Security Engineer
Security architect job in Cary, NC
We are seeking a skilled Security Engineer with strong Networking and Compliance experience to join our team in Millennia. This position is required to reside in the vicinity of our Durham, NC Data Center. In this role, you will be crucial in maintaining the integrity and security of our network systems, ensuring privacy and security controls within processes, assets, and data flow within our healthcare-focused environment
Responsibilities:
· Maintain and manage all processes systems supporting Millennia's security posture.
· Monitor, manage, and implement security infrastructure to support organizational needs
· Monitor logs and alerts to identify incidents. Perform and or document Root Cause Analysis and remediation on Security Incidents.
· Monitor network performance and troubleshoot issues and Security Incidents.
· Plan, manage, and execute system upgrades and weekly patches to all endpoints.
· Develop and enforce security policies to protect sensitive patient data.
· Conduct regular system audits and vulnerability assessments.
· Provide technical support for network-related issues to staff and clients.
· Maintain documentation of network configurations and procedures.
· Stay updated on industry trends and emerging technologies
· Collaborate with IT teams to integrate new technologies into existing systems.
· Provide hand-on support to our offices and data center.
Qualifications:
· Strong knowledge of network and security administration, controls, protocols, and best practices.
· Experience with SOC2 or HITRUST, and HIPAA Security and Privacy Rule.
· Proven experience as a Network Administrator or similar role.
· Proficiency in configuring firewalls, routers, and switches, encryption protocols, and certificates.
· Familiarity with cybersecurity principles and incident response strategies.
· Excellent problem-solving skills and attention to detail.
· Exceptional communication skills and ability to work independently and collaboratively in a team-oriented environment.
· Experience with cloud computing platforms (AWS, Azure) is a plus.
Relevant certifications (e.g., CCNA, CompTIA Security+) are preferred
AI Security Architect
Security architect job in Morrisville, NC
General Information Req # WD00072996 Career area: Hardware Engineering Country/Region: United States of America State: North Carolina City: Morrisville Working time: Full-time Additional Locations: * United States of America - North Carolina - Morrisville Why Work at Lenovo
We are Lenovo. We do what we say. We own what we do. We WOW our customers.
Lenovo is a US$57 billion revenue global technology powerhouse, ranked #248 in the Fortune Global 500, and serving millions of customers every day in 180 markets. Focused on a bold vision to deliver Smarter Technology for All, Lenovo has built on its success as the world's largest PC company with a full-stack portfolio of AI-enabled, AI-ready, and AI-optimized devices (PCs, workstations, smartphones, tablets), infrastructure (server, storage, edge, high performance computing and software defined infrastructure), software, solutions, and services. Lenovo's continued investment in world-changing innovation is building a more equitable, trustworthy, and smarter future for everyone, everywhere. Lenovo is listed on the Hong Kong stock exchange under Lenovo Group Limited (HKSE: 992) (ADR: LNVGY).
This transformation together with Lenovo's world-changing innovation is building a more inclusive, trustworthy, and smarter future for everyone, everywhere. To find out more visit *************** and read about the latest news via our StoryHub.
Description and Requirements
Why Work at Lenovo
Here at Lenovo, we believe in smarter technology for all and we are the best. We're not just a Fortune Global 500 company, we're one of Fortune's Most Admired. We're in 180 markets, working with 63,000 brilliant colleagues and counting. And we're known for the world's most complete portfolio of smart technology, from devices to software to infrastructure. With our ingenuity, we help millions-not just the select few-experience our version of a smarter future. The one thing that's missing? Well…you… We are focused on a bold vision to deliver smarter technology for all, we are developing world-changing technologies that create a more inclusive, trustworthy, and sustainable digital society. By designing, engineering, and building the world's most complete portfolio of smart devices and infrastructure, we are also leading an Intelligent Transformation - to create better experiences and opportunities for millions of customers around the world. Join us in defining our world of tomorrow and creating smarter technology for all!
