Post Job

SAP Security Consultant Full Time jobs

- 246 Jobs
  • Senior Manager, Information Security Office Consultant

    Capital One 4.7company rating

    McLean, VA

    At Capital One, you will help consult on initiatives, programs, and projects to raise their game in Information Security. You are pragmatic and practical in your understanding of risk and security, but also willing to know when to pull in experts and escalate. You collaborate and innovate with other teams within Capital One to push the envelope. You are comfortable with Cloud Service technologies like Storage Services, Security & Access Control Management, Container Services, and API Implementation and Management. You are familiar with various Cloud computing models to include IaaS, PaaS, and SaaS along with their architectural differences. Security is essential to what we do here, from protecting our customers to our associates. Responsibilities: Act as an Information Security point of contact supporting the Card line of business. Leverage strong technical acumen and be security SME reviewing architecture, providing risk mitigation solutions and driving overall risk management. Work closely with engineers, product managers, and other cross-functional partners to help break down complexity and organizational silos Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes Coordinate and execute proactive Information Security consulting to the business and technology teams covering Infrastructure Security, Resiliency, Data Security, Network Architecture and Design, and User Access Management Serve as an expert in Capital One's Information Security capabilities, solutions, policies, procedures and standards Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes Escalate and manage cyber security risk Provide ad hoc support on special Information Security hot topics for the business Provide regular updates to executive leadership with your line of business on the overall Information Security health and risk environment About You: You have a desire to work in a very fast moving, forward leaning, and modern computing environment You have a deep passion for Securing modern computing platforms You have a strong desire to continually learn about new technologies You possess strong conceptual thinking and communication skills You are able to work well under minimal supervision You are a demonstrated leader with team-oriented interpersonal skills and the ability to interface effectively with a broad range of people and roles, including upper management, IT leaders, and technology vendors You maintain calmness and clarity of thought under pressure and ability to maintain confidentiality You have a deep understanding of strategic business objectives and the ability to drive results toward those objectives Basic Qualifications: High School Diploma, GED or equivalent certification At least 6 years of experience working in cybersecurity or information technology At least 5 years of experience providing guidance and oversight of Security concepts At least 5 years of experience performing security risk assessments and security architecture reviews At least 5 years of experience with architecture, software design, networking, and cloud infrastructure At least 3 years of experience with cloud security engineering Preferred Qualifications: Bachelor's Degree 6+ years of experience with architecture, software design, networking, and cloud infrastructure 6+ years of experience with Application Security, Threat Modeling, Penetration Testing, or Vulnerability Management 6+ years of experience in securing a public cloud environment and building software utilizing public cloud 6+ years of experience with Cloud patch management practices such as system rehydration or image management 1+ years of experience in PCI, SOC2, or ISO27001 1+ years of experience utilizing Agile methodologies 1+ years of experience with integrating SaaS products into an Enterprise Environment 1+ years of experience with securing Container services 1+ years of experience with Splunk-Fu and Enterprise Monitoring 1+ years of experience with Offensive or Defensive Security techniques 1+ years of experience in a Financial services industry 1+ years of experience in a regulated environment AWS Certified Solutions Architect or Certified Information Systems Security Professional (CISSP) certification At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, or another type of work authorization). The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked. McLean, VA: $225,400 - $257,200 for Sr Manager, Cyber Technical New York, NY: $245,900 - $280,600 for Sr Manager, Cyber Technical Plano, TX: $204,900 - $233,800 for Sr Manager, Cyber Technical Richmond, VA: $204,900 - $233,800 for Sr Manager, Cyber Technical San Jose, CA: $245,900 - $280,600 for Sr Manager, Cyber Technical Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter. This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan. Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level. This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to sex (including pregnancy, childbirth or related medical conditions), race, color, age, national origin, religion, disability, genetic information, marital status, sexual orientation, gender identity, gender reassignment, citizenship, immigration status, protected veteran status, or any other basis prohibited under applicable federal, state or local law. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries. If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at ************** or via email at RecruitingAccommodation@capitalone.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations. For technical support or questions about Capital One's recruiting process, please send an email to ********************** Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site. Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).
    $84k-108k yearly est. 1d ago
  • Physical, Personnel, Special, SAP & Industrial Security Support

    Cherokee Federal 4.6company rating

    Arlington, VA

    Physical, Personnel, Special, SAP & Industrial Security Specialist requires an active TS/SCI security clearance*** Cherokee Preting is seeking Security Specialists with experience conducting physical, personnel, SAP and Industrial security functions to support USSOCOM. Compensation & Benefits: Pay commensurate with experience. Full time benefits include Medical, Dental, Vision, 401K and other possible benefits as provided. Benefits are subject to change with or without notice. Physical, Personnel, Special, SAP & Industrial Security Specialist Responsibilities Include: Assists, monitors, and advises on all aspects of security activities Plans and assists in implementation of security activities at the Top Secret and higher classification to ensure USSOCOM personnel (Military, Civilians, Contractors) and all supported tenant organizations are prepared to operate in non-traditional environments to perform critical contingency tasks. Develops written technical approaches and methodologies with regard to security proposals Processes personnel background investigations for special security clearance actions including: Formulating and ensuring compliance with automated information systems security procedures Suggesting, implementing, and monitoring compliance with special security policies and procedures Conducting and coordinating the training for special security representatives Performing as a liaison with Government and industrial security officials, overseeing collateral and higher access and badge procedures. Performs other job-related duties as assigned Physical, Personnel, Special, SAP & Industrial Security Specialist Experience, Education, Skills, Abilities requested: Active TS/SCI security clearance Minimum of six (6) years Physical, Personnel and Special Security experience within DoD or equivalent Government agencies required, with operational level experience preferred Experience in compartmented programs in DoD, U.S. Intelligence Community or supporting U.S. Contractors Experience in planning/accrediting facilities in accordance with the ICD 7051 standard. Working knowledge of security policies and procedures to include National Industrial Security Program Supplement, and DoD 5105.21 Volumes 1-3 Experience in security training or security inspections is highly desirable Thorough familiarity with all security processes Must possess a valid US passport Ability to successfully complete all medical examinations required by the client, including for any temporary duty or full-time deployment as required Must be able to pass all pre-deployment requirements as deemed necessary to be considered deployable Must pass pre-employment qualifications of Cherokee Federal Company Information: Cherokee Preting provides support, services, and solutions to federal and commercial customers. The company takes a personalized approach to solving our clients' toughest challenges, helping you make the most of your skills. Cherokee Preting is part of Cherokee Federal - a team of tribally owned federal contracting companies. For more information, visit cherokee-federal.com. #CherokeeFederal #LI-CK2 Special Security Technician Operational Security Coordinator SAP Security Officer Industrial Security Coordinator Personnel Security Administrator Special Security Operational Security Personnel Security Information Security Industrial Security Legal Disclaimer: Cherokee Federal is an equal opportunity employer. Please visit cherokee-federal.com/careers for information regarding our Affirmative Action and Equal Opportunity Employer Statement, Accommodation request, and Presidential EO 14042 Notice.
    $90k-111k yearly est. 60d+ ago
  • SAP Security Analyst

