Cloud Security Engineer III - Lead
Boston, MA jobs
App & Cloud Security Engineer - Lead
Start: 2-3 weeks from date of offer
*Background Check Required*
*No VISA Sponsorship*
Hospital based in Boston, MA is building out a unified security team that will encompass both App and Cloud. This team will manage security across the full application lifecycle- from inception and code review to deployment and underlying infrastructure maintenance.
This position is the 1st hire for this department will be instrumental in the build out. Growth plans are to be a team of 8 over the next 3 years.
The Role: Lead Engineer (First Hire)
Position: High-level Individual Contributor (Engineer III) acting as the "founding member" and leader of this new function.
Key Responsibilities:
Define the strategy and build the program from the ground up.
Serve as the Product Owner for Wiz and Snyk.
Collaborate closely with separate Cloud Engineering and Security Remediation teams.
Ideal Candidate Profile: Someone with a background in Cloud Incident Response is highly desired. The client values the unique perspective this brings to defining a risk-prioritized approach to remediation.
Career Trajectory: Opportunity to evolve into a Principal IC (Engineer IV) or pivot into leadership (Manager/Sr. Manager) as the team grows.
Environment:
Predominately Azure with some AWS as well. GCP is being sun-setted.
Qualifications
Bachelor's degree in Information Security, Computer Science, or related field; advanced degrees or equivalent professional experience preferred.
Minimum of 5+ years of progressive experience in application security, cloud security, or related cybersecurity roles.
Relevant industry certifications preferred (CISSP, CCSP, CSSLP, AWS/Azure Security Specialty, GIAC certifications).
Skills for Success
Expert-level knowledge and practical experience in secure software development methodologies, OWASP Top 10, and application security testing tools (SAST, DAST, IAST).
A comprehensive understanding of secure coding principles, with the ability to guide development teams in adhering to these best practices. Hands-on experience with static and dynamic application security testing tools is preferred.
Proven expertise in securing major cloud platforms (AWS, Azure, GCP), including experience with Cloud Security Posture Management tools, cloud-native security services, and infrastructure-as-code security.
Deep understanding of modern software architectures, microservices, APIs, and container security best practices (e.g., Docker, Kubernetes).
Ability to think strategically, creatively, and innovatively to design and implement robust security controls.
Demonstrated leadership skills with strong project management capabilities, able to effectively communicate complex technical security issues clearly to technical and non-technical stakeholders.
Proven track record of delivering and managing successful security projects and continuous improvement initiatives.
Strong ability to apply documented processes, playbooks, and frameworks (e.g., OWASP, NIST CSF, etc.) to effectively address and resolve a wide variety of application security challenges.
Knowledge of established security frameworks, including NIST Cybersecurity Framework (CSF), NIST 800-53 with a focus on their application in securing software and application environments.
Preferred certifications include: Offensive Security Certified Professional (OSCP), Offensive Security Certified Expert (OSCE), GIAC Penetration Tester Certification (GPEN), GIAC Experienced Penetration Tester (GX-PT), GIAC Certified Red Team Professional (GRTP), GIAC Security Operations Certified (GSOC), GIAC Security Expert (GSE), etc.
Must know how to use common M365 Office Suite of products.
Physical Security Engineer
Remote
Due to continued growth, ENERCON's Nuclear Services Design Instrumentation and Controls Group has immediate openings for Physical Security Technicians/Engineers to join our team. In this dynamic role, you'll forge powerful relationships with both internal teams and external clients, especially in the cutting-edge field of Physical Security, while leading engineering efforts to deliver innovative solutions. You'll drive project success by solving complex technical challenges, ensuring top-quality results, and guiding your team to exceed customer expectations with every step! This role can be located in the following locations:
King of Prussia, PA
Crane Clean Energy Center - Middletown, PA
Remote in Palo, IA
Palisades - Covert, MI
Birmingham, AL
Naperville, IL (Suburb of Chicago)
Kennesaw, GA (Suburb of Atlanta)
This role can be Full Time, Part Time, or LTLB (Contract).
Responsibilities
Imagine a day where you're at the forefront of collaboration, working with engineering teams and clients to deliver cutting-edge solutions in Physical Security. You lead technical discussions, resolve challenges, and ensure designs meet all requirements. Your guidance keeps projects on track while you research improvements, propose innovations, and provide key updates to senior management-making a real impact and strengthening vital relationships every step of the way.
Relationship Building & Client Interaction: Work interactively with internal engineering and external clients to develop strong relationships, particularly in Physical Security. Ability to interface with site physical security management and engineering stakeholders
Engineering Support & Technical Leadership: Provide direct engineering support to project engineering staff to ensure design products satisfy customer expectations, contract requirements, and regulatory requirements. Provide technical leadership and support to engineering staff. Guide and review deliverables, review progress, and update senior management, as needed
Issue Resolution & Quality Assurance: Facilitate resolution of inter-disciplinary and cross-disciplinary technical and quality issues. Research and assess best practices, proposing methods and improvements
Project Planning & Execution: Plan and direct the timely execution of assigned engineering activities. Work with the Project Engineer (PE), engineering supervision, and project management to provide timely updates of progress, challenges, and implementation
#LI-MB1
Qualifications
A minimum of 3 years of relevant design engineering and or technician experience is required for this role
Bachelor's Degree in engineering field is preferred, HS Diploma/GED and equivalent relevant experience is required
Experience with AIM or NSMART security platforms is highly preferred
Experience in the design, installation, and testing of large scale (complete systems) digital control and computer monitoring system upgrades at power plants preferred
Types of upgrades include replacement of Turbine/Generator Control Systems with DCS platforms, process computer, and cybersecurity systems
Nuclear plant design experience and/or field experience working for a nuclear QA Program preferred
Must be proficient with MS Word, Excel, Visio, Access and PowerPoint
Good verbal and written communication skills and the ability to comprehend and convey detailed technical data
Knowledge of Physical Security related principles, standards, and regulations
An ability to perform walkdowns across multiple areas at a nuclear power plant and to provide feedback to the engineers on deviations from plant equipment when compared with plant drawings (i.e. as-built walkdowns)
Demonstrated leadership ability to manage multiple tasks and projects and ability to work effectively with all levels of staff and management
Excellent verbal and written communication skills including demonstrated ability to present to clients
Ability to travel to client sites for meetings and walkdowns, approximately 30% of the time
Senior level should be familiar with the Standard Design Process and Digital Engineering Guide
Pay Range USD $85,000.00 - USD $165,000.00 /Yr. Additional Information
About ENERCON:
At Enercon Services, Inc. (ENERCON), we're driven by our people-and we're proud to offer rewarding careers in a culture of excellence. We provide a comprehensive benefits package and professional development opportunities that support your long-term growth.
What We Offer:
Enjoy full benefits for you and your dependents starting day one, no waiting period
Flexible work arrangements, including hybrid and alternative schedules
401(k) with employer matching
Tuition reimbursement
Professional Engineer (PE) license support and incentives
Want to see the full picture? Click HERE to see our Comprehensive Benefits
Salary Range Information:
If a salary range is listed, it reflects the typical range for this full-time position based on the role, level, and location. Individual compensation within the range will be determined by factors such as work location, relevant experience, job-related skills, and education or training.
Eligibility to Work:
Candidates must be legally eligible to work in the US without requiring current or future sponsorship.
Ability to pass a pre-employment and random drug and alcohol screenings, ENERCON and client specific background checks, and annual motor vehicle record (MVR) according to company and client policies.
Equal Opportunity Employer:
ENERCON does not discriminate in employment opportunities or practices based on race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other characteristic protected by law.
Connect with Us: *************** | LinkedIn
Auto-ApplyCyber Security Analyst
Atlanta, GA jobs
A Southern Company Security Analyst participates in monitoring, hunting and responding to cyber security events. He or She, provides a front-line role during cyber security incidents, identifying the extent of the threat, business impacts and advising or sometimes performing the most suitable course of action to contain, eradicate and remediate an incident. A Southern Company Security Analyst maintains a good knowledge of the threat landscape, helps enhance visibility and response capabilities by identifying new methods of detecting threats. A Southern Company Security Analyst is proactive and seeks out adversaries determined to negatively impact Southern Companies reputation, financial interest or threatens the safety of our employees and customers.
Candidates are expected to discuss and demonstrate they meet required qualifications for applicable roles.
Responsibilities
Take action on security events presented to Analyst via SIEM, user submissions, dashboards, etc.
Self-initiate hunting initiatives to discover potential breaches or undiscovered cyber threats
Remain abreast of emerging threat patterns and provide recommendations to detect threats
Assists with patching recommendations and workarounds for zero-day threats.
Coordinate mitigation or remediations task with stakeholders or supporting teams
Communicates with management on incident updates.
Monitors SIEM and analyzes security events to determine appropriate actions
Monitors emails containing links/attachments associated with potential phishing attempts to determine appropriate actions
Identify and tune false positives associated with current security events
Document analytical steps and findings associated with security event investigations
Qualifications Required for Cyber Security Analyst
2 years IT security experience
Minimum 2 years of experience in performing analysis on Windows and LINUX/UNIX systems
Minimum 2 years of experience and/or familiarity in the following areas:
Network/Endpoint: analysis tools
Scripting languages
Windows/Unix command line utilities
Reputation analysis associated with IP's, Domains, Email Addresses
Ticketing Systems
Required to submit to a background examination.
Experience operating within a security application such as Kali, Metasploit, and etc.
Familiar with and have worked within Cyber Security Frameworks such as:
NIST 800 - 61
Attack Life Cycle
SANS Security Controls
MITRE
SANS Security 500 Series or other industry standard equivalent
Experience with PCAP analysis
Experience investigating endpoint and network security events
Experience investigating user reported Phishing events (specifically investigating suspicious links and attachments)
Experience analyzing security events utilizing sandbox technology
Experience operating within a security application such as Kali, Metasploit, and etc.
Oral and written communication skills
Experience taking ownership of incidents from acknowledgement to resolution
Ability to identify and mitigate security events by recommending and/or implementing defensive/preventive strategies
Experience initiating security event investigations
Preferred capabilities:
Oral and written communication skills
Ability to take ownership of incidents from acknowledgement to resolution
Ability to initiate security event investigations
Ability to comprehend and articulate business impact associated with security events
Interacting with vendors to support proof of concepts
Proficient in Microsoft Office products: Excel, Word, Outlook and etc.
Exposure, experience and/or knowledge of cloud technology
Familiar with NIST 800-61 and SANS Critical Security Controls
Ability to identify and mitigate security events by recommending and/or implementing defensive/preventive strategies
Desired certifications:
GIAC Security Essentials (GCIH)
GIAC Certified Intrusion Analyst (GCIA)
Security+
Other certifications within IT Security
Characteristics of an Southern Company Cyber Analyst
Self-Motivated - Cyber Analysts do not only act when security tools trigger alerts, we are suspicious by nature and can generate security events based on self-initiated task.
Perseverance - Cyber Analysts identify resources that allow us to move through or around barriers as we analyze cyber security events.
Dependable - Cyber Analysts work within a team environment and thus, we rely on one another for knowledge-sharing and dependence.
Integrity - As Cyber Analysts, our reputation is our code of ethics. We are not perfect. We admit our mistakes. We do the right thing.
Sense of Humor - Although this may vary, just have one; I promise we can work with it. We have a lot of fun in what we do, so you will need a sense of humor to keep up.
This position falls under the company's Insider Threat Program and will have access to, and control over sensitive data, systems or assets. Enhanced personnel screening, which includes a background review, drug screen and psychological assessment, will be required if you are selected for this position
Auto-ApplySenior Security Specialist
Oklahoma City, OK jobs
Required Travel: 0 - 10% Employment Type: Full Time/Salaried/Exempt Anticipated Salary Range: $81,523.00 - $115,000.00 Security Clearance: TS/SCI Level of Experience: Senior Employee Referral Amount: $4,500.00 Meet HII's Mission Technologies Division
Our team of more than 7,000 professionals worldwide delivers all-domain expertise and advanced technologies in service of mission partners across the globe. Mission Technologies is leading the next evolution of national defense - the data evolution - by accelerating a breadth of national security solutions for government and commercial customers. Our capabilities range from C5ISR, AI and Big Data, cyber operations and synthetic training environments to fleet sustainment, environmental remediation and the largest family of unmanned underwater vehicles in every class. Find the role that's right for you. Apply today. We look forward to meeting you.
Job Description
HII - Mission Technologies Corp; is looking for a Senior Security Specialist to provide overall security support and oversight of all unit SAP activities. Responsible for developing & implementing security policy and guidance for conducting classified operations and activities. Familiar and functional with the Joint Personnel Adjudication System (JPAS), Joint Access Database Environment (JADE), Defense Central Index of Investigations (DCII), and Industrial Security Facilities Database.
Essential Job Responsibilities
Document Control: Preparation and dispatch of classified mail packages to other agencies. Protect, transmit/receive classified materials, proprietary and sensitive information via classified networks and secure fax. Enforce two-person integrity requirements to upload/download files onto secure networks.
