Application Security Architect
Security architect job in Saint Louis, MO
The Application Security Architect is responsible for designing, implementing, and maintaining the security of the company's applications, systems, and networks. The position requires expertise in security principles, methods, and technologies related to application development, deployment, and maintenance. The Application Security Architect is also responsible for conducting security assessments and audits, identifying vulnerabilities, and recommending solutions to mitigate risks.
Essential Duties and Responsibilities
Design and implement application security strategies, policies, and procedures that meet business and regulatory requirements.
Work with software development teams to integrate security into the development process and ensure that applications are built securely from the ground up.
Evaluate application code and conduct threat modeling to identify potential security risks and recommend solutions.
Conduct vulnerability assessments and penetration testing to identify security vulnerabilities and weaknesses in applications, systems, and networks.
Develop and maintain security metrics and key performance indicators (KPIs) to measure the security program's effectiveness.
Collaborate with internal and external stakeholders to communicate security risks, guide best practices, and facilitate compliance with relevant security standards and regulations.
Develop and maintain knowledge of emerging security threats, vulnerabilities, and technologies to proactively identify and mitigate security risks.
Conduct security awareness training and education for employees to promote a security culture across the organization.
Google Cloud Security Architect
Security architect job in Saint Louis, MO
Who You'll Work With As a modern technology company, our Slalom Technologists are disrupting the market and bringing to life the art of the possible for our clients. We have passion for building strategies, solutions, and creative products to help our clients solve their most complex and interesting business problems. We surround our technologists with interesting challenges, innovative minds, and emerging technologies
As a Consultant or Senior Consultant, you will collaborate with cross-functional teams, including IT, security, and business units, to design and implement Google Cloud-based application innovation solutions. You will work alongside experienced cloud architects, data scientists, and other specialists, ensuring the successful delivery of scalable, cloud-native applications and AI-powered solutions.
What You'll Do
* Stay current with security trends, technologies, and best practices around Google Cloud solutions, leveraging tools like Cloud IAM, Cloud Security Command Center, BeyondCorp, and Cloud Armor.
* Define and guide transformational security strategies for Google Cloud environments, ensuring alignment with Google's Zero Trust and BeyondCorp principles.
* Translate complex regulatory requirements (e.g., GDPR, SOC 2, HIPAA) and technology standards into actionable functional and technical requirements for cloud and hybrid environments, ensuring security and compliance.
* Lead teams through various phases of gap analyses, including security assessments, remediation planning, roadmap development, and implementation of remediation actions using Google Cloud-native tools.
* Deliver on the vision, architecture, execution, and quality assurance of security projects on Google Cloud, driving initiatives that secure enterprise workloads and data.
* Guide stakeholders and senior leaders on aligning security solutions with broader business goals, ensuring the architecture follows Google Cloud's security best practices and roadmap.
* Establish security architecture patterns based on Google Cloud security frameworks and industry standards to meet the unique needs of enterprise clients.
* Collaborate with other Google Cloud architects and security teams to continuously improve security knowledge assets and best practices, ensuring the most effective security solutions for clients.
* Design and architect solutions to secure Generative AI models and applications against adversarial attacks, prompt injection, and their potential misuse for malicious cyber activities.
What You'll Bring
* Proven experience with Google Cloud security architecture, with hands-on experience in tools like Cloud IAM, VPC Service Controls, Cloud DLP, and Cloud Armor.
* Strong background in defining and implementing Zero Trust and BeyondCorp security models within Google Cloud environments.
* Familiarity or direct experience with Identity and Access Management (IAM), Data Protection, Vulnerability Management, and Cloud Security solutions in Google Cloud.
* Extensive experience with security design patterns specific to Google Cloud, as well as hybrid and multi-cloud security architecture.
* Experience in security and risk advisory consulting, particularly related to cloud security transformations.
* Ability to lead the development and implementation of cloud security roadmaps aligned with business goals and compliance needs.
* Familiarity with Google Cloud's Artificial Intelligence (AI) capabilities (e.g., Vertex AI, Generative AI services, Model Armor) including their applications, associated security risks (e.g., prompt injection, data poisoning, privacy concerns), and proven strategies for implementing security controls, governance, and responsible AI practices.
* Relevant certifications are strongly desired, including (but not limited to):
* GCP Professional Security Engineer
* GCP Professional Cloud Architect
* CISSP
* Security+
About Us
Slalom is a fiercely human business and technology consulting company that leads with outcomes to bring more value, in all ways, always. From strategy through delivery, our agile teams across 52 offices in 12 countries collaborate with clients to bring powerful customer experiences, innovative ways of working, and new products and services to life. We are trusted by leaders across the Global 1000, many successful enterprise and mid-market companies, and 500+ public sector organizations to improve operations, drive growth, and create value. At Slalom, we believe that together, we can move faster, dream bigger, and build better tomorrows for all.
Compensation and Benefits
Slalom prides itself on helping team members thrive in their work and life. As a result, Slalom is proud to invest in benefits that include meaningful time off and paid holidays, parental leave, 401(k) with a match, a range of choices for highly subsidized health, dental, & vision coverage, adoption and fertility assistance, and short/long-term disability. We also offer yearly $350 reimbursement account for any well-being-related expenses, as well as discounted home, auto, and pet insurance.
Slalom is committed to fair and equitable compensation practices. For this position the base salary pay ranges are listed below. In addition, individuals may be eligible for an annual discretionary bonus. Actual compensation will depend upon an individual's skills, experience, qualifications, location, and other relevant factors. The salary pay range is subject to change and may be modified at any time.
East Bay, San Francisco, Silicon Valley:
* Consultant: $120,000-$177,000
* Senior Consultant: $140,000-$203,000
San Diego, Los Angeles, Orange County, Seattle, Houston, New Jersey, New York City, Westchester, Boston, Washington DC:
* Consultant: $110,000-$162,000
* Senior Consultant: $130,000-$186,000
All other locations:
* Consultant: $105,000-$148,000
* Senior Consultant: $115,000-$171,000
EEO and Accommodations
Slalom is an equal opportunity employer and is committed to inclusion, diversity, and equity in the workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veterans' status, or any other characteristic protected by federal, state, or local laws. Slalom will also consider qualified applications with criminal histories, consistent with legal requirements. Slalom welcomes and encourages applications from individuals with disabilities. Reasonable accommodations are available for candidates during all aspects of the selection process. Please advise the talent acquisition team if you require accommodations during the interview process.
We are accepting applications until 12/31.
Information System Security Manager (ISSM), Public Sector
Security architect job in Saint Louis, MO
Our Security team works on operational issues at the leading edge of machine learning technology. You will join a creative and solutions-oriented team collaborating with internal teams at Scale and externally with our customers. Scale is looking for an experienced security and compliance professional to support Assessment and Authorization and agency audit activities for Scale's products that are offered in the US Government and global Public Sector space. We are looking for relentlessly curious, deliberately open-minded, and action-oriented generalists who can design effective legal advice, internal policies, and operational processes while employing an empathetic interpersonal style. If you enjoy solving novel and challenging problems and building strong teams and relationships while doing it, we'd love to hear from you!
You will:
Lead public sector security compliance projects and audits (FedRAMP HIGH, DoD Cloud Computing SRG IL4/IL5/IL6 , NIST 800-53 rev 5, NIST 800-171/CMMC, Risk Management Framework)
Collaborate with product, engineering, security, operations, people operations, and legal to implement new technical, administrative, and operational controls
Work with 3PAOs and federal government AOs to achieve compliance certifications and reports
Ensure the implementation, oversight, monitoring, and maintenance of security configurations, practices, and procedures
Serve as a liaison between system owners and other security personnel, ensuring that selected security controls are effectively implemented and maintained throughout the lifecycle of projects
Act as a liaison between system owners and other security personnel to facilitate effective communication and collaboration
Develop, maintain, review, and update system security documentation on a continuous basis
Conduct required vulnerability scans and develop Plan of Action and Milestones (POAMs) in response to reported security vulnerabilities. Manage risks by coordinating correction or mitigation actions and tracking the completion of POAMs
Coordinate system owner concurrence for correction or mitigation actions and monitor security controls to maintain security Authorized To Operate (ATO)
Upload security control evidence to the Governance, Risk, and Compliance (GRC) application (eMASS or Xacta) to support security control implementation during the monitoring phase
Lead Risk Management Assessment and Authorization (A&A) processes for deployments
Perform Cloud system risk assessments, enhance process workflows, and develop new processes
Implement all applicable manual Security Technical Implementation Guides (STIGs), vendor hardening guides and ensuring timely installation of all available patches
Create and maintain ATO packages
Lead security compliance reviews for new products, changes, and features
Proactively evaluate and advise the business on new and evolving certification programs, requirements, and technologies
Develop and provide training to improve the security awareness and knowledge for all employees and contractors
Required:
Active US Top Secret security clearance with minimum IAT Level 2 certification (Security +, CASP, or similar)
Ideally you'd have:
Experience implementing and maintaining some of the following frameworks and standards: FedRAMP, DoD Cloud Computing SRG, NIST 800-171, NIST 800-53, CMMC, NIST 800-53.