    Top Secret Clearance Jobs

    Arlington, VA

    Top Secret Clearance Jobs is dedicated to helping those with the most exclusive security clearance find their next career opportunity and get interviews within 48 hours. Job ID 2410542 Date Posted 2024-09-17 Category Security Subcategory Security Schedule Full-time Shift Day Job Travel Yes, 10 % of the Time Minimum Clearance Required TS/SCI Clearance Level Must Be Able to Obtain None Potential for Remote Work No Description SAIC is seeking a SAP Security Analyst to provide comprehensive security support services for the R&E Special Access Program Central Office (SAPCO) and various program management offices across OUSD(R&E). The role demands proficiency in program protection and security management of Department of Defense (DoD) Special Access Programs (SAPs). This position will deliver a wide array of products and services covering all security disciplines. This position will be fully onsite at the Pentagon in Arlington, VA. Responsibilities Include Personnel Security Manage SAP personnel security processes, including assessing eligibility for SAP access, preparing nomination packages, waivers, or letters of compelling need, maintaining SAP databases, and managing/reporting/tracking SAP access suitability information. Industrial Security Assess security compliance of contractors on SAP contracts, review contractor requests for facility accreditations, and determine security requirements for sensitive tests and activities. Physical Security Prepare and assess SAP facility accreditation packages, manage facility folders, develop facility Standard Operating Procedures (SOPs), Memorandums of Agreement/Co-Use Agreements (MOAs/CUAs), and facility close-out packages, and develop risk mitigation strategies for threats. Information Security Oversee classification management, manage Top Secret accountability and media control, author Security Classification Guides (SCGs) and security policies, handle technology transfers, foreign disclosures, security training, and investigate security incidents. Qualifications Extensive experience and proficiency in managing security protocols and protective measures specific to Department of Defense Special Access Programs. Bachelor's Degree & 5+ years of related experience; OR Master's Degree & 4+ years of experience Must possess an active Top Secret security clearance with eligibility for Sensitive Compartmented Information (SCI) access. Proven ability to effectively communicate with senior executives, including skills in preparing and presenting briefings and reports. Demonstrated skills with the ability to work and collaborate effectively in and contribute to a small team environment. Must possess a minimum of five (5) years of relevant SAP security experience with three (3) cumulative years managing multi-discipline security programs for DoD SAPs. Preferred Requirements Hold certifications such as Certified Information Systems Security Professional (CISSP) or Certified Protection Professional (CPP). Experience in strategic planning and execution within a security framework to support senior-level decision-making. SAIC accepts applications on an ongoing basis and there is no deadline. Covid Policy SAIC does not require COVID-19 vaccinations or boosters. Customer site vaccination requirements must be followed when work is performed at a customer site.
    $72k-100k yearly est. 50d ago
  • Senior SAP Security Analyst

    SAIC (Science Applications Int 4.4company rating

    Arlington, VA

    SAIC is seeking an experienced Senior SAP Security Analyst to provide comprehensive security support services for the Office of the Under Secretary of Defense for Research & Engineering (OUSD(R&E)) Special Access Program Central Office (SAPCO). The role requires expertise across all security disciplines, including personnel, industrial, physical, and information security, with a strong emphasis on managing multi-discipline security programs for Department of Defense (DoD) Special Access Programs (SAPs). This position is full-time, on-site at the Pentagon in Arlington, VA. Responsibilities Include: * Personnel Security: * Assess eligibility for SAP access. * Prepare and manage nomination packages, waivers, and Letters of Compelling Need (LOCNs). * Maintain and track SAP access suitability in databases and manage access reporting. * Industrial Security: * Ensure security compliance of contractors on SAP contracts. * Review and approve contractor facility accreditations. * Determine security requirements for sensitive tests and activities. * Physical Security: * Prepare and assess SAP facility accreditation packages. * Manage facility folders, create facility SOPs, MOAs/CUAs, and facility close-out packages. * Develop and implement risk mitigation strategies for security threats. * Information Security: * Oversee classification management, including Top Secret accountability and media control. * Write Security Classification Guides (SCGs) and other relevant security policies. * Handle technology transfers, foreign disclosures, and provide security training. * Investigate security incidents and provide appropriate solutions. * Additional Responsibilities: * Perform site inspections, accredit SCIF/SAPF spaces, and manage document control. * Conduct security training, indoctrinations, and debriefings. * Assist in preparing briefings for senior leadership and maintaining security-focused
    $82k-113k yearly est. 26d ago
  • Physical, Personnel, Special, SAP & Industrial Security Support

    Cherokee Nation Businesses 4.8company rating

    Arlington, VA

    Physical, Personnel, Special, SAP & Industrial Security Specialist requires an active TS/SCI security clearance* Cherokee Preting is seeking Security Specialists with experience conducting physical, personnel, SAP and Industrial security functions to support USSOCOM. Compensation & Benefits: Pay commensurate with experience. Full time benefits include Medical, Dental, Vision, 401K and other possible benefits as provided. Benefits are subject to change with or without notice. Physical, Personnel, Special, SAP & Industrial Security Specialist Responsibilities Include: * Assists, monitors, and advises on all aspects of security activities * Plans and assists in implementation of security activities at the Top Secret and higher classification to ensure USSOCOM personnel (Military, Civilians, Contractors) and all supported tenant organizations are prepared to operate in non-traditional environments to perform critical contingency tasks. * Develops written technical approaches and methodologies with regard to security proposals * Processes personnel background investigations for special security clearance actions including: * Formulating and ensuring compliance with automated information systems security procedures * Suggesting, implementing, and monitoring compliance with special security policies and procedures * Conducting and coordinating the training for special security representatives * Performing as a liaison with Government and industrial security officials, overseeing collateral and higher access and badge procedures. * Performs other job-related duties as assigned Physical, Personnel, Special, SAP & Industrial Security Specialist Experience, Education, Skills, Abilities requested: * Active TS/SCI security clearance * Minimum of six (6) years Physical, Personnel and Special Security experience within DoD or equivalent Government agencies required, with operational level experience preferred * Experience in compartmented programs in DoD, U.S. Intelligence Community or supporting U.S. Contractors * Experience in planning/accrediting facilities in accordance with the ICD 7051 standard. * Working knowledge of security policies and procedures to include National Industrial Security Program Supplement, and DoD 5105.21 Volumes 1-3 * Experience in security training or security inspections is highly desirable * Thorough familiarity with all security processes * Must possess a valid US passport * Ability to successfully complete all medical examinations required by the client, including for any temporary duty or full-time deployment as required * Must be able to pass all pre-deployment requirements as deemed necessary to be considered deployable * Must pass pre-employment qualifications of Cherokee Federal Company Information: Cherokee Preting provides support, services, and solutions to federal and commercial customers. The company takes a personalized approach to solving our clients' toughest challenges, helping you make the most of your skills. Cherokee Preting is part of Cherokee Federal - a team of tribally owned federal contracting companies. For more information, visit cherokee-federal.com. #CherokeeFederal #LI-CK2 Special Security Technician Operational Security Coordinator SAP Security Officer Industrial Security Coordinator Personnel Security Administrator Special Security Operational Security Personnel Security Information Security Industrial Security Legal Disclaimer: Cherokee Federal is an equal opportunity employer. Please visit cherokee-federal.com/careers for information regarding our Affirmative Action and Equal Opportunity Employer Statement, Accommodation request, and Presidential EO 14042 Notice.
    $72k-94k yearly est. 60d+ ago
  • Senior Security Analyst, Business Technology

    Okta 4.3company rating

    Washington, DC

    Get to know Okta Okta is The World's Identity Company. We free everyone to safely use any technology-anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transforms how people move through the digital world, putting Identity at the heart of business security and growth. At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every single box - we're looking for lifelong learners and people who can make us better with their unique experiences. Join our team! We're building a world where Identity belongs to you. Business Technology Team The Business Technology Team plays a vital role in Okta's mission to “Accelerate Okta's Scale and Growth.” As a key member of this team, you'll thrive in a dynamic environment where collaboration, accountability, and delivering business outcomes are at the forefront. We're looking for motivated individuals who are energized by solving complex challenges, shaping the future of technology, and making a tangible impact on Okta's success. Senior Security Analyst, Business Technology We seek a detail-oriented and motivated Senior Security Analyst, Business Technology focusing on security to join our Engineering Services team. This role is critical in bridging the gap between technical teams and business stakeholders, ensuring security remains a cornerstone of our SaaS, cloud, productivity, and endpoint applications. The Product Analyst will evaluate business needs, define technical and security requirements, and drive improvements in our security programs. The ideal candidate is passionate about technology, skilled in communication, and experienced in implementing security best practices. This role requires travel to our San Francisco, CA or Chicago, IL office for in-person onboarding during the first week of employment. If reasonable accommodation is needed to participate in the job application, interview process, or onboarding please use this Form to request an accommodation. What you'll be doing Evaluate business processes, anticipate requirements, and identify areas for improvement. Define technical, business, and security requirements for projects and systems. Translate complex technical requirements into functional specifications and user stories. Help teams maintain focus and alignment with project goals, ensuring adherence to agreed deliverables and minimizing deviations from scope. Educate teams on security practices and ensure adherence to security policies. Identify and track key metrics to measure the success of security programs. Help develop and maintain incident response playbooks and ensure alignment with organizational goals Develop runbooks, procedure manuals, and other documentation to support cross-training and operational readiness. What you'll bring to the role 3-5 years of experience in a product management or analyst role, ideally with a focus on security. Strong understanding of security fundamentals and frameworks (e.g., NIST, ISO 27001, CIS). Experience working with IT security tools such as Okta, EDR, DLP, and MDM, as well as SaaS platforms like Salesforce, Microsoft 365, and Google Workspace. Proficiency in tools like Jira and Confluence for managing requirements and project tracking. Ability to translate technical requirements into actionable business insights and functional documentation. Excellent communication skills, with the ability to convey complex security concepts to technical and non-technical stakeholders. Familiarity with scripting languages (Python preferred) and REST APIs is a plus. And extra credit if you have experience in any of the following! Educational Foundation: A bachelor's degree (or equivalent experience) is required; an advanced degree is a plus. #LI-CM1 #LI-Hybrid Below is the annual base salary range for candidates located in California, Colorado, New York and Washington. Your actual base salary will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: **************************** The annual base salary range for this position for candidates located in California (excluding San Francisco Bay Area), Colorado, New York, and Washington is between:$132,000—$198,000 USD What you can look forward to as a Full-Time Okta employee! Amazing Benefits Making Social Impact Fostering Diversity, Equity, Inclusion and Belonging at Okta Okta cultivates a dynamic work environment, providing the best tools, technology and benefits to empower our employees to work productively in a setting that best and uniquely suits their needs. Each organization is unique in the degree of flexibility and mobility in which they work so that all employees are enabled to be their most creative and successful versions of themselves, regardless of where they live. Find your place at Okta today! ************************************** Some roles may require travel to one of our office locations for in-person onboarding. Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws. If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation. Okta is committed to complying with applicable data privacy and security laws and regulations. For more information, please see our Privacy Policy at *************************************
    $132k-198k yearly 17h ago
  • Federal Post Sales Security Engineer, FS Poly, MD-based, $230k base + bonuses

