About the role
We're looking for a detail oriented, technically skilled engineer to join our Application Security team. This role offers opportunities to influence the group's growth and direction while integrating security within the entire Software Development Life Cycle (SDLC).
Security Engineers will collaborate with Product and Engineering teams to embed security into all phases of the SDLC from feature design and implementation to deployment. They also establish and evaluate authentication, authorization, and privacy controls for B2C, B2B and M2M entity types and use cases.
They will identify, prioritize, and remediate vulnerabilities identified via internal and third party penetration testing, Software Composition Analysis (SCA), Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST). They will also deploy, maintain and tune the tools used to perform this testing.
Security Engineers serve as subject matter experts on authentication and authorization security, partnering with product and engineering teams to implement security and privacy best practices for healthcare applications.
The ideal candidate will have experience securing, hardening, and identifying vulnerabilities in web applications, RESTful and GraphQL APIs, and mobile applications (iOS and Android) in a cloud hosted microservice environment.
The ideal candidate will also have experience risk assessing the results of automated SCA, SAST and DAST to validate severity before assigning to engineers for remediation.
They may also have experience in securing Generative AI LLM services, including, but not limited to security guardrails to prevent jailbreaks, sensitive information disclosure, data/model poisoning, and safety guardrail verification and testing.
What You'll Accomplish
Implement and maintain automated security scanning tools (SCA, SAST, DAST) and perform manual and AI assisted security assessments including source code review to identify and remediate vulnerabilities in Hinge Health web applications, mobile applications and API endpoints.
Enable the product teams to create secure by design product features and services by working alongside product managers and engineers during the design phase of projects including Generative AI projects.
Assist with third party security assessments and penetration tests of Hinge Health web applications, API endpoints, and mobile applications, including interpretation of results and verification of remediations.
Contribute to the improvement of Software Development Life Cycle management policies, procedures, and standards.
Basic Qualifications
3+ years of experience in application security, product security, or related security engineering roles
Experience securing web applications, mobile applications (iOS/Android), or API endpoints
Experience with automated security testing, including configuring and automating security scans as part of the CI/CD process, and interpreting the results and working directly with engineers on prioritization and remediation.
Experience in examining source code in multiple languages to evaluate security controls and identifying common coding and design vulnerabilities. Experience with OWASP Top 10 and other common security flaw patterns.
Demonstrated ability to collaborate with engineering and product teams to address security concerns.
Preferred Qualifications
Experience securing applications in Health Care, securing ePHI and HIPAA/HITECH regulations.
Experience with modern authentication and authorization technologies including OAuth 2.0, OIDC, SAML, JWT validation, SSO integrations, MFA/OTP implementations, API tokens, and identity platforms such as Auth0 or Okta. Understanding of session management, refresh tokens, and secure authentication flows for B2C, B2B, and M2M use cases.
Experience assessing the security and safety of Generative AI LLM solutions and in evaluating and implementing solutions for their continuous monitoring
Familiarity with HITRUST CSF and NIST control frameworks.
Experience in Threat Modeling
Experience performing security assessments and secure design of hardware and firmware of medical devices communicating over Bluetooth
Experience with any of the following, deploying web based services on AWS infrastructure, Kubernetes, Typescript, ReactNative, Python, Go, Ruby on Rails, GraphQL, IaC using Terraform.
Incident Handling: Be able to work as a subject matter expert in the security controls, internal communications, and infrastructure of Hinge Health applications during security incidents.
Hinge Health Hybrid Model
We believe that remote work and in-person work have their own advantages and disadvantages, and we want to be able to leverage the best of both worlds. Employees in hybrid roles are required to be in the office 3 days/week. The San Francisco office has a dog-friendly workplace program.
Compensation
This position will have an annual salary, plus equity and benefits. Please note the annual salary range is a guideline, and individual total compensation will vary based on factors such as qualifications, skill level, competencies, and work location. The annual salary range for this position is $192,000 - $230,400.
About Hinge Health
Hinge Health leverages software, including AI, to largely automate care for joint and muscle health, delivering an outstanding member experience, improved member outcomes, and cost reductions for its clients. The company has designed its platform to address a broad spectrum of MSK care-from acute injury, to chronic pain, to post-surgical rehabilitation-and the platform can help to ease members' pain, improve their function, and reduce their need for surgeries, all while driving health equity by allowing members to engage in their exercise therapy sessions from anywhere. The company is headquartered in San Francisco, California.
Learn more at **************************
What You'll Love About Us
Inclusive healthcare and benefits: On top of comprehensive medical, dental, and vision coverage, we offer employees and their family members help with gender-affirming care, tools for family and fertility planning, and travel reimbursements if healthcare isn't available where you live.
Planning for the future: Start saving for the future with our traditional or Roth 401k retirement plan options which include a 2% company match.
Modern life stipends: Manage your own learning and development
Culture & Engagement
Hinge Health is an equal opportunity employer and prohibits discrimination and harassment of any kind. We make employment decisions without regards to race, color, religion, sex, sexual orientation, gender identity, national origin, age, veteran status, disability status, pregnancy, or any other basis protected by federal, state or local law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. We provide reasonable accommodations for candidates with disabilities. If you feel you need assistance or an accommodation due to a disability, let us know by reaching out to your recruiter.
By submitting your application you are acknowledging we are using your personal data as outlined in personnel and candidate privacy policy.
#J-18808-Ljbffr
$192k-230.4k yearly 2d ago
Looking for a job?
Let Zippia find it for you.
Senior Security Engineer II (DevSecOps)
Aledade, Inc. 4.1
Bethesda, MD jobs
As a Senior Security Engineer II at Aledade, we play a central role in helping secure our enterprise, cloud native environments, and applications. We're looking for security engineers that understand data and automation are important ingredients to our mission and know how to actively employ these ingredients at scale. Beyond the technical expertise, we value individuals who can partner cross-functionally across various teams, driving impactful outcomes and further securing our digital landscape.
Primary Duties
Working cross functionally to design, build, and operate solutions that continuously improve and automate our security capabilities
Leveraging data to understand trends, metrics, and opportunities to improve our security posture and then helping execute on those opportunities with stakeholders
Leading and enhancing incident response efforts, spearheading analysis, containment, and mitigation strategies in a cross-functional environment to ensure effective resolution and remediation of security incidents
Helping craft and refine security documentation pertinent to our Security Program, such as policies, standards, baselines, and standard operating procedures
Mentoring and coaching more junior engineers or analysts
Minimum Qualifications
BS / BTech (or higher) in Computer Science, Information Technology, Cybersecurity or a related field, 8 years security domain experience without degree
4+ years of experience acting as a trusted advisor in a team setting, solving for short-term and long-term business value
4+ years of experience coaching other engineers or analysts
Domain Specific
6+ years of experience in securing and deploying applications within Cloud Native environments
5+ years of experience in a dedicated DevOps/DevSecOps/SRE role with focus on establishing secure SDLC and DevSecOps processes.
Experience in scripting languages such as Python and Bash.
Experience with Cloud Native Software Development environments and practices with a focus on multi-cloud deployments in AWS, Azure and/or GCP.
Preferred KSA's
Prior experience working in the healthcare industry with health-tech systems, like Electronic Health Records, Clinical data, etc.
Prior experience with a focus on tooling, automation, and distributed systems development is preferred.
Experience generating automated metrics to measure service and program effectiveness and consistency
Strong communication skills, both written and verbal, with the capability to articulate complex technical issues to a diverse audience
Domain Specific
Experience with continuous integration tools (e.g. Cloud formation, Code deploy, Jenkins, CircleCI, Codefresh, Github Actions etc.).
Experience with configuration management platforms (e.g. Ansible, Chef, Salt).
Hands-on experience using Terraform, Python and/or other orchestration platforms at scale.
Familiarity with Agile and waterfall development methodologies.
Familiarity with automated testing methodologies, and continuous integration concepts.
Experience in creating, deploying, maintaining, and troubleshooting Docker images.
Experience in scoping, deploying, maintaining and troubleshooting Kubernetes clusters.
Experience with deploying policies with AWS Control tower, Azure Security hub, Google Resource Manager etc.
Physical Requirements
Sitting for prolonged periods of time. Extensive use of computers and keyboard. Occasional walking and lifting may be required.
Who We Are
Aledade, a public benefit corporation, exists to empower the most transformational part of our health care landscape - independent primary care. We were founded in 2014, and since then, we've become the largest network of independent primary care in the country - helping practices, health centers and clinics deliver better care to their patients and thrive in value-based care. Additionally, by creating value-based contracts across a wide variety of health plans, we aim to flip the script on the traditional fee-for-service model. Our work strengthens continuity of care, aligns incentives and ensures primary care physicians are paid for what they do best - keeping patients healthy. If you want to help create a health care system that is good for patients, good for practices and good for society - and if you're eager to join a collaborative, inclusive and remote-first culture - you've come to the right place.
What Does This Mean for You?