STIG/RMF policy knowledge & implementation, including validating compliance via ACAS and other relevant tests.
Experience in project management and taking projects from conception to launch
An ability to translate between business and technical risk and communicate clearly to leadership
Excellent organizational and communications skills
Understanding of cybersecurity controls for cloud service providers
Knowledge of AWS and other government authorized cloud services
5+ years of security compliance or technology audit related experience
Nice-to-haves:
Bachelor's degree in accounting, information systems, computer science, or a related field
Compensation packages at Scale for eligible roles include base salary, equity, and benefits. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position, determined by work location and additional factors, including job-related skills, experience, interview performance, and relevant education or training. Scale employees in eligible roles are also granted equity based compensation, subject to Board of Director approval. Your recruiter can share more about the specific salary range for your preferred location during the hiring process, and confirm whether the hired role will be eligible for equity grant. You'll also receive benefits including, but not limited to: Comprehensive health, dental and vision coverage, retirement benefits, a learning and development stipend, and generous PTO. Additionally, this role may be eligible for additional benefits such as a commuter stipend.
The base salary range for this full-time position in the location of Washington DC is:$236,500-$295,900 USD
Compensation packages at Scale for eligible roles include base salary, equity, and benefits. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position, determined by work location and additional factors, including job-related skills, experience, interview performance, and relevant education or training. Scale employees in eligible roles are also granted equity based compensation, subject to Board of Director approval. Your recruiter can share more about the specific salary range for your preferred location during the hiring process, and confirm whether the hired role will be eligible for equity grant. You'll also receive benefits including, but not limited to: Comprehensive health, dental and vision coverage, retirement benefits, a learning and development stipend, and generous PTO. Additionally, this role may be eligible for additional benefits such as a commuter stipend.
The base salary range for this full-time position in the location of St. Louis is:$236,500-$295,900 USD
PLEASE NOTE:
Our policy requires a 90-day waiting period before reconsidering candidates for the same role. This allows us to ensure a fair and thorough evaluation of all applicants.
About Us:
At Scale, our mission is to develop reliable AI systems for the world's most important decisions. Our products provide the high-quality data and full-stack technologies that power the world's leading models, and help enterprises and governments build, deploy, and oversee AI applications that deliver real impact. We work closely with industry leaders like Meta, Cisco, DLA Piper, Mayo Clinic, Time Inc., the Government of Qatar, and U.S. government agencies including the Army and Air Force. We are expanding our team to accelerate the development of AI applications.
We believe that everyone should be able to bring their whole selves to work, which is why we are proud to be an inclusive and equal opportunity workplace. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability status, gender identity or Veteran status.
We are committed to working with and providing reasonable accommodations to applicants with physical and mental disabilities. If you need assistance and/or a reasonable accommodation in the application or recruiting process due to a disability, please contact us at accommodations@scale.com. Please see the United States Department of Labor's
Know Your Rights poster
for additional information.
We comply with the United States Department of Labor's
Pay Transparency provision
.
PLEASE NOTE: We collect, retain and use personal data for our professional business purposes, including notifying you of job opportunities that may be of interest and sharing with our affiliates. We limit the personal data we collect to that which we believe is appropriate and necessary to manage applicants' needs, provide our services, and comply with applicable laws. Any information we collect in connection with your application will be treated in accordance with our internal policies and programs designed to protect personal data. Please see our privacy policy for additional information.
Auto-ApplySecurity Engineer
Security architect job in Saint Louis, MO
Job DescriptionSecurity Engineer Position: Direct HireLocation: Bridgeton, MO. If not, local you must be willing to relocate.Salary: $95K - $140K (Depending on experience).Pay Frequency: Semi Monthly.Hours: M - F (8 to 5) Fully On-Site.Status: Must be a US citizen.Travel: N/A.Benefits: PTO, Holiday Pay, Healthcare coverage, Profit-Sharing, Tuition Reimbursement, Parental Leave and free onsite fitness & rec center. Experience Level: Mid to Senior.Summary: Our client is seeking a Security Engineer to join their team.Duties:
Design, implement, manage, maintain, improve, and troubleshoot company's various security systems, including but not limited to Data Loss Prevention (DLP), SIEM and UEBA, endpoint protection, and data security/auditing platforms.
Analyze and audit systems, software, processes, implementations, and environments for compliance with policies, regulations, and security best practices; and recommend and implement refinements and enhancements, in collaboration with individuals and teams.
Conduct threat, vulnerability, and risk assessments, at times in collaboration with external auditors, to understand and eliminate potential system and network vulnerabilities.
Develop and improve monitoring and visibility capabilities of information systems, and act as a technical leader for security incident detection, response, handling, and forensics.
Provide reporting on incidents, investigations, vulnerabilities, trends, conditions, and events.
Remain current on information security topics, trends, events, and developments.
May occasionally provide end-user security training.
Provide end-user support as necessary.
Provide exceptional customer service while acting ethically and maintaining business confidentiality.
Provide after-hours support as required and be able to identify critical issues that require urgent response.
Additional duties as assigned.
Skills Needed:
7+ years of experience in Information Technology required; inclusive of up to 4 years of relevant education, including 3+ years of experience in security.
Must have demonstrable experience with:
Microsoft/Office 365 Security landscape.
Azure and on-premises Active Directory.
PowerShell and Regular Expressions.
Software Development and/or Development Security Operations.
Performing and managing proactive risk identification and mitigation, including penetration testing, network vulnerability assessments, and system risk profiling.
Security incident detection, response, handling, and forensics.
Must understand networking concepts, protocols, and services.
Must have excellent verbal and written communication skills.
Must possess a very strong troubleshooting methodology to tackle issues efficiently.
Must be self-starting and self-sufficient to complete tasks in a timely and effective manner.
Senior Information Security Analyst (Job ID: 3705)
Security architect job in Scott Air Force Base, IL
Senior Information Security Analyst (Job ID: 3705) Location: Scott AFB, IL Senior Information Security Analyst is contingent upon contract funding Purpose: * Valkyrie Enterprises has need for a Senior Information Security Analyst who will provide network and I.T. design support at Scott Air-Force Base, IL
Job Description:
* Oversees overall network security. Ensures protection from viruses or other security threats, corrupt data and maintain system backups.
* Communicates hardware/software problems with outside support personnel, i.e.: vendors and technical support representatives.
* Develop and implement security protocols to protect network infrastructure and data integrity.
* Monitor network traffic for unusual activity and respond to potential threats in real-time.
* Conduct vulnerability assessments and penetration testing to identify weaknesses in systems.
* Collaborate with IT teams to design secure cloud infrastructure solutions.
* Maintain and manage security tools such as PRTG, Juniper, and other monitoring systems.
* Document security incidents and create reports for management review.
* Stays up to date with the latest cybersecurity trends, threats, and technology advancements.
* Assists in the development of disaster recovery plans and business continuity strategies.
Qualifications
* Must have a minimum of 10 years' experience in Cyber Security.
* Must have demonstrated experience as a Cybersecurity Engineer or in a similar role.
* Must have extensive knowledge of security protocols, cryptography, and security frameworks.
* Must have significant experience in managing network IDS/IPS systems, including FireEye NX and Cisco FIREPOWER appliances.
* Must possess advanced understanding of Microsoft OS & applications.
* Must have extensive experience with hardware/software troubleshooting and analysis.
* Must demonstrate initiative, the ability to manage multiple projects, meet deadlines, and determine priorities in a fast-paced environment.
* Must have excellent people skills; communication and familiarity with a customer support environment are crucial.
* Must have IAT Level II Certification
Desired Qualifications
* C&A, RMF Certifications are preferred.
Security Requirements
* TS/SCI security clearance
Travel Requirements:
* Occasional travel- less than 10%
* If position requires travel by domestic flight or access to secure federal facilities/military bases, candidate must be able to obtain (by start of position) and maintain appropriate identification credentials, such as REAL ID. (More information regarding REAL ID can be found: *************************** )
Physical Requirements:
* Remaining in a stationary position, often standing, or sitting for prolonged periods.
* Required to use hands to finger, handle, or feel; reach with hands and arms.