    Capitol Sales Recruiting 3.7company rating

    Columbia, MD

    Role Description: Post-Sales Senior Security Engineer Territory: IC community Technology: Reseller Compensation: up to $230k base plus bonuses, full-time employee, not contract based Clearance Level: FS Poly Experience Level: 5+ years of experience working in either cybersecurity/IDM/network security
    $230k yearly 60d+ ago
  • Senior Security Analyst

    Mantech International Corporation 4.5company rating

    Washington, DC

    General information Requisition # R55647 Posting Date 10/17/2024 Security Clearance Required TS/SCI Remote Type Onsite Time Type Full time Description & Requirements Shape the future of defense with ManTech! Join a team dedicated to safeguarding our nation through advanced tech and innovative solutions. Since 1968, we've been a trusted partner to the Department of Defense, delivering cutting-edge projects that make a real impact. Dive into exciting opportunities in Cybersecurity, IT, Data Analytics and more. Propel your career forward and be part of something extraordinary. Your journey starts now-protect and innovate with ManTech! Become an integral part of a diverse team that leads the world in Mission, Cyber, and Technology Solutions. At ManTech International Corporation, you will help protect our national security while working on innovative projects that offer opportunities for advancement. Currently, ManTech is seeking a motivated, career and customer-oriented Senior Security Analyst - SSO Support- PERSEC Task to join our team in Washington, D.C. or Germantown, MD. Senior Security Analyst - SSO Support - PERSEC Task Required Experience: * Requires min 5 years of senior level multi-disciplined security experience providing technical support to Special Access Programs (SAP), Sensitive Compartmented Information (SCI), Collateral security oversight and management functions to support the DOE mission with expert knowledge and experience in supporting personnel security programs. * Effective performance requires ability to comprehensively support tasks. * Requires Security Specialist with in-depth and/or expert knowledge of SAP, SCI, and Collateral security requirements in areas of program planning and management, physical, personnel, information, communications ,and operations security. * Our senior security analysts implement Executive Order 13526, DOE O 472.2 ADMIN CHG 1, Personnel Security; DOE O 471.5, Special Access Programs, and SAP specific Program Security guidance that explain the processes, metrics, and QA approach to ensure current clearances; timely reinvestigations; and information is accurately updated and maintained in the centralized SAP Personnel Access database system. * Our analysts are multidisciplined with strong Personnel Security experience. * Must be capable of incorporating security policies and procedures based on a keen ability to interpret and apply the guidance of Executive Orders, Public Laws, Intelligence Community Directive (ICD) series, DOE Orders and Directives, National Industrial Security Program Operating Manual (NISPOM), and DoD Special Access Program Security Manuals 5205.07 Volumes 1-4. * Proficient in Microsoft Office (i.e., Word, PowerPoint, Excel, and Outlook) and database programs to track office reporting Functional Responsibility: * Support the Special Security Officer Support Tasks as part of a multi disciplined team responsible for information protection, customer relations and task project management. * As part of the SSO task, focus on SCI Personnel Security process requests. Analyzes data, applying protection criteria and making appropriate classification decisions about the information in question. * Makes decisions about how data and policies about classification should be applied. Interacts with both internal and external clients to satisfy their needs regarding information, personnel and program security issues. * Acts occasionally as the intermediary between internal staff offices and between government officer and contractors. * May develop educational material, which initiates, indoctrinates or refreshes the knowledge about government security policy. * Assist the government in developing and applying security measures to programs during all phases of a program's life cycle. May draft security documents that instruct program participants on how to implement official security policy. * May develop, produce and deliver audio/visual presentations to large audiences on topics related to program security. * Assist with the hands-on, consultation, analysis performance and execution of multi-disciplined SAP, SCI and Collateral security functions to effectively support the SAP Security Division's mission. * Specific tasks include process requests for Sensitive Compartment Information to include submission, clearance verification and uploading and tracking requests, verify security clearances and SCI eligibility, provide and pass SCI certification, receive, process, and upload all SCI personal reporting requirements into the designated security management database, receive, process, and upload personal reporting of all SCI pre and post foreign travel notifications and coordinate foreign travel reporting. Minimum Education: * High School diploma and 8 years in a related security function required. Security Clearance: * TS/SCI with eligibility for SAP; PR within 5 years or enrolled in CE, deferred. Drug test required and must have/be subject to a poly. Desired Experience/Clearance: * Bachelors of Arts or Sciences with 12-15 years of related security experience is preferred. * Security Fundamentals Professional Certification (SFPC) preferred. Travel: * Expected travel to geographically disbursed government sites (CONUS) 10% Certs: * None Physical Requirements: * Must be able to remain in a stationary position up to 75% of the time * Must be able to move about inside the office to access file cabinets, office machinery * Must be able to position self to maintain office supplies on variable height shelving. * The person in this position frequently communicates with co-workers, management and customers, which may involve delivering presentations. * Must be able to exchange accurate information in these situations * Must be able to observe and detect employee deviations from established policy The projected compensation range for this position is $117,500.00-$195,700.00. There are differentiating factors that can impact a final salary/hourly rate, including, but not limited to, Contract Wage Determination, relevant work experience, skills and competencies that align to the specified role, geographic location (For Remote Opportunities), education and certifications as well as Federal Government Contract Labor categories. In addition, ManTech invests in it's employees beyond just compensation. ManTech's benefits offerings include, dependent upon position, Health Insurance, Life Insurance, Paid Time Off, Holiday Pay, Short Term and Long Term Disability, Retirement and Savings, Learning and Development opportunities, wellness programs as well as other optional benefit elections. ManTech International Corporation, as well as its subsidiaries proactively fulfills its role as an equal opportunity employer. We do not discriminate against any employee or applicant for employment. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. If you are a qualified individual with a disability and require a reasonable accommodation to apply for a position with ManTech through its online applicant system, please email us at ******************* and provide your name and contact information.
    $117.5k-195.7k yearly 10d ago
  • Security Engineer