Physical Security: Responsible for physical security of the unit's classified facilities to include entry control, issue badges, generate meeting rosters, conduct entry/exit checks and ensure prohibited devices are not introduced into the facilities. Activate alarms, enter unit personnel into the system, conduct alarm tests and initiate guard force response tests. Maintain an accurate door/safe combination database & change cypher/lock combinations, as required.
Security Education: Support development and implementation of SAP security education and training program that is tailored to meet specific security requirements of the unit. Develop and conduct initial, refresher and supplemental SAP security briefings and documents the training.
Training and Operations Security (OPSEC) : Assist in identifying OPSEC indicators, vulnerabilities & countermeasures to protect classified operations, programs and resources. Assist with the development, implementation and enforcement of OPSEC & ensures unit personnel are aware of current OPSEC concerns and unit security posture.
Process, review and edit unit and incoming security documentation, Facility Accreditations, Test Plans, DD 254s, Standard Operating Procedures.
Personnel Security: Informing security policies and procedures for obtaining and maintaining SAP access. Shall assist in managing SAP access quotas and maintains program access rosters. Prepare & review Program Access Requests (PAR) IAW the Special Access Program Nomination Process (SAPNP) and prepare letters of compelling need (LOCN) packages. Review the JPAS/DCII databases to confirm clearance information and send visit certifications. Responsible for entering privacy act information, foreign contact/travel information and program access data into the JADE system.
Minimum Qualifications
+ 10 years relevant experience with Bachelors in related field; 8 years relevant experience with Masters in related field; or High School Diploma or equivalent and 14 years relevant experience.
+ Must have an active TS/SCI clearance.
+ Must have 12 months or more experience in a SAP environment within the last five years.
+ Experience in protection and safeguarding of SAP
HII is more than a job - it's an opportunity to build a new future. We offer competitive benefits such as best-in-class medical, dental and vision plan choices; wellness resources; employee assistance programs; Savings Plan Options (401(k)); financial planning tools, life insurance; employee discounts; paid holidays and paid time off; tuition reimbursement; as well as early childhood and post-secondary education scholarships. Bonus/other non-recurrent compensation is occasionally offered for qualified positions, and if applicable to this role will be addressed by the recruiter at the screening phase of application.
Why HII
We build the world's most powerful, survivable naval ships and defense technology solutions that safeguard our seas, sky, land, space and cyber. Our workforce includes skilled tradespeople; artificial intelligence, machine learning (AI/ML) experts; engineers; technologists; scientists; logistics experts; and business administration professionals.
Recognized as one of America's top large company employers, we are a values and ethics driven organization that puts people's safety and well-being first. Regardless of your role or where you serve, at HII, you'll find a supportive and welcoming environment, competitive benefits, and valuable educational and training programs for continual career growth at every stage of your career.
Together we are working to ensure a future where everyone can be free and thrive.
All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, physical or mental disability, age, or veteran status or any other basis protected by federal, state, or local law.
Do You Need Assistance?
If you need a reasonable accommodation for any part of the employment process, please send an e-mail to ************************** and let us know the nature of your request and your contact information. Reasonable accommodations are considered on a case-by-case basis. Please note that only those inquiries concerning a request for reasonable accommodation will be responded to from this email address. Additionally, you may also call ************** for assistance. Press #3 for HII Mission Technologies.
Senior Security Specialist
Oklahoma City, OK jobs
Company: HII's Mission Technologies division Required Travel: 0 - 10% Employment Type: Full Time/Salaried/Exempt Anticipated Salary Range: $81,523.00 - $115,000.00 Security Clearance: TS/SCI Level of Experience: Senior Employee Referral Amount: $4,500.00
Meet HII's Mission Technologies Division
Our team of more than 7,000 professionals worldwide delivers all-domain expertise and advanced technologies in service of mission partners across the globe. Mission Technologies is leading the next evolution of national defense - the data evolution - by accelerating a breadth of national security solutions for government and commercial customers. Our capabilities range from C5ISR, AI and Big Data, cyber operations and synthetic training environments to fleet sustainment, environmental remediation and the largest family of unmanned underwater vehicles in every class. Find the role that's right for you. Apply today. We look forward to meeting you.
Job Description
HII - Mission Technologies Corp; is looking for a Senior Security Specialist to provide overall security support and oversight of all unit SAP activities. Responsible for developing & implementing security policy and guidance for conducting classified operations and activities. Familiar and functional with the Joint Personnel Adjudication System (JPAS), Joint Access Database Environment (JADE), Defense Central Index of Investigations (DCII), and Industrial Security Facilities Database.
Essential Job Responsibilities
Document Control: Preparation and dispatch of classified mail packages to other agencies. Protect, transmit/receive classified materials, proprietary and sensitive information via classified networks and secure fax. Enforce two-person integrity requirements to upload/download files onto secure networks.
Physical Security: Responsible for physical security of the unit's classified facilities to include entry control, issue badges, generate meeting rosters, conduct entry/exit checks and ensure prohibited devices are not introduced into the facilities. Activate alarms, enter unit personnel into the system, conduct alarm tests and initiate guard force response tests. Maintain an accurate door/safe combination database & change cypher/lock combinations, as required.
Security Education: Support development and implementation of SAP security education and training program that is tailored to meet specific security requirements of the unit. Develop and conduct initial, refresher and supplemental SAP security briefings and documents the training.
Training and Operations Security (OPSEC): Assist in identifying OPSEC indicators, vulnerabilities & countermeasures to protect classified operations, programs and resources. Assist with the development, implementation and enforcement of OPSEC & ensures unit personnel are aware of current OPSEC concerns and unit security posture.
Process, review and edit unit and incoming security documentation, Facility Accreditations, Test Plans, DD 254s, Standard Operating Procedures.
Personnel Security: Informing security policies and procedures for obtaining and maintaining SAP access. Shall assist in managing SAP access quotas and maintains program access rosters. Prepare & review Program Access Requests (PAR) IAW the Special Access Program Nomination Process (SAPNP) and prepare letters of compelling need (LOCN) packages. Review the JPAS/DCII databases to confirm clearance information and send visit certifications. Responsible for entering privacy act information, foreign contact/travel information and program access data into the JADE system.
Minimum Qualifications
* 10 years relevant experience with Bachelors in related field; 8 years relevant experience with Masters in related field; or High School Diploma or equivalent and 14 years relevant experience.
* Must have an active TS/SCI clearance.
* Must have 12 months or more experience in a SAP environment within the last five years.
* Experience in protection and safeguarding of SAP
HII is more than a job - it's an opportunity to build a new future. We offer competitive benefits such as best-in-class medical, dental and vision plan choices; wellness resources; employee assistance programs; Savings Plan Options (401(k)); financial planning tools, life insurance; employee discounts; paid holidays and paid time off; tuition reimbursement; as well as early childhood and post-secondary education scholarships. Bonus/other non-recurrent compensation is occasionally offered for qualified positions, and if applicable to this role will be addressed by the recruiter at the screening phase of application.
Why HII
We build the world's most powerful, survivable naval ships and defense technology solutions that safeguard our seas, sky, land, space and cyber. Our workforce includes skilled tradespeople; artificial intelligence, machine learning (AI/ML) experts; engineers; technologists; scientists; logistics experts; and business administration professionals.
Recognized as one of America's top large company employers, we are a values and ethics driven organization that puts people's safety and well-being first. Regardless of your role or where you serve, at HII, you'll find a supportive and welcoming environment, competitive benefits, and valuable educational and training programs for continual career growth at every stage of your career.
Together we are working to ensure a future where everyone can be free and thrive.
All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, physical or mental disability, age, or veteran status or any other basis protected by federal, state, or local law.
Do You Need Assistance?
If you need a reasonable accommodation for any part of the employment process, please send an e-mail to ************************** and let us know the nature of your request and your contact information. Reasonable accommodations are considered on a case-by-case basis. Please note that only those inquiries concerning a request for reasonable accommodation will be responded to from this email address. Additionally, you may also call ************** for assistance. Press #3 for HII Mission Technologies.
Sr Cyber Security Engineer
Oakbrook Terrace, IL jobs
Who We Are We're powering a cleaner, brighter future. Exelon is leading the energy transformation, and we're calling all problem solvers, innovators, community builders and change makers. Work with us to deliver solutions that make our diverse cities and communities stronger, healthier and more resilient.
We're powered by purpose-driven people like you who believe in being inclusive and creative, and value safety, innovation, integrity and community service. We are a Fortune 200 company, 19,000 colleagues strong serving more than 10 million customers at six energy companies -- Atlantic City Electric (ACE), Baltimore Gas and Electric (BGE), Commonwealth Edison (ComEd), Delmarva Power & Light (DPL), PECO Energy Company (PECO), and Potomac Electric Power Company (Pepco).
In our relentless pursuit of excellence, we elevate diverse voices, fresh perspectives and bold thinking. And since we know transforming the future of energy is hard work, we provide competitive compensation, incentives, excellent benefits and the opportunity to build a rewarding career.
Are you in?
Primary Purpose
The Cyber Security Engineer (CSE) will execute the highly technical, tactical elements of the Security Architects' (and overall CISS) cyber security strategy, eliminating a functional cyber security capability gap while providing pro-active cyber security risk management. The CSE will act as a liaison to the Security Architect and Cloud and Infrastructure Operations/Engineering and Utility IT/OT teams to effectively communicate and assist in architecting and implementing effective security solutions. The CSE will also assist with vulnerability mitigation, incident remediation, and will help manage change requests in support of cyber vulnerability remediation efforts. The CSE will ensure the implementation of system security measures in accordance with established procedures to ensure confidentiality, integrity, availability, authentication, and non-repudiation, and will perform security reviews to identify gaps in security architecture. The CSE will assist in the development of appropriate security risk management plans.
Note: This is a hybrid position (in-office with remote flexibility). Employees are required to be in office at least three days per week (Tuesday, Wednesday, and Thursday). This position must sit out of our Millsboro - DE, Philadelphia - PA, Oakbrook Terrace - IL or Owings Mills - MD office. This position is not eligible for relocation assistance.
Primary Duties
* Provide analytical and technical security recommendations to other team members, technical teams, and business clients, including: Provide cybersecurity guidance to leadership Work with stakeholders to resolve computer security incidents and vulnerability compliance Provide input to implementation plans and standard operating procedures as they relate to information systems security Develop specific cybersecurity countermeasures and risk mitigation strategies for systems and/or applications
* Work closely with technical teams to implement effective security configurations/requirements, including: Verify minimum security requirements are in place for all applications Ensure application of security patches for commercial/custom products integrated into system design Implement security measures to resolve vulnerabilities, mitigate risks, and recommend security changes to system or system components as needed Mitigate/correct security deficiencies identified during security/certification testing and/or recommend risk acceptance for the appropriate senior leadership Verify and update security documentation reflecting the application/system security design features Verify minimum security requirements are in place for all applications
* Work closely with the Vulnerability Management and application teams to ensure secure transition of applications into production.
* Assist with vulnerability mitigation, incident remediation, and associated change management activities.
Job Scope
The Cyber Security Engineer (CSE) will work closely (and primarily) with Cloud and Infrastructure Operations/Engineering and Utility IT/OT clients to implement effective security configurations and requirements; provide analytical and technical security recommendations to other team members, technical teams, and business clients; act as a senior technical lead for all Exelon security remediation efforts; meet with Exelon business clients and management to help specify and negotiate application security requirements; work closely with Exelon application teams to ensure secure transition of applications into production; develop technology to automate cyber security monitoring, logging, and compliance with CISS standards; actively participate in relevant industry cyber security workgroups and forums; act as a liaison to the Security Architect and Cloud and Infrastructure Operations/Engineering and Utility IT/OT teams to effectively communicate and assist in architecting and implementing effective security solutions; develop documentation to support ongoing security systems operations, maintenance, and problem resolution; mitigate vulnerabilities, remediate incidents, and affect change requests in support of cyber vulnerability remediation efforts; work closely with the Security Policy and Risk Office to assist with the identification, analysis, and remediation of Exelon cyber security risk
Minimum Qualifications
* Bachelor's Degree in Computer Science, Information Technology (IT), or a related discipline, and typically 8 or more years of solid, diverse experience in cyber security vulnerability assessments, or equivalent combination of education and work experience.
* At least 5-8 years of demonstrable security engineering or related experience, including: Knowledge of encryption algorithms Knowledge of cryptology
* Knowledge of database systems
* Knowledge of embedded systems
* Knowledge of how system components are installed, integrated, and optimized
* Knowledge of human-computer interaction principles
* Knowledge of cybersecurity principles and organizational requirements (relevant to confidentiality, integrity, availability, accountability, authentication, non-repudiation)
* Knowledge of operating systems
* Knowledge of IT and OT security principles and methods, such as firewalls, IDS/IPS, demilitarized zones, and encryption Skilled in evaluating the adequacy of security designs
* Knowledge of the systems engineering process
* Knowledge of network protocols, routing principles, identity and access management
* Comprehensive understanding of change management techniques associated with new technology implementation.
* Demonstrated experience producing an economic business case.
* Demonstrated leadership ability.
* Proven analytical, problem solving, and consulting skills.
* Excellent communication skills and the proven ability to work effectively with all levels of IT/OT and business management.
