scans, working with others in IT and the business to remediate and eliminate risks. The Associate Information Security Analyst is proficient in security and technical knowledge, standards development, documentation of the security program, policies and procedures, risk identification and remediation, reporting, and awareness education related to information security.
Job Description
Key Outcomes:
Monitors SIEM, IDS/IPS, endpoint protections, and identity management solutions.
Assists in the administration and engineering of the security infrastructure including the single sign-on, multi-factor authentication, business continuity, and GRC tools.
Assists coordinating group-wide and company-wide information security matters such as incident response, intrusion detection management, and cyber security advisories.
Identifies information and IT security risks including IT technical implementations or business processes.
Under general direction, monitors and audits information systems, networks, and databases to identify and isolate occurrences of unauthorized activity; prepares and coordinates corrective actions.
Assists with conducting security assessments and audits, penetration testing, IT forensic investigations and incident management.
Assists with performing and/or coordinating regular security assessments of existing or new infrastructure or applications.
Coordinates response to information security incidents and threats.
Assesses and coordinates information and cyber vulnerabilities throughout the organization.
Reviews and enforces information security policy, standards and guidelines for business operations and technology implementations.
Education/Experience:
Bachelors degree in CIS, CS, Business Administration, or similar, or combination of equivalent education and experience
1+ years' experience with information security technologies, security monitoring, incident response, open-source technologies, and various operating systems
Healthcare experience and familiarity with HIPAA/HITECH, PCI-DSS, and NIST 800-53 is highly desirable
Required License(s) and/or Certification(s):
Global Information Assurance Certification (GIAC), Security+, Offensive Security Certified Professional (OSCP), and/or Certified Ethical Hacker (C|EH) is a plus.
Skills/Knowledge/Competencies (Behaviors):
Customer Focus
Act as an owner of the business and seek to understand needs.
Able to communicate effectively and clearly to all levels of the IT organization and business when addressing a challenge or identified opportunity - take ownership.
Business Acumen
Understands the business model of MPHC and can apply that context to projects
Always looks for ways to improve processes and create value for business partners.
Understands how organizational workflows affect data meaning and use.
Drive for Results
Participates in enterprise architectural/analytical responsibilities and can plan/scope several inter-related activities to create efficiencies
Assists business stakeholders in making informed decisions.
Strong troubleshooting skills
Meticulously reviews their work and openly receives 3rd party review.
Continuous Learning
Knows limitations and is open to learning from others, especially when cross-team collaborations are needed.
Seeks new knowledge and remains current in the industry.
Process Improvement
Participates in continuous process improvement efforts within the team.
Consistently identifies opportunities for improvement in processes and work products
Ability to document and create standard work
Dealing with Ambiguity
Able to communicate complex ideas and knows who to engage in problem solving.
Understand when to bring other team members onboard.
Proactively engages in learning to bring understanding to ambiguous situations.
Information Security Analyst
Demonstrates an understanding of and alignment with Martin's Point Values
Thorough understanding of SIEMs, incident response, disaster recovery, contingency planning, encryption technologies, intrusion detection/prevention systems, and/or vulnerability management
Knowledge of Microsoft and Linux operating systems
Project management and documentation skills
Interpersonal and communication skills and the ability to work effectively with a wide range of constituencies in a diverse community
Maintains industry awareness regarding all information and cyber security trends and directions
Ability to organize and prioritize multiple tasks independently
Thorough understanding of traditional and mobile operating systems and applications
Ability to test and analyze complex system, network, and database security settings
Understands security protocols and monitoring tools
Has knowledge of how best practices integrate with company objectives
There are additional competencies linked to individual contributor, provider, and leadership roles. Please consult with your leader to discuss additional competencies that are relevant to your position.
This position is not eligible for immigration sponsorship.
We are an equal opportunity/affirmative action employer.
Martin's Point complies with federal and state disability laws and makes reasonable accommodations for applicants and employees with disabilities. If a reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact *****************************
Do you have a question about careers at Martin's Point Health Care? Contact us at: *****************************
$95k-132k yearly est. Auto-Apply 13d ago
Information Security Associate or Specialist
DHD Consulting 4.3
Alpharetta, GA jobs
The use of IT (Information Technology) infrastructure in the company is vital for daily operation. The IS (Information Security) Specialist should Provide secure Information Technology infrastructure service to the company as well as companywide employees and staff.
Role Description.
Define and implement Macro (Servers, Groups and Shared resource) and Micro (Personal and Single) IT infrastructure. Analyze, Plan, Design, Develop and Implement IT Infrastructure and IT Security solutions to support company IT requirements. Analyze and prevent any Information risk ensuring the companys information integrity. Define, maintain and monitor the execution of IS and IT policies. Execute and monitor company IT/IS Compliance.
Essential Duties and Responsibilities
-Monitoring and maintaining computer systems and networks
-Responding in a timely manner to service issues and requests
-Providing technical support across the company
-Support equipment repair and replacement service
-Testing Benchmarking new technology
-Maintain and execute IT Training program for new employs
-Monitor IT/IS Infrastructure (including servers and network devices) to ensure data integrity
-Reporting of daily system issues.
-Analyze and propose system improvements.
-Documentation related to IT/IS policies, issues, and procedures.
-Participation and active analyst, designer, and developer in IT projects.
-Monitoring of IT/IS infrastructure-related expenses.
