Thank you for your interest in a career at Regions. At Regions, we believe associates deserve more than just a job. We believe in offering performance-driven individuals a place where they can build a career --- a place to expect more opportunities. If you are focused on results, dedicated to quality, strength and integrity, and possess the drive to succeed, then we are your employer of choice.
Regions is dedicated to taking appropriate steps to safeguard and protect private and personally identifiable information you submit. The information that you submit will be collected and reviewed by associates, consultants, and vendors of Regions in order to evaluate your qualifications and experience for job opportunities and will not be used for marketing purposes, sold, or shared outside of Regions unless required by law. Such information will be stored in accordance with regulatory requirements and in conjunction with Regions' Retention Schedule for a minimum of three years. You may review, modify, or update your information by visiting and logging into the careers section of the system.
Job Description:
At Regions, the Cyber SecurityEngineer supports applicable services for cloud applications, infrastructure, platform security, and related technologies within the Cyber Security organization. The engineer at this level is considered a subject-matter expert (SME) utilizing extensive experience and technical knowledge and may lead complex projects as necessary.
Primary Responsibilities
Utilizes extensive knowledge in the design, implementation, and support of relevant cyber security technology solutions
Provides technical administration to include troubleshooting support, break-fix operations, patching, and other day-to-day activities for relevant applications
Stays abreast of industry trends and investigates organizational objectives and needs, ensuring team mutual knowledge and awareness
Reviews and maintains operational documentation and reports to support monthly trend analysis as well as project components
Leads research, proof-of-concept, selection, and implementation of technology solution
Conducts an advanced level of analysis of pros and cons and build vs buy options, offering opinion to management regarding disputes and contrasts
Explores implementation of new technologies, solutions, and methods to improve business processes, efficiency, effectiveness, and value delivered to customers
Leads the examination of technology vision, opportunities and challenges regarding security standards and the impact of the technology within the Cyber Security organization
Develops and maintains relevant metrics, controls, and other governance administration related to cyber security technology
Participates in on-call rotation for the support of any relevant cyber security technologies
Assists management collaborating with other teams on projects, ensuring alignment with the goals and objectives of the Cyber Security organization
Works jointly with management to assist in the development of technical skills and knowledge among team, ensuring the organization has adequate resources to ensure the safety and protection of Regions' technology and assets
Serves as a mentor to team members
Acts as a role model in adhering to operational processes, standards, and procedures
May serve as a leader in security incident response activities and post-event reviews of security incidents
May serve as the subject-matter expert regarding design, implementation, and maintenance of relevant cyber security solutions to business areas, project teams, and vendors
May lead complex projects as assigned by management
This position is exempt from timekeeping requirements under the Fair Labor Standards Act and is not eligible for overtime pay.
Requirements
High School Diploma or GED and ten (10) years of related post-secondary education and/or experience in Information Security and/or Information Technology
Preferences
Bachelor's degree in Information Technology, Information Security, Information Systems Management, Computer Science, Engineering, or related field
Experience within a Cyber and/or Information Security organization within the financial services industry
Applicable technology and/or security certifications (e.g. Certified Information Systems Security Professional (CISSP), CompTIA Security+, Cisco Certified Network Associate (CCNA), Microsoft Certified Solutions Associate (MCSA), etc.)
Skills and Competencies
Ability to prioritize conflicting demands
Ability to work independently
Advanced analytical and evaluative thinking capability
Advanced knowledge of modern security tools and controls
Advanced problem-solving skills to offer sound solutions to complex issues
Strong knowledge of common web technologies, cloud technologies, and enterprise and network architecture
Strong knowledge of defense in depth, trust levels, privileges, and permissions
Strong verbal, written communication, and organizational skills
Preferred Qualifications:
Strong experience with Attack Surface Management (ASM), including asset discovery, exposure identification, and risk‑based prioritization.
Hands‑on expertise with Qualys, Rapid7, or similar tools for scan tuning, analysis, and remediation support.
Working knowledge of ServiceNow workflows related to vulnerability response and remediation tracking.
Ability to interpret vulnerability and exposure data and connect it to broader security operations and risk management processes.
Strong communicator who can collaborate effectively with infrastructure, application, and cloud teams to drive remediation and elevate team capabilities.
Contribute to the growth of junior team members by sharing best practices, offering guidance, and helping elevate the team's overall vulnerability management capabilities.
This position is intended to be onsite, now or in the near future. Associates will have regular work hours, including full days in the office three or more days a week. The manager will set the work schedule for this position, including in-office expectations. Regions will not provide relocation assistance for this position, and relocation would be at your expense. The locations available for this role are Birmingham, AL, Atlanta, GA, Nashville, TN, or Charlotte, NC.
Regions will not sponsor applicants for work visas for this position at this time. Applicants for this position must currently be authorized to work in the United States on a full-time basis.
Position Type
Full time
Compensation Details
Pay ranges are job specific and are provided as a point-of-market reference for compensation decisions. Other factors which directly impact pay for individual associates include: experience, skills, knowledge, contribution, job location and, most importantly, performance in the job role. As these factors vary by individuals, pay will also vary among individual associates within the same job.
The target information listed below is based on the Metropolitan Statistical Area Market Range for where the position is located and level of the position.
Job Range Target:
Minimum:
Median:
Incentive Pay Plans:
Opportunity to participate in the Long Term Incentive Plan.
Benefits Information
Regions offers a benefits package that is flexible, comprehensive and recognizes that "one size does not fit all" for benefits-eligible associates. Listed below is a synopsis of the benefits offered by Regions for informational purposes, which is not intended to be a complete summary of plan terms and conditions.
Paid Vacation/Sick Time
401K with Company Match
Medical, Dental and Vision Benefits
Disability Benefits
Health Savings Account
Flexible Spending Account
Life Insurance
Parental Leave
Employee Assistance Program
Associate Volunteer Program
Please note, benefits and plans may be changed, amended, or terminated with respect to all or any class of associate at any time. To learn more about Regions' benefits, please click or copy the link below to your browser.
*************************************************************
Location DetailsRiverchase Operations CenterLocation:Hoover, Alabama
Equal Opportunity Employer/including Disabled/Veterans
Job applications at Regions are accepted electronically through our career site for a minimum of five business days from the date of posting. Job postings for higher-volume positions may remain active for longer than the minimum period due to business need and may be closed at any time thereafter at the discretion of the company.
$67k-87k yearly est. Auto-Apply 1d ago
Looking for a job?
Let Zippia find it for you.
Senior Offensive Security Engineer
Robinhood 4.7
Bellevue, WA jobs
Join us in building the future of finance.
Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger generations in the next two decades. The largest transfer of wealth in human history. If you're ready to be at the epicenter of this historic cultural and financial shift, keep reading.
About the team + role
We are building an elite team, applying frontier technologies to the world's biggest financial problems. We're looking for bold thinkers. Sharp problem-solvers. Builders who are wired to make an impact. Robinhood isn't a place for complacency, it's where ambitious people do the best work of their careers. We're a high-performing, fast-moving team with ethics at the center of everything we do. Expectations are high, and so are the rewards.
Robinhood is looking for an Offensive SecurityEngineer who is passionate about Red Teaming, Adversarial Simulation, and breaking / fixing systems, to join the Red Team.
The Red Team is a core pillar of the Offensive Security team and situated within the Safety & Productivity Engineering organization. The Red Team works with teams across Robinhood to ensure our products, services, and processes are secure through threat modeling, penetration testing, adversarial simulations, and red teaming.
Here are some examples of things our team does frequently that you'll be heavily involved with:
Red Teaming to validate assumptions, facilitate decisions, and improve our ability to detect and respond to incidents.
Perform threat modeling against critical and new services. Articulate the actual security risk to risk working groups.
Penetration testing our critical infrastructure, production applications, networks, offices, and processes.
Sparring with Detection and Response and other stakeholders via Adversarial Simulations to prepare for incidents.
Partnering with the physical security team to conduct assessments of Robinhood properties.
Serving as a technical advocate and Subject Matter Expert for privacy and security decisions, designs, and discussions.
Driving innovative ideas to implementation as the company evolves and grows.
Conduct vulnerability research to understand latest TTPs, exploits, and forward looking capabilities.
Leaving things better than you found them by partnering to fix the issues and not just finding broken things.
As an Offensive SecurityEngineer, you will work across multiple domains, partner with key teams across Robinhood, and help build an even more resilient and secure product for our customers.
This role is based in our Menlo Park, CA office, with in-person attendance expected at least 3 days per week.
What you'll do
Evangelize the Offensive Security Team's Findings and Projects with stakeholders throughout the company and collaborate with other teams to create solutions that balance security with other priorities.
Mentor and provide guidance to the members of the Offensive Security team.
Utilize threat modeling to identify threats and shape Red Team priorities and exercises.
Plan and execute long term, broadly scoped, black box Red Team exercises utilizing vulnerability research, exploit development, and utilizing public proof of concept code.
Perform penetration testing, code reviews, and design/architecture reviews.
Write tooling to assist with and automate Red Team assessments.
Plan and participate in Adversarial Simulation exercises with various security teams.
Lead Security Incidents when Pentest or Red Team findings require them.
Publish blog posts and present talks at security conferences.
What you bring
5+ years of Red Team experience.
Experience mentoring other team members.
Passion and demonstrated experience for challenging security assumptions.
Excellent written and verbal communication skills and ability to communicate your findings at many different levels of abstraction from Engineers to Executives.
Passion for fixing security issues and not just identifying security issues.
Familiarity with common network protocols and standards such as DNS and TCP/IP.
Experience with MacOS and Linux.
Experience with leveraging components of a modern software development stack to attack companies, including CI, container orchestration systems (Kubernetes/Docker), cloud providers (AWS, GCP), etc and be able to give hardening suggestions.
Experience/knowledge of defensive tools/techniques (IDS/IPS, Packet Capture, Network Analysis, AV, EDR, etc.) and how to evaded them.
Deep understanding of Mitre's ATT&CK Framework.
Strong understanding of the security fundamentals of access and identity.
Ability to research and execute a testing plan to access a new technology or process.
Demonstrated experience working with a distributed team.
Proficiency to communicate over a text-based medium (Slack, JIRA Issues, GitHub issues, & Email) and can succinctly document technical details.
Experience in the Financial Technology domain.
Experience being a technical lead at other organizations.
What we offer
Market competitive and pay equity-focused compensation structure
100% paid health insurance for employees with 90% coverage for dependents
Annual lifestyle wallet for personal wellness, learning and development, and more!