Preferred Qualifications
* Graduate degree in cyber security or related area of expertise.
* Relevant security certifications (CISSP, GIAC, MCSE, RHCE, CCNP, CCSP)
* Demonstrable, hands-on expertise in the following technical disciplines: Operating Systems (Microsoft, Linux, UNIX) Networking (Cisco, Checkpoint, Alcatel Lucent, Gigamon, RuggedCom) Mobility (IOS, Android, MDM, BYOD) Cryptography (PKI, lifecycle management) Network Security Engineering (secure network design, IDS/IPS, monitoring, firewalls) Virtualization (VMware, HyperV) Remote Access Methods (VPN, Citrix, MFA) ICS / SCADA System Security (design, controls) Demonstrable understanding of the 10 functional domains of security
* A strong technical understanding of scripting languages (Perl, Powershell), as well as strong proficiency in Python, Ruby, or Java
* Demonstrable experience with Industrial Control Systems, SCADA environments, and utility methods and practices for operational technologies and service delivery
* Strong understanding of enterprise, network, system, and application level security engineering principles
* Demonstrable understanding of enterprise computing environments, distributed applications, and a strong understanding of TCP/IP networks
* Demonstrable understanding of system hardening processes, tools, guidelines, and benchmarks
* Firewalls (Cisco, Palo Alto, Checkpoint), Operating Systems (UNIX, LINUX, Windows etc.)
Benefits
* Annual salary will vary based on a candidate's skills, qualifications, experience, and other factors: $98,400.00/Yr. - $135,300.00/Yr.
* Annual Bonus for eligible positions: 15%
* 401(k) match and annual company contribution
* Medical, dental and vision insurance
* Life and disability insurance
* Generous paid time off options, including vacation, sick time, floating and fixed holidays, maternity leave and bonding/primary caregiver leave or parental leave
* Employee Assistance Program and resources for mental and emotional support
* Wellbeing programs such as tuition reimbursement, adoption and surrogacy assistance and fitness reimbursement
* Referral bonus program
* And much more
Note: Exelon-sponsored compensation and benefit programs may vary or not apply based on length of service, job grade, job classification or represented status. Eligibility will be determined by the written plan or program documents.
Sr Cyber Security Engineer
Oakbrook Terrace, IL jobs
**Who We Are** We're powering a cleaner, brighter future. Exelon is leading the energy transformation, and we're calling all problem solvers, innovators, community builders and change makers. Work with us to deliver solutions that make our diverse cities and communities stronger, healthier and more resilient.
We're powered by purpose-driven people like you who believe in being inclusive and creative, and value safety, innovation, integrity and community service. We are a Fortune 200 company, 19,000 colleagues strong serving more than 10 million customers at six energy companies -- Atlantic City Electric (ACE), Baltimore Gas and Electric (BGE), Commonwealth Edison (ComEd), Delmarva Power & Light (DPL), PECO Energy Company (PECO), and Potomac Electric Power Company (Pepco).
In our relentless pursuit of excellence, we elevate diverse voices, fresh perspectives and bold thinking. And since we know transforming the future of energy is hard work, we provide competitive compensation, incentives, excellent benefits and the opportunity to build a rewarding career.
Are you in?
**Primary Purpose**
The Cyber Security Engineer (CSE) will execute the highly technical, tactical elements of the Security Architects' (and overall CISS) cyber security strategy, eliminating a functional cyber security capability gap while providing pro-active cyber security risk management. The CSE will act as a liaison to the Security Architect and Cloud and Infrastructure Operations/Engineering and Utility IT/OT teams to effectively communicate and assist in architecting and implementing effective security solutions. The CSE will also assist with vulnerability mitigation, incident remediation, and will help manage change requests in support of cyber vulnerability remediation efforts. The CSE will ensure the implementation of system security measures in accordance with established procedures to ensure confidentiality, integrity, availability, authentication, and non-repudiation, and will perform security reviews to identify gaps in security architecture. The CSE will assist in the development of appropriate security risk management plans.
**Note: This is a hybrid position (in-office with remote flexibility). Employees are required to be in office at least three days per week (Tuesday, Wednesday, and Thursday). This position must sit out of our Millsboro - DE, Philadelphia - PA, Oakbrook Terrace - IL or Owings Mills - MD office. This position is not eligible for relocation assistance.**
**Primary Duties**
+ Provide analytical and technical security recommendations to other team members, technical teams, and business clients, including: Provide cybersecurity guidance to leadership Work with stakeholders to resolve computer security incidents and vulnerability compliance Provide input to implementation plans and standard operating procedures as they relate to information systems security Develop specific cybersecurity countermeasures and risk mitigation strategies for systems and/or applications
+ Work closely with technical teams to implement effective security configurations/requirements, including: Verify minimum security requirements are in place for all applications Ensure application of security patches for commercial/custom products integrated into system design Implement security measures to resolve vulnerabilities, mitigate risks, and recommend security changes to system or system components as needed Mitigate/correct security deficiencies identified during security/certification testing and/or recommend risk acceptance for the appropriate senior leadership Verify and update security documentation reflecting the application/system security design features Verify minimum security requirements are in place for all applications
+ Work closely with the Vulnerability Management and application teams to ensure secure transition of applications into production.
+ Assist with vulnerability mitigation, incident remediation, and associated change management activities.
**Job Scope**
The Cyber Security Engineer (CSE) will work closely (and primarily) with Cloud and Infrastructure Operations/Engineering and Utility IT/OT clients to implement effective security configurations and requirements; provide analytical and technical security recommendations to other team members, technical teams, and business clients; act as a senior technical lead for all Exelon security remediation efforts; meet with Exelon business clients and management to help specify and negotiate application security requirements; work closely with Exelon application teams to ensure secure transition of applications into production; develop technology to automate cyber security monitoring, logging, and compliance with CISS standards; actively participate in relevant industry cyber security workgroups and forums; act as a liaison to the Security Architect and Cloud and Infrastructure Operations/Engineering and Utility IT/OT teams to effectively communicate and assist in architecting and implementing effective security solutions; develop documentation to support ongoing security systems operations, maintenance, and problem resolution; mitigate vulnerabilities, remediate incidents, and affect change requests in support of cyber vulnerability remediation efforts; work closely with the Security Policy and Risk Office to assist with the identification, analysis, and remediation of Exelon cyber security risk
**Minimum Qualifications**
+ Bachelor's Degree in Computer Science, Information Technology (IT), or a related discipline, and typically 8 or more years of solid, diverse experience in cyber security vulnerability assessments, or equivalent combination of education and work experience.
+ At least 5-8 years of demonstrable security engineering or related experience, including: Knowledge of encryption algorithms Knowledge of cryptology
+ Knowledge of database systems
+ Knowledge of embedded systems
+ Knowledge of how system components are installed, integrated, and optimized
+ Knowledge of human-computer interaction principles
+ Knowledge of cybersecurity principles and organizational requirements (relevant to confidentiality, integrity, availability, accountability, authentication, non-repudiation)
+ Knowledge of operating systems
+ Knowledge of IT and OT security principles and methods, such as firewalls, IDS/IPS, demilitarized zones, and encryption Skilled in evaluating the adequacy of security designs
+ Knowledge of the systems engineering process
+ Knowledge of network protocols, routing principles, identity and access management
+ Comprehensive understanding of change management techniques associated with new technology implementation.
+ Demonstrated experience producing an economic business case.
+ Demonstrated leadership ability.
+ Proven analytical, problem solving, and consulting skills.
+ Excellent communication skills and the proven ability to work effectively with all levels of IT/OT and business management.
**Preferred Qualifications**
+ Graduate degree in cyber security or related area of expertise.
+ Relevant security certifications (CISSP, GIAC, MCSE, RHCE, CCNP, CCSP)
+ Demonstrable, hands-on expertise in the following technical disciplines: Operating Systems (Microsoft, Linux, UNIX) Networking (Cisco, Checkpoint, Alcatel Lucent, Gigamon, RuggedCom) Mobility (IOS, Android, MDM, BYOD) Cryptography (PKI, lifecycle management) Network Security Engineering (secure network design, IDS/IPS, monitoring, firewalls) Virtualization (VMware, HyperV) Remote Access Methods (VPN, Citrix, MFA) ICS / SCADA System Security (design, controls) Demonstrable understanding of the 10 functional domains of security
+ A strong technical understanding of scripting languages (Perl, Powershell), as well as strong proficiency in Python, Ruby, or Java
+ Demonstrable experience with Industrial Control Systems, SCADA environments, and utility methods and practices for operational technologies and service delivery
+ Strong understanding of enterprise, network, system, and application level security engineering principles
+ Demonstrable understanding of enterprise computing environments, distributed applications, and a strong understanding of TCP/IP networks
+ Demonstrable understanding of system hardening processes, tools, guidelines, and benchmarks
+ Firewalls (Cisco, Palo Alto, Checkpoint), Operating Systems (UNIX, LINUX, Windows etc.)
**Benefits**
+ Annual salary will vary based on a candidate's skills, qualifications, experience, and other factors: $98,400.00/Yr. - $135,300.00/Yr.
+ Annual Bonus for eligible positions: 15%
+ 401(k) match and annual company contribution
+ Medical, dental and vision insurance
+ Life and disability insurance
+ Generous paid time off options, including vacation, sick time, floating and fixed holidays, maternity leave and bonding/primary caregiver leave or parental leave
+ Employee Assistance Program and resources for mental and emotional support
+ Wellbeing programs such as tuition reimbursement, adoption and surrogacy assistance and fitness reimbursement
+ Referral bonus program
+ And much more
Note: Exelon-sponsored compensation and benefit programs may vary or not apply based on length of service, job grade, job classification or represented status. Eligibility will be determined by the written plan or program documents.
Exelon is proud to be an equal opportunity employer and employees or applicants will receive consideration for employment without regard to: age, color, disability, gender, national origin, race, religion, sexual orientation, gender identity, protected veteran status, or any other classification protected by federal, state, or local law. If you are an individual with a disability and need an accommodation to complete the application, please email us at ********************.
Cyber Security System Analyst - IT Information Security
New York, NY jobs
System Analyst is responsible for utilizing cyber security monitoring tools to provide day-to-day operational support and monitoring of the IT computing infrastructure. This is Shift Work. The Analyst will be expected to provide timely response, troubleshooting and escalation of alerts and coordinate incident response efforts with Cyber Security Operations Center (CSOC) within the Information Security Group. Required Education/Experience
* Bachelor's Degree in computer science or related field and 2 years of work experience in Cyber or in an IT related field. or
* Associate's Degree in computer science or related field and 4 years of relevant work experience, with at least 2 years of work experience in an IT field or
* High School Diploma/GED and 5 years of relevant work experience, with at least 3 years of work experience in an IT field.
Relevant Work Experience
* Previous IT experience is required.
* Previous Cyber Experience is required
* Scripting experience preferred
* Knowledge of security tools is preferred
* Good understanding of industry standard policy, processes and procedures covering incident, problem and change management is preferred
Skills and Abilities
* Strong written and verbal communication skills
* Ability to work within tight timeframes and meet strict deadlines
* Must be proficient in Microsoft Office including Word, Excel, Outlook and PowerPoint, etc.
Licenses and Certifications
* Driver's License Required
* Other: Technical certifications Security+, CYSA+ or equivalent, CISSP, etc. Preferred
Physical Demands
* Sit or stand to answer a phone for the duration of the workday
* Sit or stand to use a keyboard, mouse, and computer for the duration of the workday
* Ability to read small print and symbols
* Work rotating shifts, including nights, midnights, weekends and holidays
Additional Physical Demands
* The selected candidate will be assigned a System Emergency Assignment (i.e., an emergency response role) and will be expected to work non-business hours during emergencies, which may include nights, weekends, and holidays.
* Must be available 24/7, on call, and/or participate in off-hour emergency response activities as required.
* Must be able and willing to travel within Company service territory, as needed.
Core Responsibilities
* Monitor, troubleshoot and support intrusion prevention, endpoint protection, data loss prevention, and access control technologies.
* 1st Level triage, analysis, and processing of alerts.
* Respond swiftly to all alerts; perform initial risk/impact assessments or escalating issues as appropriate.
* Open and track incidents through to resolution.
* Facilitate communications to both internal and external parties.
* Support Corporate Security through forensics analysis of systems, malware, or network.
* This is a rotating position with a shift differential that covers holidays, weekends, and nights.
* Must be available 24/7, on call, and/or participate in off-hour emergency response activities as required.
* Enforce change management controls and guidelines.
* Provide real time and near real time responses to end users, technical support groups and IT management.
* Perform other related tasks and assignments as required.
* Respond to and participate in any incident response efforts.
* 1st level threat intelligence processing.
* Metric collection.
* Perform other related tasks and assignments as required.
Cyber Security Operations Analyst
Tulsa, OK jobs
The Cyber Security Operations Analyst is primarily responsible for monitoring the front lines of the company's cyber defense program, helping to protect critical systems and data from potential threats, responding to reported security violations, analyzing internet access, connectivity and threats (virus protection, spam, etc.)
DUTIES AND RESPONSIBILITIES
The following represents the majority of the duties performed by the position but is not meant to be all-inclusive nor prevent other duties from being assigned when necessary.