At Aledade, you will be part of a creative culture that is driven by a passion for tackling complex issues with respect, open-mindedness and a desire to learn. You will collaborate with team members who bring a wide range of experiences, interests, backgrounds, beliefs and achievements to their work - and who are all united by a shared passion for public health and a commitment to the Aledade mission.
In addition to time off to support work-life balance and enjoyment, we offer the following comprehensive benefits package designed for the overall well-being of our team members:
Flexible work schedules and the ability to work remotely are available for many roles
Health, dental and vision insurance paid up to 80% for employees, dependents and domestic partners
Robust time-off plan (21 days of PTO in your first year)
Two paid volunteer days and 11 paid holidays
12 weeks paid parental leave for all new parents
Six weeks paid sabbatical after six years of service
Educational Assistant Program and Clinical Employee Reimbursement Program
401(k) with up to 4% match
Stock options
And much more!
At Aledade, we don't just accept differences, we celebrate them! We strive to attract, develop and retain highly qualified individuals representing the diverse communities where we live and work. Aledade is committed to creating a diverse environment and is proud to be an equal opportunity employer. Employment policies and decisions at Aledade are based on merit, qualifications, performance and business needs. All qualified candidates will receive consideration for employment without regard to age, race, color, national origin, gender (including pregnancy, childbirth or medical conditions related to pregnancy or childbirth), gender identity or expression, religion, physical or mental disability, medical condition, legally protected genetic information, marital status, veteran status, or sexual orientation.
Privacy Policy: By applying for this job, you agree to Aledade's Applicant Privacy Policy available at *************************************************
#J-18808-Ljbffr
$102k-141k yearly est. 2d ago
Senior Security Engineer I
Aledade 4.1
Bethesda, MD jobs
As a Senior Security Engineer I at Aledade, you will play a central role in enhancing the security posture of our enterprise, cloud-native environments, and applications. We are seeking a dedicated professional with in-depth knowledge of security principles, standards, and best practices to help safeguard our systems and support our security compliance initiatives.
In this role, you will work to design, implement, and maintain robust security solutions across diverse platforms and technologies. You will collaborate closely with various teams to ensure alignment between security solutions and organizational requirements, enabling secure operations across the enterprise. Your ability to partner cross-functionally will be key to driving impactful security outcomes and strengthening our digital landscape.
Your expertise will be crucial as we continue to mature our security capabilities and maintain our commitment to protecting critical systems and data.
Primary Duties
Working cross-functionally to design, build, and operate solutions that improve and mature our security capabilities
Leveraging data to understand trends, metrics, and opportunities to improve our security posture, researching options, and then making recommendations as options to secure those opportunities with stakeholders
Leading and enhancing incident / issues response efforts, spearheading analysis, containment, and mitigation strategies in a cross-functional environment to ensure effective resolution and remediation of security incidents / issues
Helping craft and refine security documentation pertinent to our Security Program, such as policies, standards, baselines, and standard operating procedures
Minimum Qualifications
BS / BTech (or higher) in Computer Science, Information Technology, Cybersecurity or a related field, 6 years security domain experience without degree.
4+ years combined experience as a security engineer in an enterprise environment (preferably cloud) across multiple disciplines.
3+ years of relevant work experience in security posture management.
2+ years of experience acting as a trusted technical decision-maker in a team setting, solving for short-term and long term business value.
Preferred KSA's
Prior experience working in the healthcare industry with health-tech systems, like Electronic Health Records, Clinical data, etc.
Experience in scripting languages such as Python and Bash is required.
Experience with Cloud Native Software Development environments and practices with a focus on multi-cloud deployments in AWS, Azure and/or GCP is required.
Prior experience with a focus on tooling, automation, and distributed systems development is preferred.
Experience with continuous integration tools (e.g. Cloud formation, Code deploy, Jenkins, CircleCI, Codefresh, Github Actions etc.).
Experience with configuration management platforms (e.g. Ansible, Chef, Salt).
Hands-on experience using Terraform, Python and/or other orchestration platforms at scale.
Familiarity with Agile and waterfall development methodologies.
Familiarity with automated testing methodologies, and continuous integration concepts.
Experience in creating, deploying, maintaining, and troubleshooting Docker images.
Experience in scoping, deploying, maintaining and troubleshooting Kubernetes clusters.
Experience with deploying policies with AWS Control tower, Azure Security hub, Google Resource Manager etc.
Experience generating automated metrics to measure service and program effectiveness and consistency
Strong communication skills, both written and verbal, with the capability to articulate complex technical issues to a diverse audience
Physical Requirements
Sitting for prolonged periods of time. Extensive use of computers and keyboard. Occasional walking and lifting may be required.
Who We Are:
Aledade, a public benefit corporation, exists to empower the most transformational part of our health care landscape - independent primary care. We were founded in 2014, and since then, we've become the largest network of independent primary care in the country - helping practices, health centers and clinics deliver better care to their patients and thrive in value-based care. Additionally, by creating value-based contracts across a wide variety of health plans, we aim to flip the script on the traditional fee-for-service model. Our work strengthens continuity of care, aligns incentives and ensures primary care physicians are paid for what they do best - keeping patients healthy. If you want to help create a health care system that is good for patients, good for practices and good for society - and if you're eager to join a collaborative, inclusive and remote-first culture - you've come to the right place.
What Does This Mean for You?
At Aledade, you will be part of a creative culture that is driven by a passion for tackling complex issues with respect, open-mindedness and a desire to learn. You will collaborate with team members who bring a wide range of experiences, interests, backgrounds, beliefs and achievements to their work - and who are all united by a shared passion for public health and a commitment to the Aledade mission.
In addition to time off to support work-life balance and enjoyment, we offer the following comprehensive benefits package designed for the overall well-being of our team members:
Flexible work schedules and the ability to work remotely are available for many roles
Health, dental and vision insurance paid up to 80% for employees, dependents and domestic partners
Robust time-off plan (21 days of PTO in your first year)
Two paid volunteer days and 11 paid holidays
12 weeks paid parental leave for all new parents
Six weeks paid sabbatical after six years of service
Educational Assistant Program and Clinical Employee Reimbursement Program
401(k) with up to 4% match
Stock options
And much more!
At Aledade, we don't just accept differences, we celebrate them! We strive to attract, develop and retain highly qualified individuals representing the diverse communities where we live and work. Aledade is committed to creating a diverse environment and is proud to be an equal opportunity employer. Employment policies and decisions at Aledade are based on merit, qualifications, performance and business needs. All qualified candidates will receive consideration for employment without regard to age, race, color, national origin, gender (including pregnancy, childbirth or medical conditions related to pregnancy or childbirth), gender identity or expression, religion, physical or mental disability, medical condition, legally protected genetic information, marital status, veteran status, or sexual orientation.
Privacy Policy: By applying for this job, you agree to Aledade's Applicant Privacy Policy available at *************************************************
#J-18808-Ljbffr
$102k-141k yearly est. 1d ago
Hybrid Senior Security Engineer: Corporate Security Lead
Persona 4.3
San Francisco, CA jobs
A leading identity platform company in San Francisco is seeking a Corporate Security Lead to fortify defenses against evolving threats. This full-time role involves developing endpoint security solutions and collaborating with cross-functional teams. The ideal candidate has over 3 years of IT security experience, including endpoint hardening and scripting skills. Enjoy competitive benefits like unlimited PTO, mental health days, and professional development stipends in a vibrant work culture.
#J-18808-Ljbffr
$135k-181k yearly est. 1d ago
Senior Enterprise Security Engineer - Hybrid SF
Persona 4.3
San Francisco, CA jobs
An innovative technology company in San Francisco seeks a Security Lead to fortify their defenses against evolving threats. In this role, you'll develop and implement security tools, collaborate across teams on best practices, and manage insider threat programs. Candidates should have 3+ years in IT security, experience with endpoint hardening, and strong coding skills in Ruby or Python. The company offers a competitive benefits package, promoting a supportive work culture.
#J-18808-Ljbffr
$135k-181k yearly est. 5d ago
Malware Defense Malware Analyst
Stryker Corporation 4.7
Denver, CO jobs
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day. Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates' physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve. Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations. At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us! Bank of America is one of the world's leading financial institutions, serving over 66 million consumers and small businesses. Company success is only possible with a strong cyber defense, which enables Bank of America to safely conduct global operations across the United States and in approximately 35 countries. Our primary goal is to safeguard not only the company, but our clients and their trust. The Malware Defense Team is looking for top talent who would like to join one of the most advanced cybersecurity teams in the world.
Responsibilities
In-depth analysis of malware, including authoring analysis reports.
Tracking malware campaigns, malicious actors, and related infrastructure.
Creation of tools and scripts to assist in the analysis of malware analysis.
Field escalations of potentially malicious files and websites from teams within Malware Defense.
Required Qualifications
Strong direct experience of analyzing malware.
Intermediate to advanced malware analysis skills.
Experience creating innovative ways to track progression of malware families, infrastructure, and campaigns conducted by e-crime, and cyber espionage actors.