    Govcio

    Fairfax, VA

    GovCIO is currently hiring for a Security Engineer to support Customs and Border Patrol Enterprise Network Architecture and Engineering Support Services (CBP ENAESS). This position will be located in Ashburn, VA, and will be onsite with flexibility for remote work. **Responsibilities** The Security Engineer for CBP ENAESS will design, implement, and test security controls to meet DHS and CBP security requirements. They will collaborate with Information System Security Officers (ISSOs) and the Cyber Security Directorate (CSD) to engineer or re-engineer solutions to resolve Federal Information Security Management Act (FISMA) audit findings. They will provide security-related information to the ISSO and obtain ISSO approval on CRs to implement a new solution or service or make changes to an existing solution or service. To facilitate an ATT or ATO, they will provide input or help develop a System Security Plan (SSP) for a system/solution. They will ensure SSPs include security controls to address security requirements specified in the DHS 4300A, CBP HB1400D, and applicable NIST Special Publications. CBP **Qualifications** Bachelor's with 12+ years (or commensurate experience) Required: - Knowledge and experience with designing, implementing, configuring, operating, and testing capabilities for Zero Trust Architecture as outlined in OMB M-22-09. - Experience with ZTA and Zscaler suite of products (ZPA and ZIA to include CASB). - Experience analyzing application network traffic for attack detection to mitigate Layer 4 - 7 security attacks or threats against applications. - Experience with briefing to senior leadership on network security settings, network security policies, and attack mitigation procedures. - Experience with device Secure Sockets Layer (SSL) certificate management and renewal as well as operational support. - Experience with addressing security vulnerabilities, supporting security audits, and improving security processes and risk management recommendations. Preferred: - Certified Information Systems Security Professional (CISSP) certification with minimum of five (5) years of experience is preferred. - Successfully passed CBP Background Investigation (BI). **Company Overview** GovCIO is a team of transformers--people who are passionate about transforming government IT. Every day, we make a positive impact by delivering innovative IT services and solutions that improve how government agencies operate and serve our citizens. But we can't do it alone. We need great people to help us do great things - for our customers, our culture, and our ability to attract other great people. We are changing the face of government IT and building a workforce that fuels this mission. Are you ready to be a transformer? **We are an Equal Opportunity Employer.** All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, disability, or status as a protected veteran. EOE, including disability/vets. Posted Pay Range The posted pay range, if referenced, reflects the range expected for this position at the commencement of employment, however, base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, education, experience, and internal equity. The total compensation package for this position may also include other compensation elements, to be discussed during the hiring process. If hired, employee will be in an "at-will position" and the GovCIO reserves the right to modify base salary (as well as any other discretionary payment or compensation program) at any time, including for reasons related to individual performance, GovCIO or individual department/team performance, and market factors. **Posted Salary Range** USD $145,000.00 - USD $225,000.00 /Yr. Submit a referral to this job (********************************************************************************************************************** **Location** _US-VA-Fairfax_ **ID** _2024-4318_ **Category** _Cyber Security Services_ **Position Type** _Full-Time_
    $145k-225k yearly 60d+ ago
  • Senior Manager, Information Security Office Consultant

    Working at Capital One

    McLean, VA

    At Capital One, you will help consult on initiatives, programs, and projects to raise their game in Information Security. You are pragmatic and practical in your understanding of risk and security, but also willing to know when to pull in experts and escalate. You collaborate and innovate with other teams within Capital One to push the envelope. You are comfortable with Cloud Service technologies like Storage Services, Security & Access Control Management, Container Services, and API Implementation and Management. You are familiar with various Cloud computing models to include IaaS, PaaS, and SaaS along with their architectural differences. Security is essential to what we do here, from protecting our customers to our associates. Responsibilities: Act as an Information Security point of contact supporting the Card line of business. Leverage strong technical acumen and be security SME reviewing architecture, providing risk mitigation solutions and driving overall risk management. Work closely with engineers, product managers, and other cross-functional partners to help break down complexity and organizational silos Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes Coordinate and execute proactive Information Security consulting to the business and technology teams covering Infrastructure Security, Resiliency, Data Security, Network Architecture and Design, and User Access Management Serve as an expert in Capital One's Information Security capabilities, solutions, policies, procedures and standards Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes Escalate and manage cyber security risk Provide ad hoc support on special Information Security hot topics for the business Provide regular updates to executive leadership with your line of business on the overall Information Security health and risk environment About You: You have a desire to work in a very fast moving, forward leaning, and modern computing environment You have a deep passion for Securing modern computing platforms You have a strong desire to continually learn about new technologies You possess strong conceptual thinking and communication skills You are able to work well under minimal supervision You are a demonstrated leader with team-oriented interpersonal skills and the ability to interface effectively with a broad range of people and roles, including upper management, IT leaders, and technology vendors You maintain calmness and clarity of thought under pressure and ability to maintain confidentiality You have a deep understanding of strategic business objectives and the ability to drive results toward those objectives Basic Qualifications: High School Diploma, GED or equivalent certification At least 6 years of experience working in cybersecurity or information technology At least 5 years of experience providing guidance and oversight of Security concepts At least 5 years of experience performing security risk assessments and security architecture reviews At least 5 years of experience with architecture, software design, networking, and cloud infrastructure At least 3 years of experience with cloud security engineering Preferred Qualifications: Bachelor's Degree 6+ years of experience with architecture, software design, networking, and cloud infrastructure 6+ years of experience with Application Security, Threat Modeling, Penetration Testing, or Vulnerability Management 6+ years of experience in securing a public cloud environment and building software utilizing public cloud 6+ years of experience with Cloud patch management practices such as system rehydration or image management 1+ years of experience in PCI, SOC2, or ISO27001 1+ years of experience utilizing Agile methodologies 1+ years of experience with integrating SaaS products into an Enterprise Environment 1+ years of experience with securing Container services 1+ years of experience with Splunk-Fu and Enterprise Monitoring 1+ years of experience with Offensive or Defensive Security techniques 1+ years of experience in a Financial services industry 1+ years of experience in a regulated environment AWS Certified Solutions Architect or Certified Information Systems Security Professional (CISSP) certification At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, or another type of work authorization). The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked. McLean, VA: $225,400 - $257,200 for Sr Manager, Cyber Technical New York, NY: $245,900 - $280,600 for Sr Manager, Cyber Technical Plano, TX: $204,900 - $233,800 for Sr Manager, Cyber Technical Richmond, VA: $204,900 - $233,800 for Sr Manager, Cyber Technical San Jose, CA: $245,900 - $280,600 for Sr Manager, Cyber Technical Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter. This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan. Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level. This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to sex (including pregnancy, childbirth or related medical conditions), race, color, age, national origin, religion, disability, genetic information, marital status, sexual orientation, gender identity, gender reassignment, citizenship, immigration status, protected veteran status, or any other basis prohibited under applicable federal, state or local law. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries. If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at ************** or via email at RecruitingAccommodation@capitalone.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations. For technical support or questions about Capital One's recruiting process, please send an email to ********************** Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site. Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).
    $91k-126k yearly est. 34d ago
  • Security Engineer