-Other duties as assigned.
Requirements
Qualifications: Listed below are the minimum and/or desired qualifications of the position including education, work experience, and knowledge & skills that are required to perform satisfactorily in the position:
Education and Work Experience:
-Vocational or undergraduate degree in information systems and computer science or related field.
-One (1) to three (3) years of information systems, computer science and/or IT-related experience.
Knowledge and Skills:
-PC and Server management
-IT Hardware and Software installation
-Initiative skills
-Problem-solving skills
-Understanding of IT infrastructure and application architectures
-Great Social and Communication Skills
-Great Oral and Written Communication Skills
-System process analysis and design capabilities/experience
-Server Operating systems (Windows Server, Linux, HP-UX, Unix, Sun Solaris)
-Antivirus, NAC, DLP, MDM and other IS Solutions
-IS Related definition and policies (ex. ISO 27001)
-Networking (Cisco/HP) and network devices (Routers and Switch)
-VPN
-TCP/IP, UDP, Network standards
-LDAP, Active Directory and Exchange
-Access Control
-Security Cameras
-Firewall, Web Filter and other network security appliance solutions
-Database systems (SQL Server/MySQL/Oracle) and programming skill (is a plus)
-MS Office skills (especially Excel skills)
Physical Demands:
-Position requires sitting at a desk working on a computer for at least 2/3 of time.
-Position requires regular and reliable attendance.
-Position requires local travel up to 10% of the time.
$76k-109k yearly est. 60d+ ago
Information Security Governance, Risk and Compliance Analyst
Green Thumb Industries 4.4
Chicago, IL jobs
The Role
We're looking for an Information Security Governance, Risk & Compliance Analyst to join our growing Information Security team. This role will be reporting to the Manager of Information Security Governance, Risk & Compliance. Our security team works to create a strong Information Security function within GTI that enables the business to continue its tremendous growth. The Information Security Governance, Risk & Compliance Analyst is responsible for maintaining continuous compliance with security policies, industry laws, and regulations (HIPAA, SOX, NIST, etc.). The candidate must communicate effectively with business partners and team members to help raise the level of security awareness, security compliance, and security risk. The candidate will perform environment-specific risk assessments factoring in both qualitative and quantitative risks and assist with the deployment of various controls based on those assessments. This role will also involve ongoing monitoring and improvement of security governance, ensuring a proactive approach to risk management.
The role is based out of our Chicago, office. While the role is primarily remote, you need to live in the Chicagoland area and commute to the office on an as needed basis.
Responsibilities
Own the relationship working with IT and business stakeholders to perform ongoing internal and vendor risk assessments, providing reporting to stakeholders, and ensuring appropriate action is taken.
Update and track KPIs from the Information Security risk register and work with stakeholders on developing Corrective Action Plans to address risks.
Provide guidance to newer staff working with internal IT stakeholders for vulnerability management, ensuring vulnerabilities are remediated in accordance with policy and SLAs.
Own the process for working with IT and business stakeholders to perform ongoing compliance reviews in line with security policies, information security regulations (HIPAA, SOX/ITGC), and security frameworks (NIST, MITRE, etc.).
Assist with ongoing internal operations and tasks, including ITGC security reviews.
Spearhead the ongoing internal and external SOX and HIPAA audits and other security audits that are relevant to GTI's business.
Provide updates and insight during the development and maintenance of Information Security policies, standards and procedures, aligning with NIST.
Lead the identification of security training and awareness initiatives for the organization.
Participate in incident response tabletops, business continuity tests, and other compliance activities and exercises.
Maintain KPIs and KRIs for Information Security risk & compliance activities.
Execute tasks as a member of the Information Security team as assigned by management.
Provide mentorship and guidance to Associate Information Security GRC Analysts.
Stay up to date on relevant laws and regulations to ensure continuous compliance and audit readiness.
Collaborate with the IT and security teams in response to security incidents, ensuring proper documentation and reporting.
Qualifications
3+ years of experience with responsibilities relating to security and compliance.
Bachelor's degree or higher in Information Security or Information Technology may help you stand out but is not required. Demonstrated work experience can be substituted.
Strong written and oral communication skills.
Strong conceptual understanding of Information Security theories.
Knowledge of network, application, and cloud security controls.
Knowledge of regulatory frameworks and compliance standards such as NIST, MITRE, OWASP, HIPAA, PCI-DSS and SOX.
Strong analytical and problem-solving skills with well-organized and structured work habits, and the ability to identify and mitigate risks.
Security certifications, such as CRISC, CISA are preferred, but not required.
We're doing some big things, and we'll find some roadblocks along the way, big and small. A big part of this role is keeping an even keel and finding the route through or around the obstacles.
This role requires lots of communication with customers and everyone at GTI. Your colleagues will rely on your ability to translate security requirements into digestible bits of information for them. Customers will expect you to quickly articulate components of the GTI security program to help them assess risk, including as part of the business development process.
An insatiable intellectual curiosity and the ability to learn quickly in a complex space.
Additional Requirements
Must pass any and all required background checks
Must be and remain compliant with all legal or company regulations for working in the industry
Must be a minimum of 21 years of age
#LI-HYBRID
The pay range is competitive and based on experience, qualifications, and/or location of the role. Positions may be eligible for a discretionary annual incentive program driven by organization and individual performance.
Green Thumb Pay Range$80,000-$100,000 USD