Experience creating tools and scripts to accelerate malware and threat analysis.
Background in network traffic analysis - WireShark, Fiddler, proxy logs, etc.
Experience analyzing malicious web content such as ClickFix, ClearFake, SocGholish, etc.
Experience authoring YARA, Suricata, and EKFiddle detection rules.
Experience with penetration testing and/or adversary emulation is a plus.
Able to work independently on tasks, but also work well within a team environment.
Desired Qualifications
Experience analyzing malware targeting Linux, Android, and IOT platforms.
Skills
Cyber Security
Data Privacy and Protection
Problem Solving
Process Management
Threat Analysis
Business Acumen
Data and Trend Analysis
Interpret Relevant Laws, Rules, and Regulations
Risk Analytics
Stakeholder Management
Access and Identity Management
Data Governance
Encryption
Information Systems Management
Technology System Assessment
Shift
1st shift (United States of America)
Hours Per Week
40
Pay Transparency details
US - CO - Denver - 1144 15th St - Denver Gis (CO9926), US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842), US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540)
Pay and benefits information
Pay range: $95,700.00 - $144,900.00 annualized salary, offers to be determined based on experience, education and skill set.
Discretionary incentive eligible: This role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.
Benefits
This role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.
#J-18808-Ljbffr
$95.7k-144.9k yearly 5d ago
Senior Cloud Security Engineer: Incident Response & IAM
Aledade 4.1
Bethesda, MD jobs
A healthcare technology firm located in Maryland is seeking a Senior Security Engineer I to enhance security capabilities within cloud-native environments. The candidate will design and implement security solutions, lead incident response efforts, and collaborate with various teams to strengthen security posture. Applicants should have a degree in Computer Science or related field, extensive experience in security engineering, and proficiency in scripting languages like Python and Bash. This role offers a supportive workplace that values diversity and innovation.
#J-18808-Ljbffr
$102k-141k yearly est. 1d ago
Senior Security Engineer - Endpoint Defense
Persona 4.3
San Francisco, CA jobs
A forward-thinking technology company in San Francisco seeks a skilled individual to lead their corporate security efforts. In this full-time role, you'll enhance security practices, develop innovative defense strategies, and protect the organization's operations from evolving threats. The ideal candidate has over 3 years of experience in IT security, particularly in endpoint security solutions. The company offers competitive medical, dental, and mental health benefits along with an engaging workplace culture.
#J-18808-Ljbffr
$135k-181k yearly est. 4d ago
Senior Security Engineer, Product San Francisco
Persona 4.3
San Francisco, CA jobs
Persona is the configurable identity platform built for businesses in a digital-first world.
Verifying individuals and organizations is harder - but more important - than ever, with AI enabling fraudsters to launch sophisticated accounts at scale and regulations evolving rapidly.
We've built Persona to support practically every use case and industry - that's why we're able to serve a wide range of leading companies. For example, Instacart relies on Persona to verify shoppers who onboard onto their platform before delivering groceries to your doorstep. Meanwhile, OpenAI relies on Persona to keep bad actors out, protecting one of the world's most powerful AI platforms from large-scale abuse in a time when AI is reshaping the way we work and live.
We're growing rapidly and looking for exceptional people to join us!
About the Role
We're building something special here at Persona, and our Security Team is a big part of that. Our team is made up of veterans from industry leaders like Square and Dropbox, and we're looking for someone to join us in shipping innovative products quickly and securely.
Your job? Work with our engineering teams to make sure we're delivering rock-solid security for our customers and users. As we grow fast (and we mean fast), you'll be key in managing the risks that come with that speed. We're not just looking for someone to play defense - we want you to think ahead and outsmart the bad guys before they even know what hit them. You'll get to work with the latest tech and come up with clever ways to keep our systems locked down tight.
What you'll do at Persona
Collaborate cross-functionally with our product teams to understand, manage, and mitigate the security risks associated with their work, while supporting their ability to ship quickly
Build tools and processes for automating product security controls and monitoring at scale
Support product security initiatives across our fast-growing engineering team
Participate in the on-call rotation for the Security Team
What you'll bring to Persona
Communication and Collaboration skills. Ability to explain security topics clearly to non-technical business representatives. Drive to enable other engineers to ship securely.
Bias toward shipping. Improving our product quickly and continually is one of Persona's greatest strengths. You should be excited about finding ways to integrate security into our product delivery processes without slowing things down.
Proactive approach to solving problems. We're looking for someone that can tell us how to solve our problems, not someone who waits to be told how to solve problems.
Passion for security. You should be excited about keeping your skills and knowledge sharp, and sharing that with your peers and the rest of the company.
Experience. 2+ years of software engineering, 2+ years of product security at a fast-moving technology company.
Nice to have
Experience securing a large Ruby on Rails application.
Full-time Employee Benefits and Perks
For full-time employees (excluding internship and contractor opportunities), Persona offers a wide range of benefits, including medical, dental, and vision, 3% 401(k) contribution, unlimited PTO, quarterly mental health days, family planning benefits, professional development stipend, wellness benefits, among others. While we believe competitive compensation and benefits is a critical aspect of you deciding to join us, we do hope you consider why our core values and culture are right for you. If you'd like to better understand what it's like working at Persona, feel free to check out our reviews on Glassdoor.
#J-18808-Ljbffr
$135k-181k yearly est. 4d ago
Senior Security Engineer - Ship Securely at Speed
Persona 4.3
San Francisco, CA jobs
A leading identity platform in San Francisco seeks a Security Engineer to enhance product security while supporting the fast-paced delivery processes of engineering teams. The candidate will collaborate cross-functionally to manage risks, build security automation tools, and participate in on-call rotations. Required skills include communication, collaboration, and a passion for security, with 2+ years in software engineering and product security at a tech company. This full-time role offers competitive benefits and emphasizes a culture of proactive problem-solving.
#J-18808-Ljbffr
$135k-181k yearly est. 4d ago
Senior Security Engineer, Corporate Security
Persona 4.3
San Francisco, CA jobs
Persona is the configurable identity platform built for businesses in a digital-first world. Verifying individuals and organizations is harder - but more important - than ever, with AI enabling fraudsters to launch sophisticated accounts at scale and regulations evolving rapidly.
We've built Persona to support practically every use case and industry - that's why we're able to serve a wide range of leading companies. For example, Instacart relies on Persona to verify shoppers who onboard onto their platform before delivering groceries to your doorstep. Meanwhile, OpenAI relies on Persona to keep bad actors out, protecting one of the world's most powerful AI platforms from large-scale abuse in a time when AI is reshaping the way we work and live.
We're growing rapidly and looking for exceptional people to join us!
About the Role
Persona's Security Team is looking for someone to lead our corporate security efforts. You'll play a pivotal role in fortifying our defenses against evolving threats. Your mission is to protect fellow Personerds and the systems we use to do our work. You'll have the opportunity to employ cutting-edge technologies, innovative strategies, and your expertise to thwart potential attacks before they disrupt our operations.
This is a full-time position based in our headquarters in downtown San Francisco. Our in-office days are Tuesday - Thursday, with the option to work from home on Monday and Friday.
What you'll do at Persona
Develop, enhance, and implement endpoint detection and response rules and tooling for endpoint devices
Collaborate cross-functionally with our TechOps Team in implementing security best practices for SaaS and endpoint environments and support security initiatives like 2-factor authentication, automated encryption of client devices, DLP, etc.
Build tools and processes for automating security controls and monitoring at scale
Support security initiatives across the organization and harden our corporate infrastructure against attack
Recommend endpoint and SaaS mitigations and controls based on generated telemetry
Provide recommendations and support for insider threat programs
Participate in the on-call rotation for the Security Team
What you'll bring to Persona
3+ years of experience in IT security or building endpoint security solutions, including experience supporting mac OS devices
Experience with planning and executing endpoint hardening initiatives
Experience with mobile device management (MDM) and endpoint detection and response (EDR) tools and technologies
Experience with data loss prevention (DLP) and insider threat concepts and mitigations
Experience with email security concepts and protecting a workforce against phishing
Ability to explain security topics clearly to non-technical business representatives
Ability to write code in Ruby, Python, or similar scripting languages, as well as SQL queries
Full-time Employee Benefits and Perks
For full-time employees (excluding internship and contractor opportunities), Persona offers a wide range of benefits, including medical, dental, and vision, 3% 401(k) contribution, unlimited PTO, quarterly mental health days, family planning benefits, professional development stipend, wellness benefits, among others. While we believe competitive compensation and benefits are a critical aspect of you deciding to join us, we do hope you consider why our core values and culture are right for you. If you'd like to better understand what it's like working at Persona, feel free to check out our reviews on Glassdoor.
#J-18808-Ljbffr
$135k-181k yearly est. 1d ago
Senior Security Analyst
Independent Living Systems, LLC 4.4
Miami, FL jobs
We are seeking a Senior Security Analyst to join our team at Independent Living Systems (ILS). ILS, along with its affiliated health plans known as Florida Community Care and Florida Complete Care, is committed to promoting a higher quality of life and maximizing independence for all vulnerable populations.