Valkyrie strictly adheres to a policy of equal employment opportunity. This policy is based on Valkyrie's commitment to hire and retain qualified employees consistent with position requirements; and to seek, employ, promote and treat all employees and applicants for employment without regard to race, color, religious creed, national origin, ancestry, citizenship status, pregnancy, childbirth, physical disability, mental disability, age, military status or protected veteran status, marital status, registered domestic partner or civil union status, gender (including sex stereotyping and gender identity or expression), medical condition, genetic information or sexual orientation or other protected characteristics.
Additionally, Valkyrie Enterprises provides a variety of benefits to eligible employees to support your best health, wellness, and future, to include medical/dental/vision options, company paid life and disability insurances, 401k with match, education reimbursement, as well as company paid holidays and paid time off (PTO).
Pay Range: $34 - $44 per hour
Product Security Engineer - Advanced Weapons Proprietary Programs
Security architect job in Saint Charles, MO
Company:
The Boeing Company
Boeing's Proprietary Programs in the Advanced Weapons portfolio are seeking motivated and talented
Mid-Level (Levels 3 or 4) Product Security Engineers
in St. Charles, Missouri! These positions will support the performance of product security and cybersecurity engineering for specialized Advanced Weapons Proprietary Programs which defend the United States homeland and its regional allies all over the world. Be a part of our passionate and highly motivated team who are excited to be on the forefront of defense of our nation.
Boeing offers a comprehensive benefits package including generous Paid Time Off (PTO), flexible work schedules, paid parental leave for mothers and fathers, 401k matching, tuition assistance for earning advanced degrees, and paid medical leave programs.
Come Join Us and Build the Future!
Primary Responsibilities:
Team members will work with other industry partners in the development and execution of a comprehensive assessment program supporting the specialized Advanced Weapons Proprietary Programs in the Space, Intelligence & Weapons Systems (SIWS) organization. These individuals will act as the primary product security engineers on the program for assessing, updating, and maintaining the security posture of the programs. This team will be supporting the program's systems by interacting continuously with the cyber team compliance team to remediate any vulnerabilities found during automated or manual cyber scans. A detailed oriented individual with a strong leadership skillset is a must for this position.
Assess organization-wide security and privacy risk and update assessment results on an ongoing basis.
Perform system analysis and develop system test for cyber threats, cyber test activities, and the cybersecurity of large-scale events.
Ensure product security engineering development lifecycle is followed, with an emphasis on clear requirements development/verification (using CAMEO).
Perform criticality analysis to include the ability to work with suppliers, identify critical components, and integrating them into the overall system
Perform cyber risk assessments and develop risk mitigation plans (i.e., POA&Ms, SCRM, etc.) using a variety of tools including but not limited to CAMEO.
Support and facilitate various ATO/IATT packages including processing IAVMs and CTOs for the same.
Perform software assurance tasks, including but not limited to software assurance risk reports.
Support proposal development efforts, including but not limited to: BOE generation, GR&A development, trade study analysis.
Support the engineering installation & analysis of patches and various system updates and upgrades to determine system consequence of these changes.
Attend, collect data from, out brief, and facilitate collaboration and project management from various program boards.
Applying Security Technical Implementation Guides (STIGs)
Managing and addressing any Cyber Tasking Orders (CTOs) related to the Cyber Tools.
Documentation and verification of all installation and configuration steps for the labs and operations deliveries.
Providing feedback to Cyber Leadership and engineers to improve the cybersecurity tools and processes.
Collaborating with local Information System Security Officers (ISSOs) to ensure compliance with relevant cybersecurity standards and regulations.
Support cyber threat intelligence activities.
Support the development and maintenance of cyber scanning, patching, remediation, tools and applications
Support, as required, TEMPEST, DFARS, COMSEC, CNSSI, and other compliance drivers as needed.
Perform and/or support the development of tools for cyber forensics
Develop, define efficiencies and improvements to tools to improve team productivity
Perform system analysis trade studies to define technical concepts and solutions
This position is expected to be 100% onsite. The selected candidate will be required to work onsite at one of the listed location options.
(St. Charles, MO.)
This position requires an
active
Secret U.S. Security Clearance. (A U.S. Security Clearance that has been active in the past 24 months is considered active.)
Basic Qualifications (Required Skills/Experience):
Bachelor or Master of Science degree from an accredited course of study, in Engineering, Computer Science, Mathematics, Physics, or Chemistry.
Active Secret clearance
Experience using analytical, collaboration, communication and organizational skills
5 years+ experience in product security / cybersecurity engineering
5 years+ experience with industry standard cybersecurity frameworks (NIST, OWASP, DFARS)
Preferred Qualifications (Desired Skills/Experience):
Current DoD 8570 certification at IAT Level II / IAM Level I or higher (e.g., Security+, GSEC, SCNP, SSCP, CISSP, CISA, GSE, SCNA)
Experience using CAMEO (proficiency preferred)
5 years+ experience in Windows/RHEL System admin experience, installing, tuning & troubleshooting Cyber Tools to include ESS/HBSS, ConfigOS, Splunk, etc.
5 years+ experience in configuring, running, and scripting audit tools
5 years+ experience using knowledge of Software Assurance (SwA) static and/or dynamic code analysis (e.g. Fortify)
Experience with Federal Information Security Management Act (FISMA)/RMF and National institute of Standards and Technology (NIST) 800-53 requirements
Experience leading system and component level cyber test and evaluation, including threat and security assessments, and tabletop exercises
Experienced self-starter with strong written and oral communication skills, and a focus on translating technically complex issues into simple, easy to understand concept
Growing understanding of DoD defense systems architectures and communications system concepts, mission, and common system test and data analysis techniques
Typical Education/Experience:
Mid-Level (3): Education/experience typically acquired through advanced technical education from an accredited course of study in engineering, engineering technology (includes manufacturing engineering technology), computer science, engineering data science, mathematics, physics or chemistry (e.g. Bachelor) and typically 5 or more years' related work experience or an equivalent combination of technical education and experience or non-US equivalent qualifications. In the USA, ABET accreditation is the preferred, although not required, accreditation standard.
Senior Level (4): Education/experience typically acquired through advanced technical education from an accredited course of study in engineering, engineering technology (includes manufacturing engineering technology), computer science, engineering data science, mathematics, physics or chemistry (e.g. Bachelor) and typically 9 or more years' related work experience or an equivalent combination of technical education and experience or non-US equivalent qualifications. In the USA, ABET accreditation is the preferred, although not required, accreditation standard.
Relocation:
This position offers basic relocation based on candidate eligibility.
Shift:
This position is for 1st shift.
Drug Free Workplace:
Boeing is a Drug Free Workplace where post offer applicants and employees are subject to testing for marijuana, cocaine, opioids, amphetamines, PCP, and alcohol when criteria is met as outlined in our policies.
At Boeing, we strive to deliver a Total Rewards package that will attract, engage and retain the top talent. Elements of the Total Rewards package include competitive base pay and variable compensation opportunities.
The Boeing Company also provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and a number of programs that provide for both paid and unpaid time away from work.
The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, and the applicability of collective bargaining agreements.
Please note that the salary information shown below is a general guideline only. Salaries are based upon candidate experience and qualifications, as well as market and business considerations.
Mid-Level (3) Summary pay range: $123,250 - $166,750
Mid-Level (4) Summary pay range: $153,000- $207,000
Referrals to this job are not eligible for a monetary employee bonus.
Language Requirements:
Not Applicable
Education:
Bachelor's Degree or Equivalent
Relocation:
This position offers relocation based on candidate eligibility.
Export Control Requirement:
This position must meet U.S. export control compliance requirements. To meet U.S. export control compliance requirements, a “U.S. Person” as defined by 22 C.F.R. §120.62 is required. “U.S. Person” includes U.S. Citizen, U.S. National, lawful permanent resident, refugee, or asylee.
Safety Sensitive:
This is not a Safety Sensitive Position.
Security Clearance:
This position requires an active U.S. Secret Security Clearance (U.S. Citizenship Required). (A U.S. Security Clearance that has been active in the past 24 months is considered active)
Visa Sponsorship:
Employer will not sponsor applicants for employment visa status.
Contingent Upon Award Program
This position is not contingent upon program award
Shift:
Shift 1 (United States of America)
Stay safe from recruitment fraud! The only way to apply for a position at Boeing is via our Careers website. Learn how to protect yourself from recruitment fraud - Recruitment Fraud Warning
Boeing is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national origin, gender, sexual orientation, gender identity, age, physical or mental disability, genetic factors, military/veteran status or other characteristics protected by law.