    02 Caci-Federal

    College Park, MD

    Security EngineerJob Category: Information TechnologyTime Type: Full time Minimum Clearance Required to Start: TS/SCI with PolygraphEmployee Type: RegularPercentage of Travel Required: Up to 10%Type of Travel: Local* * * The Opportunity: CACI enhances the ability of federal government customers to preserve national security, deliver justice and serve the public with advanced technologies and quality analysis. We work closely with agencies and industry to overcome technical and cultural hurdles to innovation, empowering them with the latest end-to-end cloud infrastructure, big data and cyber capabilities. Our expertise in cross-domain and boundary solutions, network analytics, DevOps and low-to-high development is unique in our industry. We develop and deliver innovative products and applications that are deployed in highly sensitive customer environments and have broad applications for federal missions Responsibilities: We are looking for a proactive and experienced Technical Security Engineer to join our cybersecurity team. As a security engineer, you will play a critical role in designing, implementing, and maintaining security solutions that protect our organization's data, networks, and systems. You will collaborate with cross-functional teams to identify vulnerabilities, ensure compliance with security policies, and respond to incidents. The ideal candidate will have a strong background in system security, threat detection, and network defense, with hands-on experience in implementing security best practices. · Implement and manage security technologies including firewalls, intrusion detection/prevention systems (IDS/IPS), endpoint protection, and security information and event management (SIEM) tools. · Conduct vulnerability assessments, penetration testing, and regular security audits to identify risks and develop mitigation strategies. · Monitor and respond to security incidents and alerts, performing root cause analysis and incident handling. · Collaborate with development, IT, and operations teams to integrate security best practices across infrastructure and applications. · Assist in the creation and maintenance of security policies, standards, and procedures, ensuring compliance with industry standards (e.g., NIST, ISO 27001). · Manage identity and access management (IAM) solutions to enforce least privilege and role-based access controls (RBAC). · Implement and manage encryption solutions to secure sensitive data at rest and in transit. · Conduct threat modeling and risk assessments to improve the security posture of systems and applications. · Assist in the development of automated security workflows using scripting (Python, Bash, or similar). · Keep up with the latest cybersecurity trends, threat landscapes, and vulnerabilities to ensure proactive measures are taken. · Participate in incident response and disaster recovery planning, testing, and documentation. Qualifications: Required: 1. Three (3) years of experience in Infrastructure Engineering and a Bachelor's Degree from an accredited college or university in Computer Science or a related discipline, or a Master's Degree with one (1) year experience, or a Ph.D with zero (0) years experience. In lieu of a Bachelors' degree an additional four (4) years experience is required for a total of seven (7) years.1-2 years of experience in Python development, including hands-on coding projects 2. Proficiency in Linux operating system, network security, including firewalls, VPNs, IDS/IPS, and monitoring tools. 3. Hands-on experience with SIEM platforms such as Splunk, QRadar, or similar. 4. Knowledge of security frameworks and standards (e.g., NIST, CIS, ISO 27001) and their application. 5. Experience with vulnerability management tools (Nessus, OpenVAS, Qualys) and penetration testing tools (Kali Linux, Metasploit). 6. Understanding of encryption technologies, identity management, and access controls. 7. Familiarity with cloud security best practices for AWS, Azure, or GCP environments. 8. Strong scripting skills (e.g., Python, PowerShell, Bash) to automate security tasks. 9. Experience responding to security incidents and performing investigations. 10. DOD 8570 IAT 2 or higher cert. Desired: 1. Industry certifications such as CISSP, CISM, CEH, or OSCP. 2. Experience with DevSecOps practices and security in CI/CD pipelines. 3. Familiarity with Zero Trust architecture and implementation. 4. Experience in forensics and malware analysis. 5. Knowledge of container security (e.g., Docker, Kubernetes). 6. Exposure to security in a hybrid cloud/on-premises infrastructure. - ________________________________________________________________________________________ What You Can Expect: A culture of integrity. At CACI, we place character and innovation at the center of everything we do. As a valued team member, you'll be part of a high-performing group dedicated to our customer's missions and driven by a higher purpose - to ensure the safety of our nation. An environment of trust. CACI values the unique contributions that every employee brings to our company and our customers - every day. You'll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality. A focus on continuous growth. Together, we will advance our nation's most critical missions, build on our lengthy track record of business success, and find opportunities to break new ground - in your career and in our legacy. Your potential is limitless. So is ours. Learn more about CACI here. ________________________________________________________________________________________ Pay Range: There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits. Learn more here. The proposed salary range for this position is: $78,700 - $165,300 CACI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any other protected characteristic.
    $78.7k-165.3k yearly 60d+ ago
  • IA Security Engineer

    Telos Corporation 4.6company rating

    Herndon, VA

    The most security-conscious organizations trust Telos Corporation to protect their vital IT assets. The reputation of our company rests on the quality of our solutions and the integrity of our people. Explore what you can bring to our solutions in the areas of cyber, cloud and enterprise security. Be a part of the Telos culture and see what sets us apart! Telos offers an excellent compensation package with benefits that include generous paid time off, medical, dental, vision, tuition reimbursement, and 401k. Our employees enjoy more than just a great work environment! This position will be based at a customer site in Herndon, VA, with up to 10% of time reporting to Telos facilities in Ashburn, VA. Responsibilities: * Become an expert in Federal Regulations and guidelines such as NIST 800-37, 53, 60, 130, and CNSSi 1253 & 1254. * Become an expert in the implementation and deployment of Xacta 360 and Xacta IO. * Become familiar with existing processes and operations to continuously maintain support for the Xacta solution. * Become familiar with new capabilities and advocate for their usage and adoption where appropriate. * Provide consistent and effective feedback to team members, client stakeholders, and end users alike. * With some oversight and guidance, identify, troubleshoot, diagnose, and provide recommendations to remediate issues within the Xacta application set. * Provide new, or update existing operational solutions to complex problems as it pertains to Xacta systems administration. * Become familiar with business process engineering best practices while developing the customers implementation of the Risk Management Framework. * Apply domain knowledge and experience to identify and implement efficiencies in the administration of an Enterprise application. A Department of Defense (DOD) Top Secret or similar clearance based upon a full scope background investigation is typically acceptable for clearance reciprocity if the clearance is active and the background investigation is less than five (5) years old. A Full Scope Polygraph is required for this position. Job Requirements Qualifications: Must have some knowledge with system security support IAW ICD 503 / Risk management Framework (RMF). Candidates must also have the following experience and knowledge: * This position requires a current TS/SCI. * Bachelor's Degree in Cybersecurity, Computer Science, Mathematics, Information Technology or related field with 8-10+ years' experience * 5 additional years of general experience in IT, IA, Cybersecurity can be substituted for a degree * 8 years of general Information Technology, Application Administration, Systems Engineering is required. * Experience in system/application administration to include issue customer relationship management, Tier 1 & Tier 2 support activities. * Significant experience with documenting and communicating technical solutions that will be disseminated to a technical user base. * Demonstrate ability to communicate effectively with technical engineers, and end users alike is required. * DoD 8570/8410 compliance is preferred. * Experience in security operations/incident response concepts and implementation and vulnerability management. * Strong written and verbal communications skills and the ability to interact with people at all levels are required. * A professional attitude regarding attention to detail and customer service and excellent organizational skills are required The successful candidate must meet eligibility requirements to access sensitive information, which requires US citizenship. Telos maintains a drug-free workplace and will conduct drug testing on all applicants who have accepted an offer of employment Telos Corporation participates in the E-Verify program. Therefore, any employment with Telos will also be contingent upon confirmation from the Social Security Administration ("SSA") and/or the Department of Homeland Security ("DHS") of your authorization to work in the United States. Telos offers excellent compensation packages including salary commensurate with experience and benefits to meet your needs for today and the future. Telos Corporation and its subsidiaries are committed to equal opportunity for all, without regard to race, religion, color, national origin, citizenship, sex, sexual orientation, gender identity, age, veteran status, disability, genetic information, or any other protected characteristic. Telos Corporation will make reasonable accommodations for known physical or mental limitations of otherwise qualified employees and applicants with disabilities unless the accommodation would impose an undue hardship on the operation of our business. If you are interested in applying for an employment opportunity and feel you need a reasonable accommodation pursuant to the ADA, please contact us at **************. If you require relay service assistance, please click on the following link to review information on your state's relay service: ********************************** Telos Corporation is an EEO/AA employer. Job Type Full-Time Location Herndon, VA 20170 US (Primary) Telos offers an excellent compensation packages including salary commensurate with experience and benefits to meet your needs for today and the future. Telos and its subsidiaries are an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.
    $80k-107k yearly est. 37d ago
  • Security Engineer (U.S. Citizens/LPR Only)

    Task Force Talent 3.8company rating

    Tysons Corner, VA

    Task Force Talent is seeking a Security Engineer for a very well-funded early-stage company working on automated methods to build highly reliable, large-scale software systems. The key responsibilities in this role will be to implement and maintain security infrastructure, develop secure communication systems using mTLS, work with eBPF for system observability, manage PKI infrastructure, and help guide the company through SOC2 compliance. The founding team at this client is exceptional: they have started and sold two prior companies, the last one to a top tech giant, and they have built systems that others said could not be built. They have assembled a team (~40-50) of incredibly talented, very high-end scientists and engineers who like to solve "impossible" problems. Morale at this company is very high, and so are the hiring standards. This company is looking for top engineers who can work with a team and enjoy what they do. Target salary range is 120k to 250k+ plus equity, depending on experience level. (Note: At $170k base salary or above, generally candidates need at least 5+ years of experience and a very strong interview.) All positions are full-time, in-office near Tysons Corner, VA, in the Virginia tech corridor. There is a small future possibility of work in the UK. This company is completely focused on the private sector, no security clearance required. However, employment is open to U.S. citizens or Lawful Permanent Residents (Green Card) only at this time. We are unable to sponsor visas. If you apply but this company is not a fit, we will consider you for other available positions as well. Not your dream job, but perfect for a friend? You can submit a referral and get a check for $2000 or more: ***************************************** (Terms and conditions apply.) ____________________________________________________________________________________________________________________________________________ Qualifications U.S. Citizen or Lawful Permanent Resident At least 3, ideally 5+ years experience Strong background in computer science; this company is open to physicists/mathematicians but in our experience candidates typically need to have theoretical computer science foundations or significant coding experience to pass the technical interviews Strong programming skills in Rust Experience with mutual TLS (mTLS) implementation Knowledge of eBPF technology and its security applications Experience with Public Key Infrastructure (PKI) Understanding of SOC2 compliance requirements and implementation Strong background in system security and threat modeling Experience with secure coding practices and security testing Knowledge of network security protocols and best practices Experience with security monitoring and incident response Strong analytical and problem-solving skills Ability to communicate security concepts to technical and non-technical stakeholders Experience with security automation and tooling ____________________________________________________________________________________________________________________________________ Interview Process The process typically involves an initial phone screen, a technical coding interview (can be virtual), and several on-site interviews. Often part of the on-site interview is a technical presentation on a problem the candidate has solved or something the candidate has built, and the discussions will go from there. This company has genius-level engineers who like to get into the details! _____________________________________________________________________________________________________________________________________ About us: Task Force Talent is a specialized recruiting firm for science, engineering, and security careers. Our clients include seed to Series C startups working on AI, cybersecurity, quantum computing, and other novel technologies. We also work with small to medium-sized government contractors, and we help leading venture capital firms find talent for their portfolio companies. We have hundreds of jobs available and consider all applicants for all roles, now and in the future. Our goal is to find the best fit for you! If you don't see the perfect fit, simply use our general application at: ****************************************************************************************
    $170k yearly 60d+ ago
  • Security Engineer