About the Role:
The Senior Security Analyst plays a critical role in safeguarding the organization's information systems and digital assets by proactively identifying, analyzing, and mitigating security threats. This position is responsible for leading advanced security investigations, managing incident response activities, and ensuring compliance with industry standards and regulatory requirements. The role requires collaboration with cross-functional teams to design and implement robust security controls and to continuously improve the organization's security posture. The Senior Security Analyst will also mentor junior team members and contribute to the development of security policies and procedures. Ultimately, this role ensures the confidentiality, integrity, and availability of sensitive data while supporting business objectives through effective risk management.
Minimum Qualifications:
Bachelor's degree in Computer Science, Information Security, or a related field.
5+ years of experience in information security or cybersecurity roles.
Strong knowledge of security frameworks such as NIST, ISO 27001, or CIS Controls.
Experience with security monitoring tools such as SIEM, IDS/IPS, and endpoint protection platforms.
Proven ability to conduct incident response and forensic investigations.
Relevant experience may substitute for the educational requirement on a year-for-year basis.
Preferred Qualifications:
Master's degree in computer science, Information Security, or a related field.
Professional certifications such as CISSP, CISM, GIAC, CISA, CRISC
Knowledge of regulatory requirements such as GDPR, HIPAA, or PCI-DSS.
Framework & compliance expertise in SOC 2 / SSAE 18, evidence collection, testing, control mapping
Audit / GRC tooling, Evidence workflows, issue tracking, remediation validation
Responsibilities:
Monitor security alerts and analyze potential threats using advanced security tools and techniques.
Lead incident response efforts, including investigation, containment, eradication, and recovery from security breaches.
Conduct vulnerability assessments and penetration testing to identify and remediate security weaknesses.
Develop and maintain security documentation, including policies, procedures, and incident reports.
Collaborate with IT, compliance, and business units to implement security best practices and ensure regulatory compliance.
Provide mentorship and guidance to junior security analysts and other team members.
Stay current with emerging security threats, technologies, and industry trends to proactively enhance security measures.
$88k-113k yearly est. 2d ago
Facets Architect III
Caresource 4.9
Dayton, OH jobs
Strategically provides solutions for the design and implementation of in-house information systems, hardware and networked software architectures that support core organizational functions and assure their high availability. This position designs and develops approaches that are implemented by others. The person in this position functions independently with minimal oversight and direction. In addition, the Facets application solutions architect provides technical leadership across the organization, from strategic decision making down to the project planning level.
Essential Functions:
Design solutions based on business outcomes
Create detailed technical requirements to achieve business outcomes
Oversee and guide delivery teams across components of the solution
Provide Detail data mapping for the Member, Provider and Claims domain to Facets data model
Produce scalable, highly available solutions
Drive delivery in an agile environment
Create solutions for real-time and event-based architectures
Report on the desired business outcomes for healthcare payor business
Provide hands-on mentoring with Facets digital integration
Managing the implementation of TriZetto Facets version upgrades, collaboration solutions, and many other custom outsourcing engagements.
Aligns his/her efforts across the various technical architectural disciplines within the team to develop innovative and appropriate architectures and roadmaps that enable the enterprise to deliver best-in-class services to their clients, partners and employees
Provide overall architecture guidance, governance, and recommendations in support of technical objectives
Direct involvement in the development of policies, standards and guidelines that direct the selection, development, implementation and use of Information Technology within the enterprise
Work with the department leadership in establishing technology architecture strategy, goals, and objectives
Partner with peers within all Information Technology groups to promote architecture principles, standards, methods, and strategic direction for the enterprise
Facilitate overall analysis, design, artifacts, and technical requirements validation for strategic initiatives
Define the future architecture and the roadmap to get from the current state to the end target
Lead / participate in vendor architecture related assessments and reviews
Develop technical architectures that will drive reduced cost, increased availability, improved security, client experience, and greater flexibility
Management of the risks associated with information and IT assets through appropriate standards and security policies
Build employee knowledge and skills in specific areas of expertise
Deliver engaging, informative and well-organized presentations
Effectively executes and communicates change management
Perform any other job duties as requested
Education and Experience:
Bachelor's degree or equivalent years of relevant work experience is required
Master's degree is preferred
Minimum of ten (10) years of experience in related areas including seven (7) years of direct experience in developing and implementing technically diverse application and infrastructure architectures for companies
Minimum of three (3) years of Facets Architecture experience preferred
Facets Applications
Facets Data Model - Provider, Member, Claims
SQL
Facets Integration Design/Development experience
Understanding of the Healthcare Payer business processes
Facets functional knowledge
Healthcare business processes
Application integration knowledge
Competencies, Knowledge and Skills:
Ability to effectively prioritize and execute tasks while working both independently and in a team-oriented, collaborative environment
Strong interpersonal skills including excellent written and verbal communication skills; listening and critical thinking; presentation skills, facilitation skills
Ability to establish effective working relationships with stakeholders at all different levels
Flexibility during organizational and/or business changes
Effective problem-solving skills with attention to detail
Customer Service oriented
Ability to lead technical evaluations and conduct research & development in emerging technologies
Effectively disseminates information to appropriate audiences verbally and in writing
Ability to actively gather appropriate level of participation and input to decision-making and foster it within teams
Licensure and Certification:
ITIL v3 Foundations or greater certification preferred
Working Conditions:
General office environment; may be required to sit or stand for extended periods of time
Compensation Range:
$135,600.00 - $237,400.00 CareSource takes into consideration a combination of a candidate's education, training, and experience as well as the position's scope and complexity, the discretion and latitude required for the role, and other external and internal data when establishing a salary level. In addition to base compensation, you may qualify for a bonus tied to company and individual performance. We are highly invested in every employee's total well-being and offer a substantial and comprehensive total rewards package.
Compensation Type:
Salary
Competencies:
- Fostering a Collaborative Workplace Culture - Cultivate Partnerships - Develop Self and Others - Drive Execution - Influence Others - Pursue Personal Excellence - Understand the Business
This is not all inclusive. CareSource reserves the right to amend this job description at any time. CareSource is an Equal Opportunity Employer. We are dedicated to fostering an environment of belonging that welcomes and supports individuals of all backgrounds.
#LI-GM1
$135.6k-237.4k yearly 3d ago
SAP IBP IO Architect
Bristlecone 3.9
Glenolden, PA jobs
About Company::
Bristlecone is a supply chain and business analytics advisor, serving customers across a wide range of industries. Rated by Gartner as among the top ten system integrators in the supply chain space, we are uniquely positioned to solve contemporary business problems, with supply chain and analytics focus as our advantage. We have been a trusted partner and advisor to many leading, globally recognized companies such as Applied Materials, Exxon Mobil, Flextronics, LSI Logic, Mahindra, Motorola, Nestle, Palm, Qatar Petroleum, Ranbaxy, Unilever and Whirlpool and many others.
Role Overview:
The SAP IBP IO Architect is responsible for designing, implementing, and optimizing SAP Integrated Business Planning (IBP) solutions with a strong focus on the Inventory Optimization (IO) with knowledge of R&S module. This role combines deep technical expertise with strong business process knowledge to deliver advanced supply chain planning capabilities that drive inventory efficiency, service level improvements, and cost reduction.
The ideal candidate will have extensive hands on experience in SAP IBP architecture, configuration, integration with S/4HANA or ECC, and strong knowledge of supply chain planning processes (inventory, demand, supply, and S&OP).
Key Responsibilities:
Lead the design and architecture of SAP IBP-IO solutions aligned with business objectives. Determine success criteria
Define and maintain the solution architecture, data flows, and integration points with SAP ECC/S4HANA, APO, or non-SAP systems.
Configure and implement SAP IBP Inventory Optimization models (e.g., safety stock calculation, multi-echelon inventory optimization).
Set up key figures, planning areas, master data, and planning operators relevant to IO.
Optimize algorithms and parameters to balance inventory levels, service targets, and cost objectives.
Collaborate with business stakeholders, process owners, and IT teams to translate business requirements into functional and technical designs.
Conduct workshops and training sessions for key users and planners.
Travel to various client slides to work with planners .
Required Qualifications:
Bachelor's degree in Supply Chain Management, Information Systems, Engineering, or related field.
12- 15 years years of experience in SAP Supply Chain Planning solutions.
5+ years of hands-on experience with SAP IBP, with at least 2 Implementations focused on Inventory Optimization (IO).
Experience integrating SAP IBP with S/4HANA, ECC, or non-SAP ERP systems using CPI-DS or other middleware tools.
Familiarity with SAP Best Practices for IBP and Supply Chain Planning KPIs.
Strong analytical and problem-solving skills with attention to detail.
Excellent communication and stakeholder management abilities.