EEO is the law
Boeing EEO Policy
Request an Accommodation
Applicant Privacy
Boeing Participates in E - Verify
E-Verify (English)
E-Verify (Spanish)
Right to Work Statement
Right to Work (English)
Right to Work (Spanish)
Auto-ApplyProduct Security Engineering 2
Security architect job in Saint Charles, MO
JOB TITLE: Product Security Engineering 2 PAY RATE: $53-67/hour
We are a national aerospace and defense staffing agency seeking highly qualified candidates for a position with a top-tier client.
Job Details:
Job Type: Contract (12 months with potential for extension)
Clearance: Active Top Secret U.S. Security Clearance required (must be active within the last 24 months)
Industry: Aerospace / Defense / Aviation
Benefits: Medical, dental, and vision (Cigna)
Perks: Bonus potential + Priority access via Tier 1 supplier
Openings Nationwide: Thousands of opportunities across the U.S.
Qualifying Questions:
Are you a U.S. person as defined under ITAR regulations?
Do you meet the educational and experience requirements for this role?
Can you commute to the job location or relocate if necessary?
Summary:
Assess organization-wide security and privacy risks, updating assessment results on an ongoing basis.
Perform system analysis and develop system tests for cyber threats, cybersecurity evaluations, and large-scale event assessments.
Ensure adherence to the product security engineering development lifecycle, emphasizing clear requirements development and verification (using CAMEO).
Conduct criticality analyses, collaborate with suppliers, identify critical components, and integrate them into overall system designs.
Perform cyber risk assessments and develop mitigation plans (e.g., POA&Ms, SCRM) using tools including but not limited to CAMEO.
Support and facilitate ATO/IATT packages, including processing IAVMs and CTOs.
Perform software assurance tasks, including developing software assurance risk reports.
Support proposal development efforts (e.g., BOE generation, GR&A development, trade studies).
Assist with the engineering installation and analysis of patches, updates, and upgrades to assess system impact.
Attend and facilitate program boards, collect data, and manage project documentation and collaboration.
Apply Security Technical Implementation Guides (STIGs) and manage Cyber Tasking Orders (CTOs).
Document and verify all installation and configuration steps for labs and operational deliveries.
Provide feedback to Cyber Leadership and engineers to improve tools and processes.
Collaborate with Information System Security Officers (ISSOs) to ensure compliance with cybersecurity standards and regulations.
Support cyber threat intelligence, scanning, patching, remediation, and tool/application development.
Assist in compliance activities including TEMPEST, DFARS, COMSEC, and CNSSI.
Develop tools for cyber forensics and identify opportunities for efficiency and productivity improvements.
Perform system analysis trade studies to define technical concepts and solutions.
Requirements:
Active Top Secret U.S. Security Clearance required (must be active within the last 24 months)
Bachelor's degree (or equivalent technical education) in engineering, engineering technology, computer science, data science, mathematics, physics, or chemistry.
2 or more years of related experience, or an equivalent combination of education and experience.
Current DoD 8570 certification at IAT Level II / IAM Level I or higher (e.g., Security+, GSEC, SCNP, SSCP, CISSP, CISA, GSE, SCNA).
1+ years of experience in product security or cybersecurity engineering.
1+ years of experience with cybersecurity frameworks (NIST, OWASP, DFARS).
Strong analytical, collaboration, communication, and organizational skills.
ABET accreditation preferred but not required.
Must be a U.S. Citizen (as defined by ITAR).
Preferred Qualifications:
Proficiency with CAMEO.
2+ years of Windows/RHEL system administration experience, including tuning and troubleshooting cyber tools (ESS/HBSS, ConfigOS, Splunk, etc.).
2+ years of experience configuring and scripting audit tools.
Experience with Software Assurance (SwA) static and/or dynamic code analysis tools (e.g., Fortify).
Familiarity with FISMA/RMF and NIST 800-53 requirements.
Experience leading cyber test and evaluation at system or component level.
Strong written and verbal communication skills with the ability to simplify complex technical issues.
Understanding of DoD defense systems architectures, communications systems, and test/data analysis methods.
About Us:
The Structures Company is a premier national aerospace and defense staffing agency specializing in contract, contract-to-hire, and direct hire placements. We deliver expert workforce solutions across engineering, IT, production, maintenance, and support roles.
As trusted partners to major aerospace OEMs and Tier 1 suppliers, we connect professionals with opportunities to grow and excel in the aviation and aerospace industries.
Eligibility Requirements:
Must be a U.S. Citizen, lawful permanent resident, or protected individual under 8 U.S.C. 1324b(a)(3) to comply with ITAR regulations.
Keywords: aerospace, aviation, engineering, maintenance, aircraft design, defense
Take your career to new heights-apply today!
Engineers - #Hotjobs
Sr Security Engineer
Security architect job in Saint Louis, MO
The Cyber Security Audit Engineer will manage a variety of technical security auditing capabilities, including a holistic auditing approach of applications, databases, servers, networking devices, and software. Responsible for demonstrating skills in assessing IT process and technology risks, identifying and evaluating the design of IT controls, designing, executing and documenting IT audit tests, and making initial determination of reportable issues. Assist with HIPAA / HITECH assessments, and data breach preparedness. Will work in close coordination with team members and other business owner's partners to carry our customer requirements. Job Description: ROLES and RESPONSIBILITIES:
Design, build, implement and monitor a holistic audit program across the enterprise.
Develop understanding of appropriate business aspects, IT risks, IT control requirements, processes and systems under review.
Perform process and technology risk analysis with a cybersecurity mindset and focus, prepare process maps and flowcharts, prepare effective and efficient compliance and substantive technical approach; and execute in depth IT audit review.
Perform assessment of IT process and security controls within information systems environment.
Evaluate test results: accurately identify symptoms, root cause, problems, identify alternative controls and develop recommendations.
Perform audit reviews of technology such as applications, databases, servers, networking devices (i.e., firewalls and routers), and security tools such as IDS/IPS, anti-malware, and authentication systems (e.g., Active Directory).
Performing technology assessments in a wide variety of business environments, including:
Information Technology Operational and Cyber Security Assessments in accordance with industry frameworks, such as COBIT 5, ISO 27001, ISO 27005, and NIST SP 800-30 and Cybersecurity Framework
HIPAA Security Rule and HITECH Act Compliance
Cloud Security Compliance
Assisting clients with the performance of Business Impact Analyses (BIAs) along with the development of business continuity and disaster recovery plans (BCPs and DRPs);
Assisting organizations with all aspects of data breach and information security Incident Response preparation and management
Performing Service Organization Control Examinations in accordance with AICPA requirements (SOC 1 SSAE 16, SOC 2 AT 101, SOC 3 AT 101)
Providing data classification services
Developing information technology and security policies and procedures
Providing trusted advisory services and guidance to clients that will reduce organizational risk and improve their overall cyber security posture
Preparing reports and other deliverables that contain strategy, technical analysis, and findings in connection with our advisory and assessment engagements and communicating those results to client management
Excellent technical and interpersonal skills required.
Experience with Qualys / Nessus Vulnerability scanning tools.
Cloud Experience a plus
EXPERIENCE, QUALIFICATION AND EDUCATION
Minimum of 5 of experience with Enterprise Network, DMZ, and Security infrastructure, including design, implementation, and ongoing management and troubleshooting required.
Minimum of 5 years' experience in designing, developing, implementing, and managing solutions across cybersecurity domains (Cyber Defense, Threat and Vulnerability Management. Advanced Security Analytics, Data Security, Identity Management, Security Operations and Managed Security Services etc.)
Three years or more of professional experience or job-related experience in Information Security, or Information Technology
Extensive knowledge and skill of IT analysis which includes expertise in analyzing confidentiality, integrity, availability of complex IT systems.
Familiarity with Secure Software Development practices
Hands On experience with various programming languages or scripting languages and tools.
Effective oral and written communication skills.
Strong interpersonal skills and demonstrable leadership ability.
Certifications in one or more of the following: CISSP, CWSP, CCNP, ACE, CCNP Security, Security+, or related.
Familiarity with various operating system platforms (Linux, Windows) and databases security best practices for each.
Strong analytical and problem-solving ability.
Ability to work independently.
Senior AI Security Engineer
Security architect job in OFallon, MO
Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Senior AI Security EngineerJob Description Summary
As an Information Security Engineer specializing in AI Security, you will be at the forefront of protecting our AI systems and data. Your role will involve deep technical expertise in designing, implementing, and maintaining advanced security measures to safeguard our AI infrastructure from sophisticated threats and vulnerabilities. You will be instrumental in ensuring the robustness, confidentiality, and availability of our AI-driven solutions.
Key Responsibilities:
- Security Architecture Design: Architect and implement robust security frameworks for AI systems, including authoring of secure coding practices and secure design principles.