1. Complies with DOT and OSHA health, safety and environmental requirements and follows safety philosophy and procedures developed by the Company including: applicable environmental, health and safety rules, procedures, and accepted safe work practices, the use of appropriate personal protective equipment and safety systems, and the reporting of workplace hazards and injury or illness arising from workplace activities; observes the workplace to identify conditions or behaviors that should be corrected and takes appropriate action.
2. Monitors Security Information and Event Management (SIEM) alerts, firewall logs, intrusion detection systems, and network activity for suspicious behavior including public and private threat intelligence sources for emerging risks; analyzes internet access, connectivity logs, and alerts related to virus protection, spam, and suspicious behavior including user account activity providing reports on potential anomalies.
3. Conducts daily security log reviews and assists in identifying potential threats; summarizes and shares relevant alerts with the cybersecurity team.
4. Monitors incoming security tickets and alerts; documents and triages security incidents, escalating to senior analysts as needed; assists with evidence collection and incident tracking.
5. Performs scheduled vulnerability scans, analyzes findings, and maintains remediation tracking logs; assists with patch management processes including deployment, tracking, and reporting.
6. Assists with internal and external audits by collecting necessary documentation and evidence.
7. Maintains regulatory compliance documentation as required by TSA, DOT, O SHA, etc.; creates and updates procedural documents, runbooks, security playbooks, and knowledge base articles.
8. Documents all incidents, assessments, and routine checks to support audit readiness and knowledge transfer; manages project tracking logs.
9. Assists with the configuration and maintenance of endpoint protection, firewall settings, and other cybersecurity tools under guidance.
10. Reviews vendor solutions and compiles initial summaries for team consideration; maintains security-related inventories, software licenses, and access lists.
11. Assists with development and dissemination of basic cybersecurity awareness content for end users; tracks completion of required security training and assists with scheduling refresher sessions.
12. Participates in a scheduled on-call rotation for after-hours and weekend security support.
REQUIREMENTS
· Associate's degree or the equivalent in experience in Cyber Security, Information Technology or related field and a minimum of two (2) years of prior experience in cybersecurity, IT support, or SOC environment. Internship or hands-on training in networking, firewalls, or security systems preferred. Certification such as CompTIA Security+, CASP+, or CEH (preferred or in progress).
Knowledge, Skills and Abilities
· Ability to actively engage in safe behavior and understand and follow the principles and methods related to pipeline and workplace safety as established by the Company.
· Knowledge of emergency and safety procedures, policies procedures, equipment operating parameters, and all applicable DOT, EPA, FERC, DHS, and OSHA requirements.
· Knowledge of Active Directory, Exchange, SharePoint, CISCO routing and switching configuration.
· Knowledge of firewall and network security and IDS (intrusion detection systems), and network management tools.
· Knowledge of TSA security requirements and regulations.
· Knowledge of identity management processes and procedures.
· Skill in project management.
· Ability to manage, track and analyze information.
· Ability to effectively work and cooperate with supervisors, co-workers, and vendors.
· Ability to follow corporate policies and the directions of supervisors.
· Ability to refrain from causing or contributing to the disruption of the workplace.
Cyber Security Operations Analyst
Tulsa, OK jobs
The Cyber Security Operations Analyst is primarily responsible for monitoring the front lines of the company's cyber defense program, helping to protect critical systems and data from potential threats, responding to reported security violations, analyzing internet access, connectivity and threats (virus protection, spam, etc.)
DUTIES AND RESPONSIBILITIES
The following represents the majority of the duties performed by the position but is not meant to be all-inclusive nor prevent other duties from being assigned when necessary.
1. Complies with DOT and OSHA health, safety and environmental requirements and follows safety philosophy and procedures developed by the Company including: applicable environmental, health and safety rules, procedures, and accepted safe work practices, the use of appropriate personal protective equipment and safety systems, and the reporting of workplace hazards and injury or illness arising from workplace activities; observes the workplace to identify conditions or behaviors that should be corrected and takes appropriate action.
2. Monitors Security Information and Event Management (SIEM) alerts, firewall logs, intrusion detection systems, and network activity for suspicious behavior including public and private threat intelligence sources for emerging risks; analyzes internet access, connectivity logs, and alerts related to virus protection, spam, and suspicious behavior including user account activity providing reports on potential anomalies.
3. Conducts daily security log reviews and assists in identifying potential threats; summarizes and shares relevant alerts with the cybersecurity team.
4. Monitors incoming security tickets and alerts; documents and triages security incidents, escalating to senior analysts as needed; assists with evidence collection and incident tracking.
5. Performs scheduled vulnerability scans, analyzes findings, and maintains remediation tracking logs; assists with patch management processes including deployment, tracking, and reporting.
6. Assists with internal and external audits by collecting necessary documentation and evidence.
7. Maintains regulatory compliance documentation as required by TSA, DOT, O SHA, etc.; creates and updates procedural documents, runbooks, security playbooks, and knowledge base articles.
8. Documents all incidents, assessments, and routine checks to support audit readiness and knowledge transfer; manages project tracking logs.
9. Assists with the configuration and maintenance of endpoint protection, firewall settings, and other cybersecurity tools under guidance.
10. Reviews vendor solutions and compiles initial summaries for team consideration; maintains security-related inventories, software licenses, and access lists.
11. Assists with development and dissemination of basic cybersecurity awareness content for end users; tracks completion of required security training and assists with scheduling refresher sessions.
12. Participates in a scheduled on-call rotation for after-hours and weekend security support.
REQUIREMENTS
* Associate's degree or the equivalent in experience in Cyber Security, Information Technology or related field and a minimum of two (2) years of prior experience in cybersecurity, IT support, or SOC environment. Internship or hands-on training in networking, firewalls, or security systems preferred. Certification such as CompTIA Security+, CASP+, or CEH (preferred or in progress).
Knowledge, Skills and Abilities
* Ability to actively engage in safe behavior and understand and follow the principles and methods related to pipeline and workplace safety as established by the Company.
* Knowledge of emergency and safety procedures, policies procedures, equipment operating parameters, and all applicable DOT, EPA, FERC, DHS, and OSHA requirements.
* Knowledge of Active Directory, Exchange, SharePoint, CISCO routing and switching configuration.
* Knowledge of firewall and network security and IDS (intrusion detection systems), and network management tools.
* Knowledge of TSA security requirements and regulations.
* Knowledge of identity management processes and procedures.
* Skill in project management.
* Ability to manage, track and analyze information.
* Ability to effectively work and cooperate with supervisors, co-workers, and vendors.
* Ability to follow corporate policies and the directions of supervisors.
* Ability to refrain from causing or contributing to the disruption of the workplace.
Space Systems Cyber Security Engineer
Englewood, CO jobs
General Atomics (GA), and its affiliated companies, is one of the world's leading resources for high-technology systems development ranging from the nuclear fuel cycle to remotely piloted aircraft, airborne sensors, and advanced electric, electronic, wireless and laser technologies.
Whether a specific satellite for a specific mission or a constellation of interconnected spacecraft, the GA-EMS Space Systems team is re-defining how customers can access the possibilities of space. GA-EMS offers modular and scalable satellite platforms backed with a history of operational flight experience to support defense, civil, commercial, and academic mission requirements.
We're seeking a Space Systems Cyber Security Engineer to join our team in Englewood, CO. In this role, you'll collaborate closely with the lead cyber security engineer to implement program strategies aimed at achieving and maintaining authority to operate (ATO) for our cutting-edge space systems solutions.
DUTIES AND RESPONSIBILITIES:
* Serve as an Information Systems Security Engineer (ISSE) for one or more development programs.
* Security requirements: Capture, refine, and integrate information security requirements into system designs and development processes
* Security assessments: Conduct technical assessments to identify system vulnerabilities and ensure compliance with applicable regulations
* Security architecture: Design and implement secure system architectures, including hardware, software, data, and operational procedures
* Threat mitigation: Evaluate and mitigate system security threats and associated risks
* Security controls: Review and tailor security controls to meet specific program needs and ensure effectiveness
* Security documentation: Develop and maintain Risk Management Framework (RMF) documentation and supporting artifacts
* Standards compliance: Assess systems against relevant cybersecurity standards, frameworks, and publications
* Secure operations: Support the secure operation, monitoring, and maintenance of deployed systems
Other Responsibilities:
* Participate in and lead discussions in cyber security/information assurance working group meetings with our customers
* Develop content and present at program design and readiness reviews.
* Support development and execution of tests required for accreditation.
* Responsible for technical and schedule execution of the cyber security scope of work of one or more programs.
* Ensures all work products are produced in accordance with the project plan to satisfy the customer requirements.
* Ensures all work product are completed on schedule.
* Define Integrated Master Schedule (IMS) tasks necessary to complete the scope of work and achieve program milestones.
* Maintains the strict confidentiality of sensitive information.
* Performs other duties as assigned.
* Responsible for observing all laws, regulations and other applicable obligations wherever and whenever business is conducted on behalf of the Company. Expected to work in a safe manner in accordance with established operating procedures and practices.
We recognize and appreciate the value and contributions of individuals with diverse backgrounds and experiences and welcome all qualified individuals to apply.
Job Category
Engineering
Travel Percentage Required
0% - 25%
Full-Time/Part-Time
Full-Time Salary
State
Colorado
Clearance Level
Top Secret
Pay Range Low
98,100
City
Englewood
Clearance Required?
Desired
Pay Range High
171,398
Recruitment Posting Title
Space Systems Cyber Security Engineer
Job Qualifications
* Typically requires a bachelors degree, masters degree or PhD in engineering or a related technical discipline from an accredited institution and progressive engineering experience as follows; six or more years of experience with a bachelors degree, four or more years of experience with a masters degree, or two or more years with a PhD. May substitute equivalent engineering experience in lieu of education.
* Possess one or more of the following security certifications: CISSP, GIAC (any), CISM, CISA, or Security+
* Experience with system design aligned to the NIST Risk Management Framework (RMF) or similar standards, including full lifecycle activities such as Approval & Authorization, POA&M development, and continuous monitoring
* Familiarity with NIST Special Publications, including SP 800-30, 800-53, 800-82, and 800-171
* Knowledge of ISO/IEC 27000 series information security standards
* Experience applying DISA Security Technical Implementation Guides (STIGs)
* Hands-on experience with virtualized environments using VMware and/or Amazon Web Services (AWS)
* Ability to work extended hours to support critical test activities or operational needs
* Must have or be able to obtain a TS/SCI security clearance.
Preferred Qualifications:
* Experience with NASA's Security Information Technology policies, specifically NPR 2810.1
* Background in the space domain, including satellite ground systems, mission management, command and control systems, or satellites
* Strong understanding of network architecture, including TCP/IP and UDP design, as well as experience with switches, routers, and firewalls
US Citizenship Required?
Yes
Experience Level
Mid-Level (3-7 years)
Relocation Assistance Provided?
Yes
Workstyle
Onsite
Information System Security Officer - ISSO
San Diego, CA jobs
General Atomics (GA), and its affiliated companies, is one of the world's leading resources for high-technology systems development ranging from the nuclear fuel cycle to remotely piloted aircraft, airborne sensors, and advanced electric, electronic, wireless and laser technologies.
We have an exciting opportunity for an ISSO to join our Security Classified Systems team. This position is located in San Diego (Rancho Bernardo) CA.
DUTIES AND RESPONSIBILITIES:
* Interprets regulations as they apply to information systems, platforms, and IT operating processes, practices, and procedures.
* Participates in the development or modification of the computer environment information assurance security program plans and requirements.
* Participates in the development, distribution, and maintenance of System Security Plans, instructions, guidance, and standard operating procedures.
* Participates in audits of IT, platforms, and operating procedures; analyzes results.
* Participates in identifying risks and makes recommendations for improvements; may participate in corrective measures when incidents or vulnerabilities are discovered.
* Maintains knowledge of applicable policies, regulations, and compliance documents related to classified computing assets and environments.
* May represent the organization as a primary contact with internal representatives.
* Maintains the strict confidentiality of sensitive information.
* Performs other duties as assigned.
* Responsible for observing all laws, regulations, and other applicable obligations wherever and whenever business is conducted on behalf of the Company.
* Expected to work in a safe manner in accordance with established operating procedures and practices.
We recognize and appreciate the value and contributions of individuals with diverse backgrounds and experiences and welcome all qualified individuals to apply.
Job Category
Information Technology
Travel Percentage Required
0% - 25%
Full-Time/Part-Time
Full-Time Salary
State
California
Clearance Level
Secret
Pay Range Low
89,180
City
San Diego
Clearance Required?
Yes
Pay Range High
155,825
Recruitment Posting Title
Information System Security Officer - ISSO
Job Qualifications
* Typically requires a bachelors degree in a related discipline and six or more years of progressive professional experience in information assurance or a related field. Equivalent professional experience may be substituted in lieu of education
* Must possess an active Secret clearance and have the ability to obtain and maintain a TS (with SAP & SCI eligibility)
* Must be able to meet the requirements to obtain and maintain a Department of Energy (DOE) Q clearance
* Must maintain DoD 8570 IAM Level I (e.g. Security +) professional certification as required by customers or contractual obligations.