$87k-127k yearly est. 3d ago
Principal Cloud and AI Security Architect
Guide Well 4.7
Remote
The Principal Cybersecurity Architect is responsible for driving enterprise-wide technology security strategy and providing technical expertise to business areas and project teams with an emphasis on implementation of innovative, leading-edge security technology solutions. The ideal candidate will display:
Strategic Leadership, Collaboration, and Accomplishments
Proven Track Record of accomplishments and experience leading the design and deployment of AI Architectures (both On-Premise and Public Cloud) and driving and deploying Secure Cloud Adoption on an enterprise scale from Foundational Security Controls to Cloud migrations. Extensive experience migrating from a large scale onprem datacenter to the cloud while maintaining the proper levels of security, compliance and regulatory adherence.
Cross-Functional Communication: Bridging gaps between data scientists, engineers, AI Architects, Cloud Architects, Data Protection professionals, legal, and executive teams.
Security Evangelism: Promoting secure-by-design principles across AI and Cloud initiatives.
Mentorship & Governance: Leading security teams and establishing governance frameworks for AI and Public Cloud adoption.
AI-Specific Security Expertise
Understanding of AI/ML Risks: Knowledge of adversarial attacks, model poisoning, data drift, and bias.
Model Connectivity & Secure Deployment: Leadership experience with connecting User Interfaces to LLMs, Retrieval-Augmented Generation “RAG” solutions, Agent to Agent architecture design, and securing Model Context Protocol “MCP” deployments, both on-premise and in the cloud.
AI Lifecycle Security: Securing data pipelines, training environments, inference APIs, and monitoring systems.
Enterprise SecurityArchitecture
Zero Trust & Identity Management: Designing architectures that enforce least privilege and secure identity across AI and Cloud systems.
Cloud & Hybrid Security: Expertise in securing AI workloads across AWS and Azure, and on-prem environments. Experience leading the Secure design of Cloud Foundational Controls across AWS and Azure.
Security Design Patterns: Lead architectural requirements and gain consensus on the use of reusable, scalable patterns for secure AI integration.
Technical Depth in AI & Cloud Infrastructure
API & Data Security: Securing AI APIs, leading design discussions on strategies to protect data within AI solutions, managing data access controls, designing secure MCP solutions and preventing data leakage.
AI System Integration: Designing secure integration points between AI systems and enterprise platforms.
Public Cloud Integration: Proven track record of driving an Enterprise on Public Cloud Foundational controls and taking a leadership role on Secure Cloud migrations from on-Premise to Public Cloud solutions.
Model Usage Procedures: Designed procedures for organization wide governance on the usage/approval of AI Models.
Regulatory & Compliance Knowledge
Healthcare Regulations: Deep familiarity with HIPAA, NIST and emerging AI and Cloud governance frameworks.
Audit & Risk Management: Ability to design systems that meet audit requirements, mitigate compliance risks, and ensuring Public Cloud environments maintain Audit Readiness.
What We Require
6+ years related work experience as an Architect working on progressively complex IT and Cybersecurity projects
Related Bachelor's degree or additional related equivalent work experience IT related field
Required Licenses and Certifications CISSP - Cert Information Systems Security Prof 180 Days
Expert proficiency in creating architectural designs for gradually complex designs
Expert consulting, negotiating, communicating, consensus building, presentation and facilitation skills
Mastery of a variety of hardware platforms including mainframes, distributed platforms, desktops, and mobile devices.
Expert-level knowledge and experience applying current and emerging technology solutions and trends including security and regulatory industry requirements
Demonstrated decision-making skills related to implementing architecture and design
Knowledge of Project Management Methodologies
Extensive knowledge of development practices of security technologies
Exceptional leadership skills demonstrated through project or technical leadership experience
Expert-level ability to understand overall IT strategy and apply/implement IT strategy in assigned projects/initiatives
Expert-level ability to communicate highly complex technical information clearly and articulately at all levels and audiences.
Extensive experience with defense in depth, trust levels, privileges and permissions
What We Prefer
2 or more years cloud security experience Identity
Access Management experience with employee and consumer identity security
Experience securing API's Health care industry related experience
Experience using Agile methodology
General Physical Demands
Exerting up to 10 pounds of force occasionally to move objects.
Jobs are sedentary if traversing activities are required only occasionally.
What We Offer
As a Florida Blue employee, you will thrive in our Be Well, Work Well, GuideWell culture where being well as an individual, and working well as a team, are both important in serving our members and communities.
To support your wellbeing, comprehensive benefits are offered. As an employee, you will have access to:
Medical, dental, vision, life and global travel health insurance
Income protection benefits: life insurance, short- and long-term disability programs
Leave programs to support personal circumstances
Retirement Savings Plan including employer match
Paid time off, volunteer time off, 10 holidays and 2 well-being days
Additional voluntary benefits available; and a comprehensive wellness program
Employee benefits are designed to align with federal and state employment laws. Benefits may vary based on the state in which work is performed. Benefits for intern, part-time and seasonal employees may differ.
To support your financial wellbeing, we offer competitive pay as well as opportunities for incentive or commission compensation. We also conduct regular annual reviews with pay for performance considerations for base pay increases.
Targeted Annualized Offer Range: $138,200 - $172,800
Annualized Salary Range: $138,200 - $224,600
Final pay will be determined with consideration of market competitiveness, internal equity, and the job-related knowledge, skills, training, and experience you bring.
We are an Equal Employment Opportunity employer committed to cultivating a work experience where everyone feels like they belong and can perform at their best in pursuit of our mission. All qualified applicants will receive consideration for employment.
$138.2k-224.6k yearly Auto-Apply 48d ago
Information Security Architect / IS - Information Security / Full-time / Days
Childrens Hospital Los Angeles 4.7
Los Angeles, CA jobs
NATIONAL LEADERS IN PEDIATRIC CARE Ranked among the top 10 pediatric hospitals in the nation, Children's Hospital Los Angeles (CHLA) provides the best care for kids in California. Here world-class experts in medicine, education and research work together to deliver family-centered care half a million times each year. From primary to complex critical care, more than 350 programs and services are offered, each one specially designed for children.
The CHLA of the future is brighter than can be imagined. Investments in technology, research and innovation will create care that is personal, convenient and empowering. Our scientists will work with clinical experts to take laboratory discoveries and create treatments that are a perfect match for every patient. And together, CHLA team members will turn health care into health transformation.
Join a hospital where the work you do will matter-to you, to your colleagues, and above all, to our patients and families. The work will be challenging, but always rewarding.
It's Work That Matters.
Overview
This position is 100% remote. CHLA requires a primary residence in CA prior to start date.
Purpose Statement/Position Summary: The Information SecurityArchitect serves a crucial role in ensuring the confidentiality, integrity, and availability of CHLA's information assets and technology resources. They will serve as lead for the information securityarchitecture and engineering team. Responsibilities include leading the planning, designing, implementation and operationalization of security solutions aligned with CHLA policies and regulatory requirements.
Minimum Qualifications/Work Experience:
* Required: 10+ years of progressively responsible experience in information security, network architecture, or related fields, with a demonstrated track record of securing complex enterprise environments.
* Deep understanding of security technologies and protocols, including VPN, IPSec, DES encryption, Digital Certificates, SSL/TLS, TCP/IP, DNS, DMZ, and web securityarchitectures.
* Hands-on experience with security tools such as Nmap, Nessus, CoreImpact, CyberArk, Qualys (Q1), WebInspect, Snort, or similar vulnerability assessment, identity management, and intrusion detection/prevention solutions.
* Familiarity with enterprise securityarchitecture frameworks and integration of security controls across cloud and on-prem environments.
* In-depth knowledge of information security standards, frameworks, and regulatory requirements including HIPAA, HITECH, NIST, and ISO 27001.
* Strong understanding of data confidentiality, risk assessment, and compliance monitoring across desktop, server, application, database, and network layers.
* Familiarity with IT governance and process frameworks, including ITIL, LEAN, and Six Sigma methodologies.
* Experience in designing and implementing enterprise-wide security policies, standards, and procedures to ensure secure operations.
* Strong analytical, problem-solving, and decision-making capabilities, with the ability to anticipate and mitigate complex security threats.
* Excellent communication (oral, written, and presentation) and interpersonal skills, with a consultative and collaborative approach to working with stakeholders at all levels.
Education/Licensure/Certification: Required: Bachelor's Degree in Computer Science or Computer Software Engineering, or equivalent combination of relevant education and experience may be considered. Training and certification on network equipment and protocols. CISSP or GIAC certifications.
Pay Scale Information
USD $122,573.13 - USD $199,181.00
CHLA values the contribution each Team Member brings to our organization. Final determination of a successful candidate's starting pay will vary based on a number of factors, including, but not limited to education and experience within the job or the industry. The pay scale listed for this position is generally for candidates that meet the specified qualifications and requirements listed on this specific job description. Additional pay may be determined for those candidates that exceed these specified qualifications and requirements. We provide a competitive compensation package that recognizes your experience, credentials, and education alongside a robust benefits program to meet your needs. CHLA looks forward to introducing you to our world-class organization where we create hope and build healthier futures.