- Vulnerability Assessment: Identify, implement and manage tooling and methodologies for penetration testing on AI models and systems to identify and remediate security weaknesses.
- Secure AI Development: Collaborate with data scientists and software engineers to integrate security best practices into the AI development lifecycle, including secure model training, validation, and deployment. Support security engineers in the evaluation of AI systems being developed and implemented.
- Compliance and Standards: Keep track of emerging industry standards, regulations, and best practices for AI security, such as NIST, ISO, and GDPR.
- Research and Innovation: Stay abreast of the latest advancements in AI security, conduct research, and contribute to the development of innovative security solutions.
- Documentation and Reporting: Prepare and document standard operating procedures, protocols, and security reports, including assessment-based findings and recommendations for further system security enhancement.
- Advisory and Support: Provide guidance and support on security matters, including answering queries, providing feedback, and advising on best practices
- Technical Training and Mentorship: Provide technical training and mentorship to team members and stakeholders on AI security principles and practices.
- Experimentation and POCs: Design and execute experiments and proof of concepts (POCs) to validate emerging threats and security solutions. Conduct R&D to explore new methodologies and technologies for enhancing AI security.
Qualifications:
- Bachelor's or Master's degree in Computer Science, Information Security, or a related field.
- Extensive experience in information security, with a strong focus on AI security.
- In-depth knowledge of AI technologies, machine learning algorithms, and data protection techniques.
- Proven expertise in designing and implementing security measures for AI systems, including secure coding, encryption, and access controls.
- Strong analytical and problem-solving skills, with the ability to conduct vulnerability assessments and penetration testing.
- Excellent technical communication and collaboration skills to work effectively with diverse teams.
- Relevant certifications such as CISSP, CEH, OSCP, or equivalent are highly desirable.Mastercard is a merit-based, inclusive, equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law. We hire the most qualified candidate for the role. In the US or Canada, if you require accommodations or assistance to complete the online application process or during the recruitment process, please contact reasonable_accommodation@mastercard.com and identify the type of accommodation or assistance you are requesting. Do not include any medical or health information in this email. The Reasonable Accommodations team will respond to your email promptly.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
Abide by Mastercard's security policies and practices;
Ensure the confidentiality and integrity of the information being accessed;
Report any suspected information security violation or breach, and
Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
In line with Mastercard's total compensation philosophy and assuming that the job will be performed in the US, the successful candidate will be offered a competitive base salary and may be eligible for an annual bonus or commissions depending on the role. The base salary offered may vary depending on multiple factors, including but not limited to location, job-related knowledge, skills, and experience. Mastercard benefits for full time (and certain part time) employees generally include: insurance (including medical, prescription drug, dental, vision, disability, life insurance); flexible spending account and health savings account; paid leaves (including 16 weeks of new parent leave and up to 20 days of bereavement leave); 80 hours of Paid Sick and Safe Time, 25 days of vacation time and 5 personal days, pro-rated based on date of hire; 10 annual paid U.S. observed holidays; 401k with a best-in-class company match; deferred compensation for eligible roles; fitness reimbursement or on-site fitness facilities; eligibility for tuition reimbursement; and many more.
Pay Ranges
O'Fallon, Missouri: $115,000 - $184,000 USD
Auto-ApplyVulnerability & Security Engineer
Security architect job in Saint Louis, MO
We are looking for experienced Vulnerability Development / Security Engineers with a background in healthcare IT to join our security team. You will focus on identifying, assessing, and remediating vulnerabilities across applications and cloud environments.
Responsibilities:
Conduct SAST and DAST scans and manage vulnerability remediation.
Perform secure code reviews and implement best practices in Java and Python.
Conduct threat modeling for applications, APIs, and cloud environments.
Collaborate with development teams to ensure secure application delivery.
Stay updated on security trends and healthcare-specific compliance requirements.
Qualifications:
6-10 years of experience in application security or vulnerability management.
Hands-on with SAST/DAST tools, patching, and secure coding.
Strong knowledge of API and cloud security.
Healthcare IT experience preferred (HIPAA, HITRUST, or related frameworks).
Excellent analytical and communication skills.
Cloud Security Engineer
Security architect job in Saint Louis, MO
Compunnel Software Group is a New Jersey based premier information technology consulting & services company into this market for nearly two decades now; with close to two decades of experience in IT Industry which includes consulting, development, e-learning etc.
Our company is going through a tremendous growth spurt and we are now interested in personnel like you to augment the work force in the company. We have several projects starting that we are staffing for. If you think you would like to become a consultant for
Compunnel Software Group Inc
., please send me an updated copy of your resume along with a detailed summary of your work experience. I need a phone number to contact you. I look forward to possibly working with you on these positions.
We offer specialized services to our clients to meet their business objectives. Successful solutions that are valued by our clients are in industry areas such as pharmaceuticals, telecommunications, banking, finance, manufacturing, publishing and consumer products.
Job Description
Position: Cloud Security Engineer
Duration: 6+ months
Location: St. Louis, MO, 63167
Must Have:
Cloud Security
Security Patches
Cloud Security Automation Engineer
Client is seeking a Cloud Security Automation Engineer with deep technical experience in securing cloud technologies.
The successful candidate possesses out of the box thinking, the ability to collaboration with development team members, and experience with automation and solving end to end application/infrastructure security problems.
Our mission is to design and build a highly secure cloud environment without sacrificing our developers' ability to quickly innovate and deliver world class software solutions.
Responsibilities:
•
Define security best practices for our cloud platform and provide guidance to development teams.
• Build tools to monitor for compliance of security policy and automate the resolution process.
• Evangelize security throughout the enterprise and collaborate to help architect secure applications.
• Research emerging technologies and build proof of concepts to investigate better ways of meeting our control objectives.
• Collaborate with incident response, risk and compliance, product security and development teams to solve critical security problems.
• Develop an AppSec pipeline and integrate it into the agile software development process.
Required Qualifications:
•
BA/BS degree in Computer Science, Information Systems, Cyber Security or a related technical field or equivalent experience.
• At least 3 years of experience in Information Security and/or infrastructure
engineering.
• An accomplished security practitioner with a strong understanding of industry trends in all areas of security.
• Experience with building IaaS cloud based solutions including AWS, Azure, etc.. and knowledge of their network security and IAM models.
• Experience working with security vendors including evaluating and implementing new products.
Desired Qualifications:
•
Expertise in common AWS services (CloudFormation, Route53, VPC, EC2, Lambda, etc...) and their security best practices.
• Programming experience in JavaScript, Java, Scala, Python, Perl, Ruby, etc.. and their use in automating security and compliance.
• Strong understanding of security technologies including host and network based protection and detection technologies.
• Experience with vulnerability management (including: running vulnerability scans, creating reports, communicating with asset owners and giving remediation guidance).
• Experience with continuous integration and automation tools (e.g. Jenkins, Chef, Puppet, Ansible).
• Experience writing security white papers and/or presenting security products and technologies to diverse audiences.
• CISSP or CSSLP (Certified Secure Software Lifecycle Professional) certification.
Qualifications
Must Have:
Cloud Security
Security Patches
Additional Information
All your information will be kept confidential according to EEO guidelines.
Digital Risk Management - Security Engineer IV (Analyst)
Security architect job in Saint Louis, MO
This job posting is anticipated to remain open for 30 days, from 11-Dec-2025. The posting may close early due to the volume of applicants. Join a financial services firm where your contributions are valued. Edward Jones is a Fortune 500¹ company where people come first. With over 9 million clients and 20,000 financial advisors across the U.S. and Canada, we're proud to be privately-owned, placing the focus on our clients rather than shareholder returns.
Behind everything we do is our purpose: We partner for positive impact to improve the lives of our clients and colleagues, and together, better our communities and society. We are an innovative, flexible, and inclusive organization that attracts, develops, and inspires performance excellence and a sense of belonging.
People are at the center of our partnership. Edward Jones associates are seen, heard, respected, and supported. This is what we believe makes us the best place to start or build your career.
View our Purpose, Inclusion and Citizenship Report.
¹Fortune 500, published June 2024, data as of December 2023. Compensation provided for using, not obtaining, the rating.
Team Overview:
As a part of the Digital Risk Management team, you'll assist management by working with the various domains within the Digital, Data, and Information Security organizations to help perform various activities related to the governance, risk, and compliance efforts of the enterprise. You will be looked at as a relationship leader with these domains, helping them manage the risks and controls associated with their functions. You will consult, analyze, work on remediation, and help ensure that the groups have the technology-related risks and controls properly managed to meet the firm's risk appetite.
What You'll Do
* Conduct detailed risk analysis efforts to measure and report on the residual risk of the various Digital functions.
* Act as a consultant to the Digital functions during any audits of their environments, helping them manage any findings and remediation efforts.