* Security + certification required.
* Experience with DoD policy such as Risk Management Framework and Joint SAP Implementation Guide.
* Operational experience with installing, troubleshooting, and auditing Windows desktop & server operating systems.
* Experience with DISA STIGs, SCAP tool, ACAS.
* Experience installing and troubleshooting common x86-based computer hardware.
* Must demonstrate a general understanding of information assurance principles, theories, concepts and techniques. Must have experience organizing, planning, scheduling, conducting, and coordinating work assignments to meet project milestones or established completion dates.
* Must possess the ability to understand new concepts quickly and apply them in an evolving environment while contributing to the development of new processes.
* Must be customer focus and possess:
* The ability to identify issues, analyze data and develop solutions to a variety of problems.
* Good analytical, verbal and written communication skills to accurately document, report, and present findings.
* Good interpersonal skills enabling an effective interface with other professionals; and good computer skills.
* Ability to work independently or in a team environment is essential as is the ability to work extended hours as required.
US Citizenship Required?
Yes
Experience Level
Mid-Level (3-7 years)
Relocation Assistance Provided?
No
Workstyle
Onsite
Network & Systems Security Analyst, Cisco Focus, Progression
Tampa, FL jobs
Title: Network & Systems Security Analyst, Cisco Focus, Progression Company: Tampa Electric Company State and City: Florida - Tampa Shift: 8 Hr. X 5 Days
Hiring Manager: David Cain
Recruiter: Mark E Koener
TITLE: Network & Systems Security Analyst Progression
PERFORMANCE COACH: Mgr Network Engineering & Cyber Security Operations
COMPANY: Tampa Electric
DEPARTMENT: High Performance Computing & BP Support
FOCUS Areas
- Cisco Networking
- Cisco Wireless
- Cisco ISE
- Networking Engineering Related Skills
POSITION CONCEPT
The Network & Systems Security Analyst is responsible for planning/designing, implementing, and supporting new and existing network, server, storage infrastructure. This role is also responsible for ensuring all network security controls (i.e., firewalls, web application firewalls [WAF], proxies, network segmentation, NAC, ACLs, etc.) are implemented and managed per corporate information security standards. Additionally, responsibilities include assessing enterprise assets and critical assets for secure configurations and maintaining and enforcing regulations and standards such as NERC Critical Infrastructure Protection (CIP), Sarbanes-Oxley (SOX), and Payment Card Industry (PCI).
Responsible for the design, planning, operation, maintenance, and support of the TECO and NMGC network infrastructure. This includes primary accountability for network technologies such as route/switch, on-premise LAN/WAN, IPAM, Wi-Fi, ISP management, site-to-site VPNs, proxies (forward and reverse), perimeter firewall management, DNS, Azure cloud environments, automation, NAC/user access, hyperconverged infrastructure, and overall network security. Partners with the Telecommunication teams on establishing/upgrading existing circuits/communication links. Responsible for the NERC Cyber Infrastructure Protection and disaster recovery plans.
Responsible for VoIP, SIP, DHCP, DNS, TCP/IP routing and routing protocols such as OSPF and BGP, binary mathematics, NAT, PAT, IPsec and SSL VPN technologies, GRE tunneling, route redistribution, traffic shaping, port-level filtering, SD-WAN, MPLS and other communications related technologies. Responsible for the installation, configuration, and maintenance of all WAN and LAN connectivity which includes core and campus switches, routers, firewalls, wireless access points, WAN scalers and load balancer technologies. Responsible for the design, installation, configuration, and maintenance of DNP over IP and serial SCADA communications between the primary and backup control centers, power plants, solar sites, and substations. Responsible for the configuration and maintenance of Smart GRID communication hardware switches and routers between the primary and backup control centers.
NETWORK & SYSTEMS SECURITY ANALYST I (LEVEL 1)
Monitors and troubleshoots server, network, and security controls related problems and failures; and installs and configures hardware/software. Works under direct supervision.
PRIMARY DUTIES AND RESPONSIBILITIES
1. Plan, design, and implement network, server, and storage infrastructure based on project requirements, capacity plans, and system support. (20%)
2. Problem solving involves basic troubleshooting following the OSI (Open Systems Interconnection) model, making or calling for equipment repairs, and problem escalation. (20%)
3. Detection and correction of work stoppages and/or errors are accomplished by monitoring systems and changing configurations, as necessary. (20%)
4. Install and support network, server, and storage hardware and software. (10%)
5. Direct participation in the planning and designing, maintenance, testing and documentation of the company's disaster recovery plans are vital. (10%)
6. Provide and apply appropriate security consulting and support for IT infrastructure across multiple platforms (Firewalls, proxies, WAFs, ACLs, NAC, Operating Systems, NetScaler load balancers, DDoS protection, and other network devices). (10%)
7. Provide third-level technical support for security systems and authentication mechanisms on all operating system platforms. (10%)
QUALIFICATIONS
EDUCATION
Required: High School Diploma or GED
Preferred: Bachelor's degree in Computer Science, Engineering, Math, or equivalent IT discipline (e.g., MIS).
LICENSES/CERTIFICATIONS
Required: Has obtained at least one related network, system, operating system, or information security professional certification: (e.g., Microsoft Certified Solutions Associate (MCSA), VMware Certified Professional (VCP), Cisco Certified Network Associate (CCNA), Certified Ethical Hacker (CEH), GIAC Certifications, Certified Information Systems Security Professional (CISSP).
Preferred: ITIL v3, CCNA, MCSA, VCP, Security+, CISSP
EXPERIENCE
Required: Minimum four (4) years of related hands-on experience implementing and maintaining Windows, VMware, firewall support, DDoS protection, proxies, WAFs, NetScaler load balancers, or Cisco Networking.
In lieu of some experience listed above, may consider three (3) years of related experience with an Associate's Degree or two (2) years of related experience with a Bachelor's Degree in Computer Science, Engineering, Math, or equivalent IT discipline (e.g., MIS).
KNOWLEDGE/SKILLS/ABILITIES (KSA)
• Working knowledge of network, server, and security controls infrastructure regardless of the complexity
• Working knowledge for most of the following technologies and operational functions: switching, routing, DNS/DHCP, Windows Active Directory, VMware, Voice over IP, Storage Area Networking, firewall support, DDoS protection, proxy, WAF, NetScaler load balancing, network segmentation, NAC, IDS/IPS, antivirus support, cyber security best practices, and networking/hardware installation and maintenance
• Working knowledge with packet analysis and denial of service protection
• Strong critical thinking, analytical, problem solving, and risk assessment skills as well as strong listening and communication skills (oral and written)
• Ability to present issues and topics of a complex technical nature to non-technical audiences
• Excellent interpersonal and organizational skills
• Basic working knowledge of the processes that ensure compliance with regulatory or industry requirements such as NERC CIP, SOX, and PCI
WORKING CONDITIONS
Normal working conditions with occasional extended hours during the week and weekends.
PHYSICAL DEMANDS/REQUIREMENTS
Normal physical demands related to an office and operational (Power Plant, Solar, Control Center) workplace environment. Must be able to lift 50-pound boxes and ascend/descend a ladder to service network access points.
NETWORK & SYSTEMS SECURITY ANALYST II (LEVEL 2)
In addition to the duties & responsibilities of the Level 1 Analyst, has increased responsibilities in consulting on small project design and plans. May serve as a project lead and mentor Level 1 Analyst. Works under general supervision.
ADDITIONAL DUTIES AND RESPONSIBILITIES
1. Monitors, troubleshoots, diagnoses, and remedies server, network, DDoS protection, NetScaler load balancers, and security controls related problems and failures. (30%)
2. Installs and configures server and network related hardware/software which meet the company's security standards. (40%)
3. Design and planning required for small projects. (20%)
4. Project leadership, consulting, or cross-train peers. (10%)
QUALIFICATIONS
EDUCATION
Required: High School Diploma or GED
Preferred: Bachelor's degree in Computer Science, Engineering, Math, or equivalent IT discipline (e.g., MIS).
LICENSES/CERTIFICATIONS
Required: Has obtained at least two related network, system, operating system, or information security professional certification: (e.g., Microsoft Certified Solutions Associate (MCSA), Microsoft Certified Solutions Expert (MCSE), VMware Certified Professional (VCP), Cisco Certified Network Associate (CCNA), Cisco Certified Network Professional (CCNP), Certified Ethical Hacker (CEH), GIAC Network Forensic Analyst (GNFA) or other GIAC Certifications, Certified Information Systems Security Professional (CISSP).
Preferred: ITIL v3, CCNP, MCSE, VCP, GNFA, CISSP
EXPERIENCE
Required: Minimum six (6) years of related hands-on experience implementing and maintaining Windows, VMware, firewall support, DDoS protection, proxies, WAFs, NetScaler load balancers, Storage Area Networks, or Cisco Networking. In lieu of some experience listed above, may consider four (4) years of related experience with an Associate's Degree or three (3) years of related experience with a Bachelor's Degree in Computer Science, Engineering, Math, or equivalent IT discipline (e.g., MIS).
QUALIFICATIONS
EDUCATION
Required: High School Diploma or GED
Preferred: Bachelor's degree in Computer Science, Engineering, Math, or equivalent IT discipline (e.g., MIS).
LICENSES/CERTIFICATIONS
Required: Has obtained at least two related network, system, operating system, or information security professional certification: (e.g., Microsoft Certified Solutions Associate (MCSA), Microsoft Certified Solutions Expert (MCSE), VMware Certified Professional (VCP), Cisco Certified Network Associate (CCNA), Cisco Certified Network Professional (CCNP), Certified Ethical Hacker (CEH), GIAC Network Forensic Analyst (GNFA) or other GIAC Certifications, Certified Information Systems Security Professional (CISSP).
Preferred: ITIL v3, CCNP, MCSE, VCP, GNFA, CISSP
EXPERIENCE
Required: Minimum six (6) years of related hands-on experience implementing and maintaining Windows, VMware, firewall support, DDoS protection, proxies, WAFs, NetScaler load balancers, Storage Area Networks, or Cisco Networking. In lieu of some experience listed above, may consider four (4) years of related experience with an Associate's Degree or three (3) years of related experience with a Bachelor's Degree in Computer Science, Engineering, Math, or equivalent IT discipline (e.g., MIS).
KNOWLEDGE/SKILLS/ABILITIES (KSA)
• Intermediate knowledge of network, server, and security controls infrastructure regardless of the complexity
• Good working knowledge for most of the following technologies and operational functions: switching, routing, DNS/DHCP, Windows Active Directory, VMware, Voice over IP, Storage Area Networking, firewall support, DDoS protection, proxy, WAF, NetScaler load balancing, network segmentation, NAC, IDS/IPS, antivirus support, cyber security best practices, and networking/hardware installation and maintenance
• Good working knowledge with packet analysis and denial of service protection
• Strong critical thinking, analytical, problem solving, and risk assessment skills as well as strong listening and communication skills (oral and written)
• Ability to present issues and topics of a complex technical nature to non-technical audiences
• Excellent interpersonal and organizational skills
• Good working knowledge of the processes that ensure compliance with regulatory or industry requirements such as NERC CIP, SOX, and PCI
NETWORK & SYSTEMS SECURITY ANALYST III (LEVEL 3)
In addition to the duties & responsibilities of the Level 2 Analyst, has increased responsibilities in consulting on small project design and plans. May serve as a project lead, cross-train peers, and mentor Analysts. Works under general direction.
ADDITIONAL DUTIES AND RESPONSIBILITIES
1. Monitors, troubleshoots, diagnoses, and remedies server, network, DDoS protection, NetScaler load balancers, and security controls related problems and failures. (20%)
2. Installs and configures server and network related hardware/software which meet the company's security standards. (20%)
3. Design and planning required for small projects. (40%)
4. Project leadership, consulting, or cross-train peers. (20%)
QUALIFICATIONS
EDUCATION
Required: High School Diploma or GED
Preferred: Bachelor's degree in Computer Science, Engineering, Math, or equivalent IT discipline (MIS).
LICENSES/CERTIFICATIONS
Required: Has obtained at least three or two, with the condition to obtain a third certification within one year of hire for this position, related network, system, operating system, or information security professional certifications: (e.g., Microsoft Certified Solutions Associate (MCSA), Microsoft Certified Solutions Expert (MCSE), VMware Certified Professional (VCP), Cisco Certified Network Associate (CCNA), Cisco Certified Network Professional (CCNP), Certified Ethical Hacker (CEH), GIAC Network Forensic Analyst (GNFA) or other GIAC Certifications, Certified Information Systems Security Professional (CISSP), Certified SCADA Security Architect (CSSA).
Preferred: ITIL v3, CCNP, MCSE, VCP, GNFA, CISSP
EXPERIENCE
Required: Minimum eight (8) years of related hands-on experience implementing and maintaining Windows, VMware, firewall support, DDoS protection, proxies, WAFs, NetScaler load balancers, Storage Area Networks, or Cisco Networking. In lieu of some experience listed above, may consider six (6) years of related experience with an Associate's Degree or four (4) years of related experience with a Bachelor's Degree in Computer Science, Engineering, Math, or equivalent IT discipline (e.g., MIS).