    Thorlabs 4.7company rating

    Jessup, MD

    Thorlabs is pleased to play a role in advancing science through the components, instruments, and systems we design and manufacture. We believe that science and innovation have great potential to improve the world around us and are committed to advancing photonics (i.e., light-based) technologies that positively impact our customers, employees, and communities. Via educational outreach and more sustainable business practices, we continuously invest in a brighter future. We recognize that each of our employees is a unique individual with the ability to contribute to our success and seek to find great people who will thrive in our fun, fast-paced culture. The Security Engineer is responsible for implementing, maintaining, and supporting security solutions and controls and processes across various security domains. This position focuses on improving the reliability and operational efficiency of security solutions while supporting ongoing and future cybersecurity initiatives. This hands-on Security Engineer works closely with other IT and security teams to ensure security services, such as cloud, network, systems, middleware, and endpoint security, are effectively deployed and configured to address potential threats. Although the location of the position is in Jessup, MD, from time to time it may be required to undertake duties at other Thorlabs locations. Essential Job Functions include the following, but are not limited to: Assist in deploying and maintaining security solutions for IT infrastructure and applications. Support the development and implementation of automated security measures to identify and address vulnerabilities. Collaborate with IT Infrastructure and Security Operations teams to ensure security requirements are integrated into IT workflows and tools. Support vulnerability management processes, including assisting in the identification, prioritization, and remediation of security vulnerabilities. Monitor and analyze security systems to ensure optimal performance and compliance with company policies. Contribute to the integration of security processes into change management and infrastructure deployment workflows. Provide support for security assessments and testing activities to proactively identify and mitigate risks. Work closely with the Governance, Risk, and Compliance (GRC) team to support compliance activities and ensure adherence to regulatory frameworks. Partner closely with Security Operations Center (SOC) teams around detection, alert and Security Orchestration Automation and Response (SOAR). In addition to the essential functions and duties listed above, all positions are also responsible for: Meeting company standards pertaining to quantity and quality of work performed on an ongoing basis, performing all work related tasks in a manner that is in compliance with all Company policies and procedures. Adhering to Company policies, procedures, and directives regarding standards of workplace behavior in completing job duties and assignments. The Company retains the right to change or assign other duties to this position. Physical Activities: This is largely a sedentary role; however, it may require the ability to lift, bend or stand as necessary. The employee may occasionally lift or move objects up to 25 pounds. Requirements Experience: 5-7 years of experience in IT or cybersecurity roles. Hands-on experience with at least two of the following areas: Security information and event management (SIEM), Network Security Tools (Firewalls, IDS/IPS, NAC), Endpoint Detection and Response (EDR), Cloud security tools. Application Security Tools (Web Application Firewall, Pen Testing) Experienced in Linux and Windows operating systems, and enterprise network equipment. Bonus: experience with Microsoft Sentinel, and Microsoft Defender suite of products. Experience with compliance and regulatory requirements, including GDPR, HIPAA, CCPA, and regulatory frameworks (PCI, NIST, CIS, ISO). Education: Bachelor's degree in computer science, Engineering, related field, or equivalent work experience. Specialized Knowledge and Skills: Familiarity with cloud platforms like Microsoft Azure, Amazon Web Services (AWS), or Google Cloud Platform. Basic knowledge of security baselines, vulnerability management, and risk assessments. Proficiency in scripting languages such as PowerShell or Python. Understanding of cybersecurity fundamentals, including attack methods, risk mitigation strategies, and incident response. Certifications such as Security+, CCNA Security, or similar are preferred but not required. Strong communication and collaboration skills. Strong analytical and problem-solving skills, with the ability to anticipate and mitigate security risks effectively. Other: Compliance with International Traffic in Arms Regulations (ITAR). Job Type - Full Time $104,000 - 145,000 d.o.e. Thorlabs values its diverse environment and is proud to be an Equal Employment Opportunity/Affirmative Action Employer. All qualified individuals will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age or veteran status. Job descriptions are not intended as and do not create employment contracts. The organization maintains its status as an at-will employer. Employees can be terminated for any reason not prohibited by law. Benefits Thorlabs offers a complete benefits package that includes medical, dental and vision insurance, company paid life insurance, a generous PTO package, a 401(k) plan, and tuition reimbursement just to name a few..
    $104k-145k yearly 39d ago
  • Product Security Engineer, Electronic Warfare - Active Clearance

    Andurilindustries

    Reston, VA

    Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century's most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril's family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center. As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years. We're seeking a product security engineer to develop novel security tooling, discover vulnerabilities, and ultimately secure our suite of advanced technologies including artificial intelligence systems, command and control platforms, aerospace vehicles, and long range sensors. The ideal candidate has a background in electrical or software engineering, with a focus on platform security, or has pivoted to a product or application security role. They will be able to conduct complex security architecture reviews, research and mitigate exploits against hardware and software, and work with other engineering teams to build resiliency into our products. Responsibilities: Owns the development and maturation of security features for Anduril's Electronic Warfare (EW) products Collaborates and builds solutions with engineering teams to meet and exceed industry-standard security goals Simulates attacks against Anduril's products and integrated components to uncover potential weaknesses Collaborates with manufacturing and operations teams to develop secure handling and operational processes Engages with teams to remediate uncovered weakness in designs, implementations, integrations, and processes Requirements: Proficient with one or more programming languages (e.g. C/C++, Golang, Rust, Haskell) Interest in and willingness to immerse in Software Defined Radio (SDR) technology Experience assessing security of firmware, applications, network, IoT, or embedded systems Experience developing features for and improving security of firmware, applications, network, or embedded systems Experience building, testing, and delivering production-ready systems, especially for embedded and/or Linux systems Familiarity with anti-tamper and reverse engineering mechanisms Strong and professional communication skills (written and verbal) Must possess and be able to maintain a U.S. Secret Security clearance Preferred Qualifications: Excels at the above listed Requirements Familiarity with security architectures of EW, aerospace, or cyber-physical systems Expertise in the field of Software Defined Radio (SDR) Experience with signals analysis tools and techniques Familiarity with machine learning techniques for signal classification Experience with programmable logic devices and their development tools Regularly builds, tests, and delivers production-ready systems, especially for embedded and/or Linux systems Possesses and able to maintain a U.S. TS Security clearance US Salary Range$168,000—$252,000 USD The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. Highly competitive equity grants are included in the majority of full time offers; and are considered part of Anduril's total compensation package. Additionally, Anduril offers top-tier benefits for full-time employees, including: Platinum Healthcare Benefits: For U.S. roles, we offer comprehensive medical, dental, and vision plans at little to no cost to you. For UK roles, Private Medical Insurance (PMI): Anduril will cover the full cost of the insurance premium for an employee and dependents. For AUS roles, Private health plan through Bupa: Coverage is fully subsidized by Anduril. Basic Life/AD&D and long-term disability insurance 100% covered by Anduril, plus the option to purchase additional life insurance for you and your dependents. Extremely generous company holiday calendar including a holiday hiatus in December, and highly competitive PTO plans. 16 weeks of paid Caregiver & Wellness Leave to care for a family member, bond with your baby, or tend to your own medical condition. Family Planning & Parenting Support: Fertility (eg, IVF, preservation), adoption, and gestational carrier coverage with additional benefits and resources to provide support from planning to parenting. Mental Health Resources: We provide free mental health resources 24/7 including therapy, life coaching, and more. Additional work-life services, such as free legal and financial support, available to you as well. A professional development stipend is available to all Andurilians. Daily Meals and Provisions: For many of our offices this means breakfast, lunch and fully stocked micro-kitchens. Company-funded commuter benefits available based on your region. Relocation assistance (depending on role eligibility). 401(k) retirement savings plan - both a traditional and Roth 401(k). (US roles only) The recruiter assigned to this role can share more information about the specific compensation and benefit details associated with this role during the hiring process. Anduril is an equal-opportunity employer committed to creating a diverse and inclusive workplace. The Anduril team is made up of incredibly talented and unique individuals, who together are disrupting industry norms by creating new paths towards the future of defense technology. All qualified applicants will be treated with respect and receive equal consideration for employment without regard to race, color, creed, religion, sex, gender identity, sexual orientation, national origin, disability, uniform service, Veteran status, age, or any other protected characteristic per federal, state, or local law, including those with a criminal history, in a manner consistent with the requirements of applicable state and local laws, including the CA Fair Chance Initiative for Hiring Ordinance. We actively encourage members of recognized minorities, women, Veterans, and those with disabilities to apply, and we work to create a welcoming and supportive environment for all applicants throughout the interview process. If you are someone passionate about working on problems that have a real-world impact, we'd love to hear from you! To view Anduril's candidate data privacy policy, please visit **********************************************
    $81k-112k yearly est. 17h ago
  • Cloud Security Engineer - Principal