* Act as a subject matter expert on cross-divisional risk assessments, helping properly represent the risks identified and being mitigated within the Digital organization.
* Perform other activities in the effort to help identify, measure, report on, and mitigate technology-related risks.
What Experience You Need
* Bachelor's degree or equivalent related work experience.
* 7+years Information Security, Internal Audit, or Financial Industry experience; or 7 years of Information Technology experience with a focus on security controls and processes.
* Working knowledge of industry control frameworks (e.g, COBIT, NIST, other applicable frameworks).
* Demonstrated success navigating complex, dynamic environments and ability to manage conflicting priorities.
* Ability to work in a team-based or matrix environment, mentoring and cross training other team members.
* Develops relationships; seen as trusted and trustworthy.
What could set you apart
* Experience working in equivalent roles within the financial services industry
* Undergraduate or graduate degrees related to technology and/or risk management
* CISA, CRISC, or other applicable and equivalent certifications
Current INTERNAL home-based associates: While this role is posted as hybrid, if selected and accepted, you may retain your home-based status. Edward Jones intends in good faith to continue offering the role as home-based, though future business or regulatory needs may require on-site work.
Candidates that live within in a commutable distance from our Tempe, AZ and St. Louis, MO home office locations are expected to work in the office three days per week, with preference for Tuesday through Thursday.
At Edward Jones, we are building a place where everyone feels like they belong. We're proud of our associates' contributions to the firm and the recognitions we have received.
Check out our U.S. awards and accolades: Insights & Information Blog Postings about Edward Jones
Check out our Canadian awards and accolades: Insights & Information Blog Postings about Edward Jones
Edward Jones does not discriminate on the basis of race, color, gender, religion, national origin, age, disability, sexual orientation, pregnancy, veteran status, genetic information or any other basis prohibited by applicable law.
Edward Jones' compensation and benefits package includes medical and prescription drug, dental, vision, voluntary benefits (such as accident, hospital indemnity, and critical illness), short- and long-term disability, basic life, and basic AD&D coverage. Short- and long-term disability, basic life, and basic AD&D coverage are provided at no cost to associates. Edward Jones offers a 401k retirement plan, and tax-advantaged accounts: health savings account, and flexible spending account. Edward Jones observes ten paid holidays and provides 15 days of vacation for new associates beginning on January 1 of each year, as well as sick time, personal days, and a paid day for volunteerism. Associates may be eligible for bonuses and profit sharing. All associates are eligible for the firm's Employee Assistance Program. For more information on the Benefits available to Edward Jones associates, please visit our benefits page.
Qualified applicants with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act. Edward Jones is prohibited from hiring individuals with certain specified criminal history as set forth in Section 3(a)(39) and 15(b)(4) and Rule 17a-3(a)(12) of the Securities and Exchange Act of 1934, and conducts background reviews consistent with FINRA Rule 3110(e). A copy of a notice regarding the provisions of the Los Angeles County Fair Chance Ordinance is available at: dcba.lacounty.gov/wp-content/uploads/2024/08/FCOE-Official-Notice-Eng-Final-8.30.2024.pdf.
Security Engineer (On-Site/St. Louis, MO)
Security architect job in Saint Louis, MO
Description What you will do:
Design, implement, manage, maintain, improve, and troubleshoot various security systems, including but not limited to Data Loss Prevention (DLP), SIEM and UEBA, endpoint protection, and data security/auditing platforms.
Analyze and audit systems, software, processes, implementations, and environments for compliance with policies, regulations, and security best practices; and recommend and implement refinements and enhancements, in collaboration with individuals and teams.
Conduct threat, vulnerability, and risk assessments, at times in collaboration with external auditors, to understand and eliminate potential system and network vulnerabilities.
Develop and improve monitoring and visibility capabilities of information systems, and act as a technical leader for security incident detection, response, handling, and forensics.
Provide reporting on incidents, investigations, vulnerabilities, trends, conditions, and events.
Remain current on information security topics, trends, events, and developments.
May occasionally provide end-user security training.
Provide end-user support as necessary.
Provide exceptional customer service while acting ethically and maintaining business confidentiality.
Provide afterhours support as required and be able to identify critical issues that require urgent response.
Qualifications Include:
7+ years of experience in Information Technology required; inclusive of up to 4 years of relevant education, including 3+ years of experience in security
Must have demonstrable experience with:
Microsoft/Office 365 Security landscape.
Azure and on-premise Active Directory.
PowerShell and Regular Expressions.
Software Development and/or Development Security Operations.
Performing and managing proactive risk identification and mitigation, including penetration testing, network vulnerability assessments, and system risk profiling.
Security incident detection, response, handling, and forensics
Must understand networking concepts, protocols, and services.
Must have experience with SIEM/UEBA and EDR tools/platforms.
Must have excellent verbal and written communication skills.
Must possess a very strong troubleshooting methodology to tackle issues efficiently.
Must be self-starting and self-sufficient to complete tasks in a timely and effective manner.
Additional Qualifications Include:
Experience with RESTful web API, JSON, XML, and HTTP.
Experience with Linux.
Experience with SQL and relational databases.
Experience with the Azure Cloud landscape.
Additional programming and/or scripting experience is a plus.
Relevant certifications are a plus.
Culture of:
Innovation & Continuous Improvement
Appreciation & Recognition
Advancement Opportunities
Pay for Performance
Some Benefits and Perks Include:
Industry Leading Healthcare
Industry Leading Profit-Sharing Plan w/ Safe Harbor Contribution
Generous Paid Time Away
Tuition Reimbursement Program
Parental Leave
Free Onsite Fitness & Recreation Center
Auto-ApplyINTL GCP Cloud Security Engineer
Security architect job in Edmundson, MO
Implement fine-grained access controls for PHI/PII Automate data classification, configure security monitoring Ensure compliance, test/validate security controls We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to ********************.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: ****************************************************
Skills and Requirements
Start by December 1
Onsite in Hyderabad 4 days/week
5+ years cloud security (2+ years data security)
Strong GCP security, BigQuery, DLP, KMS, SIEM, healthcare/HIPAA experience Security certifications (CISSP, CHC, GCP Security Engineer)
Zero Trust, DevSecOps, container security
Cybersecurity - Information System Security Officer (ISSO)
Security architect job in Hazelwood, MO
Company:
The Boeing Company
The Boeing Company is looking for a highly motivated Cybersecurity - Information System Security Officer (ISSO) to join our Classified Operations Cybersecurity team based in Hazelwood, MO. This position supports Boeing's Enterprise Wide Area Network (eWAN).
The selected candidate will rely on cyber security and Information Assurance (IA) background to support Enterprise activities and Boeing customers throughout multiple classified computing domains. The ISSO is responsible for maintaining and enforcing all Information System Security policies, standards, and directives to ensure assessment and authorization of information systems processing classified information.
Position Responsibilities:
Perform security analysis of operational and development environments, threats, vulnerabilities, and internal interfaces to define and assess compliance with accepted industry and government standards
Support and implement the Assessment and Authorization (A&A) processes under the Risk Management Framework (RMF) for new and existing information systems
Facilitate development of Memorandums of Understanding (MOU), Interconnection Security Agreements (ISA), Risk Acceptance Letters (RAL) and support Continuous Monitoring (CONMON)
Perform configuration management of assigned systems; auditing systems to ensure security posture integrity
Conduct risk assessments and investigations, execute appropriate risk mitigations, and participate in incident response activities
Conduct periodic hardware/software inventory assessments
Interface with the appropriate government customers, suppliers, and company personnel to implement protective mechanisms and to ensure understanding of and compliance with cybersecurity requirements
Basic Qualifications (Required Skills/Experience):
IAM Level 1 DoD 8140.01 (previously 8570.01) compliant certification (i.e. CAP, Security+ CE, CISSP, CASP, CISM, GSLC)
1+ years of experience in cybersecurity
1+ years of experience as an information system security officer (ISSO) or information system security manager (ISSM) supporting classified programs
Preferred Qualifications (Desired Skills/Experience):
3+ years of experience utilizing security relevant tools, systems, and applications in support of Risk Management Framework (RMF) to include NESSUS, ACAS, DISA STIGs, SCAP, Audit Reduction, and HBSS
3+ years of experience assessing and documenting test or analysis data to show cyber security compliance
Drug Free Workplace:
Boeing is a Drug Free Workplace where post offer applicants and employees are subject to testing for marijuana, cocaine, opioids, amphetamines, PCP, and alcohol when criteria is met as outlined in our policies
.
Pay & Benefits:
At Boeing, we strive to deliver a Total Rewards package that will attract, engage and retain the top talent. Elements of the Total Rewards package include competitive base pay and variable compensation opportunities.