Children's Hospital Los Angeles (CHLA) is a leader in pediatric and adolescent health both here and across the globe. As a premier Magnet teaching hospital, you'll find an environment that's alive with learning, rooted in care and compassion, and home to thought leadership and unwavering support. CHLA is dedicated to creating hope and building healthier futures - for our patients, as well as for you and your career!
CHLA has been affiliated with the Keck School of Medicine of the University of Southern California since 1932.
At Children's Hospital Los Angeles, our work matters. And so do each and every one of our valued team members. CHLA is an Equal Employment Opportunity employer. We consider qualified applicants for all positions without regard to race, color, religion, creed, national origin, sex, gender identity, age, physical or mental disability, sexual orientation, marital status, veteran or military status, genetic information or any other legally protected basis under federal, state or local laws, regulations or ordinances. We will also consider for employment qualified applicants with criminal history, in a manner consistent with the requirements of state and local laws, including the LA City Fair Chance Ordinance and SF Fair Chance Ordinance.
Qualified Applicants with disabilities are entitled to reasonable accommodation under the California Fair Employment and Housing Act and the Americans with Disabilities Act. Please contact CHLA Human Resources if you need assistance completing the application process.
Our various experiences, perspectives and backgrounds allow us to better serve our patients and create a strong community at CHLA.
IS - Information Security
$122.6k-199.2k yearly 20d ago
Information Security Architect / IS - Information Security / Full-time / Days
Children's Hospital Los Angeles 4.7
Los Angeles, CA jobs
**NATIONAL LEADERS IN PEDIATRIC CARE** Ranked among the top 10 pediatric hospitals in the nation, Children's Hospital Los Angeles (CHLA) provides the best care for kids in California. Here world-class experts in medicine, education and research work together to deliver family-centered care half a million times each year. From primary to complex critical care, more than 350 programs and services are offered, each one specially designed for children.
The CHLA of the future is brighter than can be imagined. Investments in technology, research and innovation will create care that is personal, convenient and empowering. Our scientists will work with clinical experts to take laboratory discoveries and create treatments that are a perfect match for every patient. And together, CHLA team members will turn health care into health transformation.
Join a hospital where the work you do will matter-to you, to your colleagues, and above all, to our patients and families. The work will be challenging, but always rewarding.
**It's Work That Matters.**
**Overview**
**This position is 100% remote. CHLA requires a primary residence in CA prior to start date.**
**Purpose Statement/Position Summary:** The Information SecurityArchitect serves a crucial role in ensuring the confidentiality, integrity, and availability of CHLA's information assets and technology resources. They will serve as lead for the information securityarchitecture and engineering team. Responsibilities include leading the planning, designing, implementation and operationalization of security solutions aligned with CHLA policies and regulatory requirements.
**Minimum Qualifications/Work Experience:**
- Required: 10+ years of progressively responsible experience in information security, network architecture, or related fields, with a demonstrated track record of securing complex enterprise environments.
- Deep understanding of security technologies and protocols, including VPN, IPSec, DES encryption, Digital Certificates, SSL/TLS, TCP/IP, DNS, DMZ, and web securityarchitectures.
- Hands-on experience with security tools such as Nmap, Nessus, CoreImpact, CyberArk, Qualys (Q1), WebInspect, Snort, or similar vulnerability assessment, identity management, and intrusion detection/prevention solutions.
- Familiarity with enterprise securityarchitecture frameworks and integration of security controls across cloud and on-prem environments.
- In-depth knowledge of information security standards, frameworks, and regulatory requirements including HIPAA, HITECH, NIST, and ISO 27001.
- Strong understanding of data confidentiality, risk assessment, and compliance monitoring across desktop, server, application, database, and network layers.
- Familiarity with IT governance and process frameworks, including ITIL, LEAN, and Six Sigma methodologies.
- Experience in designing and implementing enterprise-wide security policies, standards, and procedures to ensure secure operations.
- Strong analytical, problem-solving, and decision-making capabilities, with the ability to anticipate and mitigate complex security threats.
- Excellent communication (oral, written, and presentation) and interpersonal skills, with a consultative and collaborative approach to working with stakeholders at all levels.
**Education/Licensure/Certification:** Required: Bachelor's Degree in Computer Science or Computer Software Engineering, or equivalent combination of relevant education and experience may be considered. Training and certification on network equipment and protocols. CISSP or GIAC certifications.
**Pay Scale Information**
USD $122,573.13 - USD $199,181.00
CHLA values the contribution each Team Member brings to our organization. Final determination of a successful candidate's starting pay will vary based on a number of factors, including, but not limited to education and experience within the job or the industry. The pay scale listed for this position is generally for candidates that meet the specified qualifications and requirements listed on this specific job description. Additional pay may be determined for those candidates that exceed these specified qualifications and requirements. We provide a competitive compensation package that recognizes your experience, credentials, and education alongside a robust benefits program to meet your needs. CHLA looks forward to introducing you to our world-class organization where we create hope and build healthier futures.
Children's Hospital Los Angeles (CHLA) is a leader in pediatric and adolescent health both here and across the globe. As a premier Magnet teaching hospital, you'll find an environment that's alive with learning, rooted in care and compassion, and home to thought leadership and unwavering support. CHLA is dedicated to creating hope and building healthier futures - for our patients, as well as for you and your career!
CHLA has been affiliated with the Keck School of Medicine of the University of Southern California since 1932.
At Children's Hospital Los Angeles, our work matters. And so do each and every one of our valued team members. CHLA is an Equal Employment Opportunity employer. We consider qualified applicants for all positions without regard to race, color, religion, creed, national origin, sex, gender identity, age, physical or mental disability, sexual orientation, marital status, veteran or military status, genetic information or any other legally protected basis under federal, state or local laws, regulations or ordinances. We will also consider for employment qualified applicants with criminal history, in a manner consistent with the requirements of state and local laws, including the LA City Fair Chance Ordinance and SF Fair Chance Ordinance.
Qualified Applicants with disabilities are entitled to reasonable accommodation under the California Fair Employment and Housing Act and the Americans with Disabilities Act. Please contact CHLA Human Resources if you need assistance completing the application process.
Our various experiences, perspectives and backgrounds allow us to better serve our patients and create a strong community at CHLA.
IS - Information Security
$122.6k-199.2k yearly 60d+ ago
Data Security Architect, Zero Trust (TS/SCI)
Kentro 3.9
Tampa, FL jobs
Thank you for considering IT Concepts dba Kentro, where innovation drives opportunity and collaboration leads to success. Our dynamic community of experts is fully committed to advancing our customers' missions, fostering professional growth, and making a positive impact on our communities.
By joining our supportive community, you will find that Kentro is dedicated to your personal and professional development. Together, we can drive meaningful change, spark innovation, and achieve extraordinary milestones.
Kentro is hiring a visionary and authoritative Data SecurityArchitect to serve as the lead technical authority for the USSOCOM Zero Trust Data Visibility, Labeling, and Governance program. As an architect within the Cross-Functional Integration Cell (CFIC), you will define the unified data security strategy that spans the Command's entire Information Environment-from the hyperscale cloud capabilities of the NIPR network to the disconnected, on-premise constraints of the SIPR and Air-Gapped enclaves.
In this high-visibility role, you will be responsible for defining the enterprise-wide data taxonomy and formally adopting the NIST Internal Report 8112 metadata schema. You will move the Command beyond simple file tagging to a complex Attribute-Based Access Control (ABAC) model, where access is brokered based on the pedigree, provenance, and verification status of user credentials. You will provide technical direction to the network-specific execution teams, ensuring that the implementation of Microsoft Purview (NIPR), BigID (SIPR), and Kiteworksremains architecturally coherent and aligned with the DoD Zero Trust Strategy.
Responsibilities
Enterprise Architecture Strategy: Serve as the Technical Authority for the Data Pillar, defining the high-level architecture for data discovery, classification, and protection across NIPR, SIPR, and Top Secret networks.
Metadata & Taxonomy Design: Define and enforce the enterprise data taxonomy and metadata schemas (specifically adhering to NIST 8112) to standardize how "Trust Attributes" (Pedigree, Verifier, Assurance Level) are ingested and utilized for ABAC decisions.
Cross-Enclave Integration: Ensure architectural consistency between the cloud-native NIPR stack (Microsoft Purview/Sentinel) and the on-premise SIPR/Top Secret stacks (BigID, Kiteworks, NetApp BlueXP), ensuring policy logic remains uniform even when tools differ.
ABAC & Identity Integration: Design the integration points between the Data Pillar and the ICAM Pillar, defining the requirements for how User Attributes from SailPoint and Entra ID are consumed by Policy Decision Points (PDPs) like Kiteworks and Purview.
Standards & Compliance: Lead the development of System Design Documents (SDDs) and validate that all architecture aligns with the USSOCOM Zero Trust Reference Architecture and DoD 8140/8570 compliance requirements.