Lifetime maximum benefit for family forming and fertility benefits
Dedicated mental health support for employees and eligible dependents
Generous time away including company holidays, paid time off, sick time, parental leave, and more!
Lively office environment with catered meals, fully stocked kitchens, and geo-specific commuter benefits
In addition to the base pay range listed below, this role is also eligible for bonus opportunities + equity + benefits.
Base pay for the successful applicant will depend on a variety of job-related factors, which may include education, training, experience, location, business needs, or market demands. The expected base pay range for this role is based on the location where the work will be performed and is aligned to one of 3 compensation zones. For other locations not listed, compensation can be discussed with your recruiter during the interview process.
Base Pay Range:
Zone 1 (Menlo Park, CA; New York, NY; Bellevue, WA; Washington, DC)
$187,000 - $220,000 USD
Zone 2 (Denver, CO; Westlake, TX; Chicago, IL)
$165,000 - $194,000 USD
Zone 3 (Lake Mary, FL; Clearwater, FL; Gainesville, FL)
$146,000 - $172,000 USD
Click here to learn more about our Total Rewards, which vary by region and entity.
If our mission energizes you and you're ready to build the future of finance, we look forward to seeing your application.
Robinhood provides equal opportunity for all applicants, offers reasonable accommodations upon request, and complies with applicable equal employment and privacy laws. Inclusion is built into how we hire and work-welcoming different backgrounds, perspectives, and experiences so everyone can do their best. Please review the Privacy Policy for your country of application.
Equal Employment Opportunity Information
At Robinhood, we care deeply about diverse representation in our workforce as it supports our mission to democratize finance for all. In support of this goal, we encourage applicants to voluntarily identify demographic information. This information helps us to continue building a more inclusive workplace and to ensure effective recruiting programs that are inclusive of individuals across all backgrounds.
Self-identifying in this section is completely voluntary and if you choose not to provide any information, please select the "I don't wish to answer" option under that question. Whatever your decision, data that you provide in this section will not be considered in the hiring process or thereafter. Individuals seeking employment at Robinhood are considered without regard to race, color, religion, national origin, age, sex, sexual orientation, marital status, ancestry, physical or mental disability, neurodivergence, veteran status, gender identity or expression, or any other characteristic protected by law.
You are being given the opportunity to provide the following information in order to help us comply with federal and state Equal Employment Opportunity recordkeeping, reporting, and other legal requirements, and to be used in our efforts to recruit a diverse workforce. Any information that you do provide will be recorded and maintained in a confidential manner. For more information on EEOC definitions, please reference this document .
By checking this box, I consent to Robinhood collecting, storing, and processing my responses to the demographic data surveys above. *
#J-18808-Ljbffr
$187k-220k yearly 21h ago
Senior Red Team Engineer - Finance Security & Adversarial Testing
Robinhood 4.7
Menlo Park, CA jobs
A leading financial technology company based in Menlo Park, CA seeks an Offensive SecurityEngineer to enhance security and build resilience across their products. This role involves mentoring, conducting Red Team exercises, and collaborating on security findings with various teams. Ideal candidates have 5+ years of experience and strong communication skills. Attractive compensation includes health insurance and support for personal wellness. Join us to help democratize finance for all.
#J-18808-Ljbffr
A financial services company in San Francisco is seeking an experienced security professional to assess access controls and mentor peers in security best practices. The candidate should have over 6 years of experience in security operations and a Bachelor's degree. The role offers competitive compensation ranging from $157,000 to $200,000, along with a hybrid work model and comprehensive benefits.
#J-18808-Ljbffr
$157k-200k yearly 4d ago
Senior Red Team Engineer - Finance Security & Adversarial Testing
Robinhood 4.7
Bellevue, WA jobs
A leading financial technology company based in Menlo Park, CA seeks an Offensive SecurityEngineer to enhance security and build resilience across their products. This role involves mentoring, conducting Red Team exercises, and collaborating on security findings with various teams. Ideal candidates have 5+ years of experience and strong communication skills. Attractive compensation includes health insurance and support for personal wellness. Join us to help democratize finance for all.
#J-18808-Ljbffr
A leading financial institution in Washington, DC is seeking a cybersecurity expert to enhance its malware defense team. Responsibilities include analyzing malware, tracking campaigns, and authoring reports. The ideal candidate must possess strong malware analysis skills, experience in creating analytical tools, and a solid understanding of network traffic analysis. This position offers an annual salary between $95,700.00 and $144,900.00 based on experience, alongside robust benefits aimed at ensuring employee wellness.
#J-18808-Ljbffr
$95.7k-144.9k yearly 4d ago
Lead AI Security Engineer
Capital Group 4.4
San Antonio, TX jobs
"I can be myself at work."
You are more than a job title. We want you to feel comfortable doing great work and bringing your best, authentic self to everything you do. We value your talents, traditions, and uniqueness-and we're committed to fostering a strong sense of belonging in a respectful workplace.
We intentionally seek diverse perspectives, experiences, and backgrounds, investing in a culture designed to celebrate differences. We believe that belonging leads to better outcomes and a stronger community of associates united by our mission. At Capital, we live our core values every day: Integrity, Client Focus, Diverse Perspectives, Long-Term Thinking, and Community.
"I can influence my income."
You want to feel recognized at work. Your performance will be reviewed annually, and your compensation will be designed to motivate and reward the value that you provide. You'll receive a competitive salary, bonuses and benefits. Your company-funded retirement contribution will factor in salary and variable pay, including bonuses.
"I can lead a full life."
You bring unique goals and interests to your job and your life. Whether you're raising a family, you're passionate about where you volunteer, or you want to explore different career paths, we'll give you the resources that can set you up for success.
Enjoy generous time-away and health benefits from day one, with the opportunity for flexible work options
Receive 2-for-1 matching gifts for your charitable contributions and the opportunity to secure annual grants for the organizations you love
Access on-demand professional development resources that allow you to hone existing skills and learn new ones
"I can succeed as a Lead AI SecurityEngineer at Capital Group"
As aLeadAISecurity Engineer, you willbe responsible forsecuring Capital Group's enterprise AI Platforms.You willhelp enable Capital Group's AIstrategy bybuilding and/orprocuringsolutions toprotecta diverse set of enterprise AI platforms being built and deployed at Capital Group.You'llcollaborate with platformengineering, securityengineering, and risk teams toensure their solutions support scalable, secureadoption of AI.
Additionally,you'llbe expected toprovidementoring,advising diverse teams across the organization, andpromoting AI Securityprinciples across Capital Group.
AISecurityProcurementManagements:You willprocureand/or build technical solutionsto reducethe riskof misconfiguration, exploitation, andother security issues formultipleenterprise AI platforms.
Embedding Security in the AIPlatform Ecosystem:Working closely withplatform teams tointegrate securityintoeverycomponentof the AI Platform.
Implementing Security Controls & "Guardrails" for GenAI:Designing, deploying, andoperatingtechnical controls to prevent misuse of AI systems.Guardrails designincludescontent filtering systems, usage policies, and safety checks that mitigate issues like prompt injection attacks, unauthorized data extraction, model bias or hallucinations, and other misuse of generative AIplatforms.
AI Runtime Security:Engineer continually tests and updatestothe guardrails, replacing weaker controls with more robust solutions as threats evolve.
AI Governance:You will work cross functionally with architecture and platform teams tomonitoralignment of solutions to AI Governance processes
Contribute to Standards and Policies:You will providethought leadership for Information Security policies and standards for AIin collaboration with technology risk
AI/Agent SME:Youwill provide AI/Agent subject matterexpertisefor AI Incidentsand Security Reviews, and helpdevelop incident response playbooks for AI-related security incidents
"I am the person Capital Group is looking for."
You have 8+yearsof experience in information security, application security, platform security, or penetration testing,DevSecOps, networksecurityand other security disciplines.
You have experience securing AI platforms, whetherinternal AIplatforms or offerings such as CoPilot Studio, Amazon Bedrock, and/or Azure AI Gateway
Proficient in Programming & ML Tool.Strong Python skillsrequired, with experience in AI/ML frameworks.Abilityto review and write ML code to implement security measures (e.g., model validation, adversarial testing) isdesired.
You have5+ years of relevant professional experience ordemonstrated anequivalent level ofexpertisein securityengineering, such as cloud, API, or platform security.
You have3+ years of experience embedded identity, network, and encryption controls into enterprise platforms
Youcaneffectively partner and collaborate with stakeholder teams.
You have effective communication skills andthe abilityto outline security riskstoleadership.
You are familiar with cloud and API security vendors and managed services providers.
Preferred Qualifications:
You have knowledge and experience with technologies including Kubernetes, Containers, CI/CD, and Cloud Service Providers
You are familiar withfunctionand purpose of key AI platform components such as AI gateways (Kong, Databricks Mosaic AI Gateway, custom API orchestration), Model Orchestration (ExamplesLangChain,LlamaIndex, etc.)
You are familiar with key AI regulatory frameworks such as NIST AI RMF, MITRE ATLAS, GDPR, EU AI Act,etc
You have information Security certifications (CISSP, SANS GIAC, CISA, etc.)
"I can apply in less than 4 minutes."
You've reviewed this job posting and you're ready to start the candidate journey with us. Apply now to move to the next step in our recruiting process. If this role isn't what you're looking for, check out our other opportunities and join our talent community.
"I can learn more about Capital Group."
At Capital Group, the success of the people who invest with us depends on the people in whom we invest. That's why we offer a culture, compensation and opportunities that empower our associates to build successful and prosperous careers. Through nine decades, our goal has been to improve people's lives through successful investing. We know that our history is a testament to the strength of the people we hire. More than 9,000 associates in 30+ offices around the world help our clients and each other grow and thrive every day. Find us on LinkedIn, Instagram, YouTube and Glassdoor.
Southern California Base Salary Range: $179,273-$286,837San Antonio Base Salary Range: $147,378-$235,805New York Base Salary Range: $190,040-$304,064
In addition to a highly competitive base salary, per plan guidelines, restrictions and vesting requirements, you also will be eligible for an individual annual performance bonus, plus Capital's annual profitability bonus plus a retirement plan where Capital contributes 15% of your eligible earnings.
You can learn more about our compensation and benefits
here
.
* Temporary positions in the United States are excluded from the above mentioned compensation and benefit plans.