The Boeing Company also provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and a number of programs that provide for both paid and unpaid time away from work.
The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, and the applicability of collective bargaining agreements.
Pay is based upon candidate experience and qualifications, as well as market and business considerations.
Summary pay range: $92,650 - $125,350
Language Requirements:
Not Applicable
Education:
Bachelor's Degree or Equivalent
Relocation:
Relocation assistance is not a negotiable benefit for this position.
Export Control Requirement:
This position must meet export control compliance requirements. To meet export control compliance requirements, a “U.S. Person” as defined by 22 C.F.R. §120.15 is required. “U.S. Person” includes U.S. Citizen, lawful permanent resident, refugee, or asylee.
Safety Sensitive:
This is not a Safety Sensitive Position.
Security Clearance:
This position requires an active U.S. Secret Security Clearance (U.S. Citizenship Required). (A U.S. Security Clearance that has been active in the past 24 months is considered active)
Visa Sponsorship:
Employer will not sponsor applicants for employment visa status.
Contingent Upon Award Program
This position is not contingent upon program award
Shift:
Shift 1 (United States of America)
Stay safe from recruitment fraud! The only way to apply for a position at Boeing is via our Careers website. Learn how to protect yourself from recruitment fraud - Recruitment Fraud Warning
Boeing is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national origin, gender, sexual orientation, gender identity, age, physical or mental disability, genetic factors, military/veteran status or other characteristics protected by law.
EEO is the law
Boeing EEO Policy
Request an Accommodation
Applicant Privacy
Boeing Participates in E - Verify
E-Verify (English)
E-Verify (Spanish)
Right to Work Statement
Right to Work (English)
Right to Work (Spanish)
Auto-ApplySecurity Engineer III
Security architect job in Saint Louis, MO
Under minimal supervision, the Data Security Engineer III is a front-line member of the Data Security team that has responsibility for protecting corporate information assets. The Data Security Engineer III will be responsible for configuring and improving DLP policies on multiple tools, working towards increasing DLP Program coverage, crafting and maintaining DLP Program process documentation, defining new processes and controls to further mature the DLP Program, and addressing gaps that impact the DLP process.
Essential Duties & Responsibilities
Deploys and manages technology and process solutions to reduce the potential of data compromise
Develops technical requirements, evaluating vendor solutions, and testing of data security solutions
Utilizes security tools to enhance data loss prevention capabilities across the Enterprise
Tune DLP policies on a continuous basis to maintain a mature set of policies within the scope of the DLP Program.
Implement security policies to comply with data privacy, governance and regulatory requirements
Performs data protection monitoring and reporting, analyzes security alerts and escalates security alerts to local support teams.
Proposes improvements and assists in the implementation of enterprise wide security policies, procedures and standards to meet compliance responsibilities.
Prepares status reports to develop security risk analysis scenarios.
Assist in documenting standard operating procedures and protocols for the Data Security Pillar
Assist in the development of technical solutions and processes to help mitigate security vulnerabilities and automate repeatable tasks.
Partner with teams as needed to enhance DLP monitoring / response processes on an ongoing basis.
Cloud Security Engineer
Security architect job in Saint Louis, MO
Compunnel Software Group is a New Jersey based premier information technology consulting & services company into this market for nearly two decades now; with close to two decades of experience in IT Industry which includes consulting, development, e-learning etc.
Our company is going through a tremendous growth spurt and we are now interested in personnel like you to augment the work force in the company. We have several projects starting that we are staffing for. If you think you would like to become a consultant for Compunnel Software Group Inc., please send me an updated copy of your resume along with a detailed summary of your work experience. I need a phone number to contact you. I look forward to possibly working with you on these positions.
We offer specialized services to our clients to meet their business objectives. Successful solutions that are valued by our clients are in industry areas such as pharmaceuticals, telecommunications, banking, finance, manufacturing, publishing and consumer products.
Job Description
Position: Cloud Security Engineer
Duration: 6+ months
Location: St. Louis, MO, 63167
Must Have:
Cloud Security
Security Patches
Cloud Security Automation Engineer
Client is seeking a Cloud Security Automation Engineer with deep technical experience in securing cloud technologies.
The successful candidate possesses out of the box thinking, the ability to collaboration with development team members, and experience with automation and solving end to end application/infrastructure security problems.
Our mission is to design and build a highly secure cloud environment without sacrificing our developers' ability to quickly innovate and deliver world class software solutions.
Responsibilities:
• Define security best practices for our cloud platform and provide guidance to development teams.
• Build tools to monitor for compliance of security policy and automate the resolution process.
• Evangelize security throughout the enterprise and collaborate to help architect secure applications.
• Research emerging technologies and build proof of concepts to investigate better ways of meeting our control objectives.
• Collaborate with incident response, risk and compliance, product security and development teams to solve critical security problems.
• Develop an AppSec pipeline and integrate it into the agile software development process.
Required Qualifications:
• BA/BS degree in Computer Science, Information Systems, Cyber Security or a related technical field or equivalent experience.
• At least 3 years of experience in Information Security and/or infrastructure
engineering.
• An accomplished security practitioner with a strong understanding of industry trends in all areas of security.
• Experience with building IaaS cloud based solutions including AWS, Azure, etc.. and knowledge of their network security and IAM models.
• Experience working with security vendors including evaluating and implementing new products.
Desired Qualifications:
• Expertise in common AWS services (CloudFormation, Route53, VPC, EC2, Lambda, etc...) and their security best practices.
• Programming experience in JavaScript, Java, Scala, Python, Perl, Ruby, etc.. and their use in automating security and compliance.
• Strong understanding of security technologies including host and network based protection and detection technologies.
• Experience with vulnerability management (including: running vulnerability scans, creating reports, communicating with asset owners and giving remediation guidance).
• Experience with continuous integration and automation tools (e.g. Jenkins, Chef, Puppet, Ansible).
• Experience writing security white papers and/or presenting security products and technologies to diverse audiences.
• CISSP or CSSLP (Certified Secure Software Lifecycle Professional) certification.
Qualifications
Must Have:
Cloud Security
Security Patches
Additional Information
All your information will be kept confidential according to EEO guidelines.
Vulnerability & Security Engineer
Security architect job in Saint Louis, MO
We are looking for experienced Vulnerability Development / Security Engineers with a background in healthcare IT to join our security team. You will focus on identifying, assessing, and remediating vulnerabilities across applications and cloud environments.
Responsibilities:
Conduct SAST and DAST scans and manage vulnerability remediation.
Perform secure code reviews and implement best practices in Java and Python.
Conduct threat modeling for applications, APIs, and cloud environments.
Collaborate with development teams to ensure secure application delivery.
Stay updated on security trends and healthcare-specific compliance requirements.
Qualifications:
6-10 years of experience in application security or vulnerability management.
Hands-on with SAST/DAST tools, patching, and secure coding.
Strong knowledge of API and cloud security.
Healthcare IT experience preferred (HIPAA, HITRUST, or related frameworks).
Excellent analytical and communication skills.
Principal Information Security Engineer (Security Product Owner)
Security architect job in OFallon, MO
Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Principal Information Security Engineer (Security Product Owner) Who is Mastercard?
Mastercard is a global technology company in the payments industry. Our mission is to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart, and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments, and businesses realize their greatest potential.
Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. With connections across more than 210 countries and territories, we are building a sustainable world that unlocks priceless possibilities for all.
Overview:
The Security Threat & Response Management (STRM) program within Mastercard's Corporate Security organization is looking for a Security Product Owner to lead execution of our preventative security control strategy. The ideal candidate is driven, proactive about security, analytical, and brings strong technical cyber security expertise. This role is central to shaping and executing the roadmap and strategy for our program's primary security tools and defenses. We are looking for a technically proficient and forward-thinking professional who proactively monitors evolving security trends, modern modern defenses, and leverages advanced knowledge of security tools to foster innovation and strengthen resilience throughout our environments.
Role
• Define and drive the roadmap for the ‘Defend' product, which covers preventative and detective security controls and configurations across dozens of security tools and platforms including SIEM, SOAR, DLP, Application Control, XDR, NGFW, UEBA, NDR, and more.
• As the Defend product owner, you will be the team lead ensuring the Defend product feature team's work is prioritized, aligned to strategy, and properly road mapped.
• Partner with stakeholders from engineering, endpoint, identity, and cloud teams to deploy and optimize security technologies and controls.
• Translate security requirements, risk policies, and threat models into actionable work items and initiatives.
• Lead capability assessments and recommend technologies aligned with business needs and program strategies.
• Configure, integrate, and optimize security tools (e.g., EDR/XDR, NGFW, IDS, DLP, Application Control) in accordance with strategic objectives and initiatives.