Location: Onsite in Tampa, FL
Position Duration: The duration of this role is 18 months from project commencement, with the possibility of extension (Project expected to commence in January 2026).
Requirements
Master's degree (MA/MS) in Computer Science, Information Security / Cybersecurity, Information Systems, Data Science, or a closely related technical field
15+ years of relevant experience
Extensive experience acting as an Architect or Lead Engineer for large-scale DoD or Federal enterprise security transformations.
Deep expertise in Zero Trust Architecture principles, specifically Data Object-Level Protection (DOLP) and Attribute-Based Access Control (ABAC).
Proven experience designing architectures that utilize Microsoft Purview (Information Protection/DLP) and Digital Rights Management (DRM) technologies (e.g., Kiteworks, Virtru).
Ability to design security solutions for Disconnected, Degraded, Intermittent, and Limited Bandwidth (DDIL) and air-gapped environments.
Preferred Experience & Skills ("Nice-to-Haves")
Experience with BigID for data discovery and NetApp BlueXP for storage-level classification.
Knowledge of NIST Internal Report 8112 (Attribute Metadata) and its application to identity-centric security.
Background in supporting USSOCOM or Special Operations Forces (SOF) missions.
Certifications:
Required: IAT III: CISSP-ISSEP (Information Systems Security Engineering Professional) OR CISSP.
Preferred: One or more Cloud/Zero Trust Architecture certifications (e.g., CCSP, Microsoft Cybersecurity Architect SC-100).
DoD 8570 Compliance: Must meet IAT Level III and IASAE II requirements.
Clearance:
Active Top-Secret clearance with SCI eligibility.
Benefits
The Company
We believe in generating success collaboratively, enabling long-term mission success, and building trust for the next challenge. With you as our partner, let's solve challenges, think innovatively, and maximize impact. As a valued member of our team, you have the unique opportunity to work in a diverse range of technology and business career paths, all while supporting our nation and delivering innovative technology solutions. We are a close community of experts that pride ourselves on creating an environment defined by teamwork, dedication, and excellence.
We hold three ISO certifications (27001:2013, 20000-1:2011, 9001:2015) and two CMMI ML 3 ratings (DEV and SVC).
Industry Recognition
Growth | Inc 5000's Fastest Growing Private Companies, DC Metro List Fastest Growing; Washington Business Journal: Fastest Growing Companies, Top Performing Small Technology Companies in Greater D.C.
Culture | Northern Virginia Technology Council Tech 100 Honoree; Virginia Best Place to Work; Washington Business Journal: Best Places to Work, Corporate Diversity Index Winner - Mid-Size Companies, Companies Owned by People of Color; Department of Labor's HireVets for our work helping veterans transition; SECAF Award of Excellence finalist; Victory Military Friendly Brand; Virginia Values Veterans (V3); Cystic Fibrosis Foundation Corporate Breath Award
Benefits
We offer competitive benefits package including paid time off, healthcare benefits, supplemental benefits, 401k including an employer match, discount perks, rewards, and more. We invest in our employees - Every employee is eligible for education reimbursement for certifications, degrees, or professional development. Reimbursement amounts may fluctuate due to IRS limitations. We want you to grow as an expert and a leader and offer flexibility for you to take a course, complete a certification, or other professional growth and networking. We are committed to supporting your curiosity and sustaining a culture that prioritizes commitment to continuous professional development.
We work hard; we play hard. Kentro is committed to incorporating fun into every day. We dedicate funds for activities - virtual and in-person - e.g., we host happy hours, holiday events, fitness & wellness events, and annual celebrations. In alignment with our commitment to our communities, we also host and attend charity galas/events. We believe in appreciating your commitment and building a positive workspace for you to be creative, innovative, and happy.
Commitment Equal Opportunity Employment & VEVRAA
Kentro is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state or local law.
Kentro is strongly committed to compliance with VEVRAA and other applicable federal, state, and local laws governing equal employment opportunity. We have developed comprehensive policies and procedures to ensure our hiring practices align with these requirements.
As part of our VEVRAA compliance efforts, Kentro has established an equal opportunity plan outlining our commitment to recruiting, hiring, and advancing protected veterans. This plan is regularly reviewed and updated to ensure its effectiveness.
We encourage protected veterans to self-identify during the application process. This information is strictly confidential and will only be used for reporting and compliance purposes as required by law. Providing this information is voluntary and will not impact your employment eligibility.
Our commitment to equal employment opportunity extends beyond legal compliance. We are dedicated to fostering an inclusive workplace where all employees, including protected veterans, are treated with dignity, respect, and fairness.
How to Apply
To apply to Kentro Positions- Please click on the: “Apply for this Job” button at the bottom of this Job Description or the button at the top: “Application.” Please upload your resume and complete all the application steps. You must submit the application for Kentro to consider you for a position. If you need alternative application methods, please email ***************** and request assistance.
Accommodations
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. Reasonable Accommodations may be made to enable qualified individuals with disabilities to perform the essential functions. If you need to discuss reasonable accommodations, please email *****************.
#LI-JG1
$100k-146k yearly est. Auto-Apply 26d ago
Data Security Architect, Zero Trust (TS/SCI)
Kentro 3.9
Tampa, FL jobs
Thank you for considering IT Concepts dba Kentro, where innovation drives opportunity and collaboration leads to success. Our dynamic community of experts is fully committed to advancing our customers' missions, fostering professional growth, and making a positive impact on our communities.
By joining our supportive community, you will find that Kentro is dedicated to your personal and professional development. Together, we can drive meaningful change, spark innovation, and achieve extraordinary milestones.
Kentro is hiring a visionary and authoritative Data SecurityArchitect to serve as the lead technical authority for the USSOCOM Zero Trust Data Visibility, Labeling, and Governance program. As an architect within the Cross-Functional Integration Cell (CFIC), you will define the unified data security strategy that spans the Command's entire Information Environment-from the hyperscale cloud capabilities of the NIPR network to the disconnected, on-premise constraints of the SIPR and Air-Gapped enclaves.
In this high-visibility role, you will be responsible for defining the enterprise-wide data taxonomy and formally adopting the NIST Internal Report 8112 metadata schema. You will move the Command beyond simple file tagging to a complex Attribute-Based Access Control (ABAC) model, where access is brokered based on the pedigree, provenance, and verification status of user credentials. You will provide technical direction to the network-specific execution teams, ensuring that the implementation of Microsoft Purview (NIPR), BigID (SIPR), and Kiteworksremains architecturally coherent and aligned with the DoD Zero Trust Strategy.
Responsibilities
Enterprise Architecture Strategy: Serve as the Technical Authority for the Data Pillar, defining the high-level architecture for data discovery, classification, and protection across NIPR, SIPR, and Top Secret networks.
Metadata & Taxonomy Design: Define and enforce the enterprise data taxonomy and metadata schemas (specifically adhering to NIST 8112) to standardize how "Trust Attributes" (Pedigree, Verifier, Assurance Level) are ingested and utilized for ABAC decisions.
Cross-Enclave Integration: Ensure architectural consistency between the cloud-native NIPR stack (Microsoft Purview/Sentinel) and the on-premise SIPR/Top Secret stacks (BigID, Kiteworks, NetApp BlueXP), ensuring policy logic remains uniform even when tools differ.
ABAC & Identity Integration: Design the integration points between the Data Pillar and the ICAM Pillar, defining the requirements for how User Attributes from SailPoint and Entra ID are consumed by Policy Decision Points (PDPs) like Kiteworks and Purview.
Standards & Compliance: Lead the development of System Design Documents (SDDs) and validate that all architecture aligns with the USSOCOM Zero Trust Reference Architecture and DoD 8140/8570 compliance requirements.
Location: Onsite in Tampa, FL
Position Duration: The duration of this role is 18 months from project commencement, with the possibility of extension (Project expected to commence in January 2026).
Requirements
Master's degree (MA/MS) in Computer Science, Information Security / Cybersecurity, Information Systems, Data Science, or a closely related technical field
15+ years of relevant experience
Extensive experience acting as an Architect or Lead Engineer for large-scale DoD or Federal enterprise security transformations.
Deep expertise in Zero Trust Architecture principles, specifically Data Object-Level Protection (DOLP) and Attribute-Based Access Control (ABAC).
Proven experience designing architectures that utilize Microsoft Purview (Information Protection/DLP) and Digital Rights Management (DRM) technologies (e.g., Kiteworks, Virtru).
Ability to design security solutions for Disconnected, Degraded, Intermittent, and Limited Bandwidth (DDIL) and air-gapped environments.
Preferred Experience & Skills ("Nice-to-Haves")
Experience with BigID for data discovery and NetApp BlueXP for storage-level classification.
Knowledge of NIST Internal Report 8112 (Attribute Metadata) and its application to identity-centric security.
Background in supporting USSOCOM or Special Operations Forces (SOF) missions.