    Iomaxis 4.0company rating

    Arlington, VA

    Since 2006, MAXISIQ has advanced the state of Cyber RDT&E by bringing together industry expertise in software, hardware, communications and security, and leveraging decades of operational experience to deliver exceptional value to communities and the critical missions they support. Join us where we innovate, develop smarter solutions, technologies, services, and actionable capabilities for our clients- right when they need it most. Job Description MAXISIQ is seeking a Cloud Security Engineer (Principal) to support mission critical operations in Arlington, VA. This is a full-time position pending award, expected in March 2025. What You'll Be Doing: Assist in the design and management of the client's cloud systems, applications, network operations, policies, and strategy. Define technical direction and roadmap for cloud migrations. Manage the transition plan, including technical solutions, implementation, and adaption of the cloud process. Architect multi-network, multi-domain, and multi-cloud solutions to meet requirements. Maintain up-to-date and extensive knowledge of cloud products and technology. Advise the client on leading cloud practices and architectural approaches. Develop and modify scalable architecture to support applications and infrastructure on cloud service platforms. Identify and evaluate the best cloud solutions for the organization. Create a well-informed cloud strategy and manage the adaption process. Incorporate security management and privacy requirements into cloud hardware, software, and applications. Design controls and processes that utilize available audit tools. Support cross functional teams with implementing the Risk Management Framework (RMF) life cycle steps to achieve system authorization and operation. Provide support to cybersecurity assessment & authorization (A&A) processes to gain system authorization to operate (ATO). Engage with technical stakeholders and other third parties to interpret technical requirements, standards/policies, architectural artifacts, implementation, budget development, program briefs, and status tracking. Qualifications Education: Bachelor's degree in Computer Science, Information Technology, or related field DoD 8570 IAM/IAT Level II certification. (This will change to a DoD 8140 equivalent once a DISA 8140 policy is released.) Active and relevant industry Cloud Certification. Clearance: Secret clearance Experience: 10 years of relevant experience Experience migrating from legacy systems (databases) and deploying complex cloud-based solutions; including architecting, implementing, and optimizing core infrastructure, networking, and cloud-based services for organizations. Familiarity with enterprise architecture and application integration, IaaS/PaaS/SaaS solutions (AWS/Azure), data modeling, and Agile software development. Experience implementing DevOps, DevSecOps, and Agile standards and practices (highly desired). Strong communication skills and ability to translate complex technical topics for senior decision-makers. Prepare/deliver presentations to leadership. High proficiency with Microsoft Office suite, web-based applications, and databases. Additional Information All your information will be kept confidential according to EEO guidelines. #CJ We are an Equal Opportunity Employer that considers all qualified applicants for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status, or any other protected class.
    $92k-129k yearly est. 35d ago
  • Security Engineer (Infrastructure)

    Gtangible Corporation

    Arlington, VA

    gTANGIBLE Corporation (gTC), ****************** is a C corporation and a registered Government contractor that provides services and solutions in: National Security Programs Professional, Administrative, and Management Support Mission and Warfighter Support We are a Service-Disabled Veteran-Owned Small Business (SDVOSB) and the founder has years of successful experience in the Government contracting arena. Our leadership team is an exceptional group of Government contracting professionals. gTANGIBLE is in the process of identifying candidates for the following position. Requisition Type: Full Time Position Status: Contingent Position Title: Security Engineer (Infrastructure) Location: Arlington, VA Security Clearance: Secret Duties and Responsibilities The Security Engineer (Infrastructure) supports this Transportation Security Administration Information Technology (TSA IT) Task Order (TO) by conducting Infrastructure Security Testing to include Operating System (OS), database, Network Fabric assets and Wireless Communications. Duties include the following: Tests for continuous monitoring, continuous diagnostic & mitigation, Incidents of Compromise, and automated unendorsed scanning. Maintains and stays current with in-depth technical knowledge of operating system security testing tools in use by the Information Assurance & Cybersecurity Division (IAD), and testing techniques in general, to perform automated security testing, manual validation of automated results, and manual configuration validation of items not covered by automated testing, of operating systems on servers, workstations, appliances, and other similar assets. Assists with endpoint software, hardware, and operating system image security evaluations. Becomes familiar with TSA and DHS security policies and Technical Standards (TS) relating to the configuration and operation of operating system to facilitate effective security assessments. Makes recommendations for updates, additions, and modifications to TSA security policy as they are identified. Engages with stakeholders to gather all required information to create detailed test plans. Conducts security infrastructure testing using manual and automated tools. Reviews and validates findings during security testing engagements. Participates with stakeholders regarding findings meetings and responses. Provides Subject Matter Expertise on emerging web and mobile technologies, languages, and frameworks. Provides expertise and support on DHS Cyber Hygiene and external security audits conducted of the TSA. Knowledge and Qualifications At least ten (10) years of technical IT security experience. At least five (5) years of experience performing security assessments. At least three (3) years of experience performing security assessments of Windows and Linux operating systems, databases, network devices, and wireless components. At least one (1) year of experience performing security assessments for Federal IT systems. Ability to work independently/minimal oversight. Experience using automated tools: SuperScan, NMAP, Nessus, Tenable.sc, NIPPER, RedSeal, AppDetective, Aquafold Studio, Wireshark, Fluke Devices, NetStubler, Nikto. Strong understanding of NIST SP 800-53, NIST 800-97, and DISA STIGS. Required Certifications: CISSP, CEH or other relevant certifications. Experience with Cisco switches, routers, firewalls, VPN, ISE; Palo Alto firewalls; Juniper firewalls, VPN; F5 BIG-IP GTM, LTM, HEM; DELL switches, and McAfee WebGateway. Experience with Microsoft SQL, Oracle, MySQL, DB2, Informix, Splunk, Elasticsearch, as well as Cloud-based databases such as Amazon DynamoDB and Azure SQL. Experience with Windows Server and Windows Desktop platforms, Unix, Linux, AIX, Solaris, MacOS and iOS. Strong organizational, analytical, and technical writing skills to be able to document findings in reports. Experience with Wi-Fi, Bluetooth, Near Field Communication (NFC), RFI, Infrared and other non-wired technologies. Experience with identifying and mitigating common security vulnerabilities such as OWASP Mobile Top 10 and SANS Top 25. Experience with scripting languages such as but not limited to Python, BASH, or PowerShell. gTANGIBLE Corporation is an equal opportunity employer and does not discriminate against any employee or applicant because of race, age, sex, color, physical or mental disability, religion, sexual orientation, marital status, national origin, or political affiliation.
    $81k-113k yearly est. 60d+ ago
  • Cloud Security Engineer - Principal