We are an equal opportunity employer, which means we comply with all federal, state and local laws that prohibit discrimination when making all decisions about employment. As equal opportunity employers, our policies prohibit unlawful discrimination on the basis of race, religion, color, national origin, ancestry, sex (including gender and gender identity), pregnancy, childbirth and related medical conditions, age, physical or mental disability, medical condition, genetic information, marital status, sexual orientation, citizenship status, AIDS/HIV status, political activities or affiliations, military or veteran status, status as a victim of domestic violence, assault or stalking or any other characteristic protected by federal, state or local law.
$190k-304.1k yearly 1d ago
Lead AI Security Engineer
Capital Group 4.4
Irvine, CA jobs
"I can be myself at work."
You are more than a job title. We want you to feel comfortable doing great work and bringing your best, authentic self to everything you do. We value your talents, traditions, and uniqueness-and we're committed to fostering a strong sense of belonging in a respectful workplace.
We intentionally seek diverse perspectives, experiences, and backgrounds, investing in a culture designed to celebrate differences. We believe that belonging leads to better outcomes and a stronger community of associates united by our mission. At Capital, we live our core values every day: Integrity, Client Focus, Diverse Perspectives, Long-Term Thinking, and Community.
"I can influence my income."
You want to feel recognized at work. Your performance will be reviewed annually, and your compensation will be designed to motivate and reward the value that you provide. You'll receive a competitive salary, bonuses and benefits. Your company-funded retirement contribution will factor in salary and variable pay, including bonuses.
"I can lead a full life."
You bring unique goals and interests to your job and your life. Whether you're raising a family, you're passionate about where you volunteer, or you want to explore different career paths, we'll give you the resources that can set you up for success.
Enjoy generous time-away and health benefits from day one, with the opportunity for flexible work options
Receive 2-for-1 matching gifts for your charitable contributions and the opportunity to secure annual grants for the organizations you love
Access on-demand professional development resources that allow you to hone existing skills and learn new ones
"I can succeed as a Lead AI SecurityEngineer at Capital Group"
As aLeadAISecurity Engineer, you willbe responsible forsecuring Capital Group's enterprise AI Platforms.You willhelp enable Capital Group's AIstrategy bybuilding and/orprocuringsolutions toprotecta diverse set of enterprise AI platforms being built and deployed at Capital Group.You'llcollaborate with platformengineering, securityengineering, and risk teams toensure their solutions support scalable, secureadoption of AI.
Additionally,you'llbe expected toprovidementoring,advising diverse teams across the organization, andpromoting AI Securityprinciples across Capital Group.
AISecurityProcurementManagements:You willprocureand/or build technical solutionsto reducethe riskof misconfiguration, exploitation, andother security issues formultipleenterprise AI platforms.
Embedding Security in the AIPlatform Ecosystem:Working closely withplatform teams tointegrate securityintoeverycomponentof the AI Platform.
Implementing Security Controls & "Guardrails" for GenAI:Designing, deploying, andoperatingtechnical controls to prevent misuse of AI systems.Guardrails designincludescontent filtering systems, usage policies, and safety checks that mitigate issues like prompt injection attacks, unauthorized data extraction, model bias or hallucinations, and other misuse of generative AIplatforms.
AI Runtime Security:Engineer continually tests and updatestothe guardrails, replacing weaker controls with more robust solutions as threats evolve.
AI Governance:You will work cross functionally with architecture and platform teams tomonitoralignment of solutions to AI Governance processes
Contribute to Standards and Policies:You will providethought leadership for Information Security policies and standards for AIin collaboration with technology risk
AI/Agent SME:Youwill provide AI/Agent subject matterexpertisefor AI Incidentsand Security Reviews, and helpdevelop incident response playbooks for AI-related security incidents
"I am the person Capital Group is looking for."
You have 8+yearsof experience in information security, application security, platform security, or penetration testing,DevSecOps, networksecurityand other security disciplines.
You have experience securing AI platforms, whetherinternal AIplatforms or offerings such as CoPilot Studio, Amazon Bedrock, and/or Azure AI Gateway
Proficient in Programming & ML Tool.Strong Python skillsrequired, with experience in AI/ML frameworks.Abilityto review and write ML code to implement security measures (e.g., model validation, adversarial testing) isdesired.
You have5+ years of relevant professional experience ordemonstrated anequivalent level ofexpertisein securityengineering, such as cloud, API, or platform security.
You have3+ years of experience embedded identity, network, and encryption controls into enterprise platforms
Youcaneffectively partner and collaborate with stakeholder teams.
You have effective communication skills andthe abilityto outline security riskstoleadership.
You are familiar with cloud and API security vendors and managed services providers.
Preferred Qualifications:
You have knowledge and experience with technologies including Kubernetes, Containers, CI/CD, and Cloud Service Providers
You are familiar withfunctionand purpose of key AI platform components such as AI gateways (Kong, Databricks Mosaic AI Gateway, custom API orchestration), Model Orchestration (ExamplesLangChain,LlamaIndex, etc.)
You are familiar with key AI regulatory frameworks such as NIST AI RMF, MITRE ATLAS, GDPR, EU AI Act,etc
You have information Security certifications (CISSP, SANS GIAC, CISA, etc.)
"I can apply in less than 4 minutes."
You've reviewed this job posting and you're ready to start the candidate journey with us. Apply now to move to the next step in our recruiting process. If this role isn't what you're looking for, check out our other opportunities and join our talent community.
"I can learn more about Capital Group."
At Capital Group, the success of the people who invest with us depends on the people in whom we invest. That's why we offer a culture, compensation and opportunities that empower our associates to build successful and prosperous careers. Through nine decades, our goal has been to improve people's lives through successful investing. We know that our history is a testament to the strength of the people we hire. More than 9,000 associates in 30+ offices around the world help our clients and each other grow and thrive every day. Find us on LinkedIn, Instagram, YouTube and Glassdoor.
Southern California Base Salary Range: $179,273-$286,837San Antonio Base Salary Range: $147,378-$235,805New York Base Salary Range: $190,040-$304,064
In addition to a highly competitive base salary, per plan guidelines, restrictions and vesting requirements, you also will be eligible for an individual annual performance bonus, plus Capital's annual profitability bonus plus a retirement plan where Capital contributes 15% of your eligible earnings.
You can learn more about our compensation and benefits
here
.
* Temporary positions in the United States are excluded from the above mentioned compensation and benefit plans.
We are an equal opportunity employer, which means we comply with all federal, state and local laws that prohibit discrimination when making all decisions about employment. As equal opportunity employers, our policies prohibit unlawful discrimination on the basis of race, religion, color, national origin, ancestry, sex (including gender and gender identity), pregnancy, childbirth and related medical conditions, age, physical or mental disability, medical condition, genetic information, marital status, sexual orientation, citizenship status, AIDS/HIV status, political activities or affiliations, military or veteran status, status as a victim of domestic violence, assault or stalking or any other characteristic protected by federal, state or local law.
$190k-304.1k yearly 1d ago
Prin Security Analyst
Compeer Financial 4.1
Bloomington, IL jobs
Empowered to live. Inspired to work. Compeer Financial is a member-owned cooperative located in Illinois, Minnesota and Wisconsin. We bring together team members with a variety of backgrounds and experiences to help provide financial services to support agriculture and rural communities. Join us in a culture that not only promotes meaningful work and professional development, but provides a flexible, hybrid work environment and excellent benefits, which empower you to thrive both personally and professionally.
How we support you:
Hybrid model - up to 50% work from home
Flexible schedules including ample flexibility in the summer months
Up to 9% towards 401k (3% fixed Compeer contribution plus up to 6% match)
Benefits: medical, dental, vision, HSA/FSA, life & AD&D insurance, short-term and long-term disability, wellness program & EAP
Vacation, sick leave, holidays/floating holidays, parental leave, and volunteer paid time off
Learning and development programs
Mentorship programs
Cross-functional committee opportunities (i.e. Inclusion Council, emerging professional groups, etc.)
Professional membership/certification reimbursement and more!
Casual/seasonal & intern team members are not eligible for benefits except for state-mandated programs.
To learn more about Compeer Financial visit************************
Where you will work: This position offers a hybrid work option up to 50% remote and is based out of any of Compeer's office locations.
The contributions you will make:
This position creates, implements and maintains corporate-wide security programs that assist in improving overall security posture of the organization. Provides guidance, assurance and information protection to maintain the confidentiality, integrity, and availability of Compeer critical resources. Contributes knowledge and expertise to ensure that information assets are protected and secure. In this position, you will guide solutions to promote secure business-to-business initiatives, third-part relationships, outsourced solutions and vendors. Provides mentorship and guidance to less experienced team members.
A typical day:
Remains current with new security threats and assess systems and solutions to ensure they can defend the business.
Researches capabilities of current and new disruptive solutions on the market and makes recommendations to security group on a consistent basis.
Develops security team standards, policies, procedures and processes.
Support and provide direction for use of technical systems, monitors for unusual and suspicious activity across a wide range of products, data centers, and cloud systems.
Partners with Business Technology on security configuration standards for systems and business applications.
Participates in technical and non-technical projects requiring information security oversight and to ensure policies and procedures are met.
Provides cybersecurity guidance to leadership.
Ensures that cybersecurity-enabled products or other compensating security control technologies or processes reduce identified risk to an acceptable level.
Performs security reviews, identifies gaps in security architecture, and develops a security risk management plan.
Implements security measures to resolve vulnerabilities, mitigate risks, and recommend security changes to system or system components as needed.
Analyzes and reports system security posture trends.
Analyzes cyber defense policies and configurations and evaluates compliance with regulations and organizational directives.
Prepares audit reports that identify technical and procedural findings and provide recommended remediation strategies/solutions.
Leads the Incident Response Team during activations for security or operational events.
Coordinates, leads and conducts adversary simulation, hunt teaming, assumed breaches and whitebox penetration tests. Develops and executes attack plans, scripts, tools and methodologies to strengthen the offensive operations.
Plans and coordinates the delivery of classroom techniques and formats (e.g., lectures, demonstrations, interactive exercises, and multimedia presentations) for the most effective learning environment.
The skills and experience we prefer you have:
Bachelor's degree in security management, cybersecurity, computer science, management information systems, or business with technical training in networking, technical support or security or an equivalent combination of education and experience sufficient to perform the essential functions of the job.
Expert-level experience in physical asset security, information technology, risk management, security services, or infrastructure technology.
CISSP certification preferred.