Certifications:
Required: IAT III: CISSP-ISSEP (Information Systems Security Engineering Professional) OR CISSP.
Preferred: One or more Cloud/Zero Trust Architecture certifications (e.g., CCSP, Microsoft Cybersecurity Architect SC-100).
DoD 8570 Compliance: Must meet IAT Level III and IASAE II requirements.
Clearance:
Active Top-Secret clearance with SCI eligibility.
Benefits
The Company
We believe in generating success collaboratively, enabling long-term mission success, and building trust for the next challenge. With you as our partner, let's solve challenges, think innovatively, and maximize impact. As a valued member of our team, you have the unique opportunity to work in a diverse range of technology and business career paths, all while supporting our nation and delivering innovative technology solutions. We are a close community of experts that pride ourselves on creating an environment defined by teamwork, dedication, and excellence.
We hold three ISO certifications (27001:2013, 20000-1:2011, 9001:2015) and two CMMI ML 3 ratings (DEV and SVC).
Industry Recognition
Growth | Inc 5000's Fastest Growing Private Companies, DC Metro List Fastest Growing; Washington Business Journal: Fastest Growing Companies, Top Performing Small Technology Companies in Greater D.C.
Culture | Northern Virginia Technology Council Tech 100 Honoree; Virginia Best Place to Work; Washington Business Journal: Best Places to Work, Corporate Diversity Index Winner - Mid-Size Companies, Companies Owned by People of Color; Department of Labor's HireVets for our work helping veterans transition; SECAF Award of Excellence finalist; Victory Military Friendly Brand; Virginia Values Veterans (V3); Cystic Fibrosis Foundation Corporate Breath Award
Benefits
We offer competitive benefits package including paid time off, healthcare benefits, supplemental benefits, 401k including an employer match, discount perks, rewards, and more. We invest in our employees - Every employee is eligible for education reimbursement for certifications, degrees, or professional development. Reimbursement amounts may fluctuate due to IRS limitations. We want you to grow as an expert and a leader and offer flexibility for you to take a course, complete a certification, or other professional growth and networking. We are committed to supporting your curiosity and sustaining a culture that prioritizes commitment to continuous professional development.
We work hard; we play hard. Kentro is committed to incorporating fun into every day. We dedicate funds for activities - virtual and in-person - e.g., we host happy hours, holiday events, fitness & wellness events, and annual celebrations. In alignment with our commitment to our communities, we also host and attend charity galas/events. We believe in appreciating your commitment and building a positive workspace for you to be creative, innovative, and happy.
Commitment Equal Opportunity Employment & VEVRAA
Kentro is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state or local law.
Kentro is strongly committed to compliance with VEVRAA and other applicable federal, state, and local laws governing equal employment opportunity. We have developed comprehensive policies and procedures to ensure our hiring practices align with these requirements.
As part of our VEVRAA compliance efforts, Kentro has established an equal opportunity plan outlining our commitment to recruiting, hiring, and advancing protected veterans. This plan is regularly reviewed and updated to ensure its effectiveness.
We encourage protected veterans to self-identify during the application process. This information is strictly confidential and will only be used for reporting and compliance purposes as required by law. Providing this information is voluntary and will not impact your employment eligibility.
Our commitment to equal employment opportunity extends beyond legal compliance. We are dedicated to fostering an inclusive workplace where all employees, including protected veterans, are treated with dignity, respect, and fairness.
How to Apply
To apply to Kentro Positions- Please click on the: “Apply for this Job” button at the bottom of this Job Description or the button at the top: “Application.” Please upload your resume and complete all the application steps. You must submit the application for Kentro to consider you for a position. If you need alternative application methods, please email ***************** and request assistance.
Accommodations
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. Reasonable Accommodations may be made to enable qualified individuals with disabilities to perform the essential functions. If you need to discuss reasonable accommodations, please email *****************.
#LI-JG1
$100k-146k yearly est. 28d ago
Manager Information Security - USFHP
Providence Health & Services 4.2
Renton, WA jobs
Manager Information Security- Renton, Washington Schedule- Full Time/ Days Oversees day-to-day operations and staff of the Security team. Prioritizes workloads of the group and acts in a supervisory role. Responsible for security policy and procedure development, enterprise security awareness and working to ensure compliance with internal and external regulatory standards such as HIPAA and DIACAP related to information security.
Providence caregivers are not simply valued - they're invaluable. Join our team at USFHP and thrive in our culture of patient-focused, whole-person care built on understanding, commitment, and mutual respect. Your voice matters here, because we know that to inspire and retain the best people, we must empower them.
Benefits and perks:
+ Competitive pay (including holiday pay & shift pay differentials)
+ Best-in-class benefits - full medical, dental and vision coverage from your first day
+ 401(k) plan with employer matching & complementary retirement planner
+ Generous paid time off for vacation, sick days and holidays
+ Tuition reimbursement & student loan forgiveness programs
+ Wellness & mental health assistance programs
+ Back-up child & elder care to help with care disruptions for your family
+ Voluntary benefits, like pet, auto and home insurance, and more!
Required Qualifications:
+ Bachelor's Degree in Information technology Or Equivalent IT technical and managerial experience.
+ 3 years of Managing technical and/or security staff.
+ Demonstrated experience developing customer service work processes in the area of technology.
Preferred Qualifications:
+ Upon hire: CISSP, CISA, CHP, CHSS, GIAC, MCSE, MCSA certifications
+ Experience in a healthcare IT setting.
Why Join Providence?
Our best-in-class benefits are uniquely designed to support you and your family in staying well, growing professionally and achieving financial security. We take care of you, so you can focus on delivering our mission to advocate, educate and provide extraordinary care.
Accepting a new position at another facility that is part of the Providence family of organizations may change your current benefits. Changes in benefits, including paid time-off, happen for various reasons. These reasons can include changes of Legal Employer, FTE, Union, location, time-off plan policies, availability of health and welfare benefit plan offerings, and other various reasons.
About Providence
At Providence, our strength lies in Our Promise of "Know me, care for me, ease my way." Working at our family of organizations means that regardless of your role, we'll walk alongside you in your career, supporting you so you can support others. We provide best-in-class benefits and we foster an inclusive workplace where diversity is valued, and everyone is essential, heard and respected. Together, our 120,000 caregivers (all employees) serve in over 50 hospitals, over 1,000 clinics and a full range of health and social services across Alaska, California, Montana, New Mexico, Oregon, Texas and Washington. As a comprehensive health care organization, we are serving more people, advancing best practices and continuing our more than 100-year tradition of serving the poor and vulnerable.
Posted are the minimum and the maximum wage rates on the wage range for this position. The successful candidate's placement on the wage range for this position will be determined based upon relevant job experience and other applicable factors. These amounts are the base pay range; additional compensation may be available for this role, such as shift differentials, standby/on-call, overtime, premiums, extra shift incentives, or bonus opportunities.
Providence offers a comprehensive benefits package including a retirement 401(k) Savings Plan with employer matching, health care benefits (medical, dental, vision), life insurance, disability insurance, time off benefits (paid parental leave, vacations, holidays, health issues), voluntary benefits, well-being resources and much more. Learn more at providence.jobs/benefits.
Applicants in the Unincorporated County of Los Angeles: Qualified applications with arrest or conviction records will be considered for employment in accordance with the Unincorporated Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.
About the Team
Pacific Medical Centers (PacMed) is a private, not-for-profit, primary and integrated multi-specialty health care network with outpatient clinics and primary and specialty care providers in King, Snohomish and Pierce counties. We combine decades of patient-centered care with cutting-edge technology, first-class facilities and board-certified providers.
Our strong team environment and respect for our people-at all levels and from all backgrounds-allow us to provide authentic care that achieves the highest-quality patient outcomes, backed by the strong network of resources and support through our affiliation with the Providence family, including local partners like Swedish Health Services.
Providence is proud to be an Equal Opportunity Employer. We are committed to the principle that every workforce member has the right to work in surroundings that are free from all forms of unlawful discrimination and harassment on the basis of race, color, gender, disability, veteran, military status, religion, age, creed, national origin, sexual identity or expression, sexual orientation, marital status, genetic information, or any other basis prohibited by local, state, or federal law. We believe diversity makes us stronger, so we are dedicated to shaping an inclusive workforce, learning from each other, and creating equal opportunities for advancement.
For any concerns with this posting relating to the posting requirements in RCW 49.58.110(1), please click here where you can access an email link to submit your concern.
Requsition ID: 408336
Company: Pacific Medical Jobs
Job Category: Information Security
Job Function: Information Technology
Job Schedule: Full time
Job Shift: Day
Career Track: Leadership
Department: 3060 WA USFHP
Address: WA Renton 620 Naches Ave SW
Work Location: Blackriver Corporate Park-Renton
Workplace Type: On-site
Pay Range: $74.17 - $117.10
The amounts listed are the base pay range; additional compensation may be available for this role, such as shift differentials, standby/on-call, overtime, premiums, extra shift incentives, or bonus opportunities.