KNOWLEDGE/SKILLS/ABILITIES (KSA)
• Expert knowledge of network, server, and security controls infrastructure regardless of the complexity
• Thorough working knowledge for most of the following technologies and operational functions: switching, routing, DNS/DHCP, Windows Active Directory, VMware, Voice over IP, Storage Area Networking, firewall support, DDoS protection, proxy, WAF, NetScaler load balancing, network segmentation, NAC, IDS/IPS, antivirus support, cyber security best practices, and networking/hardware installation and maintenance
• Thorough working knowledge with packet analysis and denial of service protection
• Strong critical thinking, analytical, problem solving, and risk assessment skills as well as strong listening and communication skills (oral and written)
• Ability to present issues and topics of a complex technical nature to non-technical audiences
• Excellent interpersonal, mentoring, and organizational skills
• Good working knowledge of the processes that ensure compliance with regulatory or industry requirements such as NERC CIP, SOX, and PCI
NETWORK & SYSTEMS SECURITY ARCHITECT (LEVEL 4)
In addition to the duties & responsibilities of the Level 3 Analyst, has increased responsibilities in consulting on small project design and plans. May serve as a project lead on larger projects, cross-train peers, and mentor all levels of Analysts. Works under general direction.
ADDITIONAL DUTIES AND RESPONSIBILITIES
1. Monitors, troubleshoots, diagnoses, and remedies server, network, DDoS protection, NetScaler load balancers, and security controls related problems and failures. (10%)
2. Installs and configures server and network related hardware/software which meet the company's security standards. (10%)
3. Design and planning required for small and large projects. (40%)
4. Project leadership, consulting, or cross-train peers. (40%)
QUALIFICATIONS
EDUCATION
Required: High School Diploma or GED
Preferred: Bachelor's degree in Computer Science, Engineering, Math, or equivalent IT discipline (MIS).
LICENSES/CERTIFICATIONS
Required: Has obtained at least three related network, system, operating system, or information security professional certifications: (e.g., Microsoft Certified Solutions Associate (MCSA), Microsoft Certified Solutions Expert (MCSE), VMware Certified Professional (VCP), Cisco Certified Network Associate (CCNA), Cisco Certified Network Professional (CCNP), Certified Ethical Hacker (CEH), GIAC Network Forensic Analyst (GNFA) or other GIAC Certifications, Certified Information Systems Security Professional (CISSP), Certified SCADA Security Architect (CSSA).
Preferred: ITIL v3, CCNP, MCSE, VCP, GNFA, CISSP
EXPERIENCE
Required: Minimum ten (10) years of related hands-on experience implementing and maintaining Windows, VMware, firewall support, DDoS protection, proxies, WAFs, NetScaler load balancers, Storage Area Networks, or Cisco Networking.
In lieu of some experience listed above, may consider eight (8) years of related experience with an Associate's Degree or six (6) years of related experience with a Bachelor's Degree in Computer Science, Engineering, Math, or equivalent IT discipline (e.g., MIS).
KNOWLEDGE/SKILLS/ABILITIES (KSA)
• Expert knowledge of network, server, and security controls infrastructure regardless of the complexity
• Thorough working knowledge for most of the following technologies and operational functions: switching, routing, DNS/DHCP, Windows Active Directory, VMware, Voice over IP, Storage Area Networking, firewall support, DDoS protection, proxy, WAF, NetScaler load balancing, network segmentation, NAC, IDS/IPS, antivirus support, cyber security best practices, and networking/hardware installation and maintenance
• Thorough working knowledge with packet analysis and denial of service protection
• Strong critical thinking, analytical, problem solving, and risk assessment skills as well as strong listening and communication skills (oral and written)
• Ability to present issues and topics of a complex technical nature to non-technical audiences
• Excellent interpersonal, mentoring, consulting, and organizational skills
• Thorough working knowledge of the processes that ensure compliance with regulatory or industry requirements such as NERC CIP, SOX, and PCI
LEAD NETWORK & SYSTEMS SECURITY ANALYST (PERFORMANCE COACH)
In addition to the duties & responsibilities of the Level 3 Analyst, has increased responsibilities in leading and managing Level 1 through 3 Analyst. May serve as a project lead on larger projects, cross-train peers, and mentor all levels of Analyst. Works under general direction.
ADDITIONAL DUTIES AND RESPONSIBILITIES
1. Monitors, troubleshoots, diagnoses, and remedies server, network, DDoS protection, NetScaler load balancers, and security controls related problems and failures. (10%)
2. Installs and configures server and network related hardware/software which meet the company's security standards. (10%)
3. Design and planning required for small and large projects. (25%)
4. Project leadership, consulting, or cross-train peers. (25%)
5. Lead and manage the network analyst (Level 1, 2, and 3) team (30%)
QUALIFICATIONS
LICENSES/CERTIFICATIONS
Required: Has obtained at least three or two, with the condition to obtain a third certification within one year of hire for this position, related network, system, operating system, or information security professional certifications: (e.g., Microsoft Certified Solutions Associate (MCSA), Microsoft Certified Solutions Expert (MCSE), VMware Certified Professional (VCP), Cisco Certified Network Associate (CCNA), Cisco Certified Network Professional (CCNP), Certified Ethical Hacker (CEH), GIAC Network Forensic Analyst (GNFA) or other GIAC Certifications, Certified Information Systems Security Professional (CISSP), Certified SCADA Security Architect (CSSA). Leadership/management certifications/certificates may be considered in lieu of professional certifications.
Preferred: ITIL v3, CCNP, MCSE, VCP, GNFA, CISSP
EDUCATION
Required: High School Diploma or GED
Preferred: Bachelor's degree in Computer Science, Engineering, Math, or equivalent IT discipline (MIS).
EXPERIENCE
Required: Minimum ten (10) years of related hands-on experience implementing and maintaining Windows, VMware, firewall support, DDoS protection, proxies, WAFs, NetScaler load balancers, Storage Area Networks, or Cisco Networking.
In lieu of some experience listed above, may consider eight (8) years of related experience with an Associate's Degree or six (6) years of related experience with a Bachelor's Degree in Computer Science, Engineering, Math, or equivalent IT discipline (e.g., MIS).
KNOWLEDGE/SKILLS/ABILITIES (KSA)
• Expert knowledge of network, server, and security controls infrastructure regardless of the complexity
• Thorough working knowledge for most of the following technologies and operational functions: switching, routing, DNS/DHCP, Windows Active Directory, VMware, Voice over IP, Storage Area Networking, firewall support, DDoS protection, proxy, WAF, NetScaler load balancing, network segmentation, NAC, IDS/IPS, antivirus support, cyber security best practices, and networking/hardware installation and maintenance
• Thorough working knowledge with packet analysis and denial of service protection
• Strong critical thinking, analytical, problem solving, and risk assessment skills as well as strong listening and communication skills (oral and written)
• Ability to present issues and topics of a complex technical nature to non-technical audiences
• Excellent interpersonal, mentoring, coaching, and organizational skills
• Thorough working knowledge of the processes that ensure compliance with regulatory or industry requirements such as NERC CIP, SOX, and PCI
#LI-SC1
TECO offers a competitive Benefits package!!
Competitive Salary *401k Savings plan w/ company matching * Pension plan * Paid time off* Paid Holiday time * Medical, Prescription Drug, & Dental Coverage *Tuition Assistance Program * Employee Assistance Program * Wellness Programs * On-site Fitness Centers * Bonus Plan and more!
Cloud Security Specialist Information Security Engineering
New York, NY jobs
The Cloud Security Specialist is a senior technical and leadership position responsible for implementing, managing, and continuously improving cloud security across multi cloud environments including AWS, Azure, Google Cloud, and Oracle Cloud Infrastructure (OCI).This role combines hands on technical execution with team leadership. The successful candidate will lead a team of cloud security engineers, develop secure architectures, and manage enterprise grade cloud security solutions such as Cloud Security Posture Management (CSPM), Cloud Workload Protection (CWP), Container Security, API Security, and AI Security Posture Management (AISPM).The individual will partner with cloud service, DevOps, and application teams to design secure deployments, enforce policies, and integrate automation for vulnerability remediation, threat detection, and compliance. They will also implement secure private connectivity between cloud and on premise networks using technologies such as AWS PrivateLink and Azure ExpressRoute. Required Education/Experience
* Master's Degree and with 3 years of relevant experience IT or Information security or
* Bachelor's Degree and with 5 years of relevant experience IT or Information security or
* Associate's Degree and with 6 years of relevant experience IT or Information security or
* High School Diploma/GED and with 8 years of relevant experience IT or Information security.
Preferred Education/Experience
* Master's Degree in Cybersecurity, Computer Engineering, Computer Science, Information Systems Security, Information Technology. and 3 years in Information security, Cloud Security or Cloud Architect in a senior technical role. With certifications such as CCSP, AWS Certified Security, Azure Security Engineer Associate, or GCP Cloud Security Engineer. Experience in cloud security or cloud architecture. Experience with CSPM, CWP, AISPM, and API security implementations. Handson work with identity management, hybrid connectivity (PrivateLink, ExpressRoute).
* Bachelor's Degree in Cybersecurity, Computer Engineering, Computer Science, Information Systems Security, Information Technology. and 5 years in Information security, Cloud Security or Cloud Architect in a senior technical role. With certifications such as CCSP, AWS Certified Security, Azure Security Engineer Associate, or GCP Cloud Security Engineer. Experience in cloud security or cloud architecture. Experience with CSPM, CWP, AISPM, and API security implementations. Handson work with identity management, hybrid connectivity (PrivateLink, ExpressRoute).
Relevant Work Experience
* Handson experience with at least two major cloud providers (AWS, Azure, GCP, or OCI), required.
* Implementation and management experience with CSPM, CWP, AISPM, and API security platforms, required.
* Knowledge of IAM, rolebased access control, and policy enforcement, required.
* Experience integrating cloud telemetry and logs with SIEM tools, required.
* Understanding of hybrid connectivity and private link technologies (PrivateLink, ExpressRoute), required.
* Experience with scripting (Python, PowerShell, Bash) and automation, required.
* Experience with WAF and cloud API gateway configurations, required.
* Strong understanding of cloud network fundamentals and background in cloud network security, and secure architecture design, required.
* Experience collaborating with cloud service teams for planning and remediation, required.
* Experience implementing application security best practices and training engineering teams, required.
* Familiarity with CDN operations, certificates, and brand monitoring preferred, required.
* Experience with SIEM integration, telemetry collection, and event analysis, preferred.
* Demonstrated experience leading technical teams or project groups, preferred.
* Experience with Container Security, preferred.
* Experience securing API endpoints and implementing advanced cloud application protections, preferred.
* Knowledge of AI/ML data protection and secure model deployment practices, preferred.
* Experience integrating security automation into DevSecOps workflows using Terraform or Ansible, preferred.
* Experience developing and delivering cloud security training and awareness programs, preferred.
Skills and Abilities
* Effective leadership skills
* Demonstrated problem solving skills
* Demonstrated problem solving skills
* Strong written and verbal communication skills
* Ability to drive multiple projects to successful completion
* Proactively approaches responsibilities
Licenses and Certifications
* Driver's License Required
* Other: CISSP, CCNP Security, GSEC, GCIH, CEH, or equivalent certifications. Preferred
* Other: CCSP, AWS Certified Security, Azure Security Engineer Associate, GCP Professional Cloud Security Engineer, or OCI Security Professional. Preferred
Physical Demands
* Ability to push, pull, and lift up to 25 pounds
* Sit or stand to use a keyboard, mouse, and computer for the duration of the workday
Additional Physical Demands
* The selected candidate will be assigned a System Emergency Assignment (i.e., an emergency response role) and will be expected to work non-business hours during emergencies, which may include nights, weekends, and holidays.
* The selected candidate will be assigned a System Emergency Assignment (i.e., an emergency response role) and will be expected to work non-business hours during emergencies, which may include nights, weekends, and holidays.
Core Responsibilities
* Lead and mentor a team of cloud security engineers, fostering technical excellence and professional growth.
* Architect and maintain secure multi-cloud environments across AWS, Azure, GCP, and OCI in partnership with Enterprise Architecture.
* Deploy and manage CSPM platforms to drive continuous visibility, compliance, and risk posture improvement.
* Implement CWP solutions to protect cloud workloads, prevent threats, and manage vulnerabilities effectively.
* Define and enforce IAM policies and least-privilege principles to strengthen identity security across all platforms.
* Design and secure private and hybrid connectivity using technologies such as AWS PrivateLink, Azure ExpressRoute, and Google Cloud Interconnect.
* Integrate cloud telemetry and security events with SIEM systems to enhance incident detection and response capabilities.
* Automate provisioning, configuration, and remediation workflows using IaC tools like Terraform and Ansible, supported by Python or PowerShell scripting.
* Implement and manage WAF policies and API gateways to safeguard cloud applications and services.
* Partner with DevOps and engineering teams to embed security within CI/CD pipelines and promote secure development practices.
* Collaborate with risk and architecture teams to assess emerging technologies and align them with enterprise security strategy.
* Stay informed on evolving threats, regulatory frameworks, and AI security trends to continuously improve cloud security posture.