Ability to adapt and stay a step ahead of cyber attackers and stay up to date on the latest attack methods.
Expert experience driving measurable improvement in monitoring and response capabilities at scale.
Expert ability to identify and resolve problems, utilizing strong analytical skills.
Advanced experience in cloud computing technologies, including software, infrastructure and platform-as-a-service, as well as public, private and hybrid environments.
Expert knowledge of traditional security controls and technologies, such as Security Information and Event Management (SIEM) systems, intrusion detection/prevention systems (IDS/IPS), public key infrastructure (PKI), identity and access management (IDAM) systems, antivirus and firewalls, in addition to endpoint detection and response (EDR), threat intelligence platforms, data loss prevention (DLP), security automation and orchestration, deception technologies, application controls, and other network and system monitoring tools.
Experience with purple teaming (red and blue) to train, identify and remediate issues cohesively.
Advanced experience with Amazon Web Services (AWS) or Microsoft Azure.
Expert experience conducting risk analysis to protect the business and adhere with compliance requirements and privacy laws.
Expert experience with vulnerability and penetration testing engagements.
Advanced knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
Expert knowledge of what constitutes a network attack and a network attack's relationship to both threats and vulnerabilities.
Knowledge of multiple cognitive domains and tools and methods applicable for learning in each domain.
Knowledge of media production, communication, and dissemination techniques and methods, including alternative ways to inform via written, oral, and visual media.
Knowledge of training and education principles and methods for curriculum design, teaching and instruction for individuals and groups, and the measurement of training and education effects.
How we will take care of you:
Our job titles may span more than one career level (associate, senior, principal, etc.). The actual title and base pay offered is dependent upon many factors, such as: training, transferable skills, work experience, business needs and market demands. The base pay range is subject to change and may be modified in the future. This role is eligible for variable compensation and other benefits.
Base Pay$103,100-$156,400 USD
Compeer Financial is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law.
Must be authorized to work for any employer in the United States. Compeer is unable to sponsor or take over sponsorship of an employment visa at this time.
Click here to view federal employment laws applicable for applicants.
$103.1k-156.4k yearly 1d ago
Lead AI Security Engineer
Capital Group 4.4
New York, NY jobs
"I can be myself at work."
You are more than a job title. We want you to feel comfortable doing great work and bringing your best, authentic self to everything you do. We value your talents, traditions, and uniqueness-and we're committed to fostering a strong sense of belonging in a respectful workplace.
We intentionally seek diverse perspectives, experiences, and backgrounds, investing in a culture designed to celebrate differences. We believe that belonging leads to better outcomes and a stronger community of associates united by our mission. At Capital, we live our core values every day: Integrity, Client Focus, Diverse Perspectives, Long-Term Thinking, and Community.
"I can influence my income."
You want to feel recognized at work. Your performance will be reviewed annually, and your compensation will be designed to motivate and reward the value that you provide. You'll receive a competitive salary, bonuses and benefits. Your company-funded retirement contribution will factor in salary and variable pay, including bonuses.
"I can lead a full life."
You bring unique goals and interests to your job and your life. Whether you're raising a family, you're passionate about where you volunteer, or you want to explore different career paths, we'll give you the resources that can set you up for success.
Enjoy generous time-away and health benefits from day one, with the opportunity for flexible work options
Receive 2-for-1 matching gifts for your charitable contributions and the opportunity to secure annual grants for the organizations you love
Access on-demand professional development resources that allow you to hone existing skills and learn new ones
"I can succeed as a Lead AI SecurityEngineer at Capital Group"
As aLeadAISecurity Engineer, you willbe responsible forsecuring Capital Group's enterprise AI Platforms.You willhelp enable Capital Group's AIstrategy bybuilding and/orprocuringsolutions toprotecta diverse set of enterprise AI platforms being built and deployed at Capital Group.You'llcollaborate with platformengineering, securityengineering, and risk teams toensure their solutions support scalable, secureadoption of AI.
Additionally,you'llbe expected toprovidementoring,advising diverse teams across the organization, andpromoting AI Securityprinciples across Capital Group.
AISecurityProcurementManagements:You willprocureand/or build technical solutionsto reducethe riskof misconfiguration, exploitation, andother security issues formultipleenterprise AI platforms.
Embedding Security in the AIPlatform Ecosystem:Working closely withplatform teams tointegrate securityintoeverycomponentof the AI Platform.
Implementing Security Controls & "Guardrails" for GenAI:Designing, deploying, andoperatingtechnical controls to prevent misuse of AI systems.Guardrails designincludescontent filtering systems, usage policies, and safety checks that mitigate issues like prompt injection attacks, unauthorized data extraction, model bias or hallucinations, and other misuse of generative AIplatforms.
AI Runtime Security:Engineer continually tests and updatestothe guardrails, replacing weaker controls with more robust solutions as threats evolve.
AI Governance:You will work cross functionally with architecture and platform teams tomonitoralignment of solutions to AI Governance processes
Contribute to Standards and Policies:You will providethought leadership for Information Security policies and standards for AIin collaboration with technology risk
AI/Agent SME:Youwill provide AI/Agent subject matterexpertisefor AI Incidentsand Security Reviews, and helpdevelop incident response playbooks for AI-related security incidents
"I am the person Capital Group is looking for."
You have 8+yearsof experience in information security, application security, platform security, or penetration testing,DevSecOps, networksecurityand other security disciplines.
You have experience securing AI platforms, whetherinternal AIplatforms or offerings such as CoPilot Studio, Amazon Bedrock, and/or Azure AI Gateway
Proficient in Programming & ML Tool.Strong Python skillsrequired, with experience in AI/ML frameworks.Abilityto review and write ML code to implement security measures (e.g., model validation, adversarial testing) isdesired.
You have5+ years of relevant professional experience ordemonstrated anequivalent level ofexpertisein securityengineering, such as cloud, API, or platform security.
You have3+ years of experience embedded identity, network, and encryption controls into enterprise platforms
Youcaneffectively partner and collaborate with stakeholder teams.
You have effective communication skills andthe abilityto outline security riskstoleadership.
You are familiar with cloud and API security vendors and managed services providers.
Preferred Qualifications:
You have knowledge and experience with technologies including Kubernetes, Containers, CI/CD, and Cloud Service Providers
You are familiar withfunctionand purpose of key AI platform components such as AI gateways (Kong, Databricks Mosaic AI Gateway, custom API orchestration), Model Orchestration (ExamplesLangChain,LlamaIndex, etc.)
You are familiar with key AI regulatory frameworks such as NIST AI RMF, MITRE ATLAS, GDPR, EU AI Act,etc
You have information Security certifications (CISSP, SANS GIAC, CISA, etc.)
"I can apply in less than 4 minutes."
You've reviewed this job posting and you're ready to start the candidate journey with us. Apply now to move to the next step in our recruiting process. If this role isn't what you're looking for, check out our other opportunities and join our talent community.
"I can learn more about Capital Group."
At Capital Group, the success of the people who invest with us depends on the people in whom we invest. That's why we offer a culture, compensation and opportunities that empower our associates to build successful and prosperous careers. Through nine decades, our goal has been to improve people's lives through successful investing. We know that our history is a testament to the strength of the people we hire. More than 9,000 associates in 30+ offices around the world help our clients and each other grow and thrive every day. Find us on LinkedIn, Instagram, YouTube and Glassdoor.
Southern California Base Salary Range: $179,273-$286,837San Antonio Base Salary Range: $147,378-$235,805New York Base Salary Range: $190,040-$304,064
In addition to a highly competitive base salary, per plan guidelines, restrictions and vesting requirements, you also will be eligible for an individual annual performance bonus, plus Capital's annual profitability bonus plus a retirement plan where Capital contributes 15% of your eligible earnings.
You can learn more about our compensation and benefits
here
.
* Temporary positions in the United States are excluded from the above mentioned compensation and benefit plans.
We are an equal opportunity employer, which means we comply with all federal, state and local laws that prohibit discrimination when making all decisions about employment. As equal opportunity employers, our policies prohibit unlawful discrimination on the basis of race, religion, color, national origin, ancestry, sex (including gender and gender identity), pregnancy, childbirth and related medical conditions, age, physical or mental disability, medical condition, genetic information, marital status, sexual orientation, citizenship status, AIDS/HIV status, political activities or affiliations, military or veteran status, status as a victim of domestic violence, assault or stalking or any other characteristic protected by federal, state or local law.
$190k-304.1k yearly 1d ago
Network and Security Engineer - VP
Natixis Corporate & Investment Banking 4.9
New York, NY jobs
Natixis CIB is seeking a dynamic and experienced Vice President of Network Security to lead and enhance our network security infrastructure across the AMER region. This strategic leadership role requires a deep technical understanding of network security and the ability to drive initiatives that protect our systems while mentoring a talented engineering team.
The job responsibilities include, but are not limited, to the following:
Infrastructure Oversight: Lead the design and administration of Natixis CIB AMER's network security infrastructure, focusing on critical components including DNS, F5 Load Balancers, Fortinet and Palo Alto firewalls, VPNs, proxies, Remote Access and DMZ connectivity.
Technology Initiatives: Drive technology projects aimed at enhancing cybersecurity and improving network performance in alignment with organizational goals.
Continuous Monitoring: Ensure optimal network performance through continuous monitoring, dashboard creation, promptly addressing any security incidents.
Documentation Management: Maintain comprehensive documentation, including network security asset inventories, diagrams, procedures and vendor contacts, to support operational efficiency and facilitate effective communication.
Cross-Department Collaboration: Collaborate with infrastructure teams to resolve network-related challenges and ensure seamless operations across departments.
Audit and Security Coordination: Work closely with audit and IT Security teams in both AMER and BPCE-IT to provide necessary documentation and implement remediation plans as required.
Staff Mentorship and Training: Mentor and train junior engineering staff, fostering a culture of growth and skill development within the network team.
Vulnerability Assessments: Conduct vulnerability assessments and manage patching processes to effectively mitigate and report security risks across the AMER region.
Security Reporting: Develop and deliver regular security reports to Leadership, highlighting key metrics, incidents, and trends to inform strategic decision-making.
LOD1 Security Management: Manage Line of Defense 1 (LOD1) network security controls and request as specified by the IT Risk Department.
Strategy Alignment: Coordinate with AMER and Head Office IT Security teams to assure alignment on security strategies and policies.
Tool Proficiency: Profiecent knowledge of security tools such as SIEM, Splunk, Centreon and Qualys for effective monitoring and incident response.