• Monitor control effectiveness and continuously tune policies to reduce friction and increase coverage.
• Ensure alignment with internal standards, regulatory frameworks, and industry best practices.
All About You
The ideal candidate for this position should:
• Be an advanced technical expert with hands-on experience across multiple SecOps teams and functions such as Security Operations Center, Security Engineering, Incident Response, Detection Engineering, Threat Hunting, and Insider Threat for a large, global enterprise.
• Understand modern agile methodologies and how to define, assign, and track work for product feature teams and partner engineering teams.
• Be skilled at translating complex security requirements into clear, actionable technical plans in accordance with relevant security strategies and objectives.
• Be confident in how to approach complex security tooling and dependencies such as configuring access controls, tuning detection policies, and integrating tools into detection models and lifecycles.
• Be a strong communicator, able to articulate vision and strategy to technical and non-technical stakeholders at all levels.
Additional capabilities that will set you apart:
• Experience with proactive security strategies and security technology products, platforms, and key technology.
• Expertise in successfully integrating and leveraging threat intelligence data into security controls and tools for proactive, targeted security prevention.
• Deep understanding of modern SecOps concepts and strategies such as ‘SOC 3.0', posture management domains, attack surface reduction, adaptive protections, automated triage and response, zero trust, cloud-native security, etc.
• Familiarity with regulatory compliance standards and frameworks (e.g., NIST, ISO, ATT&CK, D3FEND, PCI).
• Ability to collaborate effectively with SOC, IR, Engineering, and other key stakeholders.
• Passion for innovation and continuous improvement in security technology optimization.
Corporate Security Responsibility:
Every person working for, or on behalf of, Mastercard is responsible for information security. All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and therefore, it is expected that the successful candidate for this position must:
• Abide by Mastercard's security policies and practices;
• Ensure the confidentiality and integrity of the information being accessed;
• Report any suspected information security violation or breach;
• Complete all periodic mandatory security training in accordance with Mastercard's guidelines.Mastercard is a merit-based, inclusive, equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law. We hire the most qualified candidate for the role. In the US or Canada, if you require accommodations or assistance to complete the online application process or during the recruitment process, please contact reasonable_accommodation@mastercard.com and identify the type of accommodation or assistance you are requesting. Do not include any medical or health information in this email. The Reasonable Accommodations team will respond to your email promptly.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
Abide by Mastercard's security policies and practices;
Ensure the confidentiality and integrity of the information being accessed;
Report any suspected information security violation or breach, and
Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
In line with Mastercard's total compensation philosophy and assuming that the job will be performed in the US, the successful candidate will be offered a competitive base salary and may be eligible for an annual bonus or commissions depending on the role. The base salary offered may vary depending on multiple factors, including but not limited to location, job-related knowledge, skills, and experience. Mastercard benefits for full time (and certain part time) employees generally include: insurance (including medical, prescription drug, dental, vision, disability, life insurance); flexible spending account and health savings account; paid leaves (including 16 weeks of new parent leave and up to 20 days of bereavement leave); 80 hours of Paid Sick and Safe Time, 25 days of vacation time and 5 personal days, pro-rated based on date of hire; 10 annual paid U.S. observed holidays; 401k with a best-in-class company match; deferred compensation for eligible roles; fitness reimbursement or on-site fitness facilities; eligibility for tuition reimbursement; and many more.
Pay Ranges
O'Fallon, Missouri: $165,000 - $264,000 USD
Auto-ApplyPrincipal Information Security Engineer (Security Product Owner)
Security architect job in OFallon, MO
**Our Purpose** _Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential._
**Title and Summary**
Principal Information Security Engineer (Security Product Owner)
Who is Mastercard?
Mastercard is a global technology company in the payments industry. Our mission is to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart, and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments, and businesses realize their greatest potential.
Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. With connections across more than 210 countries and territories, we are building a sustainable world that unlocks priceless possibilities for all.
Overview:
The Security Threat & Response Management (STRM) program within Mastercard's Corporate Security organization is looking for a Security Product Owner to lead execution of our preventative security control strategy. The ideal candidate is driven, proactive about security, analytical, and brings strong technical cyber security expertise. This role is central to shaping and executing the roadmap and strategy for our program's primary security tools and defenses. We are looking for a technically proficient and forward-thinking professional who proactively monitors evolving security trends, modern modern defenses, and leverages advanced knowledge of security tools to foster innovation and strengthen resilience throughout our environments.
Role
- Define and drive the roadmap for the 'Defend' product, which covers preventative and detective security controls and configurations across dozens of security tools and platforms including SIEM, SOAR, DLP, Application Control, XDR, NGFW, UEBA, NDR, and more.
- As the Defend product owner, you will be the team lead ensuring the Defend product feature team's work is prioritized, aligned to strategy, and properly road mapped.
- Partner with stakeholders from engineering, endpoint, identity, and cloud teams to deploy and optimize security technologies and controls.
- Translate security requirements, risk policies, and threat models into actionable work items and initiatives.
- Lead capability assessments and recommend technologies aligned with business needs and program strategies.
- Configure, integrate, and optimize security tools (e.g., EDR/XDR, NGFW, IDS, DLP, Application Control) in accordance with strategic objectives and initiatives.
- Monitor control effectiveness and continuously tune policies to reduce friction and increase coverage.
- Ensure alignment with internal standards, regulatory frameworks, and industry best practices.
All About You
The ideal candidate for this position should:
- Be an advanced technical expert with hands-on experience across multiple SecOps teams and functions such as Security Operations Center, Security Engineering, Incident Response, Detection Engineering, Threat Hunting, and Insider Threat for a large, global enterprise.
- Understand modern agile methodologies and how to define, assign, and track work for product feature teams and partner engineering teams.
- Be skilled at translating complex security requirements into clear, actionable technical plans in accordance with relevant security strategies and objectives.
- Be confident in how to approach complex security tooling and dependencies such as configuring access controls, tuning detection policies, and integrating tools into detection models and lifecycles.
- Be a strong communicator, able to articulate vision and strategy to technical and non-technical stakeholders at all levels.
Additional capabilities that will set you apart:
- Experience with proactive security strategies and security technology products, platforms, and key technology.
- Expertise in successfully integrating and leveraging threat intelligence data into security controls and tools for proactive, targeted security prevention.
- Deep understanding of modern SecOps concepts and strategies such as 'SOC 3.0', posture management domains, attack surface reduction, adaptive protections, automated triage and response, zero trust, cloud-native security, etc.
- Familiarity with regulatory compliance standards and frameworks (e.g., NIST, ISO, ATT&CK, D3FEND, PCI).
- Ability to collaborate effectively with SOC, IR, Engineering, and other key stakeholders.
- Passion for innovation and continuous improvement in security technology optimization.
Corporate Security Responsibility:
Every person working for, or on behalf of, Mastercard is responsible for information security. All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and therefore, it is expected that the successful candidate for this position must:
- Abide by Mastercard's security policies and practices;
- Ensure the confidentiality and integrity of the information being accessed;
- Report any suspected information security violation or breach;
- Complete all periodic mandatory security training in accordance with Mastercard's guidelines.
Mastercard is a merit-based, inclusive, equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law. We hire the most qualified candidate for the role. In the US or Canada, if you require accommodations or assistance to complete the online application process or during the recruitment process, please contact reasonable_accommodation@mastercard.com and identify the type of accommodation or assistance you are requesting. Do not include any medical or health information in this email. The Reasonable Accommodations team will respond to your email promptly.
**Corporate Security Responsibility**
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
+ Abide by Mastercard's security policies and practices;
+ Ensure the confidentiality and integrity of the information being accessed;
+ Report any suspected information security violation or breach, and
+ Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
In line with Mastercard's total compensation philosophy and assuming that the job will be performed in the US, the successful candidate will be offered a competitive base salary and may be eligible for an annual bonus or commissions depending on the role. The base salary offered may vary depending on multiple factors, including but not limited to location, job-related knowledge, skills, and experience. Mastercard benefits for full time (and certain part time) employees generally include: insurance (including medical, prescription drug, dental, vision, disability, life insurance); flexible spending account and health savings account; paid leaves (including 16 weeks of new parent leave and up to 20 days of bereavement leave); 80 hours of Paid Sick and Safe Time, 25 days of vacation time and 5 personal days, pro-rated based on date of hire; 10 annual paid U.S. observed holidays; 401k with a best-in-class company match; deferred compensation for eligible roles; fitness reimbursement or on-site fitness facilities; eligibility for tuition reimbursement; and many more.
**Pay Ranges**
O'Fallon, Missouri: $165,000 - $264,000 USD