Cloud Security Specialist Information Security Engineering
New York, NY jobs
The Cloud Security Specialist is a senior technical and leadership position responsible for implementing, managing, and continuously improving cloud security across multi cloud environments including AWS, Azure, Google Cloud, and Oracle Cloud Infrastructure (OCI).This role combines hands on technical execution with team leadership. The successful candidate will lead a team of cloud security engineers, develop secure architectures, and manage enterprise grade cloud security solutions such as Cloud Security Posture Management (CSPM), Cloud Workload Protection (CWP), Container Security, API Security, and AI Security Posture Management (AISPM).The individual will partner with cloud service, DevOps, and application teams to design secure deployments, enforce policies, and integrate automation for vulnerability remediation, threat detection, and compliance. They will also implement secure private connectivity between cloud and on premise networks using technologies such as AWS PrivateLink and Azure ExpressRoute. Required Education/Experience
Master's Degree and with 3 years of relevant experience IT or Information security or
Bachelor's Degree and with 5 years of relevant experience IT or Information security or
Associate's Degree and with 6 years of relevant experience IT or Information security or
High School Diploma/GED and with 8 years of relevant experience IT or Information security.
Preferred Education/Experience
Master's Degree in Cybersecurity, Computer Engineering, Computer Science, Information Systems Security, Information Technology. and 3 years in Information security, Cloud Security or Cloud Architect in a senior technical role. With certifications such as CCSP, AWS Certified Security, Azure Security Engineer Associate, or GCP Cloud Security Engineer. Experience in cloud security or cloud architecture. Experience with CSPM, CWP, AISPM, and API security implementations. Handson work with identity management, hybrid connectivity (PrivateLink, ExpressRoute).
Bachelor's Degree in Cybersecurity, Computer Engineering, Computer Science, Information Systems Security, Information Technology. and 5 years in Information security, Cloud Security or Cloud Architect in a senior technical role. With certifications such as CCSP, AWS Certified Security, Azure Security Engineer Associate, or GCP Cloud Security Engineer. Experience in cloud security or cloud architecture. Experience with CSPM, CWP, AISPM, and API security implementations. Handson work with identity management, hybrid connectivity (PrivateLink, ExpressRoute).
Relevant Work Experience
Handson experience with at least two major cloud providers (AWS, Azure, GCP, or OCI), required.
Implementation and management experience with CSPM, CWP, AISPM, and API security platforms, required.
Knowledge of IAM, rolebased access control, and policy enforcement, required.
Experience integrating cloud telemetry and logs with SIEM tools, required.
Understanding of hybrid connectivity and private link technologies (PrivateLink, ExpressRoute), required.
Experience with scripting (Python, PowerShell, Bash) and automation, required.
Experience with WAF and cloud API gateway configurations, required.
Strong understanding of cloud network fundamentals and background in cloud network security, and secure architecture design, required.
Experience collaborating with cloud service teams for planning and remediation, required.
Experience implementing application security best practices and training engineering teams, required.
Familiarity with CDN operations, certificates, and brand monitoring preferred, required.
Experience with SIEM integration, telemetry collection, and event analysis, preferred.
Demonstrated experience leading technical teams or project groups, preferred.
Experience with Container Security, preferred.
Experience securing API endpoints and implementing advanced cloud application protections, preferred.
Knowledge of AI/ML data protection and secure model deployment practices, preferred.
Experience integrating security automation into DevSecOps workflows using Terraform or Ansible, preferred.
Experience developing and delivering cloud security training and awareness programs, preferred.
Skills and Abilities
Effective leadership skills
Demonstrated problem solving skills
Demonstrated problem solving skills
Strong written and verbal communication skills
Ability to drive multiple projects to successful completion
Proactively approaches responsibilities
Licenses and Certifications
Driver's License Required
Other: CISSP, CCNP Security, GSEC, GCIH, CEH, or equivalent certifications. Preferred
Other: CCSP, AWS Certified Security, Azure Security Engineer Associate, GCP Professional Cloud Security Engineer, or OCI Security Professional. Preferred
Physical Demands
Ability to push, pull, and lift up to 25 pounds
Sit or stand to use a keyboard, mouse, and computer for the duration of the workday
Additional Physical Demands
The selected candidate will be assigned a System Emergency Assignment (i.e., an emergency response role) and will be expected to work non-business hours during emergencies, which may include nights, weekends, and holidays.
The selected candidate will be assigned a System Emergency Assignment (i.e., an emergency response role) and will be expected to work non-business hours during emergencies, which may include nights, weekends, and holidays.
Core Responsibilities
Lead and mentor a team of cloud security engineers, fostering technical excellence and professional growth.
Architect and maintain secure multi-cloud environments across AWS, Azure, GCP, and OCI in partnership with Enterprise Architecture.
Deploy and manage CSPM platforms to drive continuous visibility, compliance, and risk posture improvement.
Implement CWP solutions to protect cloud workloads, prevent threats, and manage vulnerabilities effectively.
Define and enforce IAM policies and least-privilege principles to strengthen identity security across all platforms.
Design and secure private and hybrid connectivity using technologies such as AWS PrivateLink, Azure ExpressRoute, and Google Cloud Interconnect.
Integrate cloud telemetry and security events with SIEM systems to enhance incident detection and response capabilities.
Automate provisioning, configuration, and remediation workflows using IaC tools like Terraform and Ansible, supported by Python or PowerShell scripting.
Implement and manage WAF policies and API gateways to safeguard cloud applications and services.
Partner with DevOps and engineering teams to embed security within CI/CD pipelines and promote secure development practices.
Collaborate with risk and architecture teams to assess emerging technologies and align them with enterprise security strategy.
Stay informed on evolving threats, regulatory frameworks, and AI security trends to continuously improve cloud security posture.
Auto-ApplyPhysical Security Engineer
Kennesaw, GA jobs
Due to continued growth, ENERCON's Nuclear Services Design Instrumentation and Controls Group has immediate openings for Physical Security Technicians/Engineers to join our team. In this dynamic role, you'll forge powerful relationships with both internal teams and external clients, especially in the cutting-edge field of Physical Security, while leading engineering efforts to deliver innovative solutions. You'll drive project success by solving complex technical challenges, ensuring top-quality results, and guiding your team to exceed customer expectations with every step! This role can be located in the following locations:
King of Prussia, PA
Crane Clean Energy Center - Middletown, PA
Remote in Palo, IA
Palisades - Covert, MI
Birmingham, AL
Naperville, IL (Suburb of Chicago)
Kennesaw, GA (Suburb of Atlanta)
This role can be Full Time, Part Time, or LTLB (Contract).
Responsibilities
Imagine a day where you're at the forefront of collaboration, working with engineering teams and clients to deliver cutting-edge solutions in Physical Security. You lead technical discussions, resolve challenges, and ensure designs meet all requirements. Your guidance keeps projects on track while you research improvements, propose innovations, and provide key updates to senior management-making a real impact and strengthening vital relationships every step of the way.
Relationship Building & Client Interaction: Work interactively with internal engineering and external clients to develop strong relationships, particularly in Physical Security. Ability to interface with site physical security management and engineering stakeholders
Engineering Support & Technical Leadership: Provide direct engineering support to project engineering staff to ensure design products satisfy customer expectations, contract requirements, and regulatory requirements. Provide technical leadership and support to engineering staff. Guide and review deliverables, review progress, and update senior management, as needed
Issue Resolution & Quality Assurance: Facilitate resolution of inter-disciplinary and cross-disciplinary technical and quality issues. Research and assess best practices, proposing methods and improvements
Project Planning & Execution: Plan and direct the timely execution of assigned engineering activities. Work with the Project Engineer (PE), engineering supervision, and project management to provide timely updates of progress, challenges, and implementation
#LI-MB1
Qualifications
A minimum of 3 years of relevant design engineering and or technician experience is required for this role
Bachelor's Degree in engineering field is preferred, HS Diploma/GED and equivalent relevant experience is required
Experience with AIM or NSMART security platforms is highly preferred
Experience in the design, installation, and testing of large scale (complete systems) digital control and computer monitoring system upgrades at power plants preferred
Types of upgrades include replacement of Turbine/Generator Control Systems with DCS platforms, process computer, and cybersecurity systems
Nuclear plant design experience and/or field experience working for a nuclear QA Program preferred
Must be proficient with MS Word, Excel, Visio, Access and PowerPoint
Good verbal and written communication skills and the ability to comprehend and convey detailed technical data
Knowledge of Physical Security related principles, standards, and regulations
An ability to perform walkdowns across multiple areas at a nuclear power plant and to provide feedback to the engineers on deviations from plant equipment when compared with plant drawings (i.e. as-built walkdowns)
Demonstrated leadership ability to manage multiple tasks and projects and ability to work effectively with all levels of staff and management
Excellent verbal and written communication skills including demonstrated ability to present to clients
Ability to travel to client sites for meetings and walkdowns, approximately 30% of the time
Senior level should be familiar with the Standard Design Process and Digital Engineering Guide
Pay Range USD $85,000.00 - USD $165,000.00 /Yr. Additional Information
About ENERCON:
At Enercon Services, Inc. (ENERCON), we're driven by our people-and we're proud to offer rewarding careers in a culture of excellence. We provide a comprehensive benefits package and professional development opportunities that support your long-term growth.
What We Offer:
Enjoy full benefits for you and your dependents starting day one, no waiting period
Flexible work arrangements, including hybrid and alternative schedules
401(k) with employer matching
Tuition reimbursement
Professional Engineer (PE) license support and incentives
Want to see the full picture? Click HERE to see our Comprehensive Benefits
Salary Range Information:
If a salary range is listed, it reflects the typical range for this full-time position based on the role, level, and location. Individual compensation within the range will be determined by factors such as work location, relevant experience, job-related skills, and education or training.
Eligibility to Work:
Candidates must be legally eligible to work in the US without requiring current or future sponsorship.
Ability to pass a pre-employment and random drug and alcohol screenings, ENERCON and client specific background checks, and annual motor vehicle record (MVR) according to company and client policies.
Equal Opportunity Employer:
ENERCON does not discriminate in employment opportunities or practices based on race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other characteristic protected by law.
Connect with Us: *************** | LinkedIn
Auto-ApplyStaff Infrastructure Security Engineer
San Francisco, CA jobs
Job Description
Crusoe's mission is to accelerate the abundance of energy and intelligence. We're crafting the engine that powers a world where people can create ambitiously with AI - without sacrificing scale, speed, or sustainability.
Be a part of the AI revolution with sustainable technology at Crusoe. Here, you'll drive meaningful innovation, make a tangible impact, and join a team that's setting the pace for responsible, transformative cloud infrastructure.
We are seeking a highly skilled Staff Infrastructure Security Engineer to architect, deploy, and operationalize the foundational security services that will underpin our shift to a Zero Trust model.
In this strategic role, you will define and establish the "roots of trust" for our organization, serving as a technical leader in Secrets Management and Identity architecture. While your immediate focus is to serve as the Subject Matter Expert (SME) driving our enterprise HashiCorp Vault platform from Proof-of-Concept (PoC) to global production readiness, your long-term scope is far broader. You will be responsible for evolving our credentials management strategy, onboarding engineering teams to secure self-service workflows, and designing scalable trust patterns across our hybrid multi-cloud environment.
Key Responsibilities
1. Strategic Architecture & Governance
Zero Trust Architecture: Architect a highly available, disaster-resilient, and scalable multi-cluster secrets management platform that serves as the foundation for the organization's Zero Trust strategy.
Technical Leadership: Drive consensus across Cloud Engineering, DevOps, and SRE teams to define standardized secret management workflows and integrate security patterns into the SDLC.
Compliance & Governance: Ensure the platform design meets rigorous internal policies and external compliance frameworks (e.g., SOX, ISO 27001).
Policy as Code: Design and implement advanced governance controls, including Sentinel Policy as Code, to automate security guardrails and access decisions.
2. Platform Engineering & Implementation
Infrastructure as Code (IaC): Lead the engineering of the Vault infrastructure using Terraform, ensuring all deployments are reproducible, version-controlled, and automated.
Identity Integration: Architect the integration between the secrets platform, Identity Providers (Okta), and workload identities (Kubernetes Service Accounts) to establish robust machine-to-machine authentication.
Advanced Secrets Capabilities: Configure and tune essential secrets engines (KV, Transit, KMIP) and Enterprise features (Performance Replication, Seal automation) to support diverse engineering use cases.
3. Operational Excellence & Developer Enablement
Vault as a Service (VaaS): Operationalize the platform by building self-service mechanisms, distinct "paved road" onboarding procedures, and documentation that allows engineering teams to easily consume security services.
Observability: Implement comprehensive monitoring, alerting, and audit logging to ensure platform health, provide visibility into usage patterns, and satisfy audit requirements.
Lifecycle Management: Own the full operational lifecycle of the production environment, including patching, version upgrades, backup/restore procedures, and incident response runbooks.
Required Qualifications
6+ years (or equivalent) hands-on experience in cloud security, DevOps, or infrastructure engineering.
Deep expertise and proven track record deploying and managing HashiCorp Vault in an enterprise environment (experience with the Enterprise edition is highly preferred).