Bachelor's degree in computer science, Information Technology, Cybersecurity, or a related field; Master's preferred.
6+ years of hands-on experience in network security management, preferably within the financial services industry.
Extensive experience managing Cisco Firepower, Fortinet and Palo Alto firewalls, including DMZ design implementation.
Relevant certifications such as Fortinet NSE 4/5, Palo Alto Networks Certified Network SecurityEngineer (PCNSE), Cisco CCNP Enterprise and CCNP Security is a plus. Highly desirable CISSP, CISM.
Strong project management and leadership experience.
Excellent communication and problem-solving skills, with a focus on collaboration and teamwork.
Extensive understanding of network technologies - L2, L3, VXLAN, BGP, LAN/WAN/VPN
Extensive understanding of security technologies such as firewall, load balancing, proxy, authentication methods
Strong knowledge of DNS/DHCPWSG (Web Security Gateways), Proxy-pac scripting
Troubleshooting knowledge of network and security systems with minimal guidance is required.
OSI Layer 4 and Layer 7 protocol analysis and troubleshooting experience is required.
Excellent oral and written communication and documentation skills are essential.
Ideal candidate must have a strong understanding of Zero Trust Architecture and Network Access Control design for enterprise network infrastructure design, and troubleshooting.
Among these technologies, knowledge of Arista and Cisco design, configuration and automation is a definite plus
Knowledge of scripting languages such as Python, PoweShell, or Ansible.
The individual will need to be very organized, flexible, results oriented and able to multi-task to meet the demands of our dynamic environment
The candidate should be a self-starter, be able to work with minimal supervision, properly and effectively report project/work status to management and peers, take full ownership and responsibility of the tasks assigned to her/him and work them through completion.
The candidate should be able to demonstrate both technical capabilities and in-depth knowledge of various security and network concepts, technologies, and best practices
The candidate should have the ability to convey in non-technical terms complex technical explanations related to problems, designs, etc.
Knowledge of Ansible Scripting is a plus
Knowledge of micro segmentation tools such as Illumio or VM Ware NSX is a plus
Natixis is an equal opportunity employer, committed to a workplace free of discrimination. Natixis will not tolerate any form of discrimination based on age, color, mental or physical handicap or disability, pregnancy, marital status, sexual orientation, national origin, alienage, ancestry or citizenship status, race, religion, sex (including sex stereotyping, gender identity, gender expression or transgender status), veteran status, creed, genetic information or carrier status, or any other protected characteristic as established by law.
Respect for all means that we deal with each person as an individual and not as a member of any group. All qualified applicants will receive consideration for employment. Management is expected to provide leadership in supporting the firms EEO program by taking steps to promote EEO in all facets of employment including recruitment, hiring, retention, promotion, performance assessment, and career-development opportunities.
The salary range for the VP position will be between $150,000 - $180,000. Natixis is required by law to include a reasonable estimate of the compensation range for this role. Actual base salary will vary and will be based on several factors including, but not limited to, relevant experience, education, skills set, applicable licensure and certifications, and other business and organizational needs. Base salary is only one component of our total rewards package. Natixis also offers a generous benefits package, and you may be eligible for a discretionary incentive award depending on company and individual performance.
$150k-180k yearly 1d ago
Lead AI Security Engineer
Capital Group 4.4
Los Angeles, CA jobs
"I can be myself at work."
You are more than a job title. We want you to feel comfortable doing great work and bringing your best, authentic self to everything you do. We value your talents, traditions, and uniqueness-and we're committed to fostering a strong sense of belonging in a respectful workplace.
We intentionally seek diverse perspectives, experiences, and backgrounds, investing in a culture designed to celebrate differences. We believe that belonging leads to better outcomes and a stronger community of associates united by our mission. At Capital, we live our core values every day: Integrity, Client Focus, Diverse Perspectives, Long-Term Thinking, and Community.
"I can influence my income."
You want to feel recognized at work. Your performance will be reviewed annually, and your compensation will be designed to motivate and reward the value that you provide. You'll receive a competitive salary, bonuses and benefits. Your company-funded retirement contribution will factor in salary and variable pay, including bonuses.
"I can lead a full life."
You bring unique goals and interests to your job and your life. Whether you're raising a family, you're passionate about where you volunteer, or you want to explore different career paths, we'll give you the resources that can set you up for success.
Enjoy generous time-away and health benefits from day one, with the opportunity for flexible work options
Receive 2-for-1 matching gifts for your charitable contributions and the opportunity to secure annual grants for the organizations you love
Access on-demand professional development resources that allow you to hone existing skills and learn new ones
"I can succeed as a Lead AI SecurityEngineer at Capital Group"
As aLeadAISecurity Engineer, you willbe responsible forsecuring Capital Group's enterprise AI Platforms.You willhelp enable Capital Group's AIstrategy bybuilding and/orprocuringsolutions toprotecta diverse set of enterprise AI platforms being built and deployed at Capital Group.You'llcollaborate with platformengineering, securityengineering, and risk teams toensure their solutions support scalable, secureadoption of AI.
Additionally,you'llbe expected toprovidementoring,advising diverse teams across the organization, andpromoting AI Securityprinciples across Capital Group.
AISecurityProcurementManagements:You willprocureand/or build technical solutionsto reducethe riskof misconfiguration, exploitation, andother security issues formultipleenterprise AI platforms.
Embedding Security in the AIPlatform Ecosystem:Working closely withplatform teams tointegrate securityintoeverycomponentof the AI Platform.
Implementing Security Controls & "Guardrails" for GenAI:Designing, deploying, andoperatingtechnical controls to prevent misuse of AI systems.Guardrails designincludescontent filtering systems, usage policies, and safety checks that mitigate issues like prompt injection attacks, unauthorized data extraction, model bias or hallucinations, and other misuse of generative AIplatforms.
AI Runtime Security:Engineer continually tests and updatestothe guardrails, replacing weaker controls with more robust solutions as threats evolve.
AI Governance:You will work cross functionally with architecture and platform teams tomonitoralignment of solutions to AI Governance processes
Contribute to Standards and Policies:You will providethought leadership for Information Security policies and standards for AIin collaboration with technology risk
AI/Agent SME:Youwill provide AI/Agent subject matterexpertisefor AI Incidentsand Security Reviews, and helpdevelop incident response playbooks for AI-related security incidents
"I am the person Capital Group is looking for."
You have 8+yearsof experience in information security, application security, platform security, or penetration testing,DevSecOps, networksecurityand other security disciplines.
You have experience securing AI platforms, whetherinternal AIplatforms or offerings such as CoPilot Studio, Amazon Bedrock, and/or Azure AI Gateway
Proficient in Programming & ML Tool.Strong Python skillsrequired, with experience in AI/ML frameworks.Abilityto review and write ML code to implement security measures (e.g., model validation, adversarial testing) isdesired.
You have5+ years of relevant professional experience ordemonstrated anequivalent level ofexpertisein securityengineering, such as cloud, API, or platform security.
You have3+ years of experience embedded identity, network, and encryption controls into enterprise platforms
Youcaneffectively partner and collaborate with stakeholder teams.
You have effective communication skills andthe abilityto outline security riskstoleadership.
You are familiar with cloud and API security vendors and managed services providers.
Preferred Qualifications:
You have knowledge and experience with technologies including Kubernetes, Containers, CI/CD, and Cloud Service Providers
You are familiar withfunctionand purpose of key AI platform components such as AI gateways (Kong, Databricks Mosaic AI Gateway, custom API orchestration), Model Orchestration (ExamplesLangChain,LlamaIndex, etc.)
You are familiar with key AI regulatory frameworks such as NIST AI RMF, MITRE ATLAS, GDPR, EU AI Act,etc
You have information Security certifications (CISSP, SANS GIAC, CISA, etc.)
"I can apply in less than 4 minutes."
You've reviewed this job posting and you're ready to start the candidate journey with us. Apply now to move to the next step in our recruiting process. If this role isn't what you're looking for, check out our other opportunities and join our talent community.
"I can learn more about Capital Group."
At Capital Group, the success of the people who invest with us depends on the people in whom we invest. That's why we offer a culture, compensation and opportunities that empower our associates to build successful and prosperous careers. Through nine decades, our goal has been to improve people's lives through successful investing. We know that our history is a testament to the strength of the people we hire. More than 9,000 associates in 30+ offices around the world help our clients and each other grow and thrive every day. Find us on LinkedIn, Instagram, YouTube and Glassdoor.
Southern California Base Salary Range: $179,273-$286,837San Antonio Base Salary Range: $147,378-$235,805New York Base Salary Range: $190,040-$304,064
In addition to a highly competitive base salary, per plan guidelines, restrictions and vesting requirements, you also will be eligible for an individual annual performance bonus, plus Capital's annual profitability bonus plus a retirement plan where Capital contributes 15% of your eligible earnings.
You can learn more about our compensation and benefits
here
.
* Temporary positions in the United States are excluded from the above mentioned compensation and benefit plans.
We are an equal opportunity employer, which means we comply with all federal, state and local laws that prohibit discrimination when making all decisions about employment. As equal opportunity employers, our policies prohibit unlawful discrimination on the basis of race, religion, color, national origin, ancestry, sex (including gender and gender identity), pregnancy, childbirth and related medical conditions, age, physical or mental disability, medical condition, genetic information, marital status, sexual orientation, citizenship status, AIDS/HIV status, political activities or affiliations, military or veteran status, status as a victim of domestic violence, assault or stalking or any other characteristic protected by federal, state or local law.
$190k-304.1k yearly 1d ago
Senior SAP Security Consultant
Fintech Staffing Partners 4.2
Saint Louis, MO jobs
Senior SAP Application Security Configurator (GRC / Security)
Duration: 12-month contract
Security Requirement: U.S. Citizen with Active Secret Clearance (mandatory)
We are seeking a Senior SAP Application Security Configurator to lead and execute SAP User Management and Security activities within a highly regulated environment. This role is hands-on and strategic, responsible for SAP access design, role provisioning, Segregation of Duties (SoD) compliance, and SAP GRC security configuration across the full system lifecycle.
The ideal candidate brings deep SAP Application Security and GRC expertise, is comfortable operating in an onsite delivery model, and can lead both technical execution and governance activities while mentoring junior team members.