    Maxisiq

    Arlington, VA

    Since 2006, MAXISIQ has advanced the state of Cyber RDT&E by bringing together industry expertise in software, hardware, communications and security, and leveraging decades of operational experience to deliver exceptional value to communities and the critical missions they support. Join us where we innovate, develop smarter solutions, technologies, services, and actionable capabilities for our clients- right when they need it most. Job Description MAXISIQ is seeking a Cloud Security Engineer (Principal) to support mission critical operations in Arlington, VA. This is a full-time position pending award, expected in March 2025. What You'll Be Doing: Assist in the design and management of the client's cloud systems, applications, network operations, policies, and strategy. Define technical direction and roadmap for cloud migrations. Manage the transition plan, including technical solutions, implementation, and adaption of the cloud process. Architect multi-network, multi-domain, and multi-cloud solutions to meet requirements. Maintain up-to-date and extensive knowledge of cloud products and technology. Advise the client on leading cloud practices and architectural approaches. Develop and modify scalable architecture to support applications and infrastructure on cloud service platforms. Identify and evaluate the best cloud solutions for the organization. Create a well-informed cloud strategy and manage the adaption process. Incorporate security management and privacy requirements into cloud hardware, software, and applications. Design controls and processes that utilize available audit tools. Support cross functional teams with implementing the Risk Management Framework (RMF) life cycle steps to achieve system authorization and operation. Provide support to cybersecurity assessment & authorization (A&A) processes to gain system authorization to operate (ATO). Engage with technical stakeholders and other third parties to interpret technical requirements, standards/policies, architectural artifacts, implementation, budget development, program briefs, and status tracking. Qualifications Education: Bachelor's degree in Computer Science, Information Technology, or related field DoD 8570 IAM/IAT Level II certification. (This will change to a DoD 8140 equivalent once a DISA 8140 policy is released.) Active and relevant industry Cloud Certification. Clearance: Secret clearance Experience: 10 years of relevant experience Experience migrating from legacy systems (databases) and deploying complex cloud-based solutions; including architecting, implementing, and optimizing core infrastructure, networking, and cloud-based services for organizations. Familiarity with enterprise architecture and application integration, IaaS/PaaS/SaaS solutions (AWS/Azure), data modeling, and Agile software development. Experience implementing DevOps, DevSecOps, and Agile standards and practices (highly desired). Strong communication skills and ability to translate complex technical topics for senior decision-makers. Prepare/deliver presentations to leadership. High proficiency with Microsoft Office suite, web-based applications, and databases. Additional Information All your information will be kept confidential according to EEO guidelines. #CJ We are an Equal Opportunity Employer that considers all qualified applicants for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status, or any other protected class.
    $81k-113k yearly est. 35d ago
  • Security Engineer

    Ryde Technologies

    Washington, DC

    Will be a member of the IT security team working in a large, primarily Linux-based environment. The focus will be in application security, but the position will provide opportunities to work in others areas of cybersecurity as well. Will work on a variety of complicated tasks and a wide degree of creativity and latitude is expected. Responsibilities will be primarily hands-on and technical in nature. Specific duties will include: Performing application security assessments using both automated tools and manual code review Assisting with administration, maintenance, and auditing of CI/CD implementation and build/deploy processes. Assist development teams with integrating security scanning into their everyday workflow Assisting development teams with validation of vulnerabilities and training in secure coding practices. Developing and maintaining scripts for automating routine tasks. Assisting with administration of Linux-based virtual infrastructure servers and various security services that run on them. Assisting with maintaining security documentation, and auditing for compliance. Position Requirements Software development experience and an interest in application security OR a security practitioner with knowledge of software engineering best practices. Competency reading and understanding two or more programming languages, such as: Java, Python, Groovy, PHP, JavaScript Competency working full-time in a Linux-based environment. The shell prompt should be your friend Knowledge of common application vulnerabilities A desire to focus and expand your knowledge in various aspects of cybersecurity Ability to write code to interface with REST APIs and automate routine tasks. Bonus skills Prior experience with static code analysis, dynamic application scanning and penetration testing. Systems administration or network administration experience. Experience with the Software Development Lifecycle, CI/CD, DevSecOps Continuous monitoring, vulnerability management and network security monitoring. Hold one or more security certifications Experience with the following: NIDS, HIDS, SIEM, vulnerability scanning tools, VPN, CM automation tools Experience with containers and orchestration tools. Researching and developing security policies, standards and procedures Education BS in computer science, related discipline, or equivalent work experience. EEO Compliance: Ryde Technologies is an Equal Employment Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other characteristic protected by law. Ryde Technologies will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law.
    $84k-117k yearly est. 60d+ ago
  • Lead Software Engineer - Security Engineering

    Mastercard 4.7company rating

    Arlington, VA

    Our Purpose Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential. Title and Summary Lead Software Engineer - Security Engineering At Services within Mastercard, we are building out the APT Platform, a next generation development platform blending industry-leading analytics, advanced software architecture, and the latest web technologies to help our customers make data-driven business decisions. With a growing need to keep our platform secure, our Security Engineering team seeking a Lead Software Engineer experienced in implementing security tools and technologies in the on-premise or cloud datacenter. As a Lead Engineer, you will bring engineering expertise and leadership to a growing team of highly motivated and innovating engineers. Enjoy large scale infrastructure challenges? Come solve them with us. What you will be doing: * Help set the technical vision of the team as we work towards designing and developing Security Engineering practices. * Design, develop, and deliver simple, (re)usable, service enabled, maintainable, and scalable security solutions that meet business requirements in adherence with respective standards, processes and best practices. * Proactively identify and prioritize cross-application synergy, system enhancements, and automation of manual processes. * Contribute to the overall strategy and manage complex issues within functional area of expertise. * Research and perform PoC's (Proof of Concept) on current and upcoming technologies and application appropriate frameworks to improve security and development practices. * Perform quality inspections and walkthroughs throughout the SDLC including requirements review, architecture review, design review, code review and security review to ensure compliance with respective standards * Leverage security experience and knowledge to develop the security culture and maintain effective working relationships with a variety of internal stakeholders, including business owners, end-users, customers, project managers, engineers, and senior management * Coach junior level employees on software development and security best practices * Work on a mix of legacy and greenfield projects to enable and support full-stack modernization. Who you are: * Experienced working with F5 BIG-IP ASM, HashiCorp Vault, SAST, DSAT and SCA tools, etc. * Expertise coding in languages like Python, C#, Java, or Go. * Able to lead projects with multiple teammates and provide thoughtful technical mentorship to help grow their careers. * Able to independently research, evaluate and decide on both short-term and long-range solutions. * Skilled at breaking down problems, organizing work, and delivering against technical requirements. * Able to communicate to peers and stakeholders with impact, eloquence, and authenticity. * Experience with Azure Cloud, Chef, and Jenkins CI/CD for infrastructure management, automation, and deployment pipelines. * Proficient in using Splunk for log management, monitoring, and security event analysis. Location Requirement: This is a hybrid position based in Mastercard's Arlington, Virginia Tech Hub. This role is not eligible for Mastercard's work authorization sponsorship. As such, candidates must be eligible to work in the United States, now as well as in the future, without employer sponsorship. #LI-TE1 Mastercard is a merit-based, inclusive, equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law. We hire the most qualified candidate for the role. In the US or Canada, if you require accommodations or assistance to complete the online application process or during the recruitment process, please contact reasonable_accommodation@mastercard.com and identify the type of accommodation or assistance you are requesting. Do not include any medical or health information in this email. The Reasonable Accommodations team will respond to your email promptly. Corporate Security Responsibility All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must: * Abide by Mastercard's security policies and practices; * Ensure the confidentiality and integrity of the information being accessed; * Report any suspected information security violation or breach, and * Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines. In line with Mastercard's total compensation philosophy and assuming that the job will be performed in the US, the successful candidate will be offered a competitive base salary based on location, experience and other qualifications for the role and may be eligible for an annual bonus or commissions depending on the role. Mastercard benefits for full time (and certain part time) employees generally include: insurance (including medical, prescription drug, dental, vision, disability, life insurance), flexible spending account and health savings account, paid leaves (including 16 weeks new parent leave, up to 20 paid days bereavement leave), 10 annual paid sick days, 10 or more annual paid vacation days based on level, 5 personal days, 10 annual paid U.S. observed holidays, 401k with a best-in-class company match, deferred compensation for eligible roles, fitness reimbursement or on-site fitness facilities, eligibility for tuition reimbursement, gender-inclusive benefits and many more. Pay Ranges Arlington, Virginia: $159,000 - $254,000 USD
    $75k-101k yearly est. 14d ago

Learn More About SAP Security Consultant Jobs