Expert-level knowledge of Secrets Management, X.509 PKI (Public Key Infrastructure), Certificate Authority Operations, and Cryptography concepts.
Strong experience with Google Cloud Platform (GCP) and cloud native identity and access management (IAM).
Proficiency with Infrastructure as Code (IaC) tools, especially Terraform, for automating the deployment and configuration of Vault and its dependent infrastructure.
Technical Skills
Fluent in at least one programming language (ideally Go or Python).
Demonstrable experience with Kubernetes and container security principles, especially integrating secrets into microservices architectures.
Strong understanding of network security concepts (IP addressing, IP routing, firewalls, segmentation, Zero Trust).
Benefits:
Industry competitive pay
Restricted Stock Units in a fast growing, well-funded technology company
Health insurance package options that include HDHP and PPO, vision, and dental for you and your dependents
Employer contributions to HSA accounts
Paid Parental Leave
Paid life insurance, short-term and long-term disability
Teladoc
401(k) with a 100% match up to 4% of salary
Generous paid time off and holiday schedule
Cell phone reimbursement
Tuition reimbursement
Subscription to the Calm app
MetLife Legal
Company paid commuter benefit; $300 per month
Crusoe is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, disability, genetic information, pregnancy, citizenship, marital status, sex/gender, sexual preference/ orientation, gender identity, age, veteran status, national origin, or any other status protected by law or regulation.
Staff Infrastructure Security Engineer
San Francisco, CA jobs
Crusoe's mission is to accelerate the abundance of energy and intelligence. We're crafting the engine that powers a world where people can create ambitiously with AI - without sacrificing scale, speed, or sustainability.
Be a part of the AI revolution with sustainable technology at Crusoe. Here, you'll drive meaningful innovation, make a tangible impact, and join a team that's setting the pace for responsible, transformative cloud infrastructure.
We are seeking a highly skilled Staff Infrastructure Security Engineer to architect, deploy, and operationalize the foundational security services that will underpin our shift to a Zero Trust model.
In this strategic role, you will define and establish the "roots of trust" for our organization, serving as a technical leader in Secrets Management and Identity architecture. While your immediate focus is to serve as the Subject Matter Expert (SME) driving our enterprise HashiCorp Vault platform from Proof-of-Concept (PoC) to global production readiness, your long-term scope is far broader. You will be responsible for evolving our credentials management strategy, onboarding engineering teams to secure self-service workflows, and designing scalable trust patterns across our hybrid multi-cloud environment.
Key Responsibilities
1. Strategic Architecture & Governance
Zero Trust Architecture: Architect a highly available, disaster-resilient, and scalable multi-cluster secrets management platform that serves as the foundation for the organization's Zero Trust strategy.
Technical Leadership: Drive consensus across Cloud Engineering, DevOps, and SRE teams to define standardized secret management workflows and integrate security patterns into the SDLC.
Compliance & Governance: Ensure the platform design meets rigorous internal policies and external compliance frameworks (e.g., SOX, ISO 27001).
Policy as Code: Design and implement advanced governance controls, including Sentinel Policy as Code, to automate security guardrails and access decisions.
2. Platform Engineering & Implementation
Infrastructure as Code (IaC): Lead the engineering of the Vault infrastructure using Terraform, ensuring all deployments are reproducible, version-controlled, and automated.
Identity Integration: Architect the integration between the secrets platform, Identity Providers (Okta), and workload identities (Kubernetes Service Accounts) to establish robust machine-to-machine authentication.
Advanced Secrets Capabilities: Configure and tune essential secrets engines (KV, Transit, KMIP) and Enterprise features (Performance Replication, Seal automation) to support diverse engineering use cases.
3. Operational Excellence & Developer Enablement
Vault as a Service (VaaS): Operationalize the platform by building self-service mechanisms, distinct "paved road" onboarding procedures, and documentation that allows engineering teams to easily consume security services.
Observability: Implement comprehensive monitoring, alerting, and audit logging to ensure platform health, provide visibility into usage patterns, and satisfy audit requirements.
Lifecycle Management: Own the full operational lifecycle of the production environment, including patching, version upgrades, backup/restore procedures, and incident response runbooks.
Required Qualifications
6+ years (or equivalent) hands-on experience in cloud security, DevOps, or infrastructure engineering.
Deep expertise and proven track record deploying and managing HashiCorp Vault in an enterprise environment (experience with the Enterprise edition is highly preferred).
Expert-level knowledge of Secrets Management, X.509 PKI (Public Key Infrastructure), Certificate Authority Operations, and Cryptography concepts.
Strong experience with Google Cloud Platform (GCP) and cloud native identity and access management (IAM).
Proficiency with Infrastructure as Code (IaC) tools, especially Terraform, for automating the deployment and configuration of Vault and its dependent infrastructure.
Technical Skills
Fluent in at least one programming language (ideally Go or Python).
Demonstrable experience with Kubernetes and container security principles, especially integrating secrets into microservices architectures.
Strong understanding of network security concepts (IP addressing, IP routing, firewalls, segmentation, Zero Trust).
Benefits:
Industry competitive pay
Restricted Stock Units in a fast growing, well-funded technology company
Health insurance package options that include HDHP and PPO, vision, and dental for you and your dependents
Employer contributions to HSA accounts
Paid Parental Leave
Paid life insurance, short-term and long-term disability
Teladoc
401(k) with a 100% match up to 4% of salary
Generous paid time off and holiday schedule
Cell phone reimbursement
Tuition reimbursement
Subscription to the Calm app
MetLife Legal
Company paid commuter benefit; $300 per month
Crusoe is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, disability, genetic information, pregnancy, citizenship, marital status, sex/gender, sexual preference/ orientation, gender identity, age, veteran status, national origin, or any other status protected by law or regulation.
Auto-ApplyProduct Security Engineer - AI
San Francisco, CA jobs
Crusoe's mission is to accelerate the abundance of energy and intelligence. We're crafting the engine that powers a world where people can create ambitiously with AI - without sacrificing scale, speed, or sustainability.
Be a part of the AI revolution with sustainable technology at Crusoe. Here, you'll drive meaningful innovation, make a tangible impact, and join a team that's setting the pace for responsible, transformative cloud infrastructure.
About This Role:
At Crusoe, the AI Security Engineer is central to ensuring the safety, integrity, and resilience of our rapidly evolving AI ecosystem. You will serve as the technical authority on securing Large Language Models (LLMs), AI-powered platforms, and the infrastructure that supports them-driving both strategy and execution for our next generation of secure AI systems.
What You'll Be Working On:
AI Security SME & Strategic Partner: Act as the technical leader and SME on the practical security of our AI and LLM ecosystem and define the long-term technical roadmap for AI security architecture and drive high-impact cross-functional initiatives.
LLM Architecture & Design Ownership: Lead the design and implementation of highly secure Generative AI solutions for security applications, focusing on architectural patterns like Retrieval-Augmented Generation (RAG)
AI-Powered Tooling & Automation: Architect and implement custom, AI-powered security tooling that automates threat detection, vulnerability analysis, and data access control, moving from proof-of-concept to production at scale.
Secure MLOps & Governance: Establish governance and processes for secure MLOps pipelines. Define standards for model versioning, deployment, and monitoring, ensuring they meet rigorous compliance and security requirements.
Threat Mitigation & Mentorship: Lead threat modeling exercises for novel AI systems. Apply advanced security and privacy best practices, and mentor senior engineers on secure development practices in the GenAI domain.
System-Level Ownership: Drive the entire lifecycle of critical AI security projects.
What You'll Bring to the Team:
3+ years of professional experience building and maintaining production systems, with strong Python programming skills and experience across the stack (backend/frontend).
Deep expertise in advanced Generative AI techniques, including implementing Retrieval-Augmented Generation (RAG), designing AI Agents and Multi-step Cognitive Processes (MCP), and building with workflow orchestration frameworks.
Proven ability to own the entire model lifecycle by designing and managing robust MLOps pipelines; experience with containerization (Docker), virtualization (VMs), and cloud platforms (AWS, GCP, Azure) is a plus.
Experience in designing, implementing, and fine-tuning custom LLMs, coupled with a strong understanding of NLP fundamentals, transformer architectures, PyTorch/TensorFlow, and data structures.
Strong curiosity about security, privacy, and threat modeling; a desire to safely "break" systems to secure them and apply best practices to AI pipelines and deployments.
Strong product sense for rapid iteration and refinement based on data, combined with a collaborative mindset to work closely with engineers, product managers, and security analysts in a fast-paced environment.
Benefits:
Industry competitive pay
Restricted Stock Units in a fast growing, well-funded technology company
Health insurance package options that include HDHP and PPO, vision, and dental for you and your dependents
Employer contributions to HSA accounts
Paid Parental Leave
Paid life insurance, short-term and long-term disability
Teladoc
401(k) with a 100% match up to 4% of salary
Generous paid time off and holiday schedule
Cell phone reimbursement
Tuition reimbursement
Subscription to the Calm app
MetLife Legal
Company paid commuter benefit; $300 per month
Compensation:
Compensation will be paid in the range of $135,000 - $150,000. Restricted Stock Units are included in all offers. Compensation to be determined by the applicant's education, experience, knowledge, skills, and abilities, as well as internal equity and alignment with market data.
Crusoe is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, disability, genetic information, pregnancy, citizenship, marital status, sex/gender, sexual preference/ orientation, gender identity, age, veteran status, national origin, or any other status protected by law or regulation.
Auto-ApplyProduct Security Engineer - AI
San Francisco, CA jobs
Job Description
Crusoe's mission is to accelerate the abundance of energy and intelligence. We're crafting the engine that powers a world where people can create ambitiously with AI - without sacrificing scale, speed, or sustainability.
Be a part of the AI revolution with sustainable technology at Crusoe. Here, you'll drive meaningful innovation, make a tangible impact, and join a team that's setting the pace for responsible, transformative cloud infrastructure.
About This Role:
At Crusoe, the AI Security Engineer is central to ensuring the safety, integrity, and resilience of our rapidly evolving AI ecosystem. You will serve as the technical authority on securing Large Language Models (LLMs), AI-powered platforms, and the infrastructure that supports them-driving both strategy and execution for our next generation of secure AI systems.
What You'll Be Working On:
AI Security SME & Strategic Partner: Act as the technical leader and SME on the practical security of our AI and LLM ecosystem and define the long-term technical roadmap for AI security architecture and drive high-impact cross-functional initiatives.
LLM Architecture & Design Ownership: Lead the design and implementation of highly secure Generative AI solutions for security applications, focusing on architectural patterns like Retrieval-Augmented Generation (RAG)
AI-Powered Tooling & Automation: Architect and implement custom, AI-powered security tooling that automates threat detection, vulnerability analysis, and data access control, moving from proof-of-concept to production at scale.
Secure MLOps & Governance: Establish governance and processes for secure MLOps pipelines. Define standards for model versioning, deployment, and monitoring, ensuring they meet rigorous compliance and security requirements.
Threat Mitigation & Mentorship: Lead threat modeling exercises for novel AI systems. Apply advanced security and privacy best practices, and mentor senior engineers on secure development practices in the GenAI domain.
System-Level Ownership: Drive the entire lifecycle of critical AI security projects.
What You'll Bring to the Team:
3+ years of professional experience building and maintaining production systems, with strong Python programming skills and experience across the stack (backend/frontend).
Deep expertise in advanced Generative AI techniques, including implementing Retrieval-Augmented Generation (RAG), designing AI Agents and Multi-step Cognitive Processes (MCP), and building with workflow orchestration frameworks.
Proven ability to own the entire model lifecycle by designing and managing robust MLOps pipelines; experience with containerization (Docker), virtualization (VMs), and cloud platforms (AWS, GCP, Azure) is a plus.
Experience in designing, implementing, and fine-tuning custom LLMs, coupled with a strong understanding of NLP fundamentals, transformer architectures, PyTorch/TensorFlow, and data structures.
Strong curiosity about security, privacy, and threat modeling; a desire to safely "break" systems to secure them and apply best practices to AI pipelines and deployments.
Strong product sense for rapid iteration and refinement based on data, combined with a collaborative mindset to work closely with engineers, product managers, and security analysts in a fast-paced environment.
Benefits:
Industry competitive pay
Restricted Stock Units in a fast growing, well-funded technology company
Health insurance package options that include HDHP and PPO, vision, and dental for you and your dependents
Employer contributions to HSA accounts
Paid Parental Leave
Paid life insurance, short-term and long-term disability
Teladoc
401(k) with a 100% match up to 4% of salary
Generous paid time off and holiday schedule
Cell phone reimbursement
Tuition reimbursement
Subscription to the Calm app
MetLife Legal
Company paid commuter benefit; $300 per month
Compensation:
Compensation will be paid in the range of $135,000 - $150,000. Restricted Stock Units are included in all offers. Compensation to be determined by the applicant's education, experience, knowledge, skills, and abilities, as well as internal equity and alignment with market data.
Crusoe is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, disability, genetic information, pregnancy, citizenship, marital status, sex/gender, sexual preference/ orientation, gender identity, age, veteran status, national origin, or any other status protected by law or regulation.