Key Responsibilities
Lead SAP User Management (UM) activities, including role creation, access provisioning, audits, and ongoing access maintenance
Design, develop, configure, and test SAP GRC security components
Perform role design and provisioning aligned with SoD policies, internal controls, and security standards
Conduct SoD risk analysis, remediation support, and access reviews
Support User Acceptance Testing (UAT), production cutover, and post-go-live hypercare activities
Lead role design reviews and ensure proper security documentation and audit readiness
Collaborate with functional, technical, and compliance stakeholders to ensure secure system design
Mentor junior SAP Security team members and support planning and delivery activities
Required Qualifications
8+ years of hands-on SAP Application Security experience
Expert-level experience with SAP GRC and SAP role design
Strong knowledge of User Access Management, SoD concepts, and compliance controls
Experience supporting UAT, go-live, and post-production environments
CompTIA Security+ certification
U.S. Citizenship with active Secret Clearance (required)
Ability to work 100% onsite in St. Louis, MO
Preferred Skills
Experience supporting SAP security in highly regulated or government-adjacent environments
Strong documentation, communication, and stakeholder management skills
Experience mentoring or leading junior security resources
$84k-110k yearly est. 2d ago
System Security Analyst
American National Bank of Texas 3.7
Plano, TX jobs
A System Security Analyst analyzes and implements system(s) security measures to protect sensitive data and infrastructure.
Implement and maintain security software like firewalls, encryption programs, and intrusion detection systems
Identify vulnerabilities in systems and networks, conduct penetration testing, and recommend mitigation strategies
Work closely with the systems team and Info Sec team to implement and enforce security policies and procedures, ensuring compliance with industry standards
Stay informed about the latest IT security trends and threats, and research new security solutions
Verify the security of third-party vendors and collaboration to meet security requirements
Technical knowledge of enterprise-class technologies such as cloud (AWS and Azure), firewalls, routers, switches, wireless access points, VPNs, and desktop and server operating systems
Thorough understanding of Microsoft's enterprise technology platform, including Azure, Active Directory, SQL, Office 365, and the Windows server and desktop operating systems, patching and vulnerabilities analysis
Hands-on experience with the following technology vendors and products: CyberArk, Okta, CyberReason, Splunk, Vulnerability Scanners
Qualifications:
Bachelor's degree or equivalent with certifications related to Information Security e.g. CISA, CISSP,
5-7 years of relevant experience
Preferred: Technical knowledge of enterprise-class technologies such as cloud (AWS and Azure), firewalls, routers, switches, wireless access points, VPNs, and desktop and server operating systems. Thorough understanding of Microsoft's enterprise technology platform, including Azure, Active Directory, SQL, Office 365, and the Windows server and desktop operating systems patching and vulnerabilities analysis
Skills:
CyberSecurity trends and latest threats and ethical hacker training
Working knowledge of Microsoft Excel and MS Word; basic keyboarding and calculator skills, must be able to do simple math and carry out written instructions
Travel to a variety of locations to perform work and/or attend meetings as required
Work occasionally requires more than 40 hours per week to perform the essential functions of the position
Lifting in an office setting may be required up to 30lbs.
ANBTX strongly encourages candidates that are fluent in English and Spanish to apply. Jobs that specifically require candidates to be bilingual will be posted as a requirement.
Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.
$78k-107k yearly est. 1d ago
Information Security Specialist
Federal Reserve Bank of Kansas City 4.7
Kansas City, MO jobs
CompanyFederal Reserve Bank of Kansas CityWhen you join the Federal Reserve-the nation's central bank-you'll play a key role, collaborating with leading tech professionals to strengthen and protect our economic, financial and payments systems. We invest in contemporary and emerging technology each year to support the Federal Reserve and our economy, and we're building a dynamic and diverse team for our future.
Important Information
Open to US citizens, Green Card holders or Permanent Residents with at least 3 years of residency, with the intent to become a US citizen.
No sponsorship is available. Candidates must have valid work authorization, without an end date, to be considered.
This position requires working on-site, in Kansas City, Denver, Oklahoma City, or Omaha, with 5 days per month remote work flexibility.
This position is not eligible to be remote and relocation assistance is not available.
We are seeking cybersecurity professionals to join our Information Security team as a security specialist focused on operating our DevSecOps program according to standards and policies.
This will be done through close partnership with peers in FRB Kansas City and other Reserve Banks across the System. It will also require healthy relationship building and tight integration with development teams. Additionally, you'll partner with business areas, vendors, and our diverse network of professionals to identify, implement, and support security across the organization.
Candidates with strong understanding and experience in cloud environment deployments, information security, data management, low-code and no-code solutions, DevSecOps, and artificial intelligence will be ideal.
Key Activities
Interpret and evaluate policies in order to mature and implement the DevSecOps program.
Assess maturity of development teams' DevSecOps practices against an existing framework.
Proactively advocate for and drive enhancements into the program.
Identify gaps/opportunities for enhancements to workflows and processes for enhancing the software development lifecycle (SDLC).
Implement and consults on secure continuous integration and continuous delivery (CI/CD) pipelines, evaluating code and/or applications, or creating code to facilitate the process.
Monitors information security policy compliance using security tooling.
Evaluate and implement security products and/or processes to enhance productivity and effectiveness for various platforms and initiatives.
Provide technical expertise and support to internal teams on security-related matters.
Collaborate with cross-functional teams to integrate security measures into existing software applications and infrastructure.
Stay current with emerging technologies, industry trends, and best practices in cybersecurity to enhance our security posture.
Support leadership decision making through timely analysis and written communications.
Qualifications
Typically requires 3-6 years of relevant experience.
Bachelor's Degree in Technology, Engineering, Computer Science, Information Systems, Cybersecurity or other related field or equivalent work experience.
Strong competence in cloud technologies such as AWS, Azure, and other platforms.
Expert understanding of DevSecOps practices, frameworks, and tools.
Expertise with tool integration for the DevOps pipeline such as Git.
Combines and organizes information into meaningful patterns; identifies underlying relationships, causes and effects; and combines pieces of information to form conclusions or general rules.
Rapidly acquires new knowledge and learns new skills, and practices agile methodologies to planning and accomplishing work.
Conveys complex and technical issues to diverse audiences.
Demonstrated competencies with artificial intelligence are beneficial.
Working knowledge of Terraform, Ansible, Cloud Formations, AWS Config, AWS Inspector, Guard Duty and others.
Strong knowledge of software development languages, tools and techniques such as Python, JSON, YAML, and Java
Technical expertise in security tools and knowledge of security practices and procedures.
A learning mindset, proactiveness, collaboration, and strong attention to detail.
Additional Information
How We Work (HWW):
On-site: 5 days per month remote work flexibility
Locations: Kansas City, Denver, Oklahoma City, Omaha
Remote Eligible: No
Relocation Assistance: No
Salary:
$79,100 - $111,500 / Experienced Level
$98,600 - $139,000 / Senior Level
Final offers are determined by factors including the candidate's qualifications, internal alignment considerations, district assignment, and geographic location.
Screening: US citizens, permanent residents with the intent to become a US citizen with at least three or more years of United States residency from the date of legal entry to the United States is required for this position.This position has additional screening requirements due to the information accessed while performing the job. These additional screenings would be initiated at the time of offer acceptance and can take up to a couple of months to be completed. You can begin work before the screening is completed; however, continued employment is contingent on acceptable screening results. The areas screened may include education/employment verification, criminal history, credit history, and reference checks.
Sponsorship: The Federal Reserve Bank of Kansas City will not sponsor a new applicant for employment authorization for this position. Applicants must be currently authorized to work in the United States without the need for visa sponsorship now or in the future.
About Us
Total Rewards & Benefits
Who We Are
What We Do
Follow us on
LinkedIn
, Instagram,
X (formerly Twitter)
, and
YouTube
#KCFedIT
Full Time / Part TimeFull time Regular / TemporaryRegularJob Exempt (Yes / No) YesJob CategoryInformation Technology Family GroupWork ShiftFirst (United States of America)
The Federal Reserve Banks are committed to equal employment opportunity for employees and job applicants in compliance with applicable law and to an environment where employees are valued for their differences.
Always verify and apply to jobs on Federal Reserve System Careers (FRS) or through verified Federal Reserve Bank social media channels.
Privacy Notice
$98.6k-139k yearly 1d ago
Enterprise Security System (ESS) Administrator - DHS Federal Law EnforcementTraining Center (FLETC)
ITC Federal, Inc. 4.7
Fairfax, VA jobs
Enterprise Security System (ESS) Administrator - DHS Federal Law Enforcement Training Center (FLETC) ID 2025-1454 Remote No
JOB TITLE: Enterprise Support System (ESS) Administrator
GOVERNMENT AGENCY: Department of Homeland Security (DHS), Federal Law Enforcement Training Center (FLETC)
POSITION INFORMATION: Full-Time Position
LOCATION: FLETC Headquarters - Glynco, GA; or other FLETC Training Delivery Points (TDPs) in Artesia, NM; Charleston, SC; or Cheltenham, MD (including the Washington, DC Office). Some services may be performed remotely. The place of performance will be dependent on the awarded proposal.
POSITION TIMING: Contingent on Contract Award
ITC Federal, LLC, (ITC) is an information technology and consulting company focused on servicing the needs of the Federal Government. ITC's mission is to apply earned expertise in DevSecOps, Cloud Computing, Federal Financial Systems, App Dev, and Cyber Security to assist our clients in achieving their mission. ITC is located in Fairfax, VA and offers outstanding compensation and benefits plan and a challenging and rewarding professional work environment.
Program Overview:
The Federal Law Enforcement Training Centers (FLETC), part of the Department of Homeland Security (DHS), is responsible for training and supporting the training of federal, state, local, and tribal law enforcement officers-as well as international partners-who enforce laws, treaties, and regulations in the United States and abroad.
Headquartered in Glynco, Georgia, with training delivery points in Artesia, New Mexico; Charleston, South Carolina; and Cheltenham, Maryland, FLETC's mission depends on secure, stable, and modern IT infrastructure.
This program delivers comprehensive Information Technology (IT) Delivery and Operations Support Services (DOSS) that ensure reliable and efficient IT and media system performance across all FLETC locations. The Enterprise Security System (ESS) Administrator will play a critical role in maintaining the availability, performance, and security of FLETC's ESS environment.
The Enterprise Security Systems (ESS) Administrator is responsible for the full lifecycle management, configuration, and sustainment of the security systems and related enterprise infrastructure supporting FLETC operations.
Responsibilities
RESPONSIBILITIES:
Design, install, configure, and maintain the FLETC Enterprise Security Systems (ESS) environment, ensuring system availability, security, and performance across all training sites.
Administer and manage physical access control systems, security-related databases, and supporting servers and network infrastructure.
Implement and maintain cybersecurity and access control measures in accordance with DHS and FLETC standards.
Coordinate with CSO and CIO stakeholders to support secure facilities and shared system operations.
Perform regular system patching, updates, and capacity planning to ensure long-term scalability and system health.
Monitor system performance and proactively identify, diagnose, and resolve issues impacting security systems or end users.
Develop and maintain detailed documentation, including system configurations, architecture diagrams, and standard operating procedures.
Support system integration efforts between security platforms and broader enterprise IT environments.
Participate in audits, compliance reviews, and incident response activities as required.
Provide advanced troubleshooting and root cause analysis for system and infrastructure issues affecting mission-critical security operations.
Qualifications
REQUIRED:
Demonstrated experience administering and maintaining enterprise-level security systems, including physical access control, surveillance, and visitor management technologies.
Expertise in server, database, and infrastructure management within a secure enterprise environment.
Strong understanding of system security principles, access control, and vulnerability management.
Proficiency in system monitoring, performance tuning, and issue resolution across hardware, software, and network layers.
Experience developing and maintaining detailed system documentation and operational procedures.
Ability to work both independently and collaboratively within cross-functional teams (Security, IT Operations, and Engineering).
Ability to obtain and maintain a Public Trust security clearance.
DESIRED:
Experience supporting Enterprise Security Systems or comparable large-scale physical security environments.
Familiarity with Windows Server, SQL Server, and enterprise infrastructure solutions.
Experience with system backups, disaster recovery, and high-availability configurations.
ITIL certification or experience operating within an IT service management framework.
Knowledge of DHS or federal IT compliance standards (FISMA, NIST, etc.).
Strong communication, documentation, and customer service skills.
WORK ENVIRONMENT AND PHYSICAL DEMANDS: Candidate must be able to function in general office environment.
ITC Federal is an equal opportunity employer and will not discriminate against any application for employment on the basis of age, race, color, gender, national origin, religion, creed, disability, veteran status, marital status, sexual orientation, genetic information, military status, disability, or sex including pregnancy and childbirth or related medical condition or on any other basis prohibited by law.
$73k-97k yearly est. 21h ago
Information Security Specialist
Federal Reserve Bank of Kansas City 4.7
Denver, CO jobs
CompanyFederal Reserve Bank of Kansas CityWhen you join the Federal Reserve-the nation's central bank-you'll play a key role, collaborating with leading tech professionals to strengthen and protect our economic, financial and payments systems. We invest in contemporary and emerging technology each year to support the Federal Reserve and our economy, and we're building a dynamic and diverse team for our future.
Important Information
Open to US citizens, Green Card holders or Permanent Residents with at least 3 years of residency, with the intent to become a US citizen.
No sponsorship is available. Candidates must have valid work authorization, without an end date, to be considered.
This position requires working on-site, in Kansas City, Denver, Oklahoma City, or Omaha, with 5 days per month remote work flexibility.
This position is not eligible to be remote and relocation assistance is not available.
We are seeking cybersecurity professionals to join our Information Security team as a security specialist focused on operating our DevSecOps program according to standards and policies.
This will be done through close partnership with peers in FRB Kansas City and other Reserve Banks across the System. It will also require healthy relationship building and tight integration with development teams. Additionally, you'll partner with business areas, vendors, and our diverse network of professionals to identify, implement, and support security across the organization.
Candidates with strong understanding and experience in cloud environment deployments, information security, data management, low-code and no-code solutions, DevSecOps, and artificial intelligence will be ideal.
Key Activities
Interpret and evaluate policies in order to mature and implement the DevSecOps program.
Assess maturity of development teams' DevSecOps practices against an existing framework.
Proactively advocate for and drive enhancements into the program.
Identify gaps/opportunities for enhancements to workflows and processes for enhancing the software development lifecycle (SDLC).
Implement and consults on secure continuous integration and continuous delivery (CI/CD) pipelines, evaluating code and/or applications, or creating code to facilitate the process.
Monitors information security policy compliance using security tooling.
Evaluate and implement security products and/or processes to enhance productivity and effectiveness for various platforms and initiatives.
Provide technical expertise and support to internal teams on security-related matters.
Collaborate with cross-functional teams to integrate security measures into existing software applications and infrastructure.
Stay current with emerging technologies, industry trends, and best practices in cybersecurity to enhance our security posture.
Support leadership decision making through timely analysis and written communications.
Qualifications
Typically requires 3-6 years of relevant experience.
Bachelor's Degree in Technology, Engineering, Computer Science, Information Systems, Cybersecurity or other related field or equivalent work experience.
Strong competence in cloud technologies such as AWS, Azure, and other platforms.
Expert understanding of DevSecOps practices, frameworks, and tools.
Expertise with tool integration for the DevOps pipeline such as Git.
Combines and organizes information into meaningful patterns; identifies underlying relationships, causes and effects; and combines pieces of information to form conclusions or general rules.
Rapidly acquires new knowledge and learns new skills, and practices agile methodologies to planning and accomplishing work.
Conveys complex and technical issues to diverse audiences.
Demonstrated competencies with artificial intelligence are beneficial.
Working knowledge of Terraform, Ansible, Cloud Formations, AWS Config, AWS Inspector, Guard Duty and others.
Strong knowledge of software development languages, tools and techniques such as Python, JSON, YAML, and Java
Technical expertise in security tools and knowledge of security practices and procedures.
A learning mindset, proactiveness, collaboration, and strong attention to detail.
Additional Information
How We Work (HWW):
On-site: 5 days per month remote work flexibility
Locations: Kansas City, Denver, Oklahoma City, Omaha
Remote Eligible: No
Relocation Assistance: No
Salary:
$79,100 - $111,500 / Experienced Level
$98,600 - $139,000 / Senior Level
Final offers are determined by factors including the candidate's qualifications, internal alignment considerations, district assignment, and geographic location.
Screening: US citizens, permanent residents with the intent to become a US citizen with at least three or more years of United States residency from the date of legal entry to the United States is required for this position.This position has additional screening requirements due to the information accessed while performing the job. These additional screenings would be initiated at the time of offer acceptance and can take up to a couple of months to be completed. You can begin work before the screening is completed; however, continued employment is contingent on acceptable screening results. The areas screened may include education/employment verification, criminal history, credit history, and reference checks.
Sponsorship: The Federal Reserve Bank of Kansas City will not sponsor a new applicant for employment authorization for this position. Applicants must be currently authorized to work in the United States without the need for visa sponsorship now or in the future.
About Us
Total Rewards & Benefits
Who We Are
What We Do
Follow us on
LinkedIn
, Instagram,
X (formerly Twitter)
, and
YouTube
#KCFedIT
Full Time / Part TimeFull time Regular / TemporaryRegularJob Exempt (Yes / No) YesJob CategoryInformation Technology Family GroupWork ShiftFirst (United States of America)
The Federal Reserve Banks are committed to equal employment opportunity for employees and job applicants in compliance with applicable law and to an environment where employees are valued for their differences.
Always verify and apply to jobs on Federal Reserve System Careers (FRS) or through verified Federal Reserve Bank social media channels.
Privacy Notice
$98.6k-139k yearly 1d ago
Enterprise Security System (ESS) Administrator - DHS Federal Law EnforcementTraining Center (FLETC)
ITC Federal, Inc. 4.7
Brunswick, GA jobs
Enterprise Security System (ESS) Administrator - DHS Federal Law Enforcement Training Center (FLETC) ID 2025-1453 Remote No
JOB TITLE: Enterprise Support System (ESS) Administrator
GOVERNMENT AGENCY: Department of Homeland Security (DHS), Federal Law Enforcement Training Center (FLETC)
POSITION INFORMATION: Full-Time Position
LOCATION: FLETC Headquarters - Glynco, GA; or other FLETC Training Delivery Points (TDPs) in Artesia, NM; Charleston, SC; or Cheltenham, MD (including the Washington, DC Office). Some services may be performed remotely. The place of performance will be dependent on the awarded proposal.
POSITION TIMING: Contingent on Contract Award
ITC Federal, LLC, (ITC) is an information technology and consulting company focused on servicing the needs of the Federal Government. ITC's mission is to apply earned expertise in DevSecOps, Cloud Computing, Federal Financial Systems, App Dev, and Cyber Security to assist our clients in achieving their mission. ITC is located in Fairfax, VA and offers outstanding compensation and benefits plan and a challenging and rewarding professional work environment.
Program Overview:
The Federal Law Enforcement Training Centers (FLETC), part of the Department of Homeland Security (DHS), is responsible for training and supporting the training of federal, state, local, and tribal law enforcement officers-as well as international partners-who enforce laws, treaties, and regulations in the United States and abroad.
Headquartered in Glynco, Georgia, with training delivery points in Artesia, New Mexico; Charleston, South Carolina; and Cheltenham, Maryland, FLETC's mission depends on secure, stable, and modern IT infrastructure.
This program delivers comprehensive Information Technology (IT) Delivery and Operations Support Services (DOSS) that ensure reliable and efficient IT and media system performance across all FLETC locations. The Enterprise Security System (ESS) Administrator will play a critical role in maintaining the availability, performance, and security of FLETC's ESS environment.
The Enterprise Security Systems (ESS) Administrator is responsible for the full lifecycle management, configuration, and sustainment of the security systems and related enterprise infrastructure supporting FLETC operations.
Responsibilities
RESPONSIBILITIES:
Design, install, configure, and maintain the FLETC Enterprise Security Systems (ESS) environment, ensuring system availability, security, and performance across all training sites.
Administer and manage physical access control systems, security-related databases, and supporting servers and network infrastructure.
Implement and maintain cybersecurity and access control measures in accordance with DHS and FLETC standards.
Coordinate with CSO and CIO stakeholders to support secure facilities and shared system operations.
Perform regular system patching, updates, and capacity planning to ensure long-term scalability and system health.
Monitor system performance and proactively identify, diagnose, and resolve issues impacting security systems or end users.
Develop and maintain detailed documentation, including system configurations, architecture diagrams, and standard operating procedures.
Support system integration efforts between security platforms and broader enterprise IT environments.
Participate in audits, compliance reviews, and incident response activities as required.
Provide advanced troubleshooting and root cause analysis for system and infrastructure issues affecting mission-critical security operations.
Qualifications
REQUIRED:
Demonstrated experience administering and maintaining enterprise-level security systems, including physical access control, surveillance, and visitor management technologies.
Expertise in server, database, and infrastructure management within a secure enterprise environment.
Strong understanding of system security principles, access control, and vulnerability management.
Proficiency in system monitoring, performance tuning, and issue resolution across hardware, software, and network layers.
Experience developing and maintaining detailed system documentation and operational procedures.
Ability to work both independently and collaboratively within cross-functional teams (Security, IT Operations, and Engineering).
Ability to obtain and maintain a Public Trust security clearance.
DESIRED:
Experience supporting Enterprise Security Systems or comparable large-scale physical security environments.
Familiarity with Windows Server, SQL Server, and enterprise infrastructure solutions.
Experience with system backups, disaster recovery, and high-availability configurations.
ITIL certification or experience operating within an IT service management framework.
Knowledge of DHS or federal IT compliance standards (FISMA, NIST, etc.).
Strong communication, documentation, and customer service skills.
WORK ENVIRONMENT AND PHYSICAL DEMANDS: Candidate must be able to function in general office environment.
ITC Federal is an equal opportunity employer and will not discriminate against any application for employment on the basis of age, race, color, gender, national origin, religion, creed, disability, veteran status, marital status, sexual orientation, genetic information, military status, disability, or sex including pregnancy and childbirth or related medical condition or on any other basis prohibited by law.
$70k-90k yearly est. 21h ago
Information Security Analyst
Cathay Bank-Headquarters 4.4
Rancho Cucamonga, CA jobs
People Drive Our Success Are you enthusiastic, highly motivated, and have a strong work ethic? If yes, come join our team! At Cathay Bank - we strive to provide a caring culture that supports your aspirations and success. We believe people are our most valuable asset and we proudly foster growth and development empowering you to achieve your professional goals. We have thrived for 60 years and persevered through many economic cycles due to our team members' drive and optimism. Together we can make a difference in the financial future of our communities.
Apply today!
What our team members are saying:
Video Clip 1
Video Clip 2
Video Clip 3
Learn more about us at cathaybank.com
GENERAL SUMMARY
This position is responsible for ensuring that the Bank's Security operations and preventive controls are managed and maintained in accordance with established Information Security policies, standards and procedures, published regulations and industry best practices.
Primarily responsible for the constant review of vendor security controls in comparison with policies and industry frameworks, risk assessments, determination of control gaps and their remediation.
ESSENTIAL FUNCTIONS
Performs vendor security risk assessments to determine inherent risk on proposed projects and assesses vendor security controls to determine residual risk.
Evaluates the potential exposure to application security risks and threats based on industry security frameworks and recommends appropriate mitigation.
Assesses security practices including Information Security governance, Identity and access control, Incident monitoring and response, Vulnerability assessment and Penetration tests, Network Security and Endpoint Security, among others.
Acts as liaison with Third Party Risk Management, Information Technology and business department Relationship Managers related to vendor risk assessments.
Reports information security risks and follows-up remediations.
Remediates audit and regulatory findings and recommendations related to Information Security and Vendor Risk Management.
QUALIFICATIONS
Education:
College degree in Information Technology or Information Security or equivalent;
Security+, SSCP, CISSP, CISM or similar information security certifications preferred.
Experience:
Minimum two years of experience in Information Security Risk, Information Security Operations or Security Auditing.
Proven experience on third-party risk management and vendor security assessments.
Working knowledge of security practices such as Endpoint Security, Network Security, Security Operations and Security Governance required.
Experience working with Vendor Risk Management (VRM) applications preferred.
Skills/Ability:
Proven ability to initiate and manage projects.
Excellent communication and problem-solving skills.
Strong inter-personal communication and collaboration skills.
Self-starter, highly motivated, and able to work with general supervision.
OTHER DETAILS
$28.84 - $33.65 / hour
Pay determined based on job-related knowledge, skills, experience, and location.
This position may be eligible for a discretionary bonus.
Cathay Bank offers its full-time employees a competitive benefits package which is a significant part of their total compensation. It is our goal to provide employees with a comprehensive benefits package to fit their needs which includes, coverage for medical insurance, dental insurance, vision insurance, life insurance, long-term disability insurance, and flexible spending accounts (FSAs), health saving account (HSA) with company contributions, voluntary coverages, and 401(k).
Cathay Bank may collect personal information from potential job candidates and applicants. For more information on how we handle personal information and your applicable rights, please review our Privacy Policy.
Cathay Bank is an Equal Opportunity and Affirmative Action Employer. We welcome applications for employment from all qualified candidates, regardless of race, color, ethnicity, ancestry, citizenship, gender, national origin, religion, age, sex (including pregnancy and related medical conditions, childbirth and breastfeeding), reproductive health decision-making, sexual orientation, gender identity and expression, genetic information or characteristics, disability or medical condition, military status or status as a protected veteran, or any other status protected by applicable law.
Click here to view the "Know Your Rights: Workplace Discrimination is Illegal" Poster:
Poster- English
Poster- Spanish
Poster- Chinese Traditional
Poster- Chinese Simplified
Cathay Bank endeavors to make **************************** to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact, Mickey Hsu, FVP, Employee Relations Manager, at or . This contact information is for accommodation requests only and cannot be used to inquire about the status of applications.
$28.8-33.7 hourly 1d ago
Cyber Security Architect
Regions Bank 4.1
Security engineer job at Regions Bank
Thank you for your interest in a career at Regions. At Regions, we believe associates deserve more than just a job. We believe in offering performance-driven individuals a place where they can build a career --- a place to expect more opportunities. If you are focused on results, dedicated to quality, strength and integrity, and possess the drive to succeed, then we are your employer of choice.
Regions is dedicated to taking appropriate steps to safeguard and protect private and personally identifiable information you submit. The information that you submit will be collected and reviewed by associates, consultants, and vendors of Regions in order to evaluate your qualifications and experience for job opportunities and will not be used for marketing purposes, sold, or shared outside of Regions unless required by law. Such information will be stored in accordance with regulatory requirements and in conjunction with Regions' Retention Schedule for a minimum of three years. You may review, modify, or update your information by visiting and logging into the careers section of the system.
Job Description:
At Regions, the Cyber Security Architect contributes to the advancement of Regions' cyber security program and its capabilities through developing, communicating, and implementing a security architecture. This position establishes secure development practices which increases the security of internal systems. Additionally, this position collaborates closely with key stakeholders and teams as part of business projects and/or initiatives.
Primary Responsibilities
Contributes to the development and establishment of a strategic cyber security architecture and strategic vision, including standards and frameworks that are aligned with the overall business and Regions' information technology strategy
Works closely with Enterprise Architecture and Application Development groups to enhance the security posture of new and existing systems
Contributes to the design of cyber security architecture, evaluates and mitigates potential risk, and, when necessary, approves implementation of systems and applications into production
Performs assessments using the National Institute of Standards and Technology (NIST) Cyber Security Framework and the Federal Financial Institutions Examination Council (FFIEC) Cyber Assessment Tool to identify gaps and remediate deficiencies
Ensures systems and applications are implemented with compensating controls to meet regulatory requirements (e.g. GLBA, SOX, HIPPA, FFIEC, etc.) as well as other organizational compliance (PCI) requirements
Tracks metrics for compliance to internal cyber security standards set by application and system owners
Offers advice and guidance to junior architects, assisting in the development of necessary skills and technical knowledge
This position is exempt from timekeeping requirements under the Fair Labor Standards Act and is not eligible for overtime pay.
Requirements
Bachelor's degree in Computer Science, or related field
Five (5) years of experience in cyber security, with a focus on software development, secure software development lifecycle (SDLC), or security architecture
Preferences
Experience in the design and implementation of cyber security solutions
Skills and Competencies
Ability to effectively evaluate risk vs. reward
Ability to independently problem solve with sound judgement
Ability to translate complex technical information across all levels of the organization through communications and/or presentations
Ability to work in a team environment when applicable
Advanced knowledge of risks associated with virtualization and cloud-based computing and the impact of those technologies on an organizations security posture
Advanced knowledge of security principles, solutions, tools, methodologies, and techniques
Proficiency in Microsoft Office (Excel, Word, PowerPoint, Outlook, etc.)
Strong project management skills
Strong verbal, written communication, and organizational skills
Strong work ethic and self-motivation
This position is intended to be onsite, now or in the near future. Associates will have regular work hours, including full days in the office three or more days a week. This position must be within a reasonable driving distance to a Branch, Consumer Operations, or Professional Office Building with the primary location being for Birmingham, AL, Nashville, TN, Atlanta, GA or Charlotte, NC. The manager will set the work schedule for this position, including in-office expectations. Regions will not provide relocation assistance for this position, and relocation would be at your expense.
Position Type
Full time
Compensation Details
Pay ranges are job specific and are provided as a point-of-market reference for compensation decisions. Other factors which directly impact pay for individual associates include: experience, skills, knowledge, contribution, job location and, most importantly, performance in the job role. As these factors vary by individuals, pay will also vary among individual associates within the same job.
The target information listed below is based on the Metropolitan Statistical Area Market Range for where the position is located and level of the position.
Job Range Target:
Minimum:
$108,104.70 USD
Median:
$143,990.00 USD
Incentive Pay Plans:
This job may participate in an annual discretionary bonus plan.
Benefits Information
Regions offers a benefits package that is flexible, comprehensive and recognizes that "one size does not fit all" for benefits-eligible associates. Listed below is a synopsis of the benefits offered by Regions for informational purposes, which is not intended to be a complete summary of plan terms and conditions.
Paid Vacation/Sick Time
401K with Company Match
Medical, Dental and Vision Benefits
Disability Benefits
Health Savings Account
Flexible Spending Account
Life Insurance
Parental Leave
Employee Assistance Program
Associate Volunteer Program
Please note, benefits and plans may be changed, amended, or terminated with respect to all or any class of associate at any time. To learn more about Regions' benefits, please click or copy the link below to your browser.
*************************************************************
Location DetailsRiverchase Operations CenterLocation:Hoover, Alabama
Equal Opportunity Employer/including Disabled/Veterans
Job applications at Regions are accepted electronically through our career site for a minimum of five business days from the date of posting. Job postings for higher-volume positions may remain active for longer than the minimum period due to business need and may be closed at any time thereafter at the discretion of the company.