Who You'll Work With:
At Lenovo, we manufacture one of the world's widest portfolios of connected products, including PCs (ThinkPad, Yoga, Lenovo Legion), tablets, smartphones and workstations as well as augmented and virtual reality (Mirage, ThinkReality) and smart home/office solutions, AI, and software and services. Lenovo's data center solutions (ThinkSystem, ThinkAgile) are creating the capacity and computing power for the connections that are changing business and society.
What You'll Do:
This position is for an AI Security Architect in the Security Center of Excellence for PC and Smart Device business (PCSD). This is an exciting role that will give you the opportunity to work with Product teams around the globe to lead the AI product security review program for PCSD's hardware, software, and services products. You will join a team of proven security-focused architects and developers to support Lenovo Products sold in every region of the world.
In Summary you will:
* Drive AI product security strategy for client devices
* Set and document security standards
* Review product designs
* Review product implementations
* Assess and manage security risk
* Foster a culture of security for AI
* Stay up to date on the latest testing techniques and tools to ensure both yourself and the teams are using the most effective methods
Position Requirements
Basic Qualifications:
* Bachelors degree in cybersecurity, computer science, computer engineering, or related fields
* 10+ years of cybersecurity review experience
* 5+ years of experience with AI/ML technologies and implementing related security controls
* Experience with AI model training, inferencing, RAG, prompt engineering, and AI guardrails
* Experience threat modeling both non-generative and generative AI solutions
* Strong written and verbal communications and interpersonal skills
* Ability to work independently under tight deadlines, responding to changing business and technical conditions with minimal direction
Preferred Qualifications:
* Masters degree in cybersecurity, computer science, computer engineering, or related fields
* Deep experience with Windows application development
* Experience with Windows device driver development
* Working knowledge of Python, Java, JavaScript, C/C++, C#, Kotlin, Swift, etc.
* Experience working in a world-wide team
We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, religion, sexual orientation, gender identity, national origin, status as a veteran, and basis of disability or any federal, state, or local protected class.
Additional Locations:
* United States of America - North Carolina - Morrisville
* United States of America
* United States of America - North Carolina
* United States of America - North Carolina - Morrisville
Enterprise Security Architect
Security architect job in Durham, NC
Who We Are At Corebridge Financial, we believe action is everything. That's why every day we partner with financial professionals and institutions to make it possible for more people to take action in their financial lives, for today and tomorrow. We align to a set of Values that are the core pillars that define our culture and help bring our brand purpose to life:
* We are stronger as one: We collaborate across the enterprise, scale what works and act decisively for our customers and partners.
* We deliver on commitments: We are accountable, empower each other and go above and beyond for our stakeholders.
* We learn, improve and innovate: We get better each day by challenging the status quo and equipping ourselves for the future.
* We are inclusive: We embrace different perspectives, enabling our colleagues to make an impact and bring their whole selves to work.
Who You'll Work With
The Information Technology organization is the technological foundation of our business and works in collaboration with our partners from across the company. The team drives technology and digital transformation, partners with business leaders to design and execute new strategies through IT and operations services and ensures the necessary IT risk management and security measures are in place and aligned with enterprise architecture standards and principles.
About The Role
The Enterprise Security Architect will help to lead the design, implementation, and oversight of secure systems and architectures across our organization. This role is critical to embedding security into enterprise processes, aligning with industry standards, and building a scalable security foundation. The ideal candidate will bring deep technical expertise, strong communication skills, and the ability to work independently or collaboratively to drive security initiatives and foster a security-first culture.
Responsibilities
* Design, document, and maintain secure architecture patterns, diagrams, and reference architectures to guide security implementations across the organization.
* Conduct comprehensive security reviews of applications, systems, and networks, identifying vulnerabilities and recommending secure design strategies.
* Perform threat modeling and risk assessments to identify potential vulnerabilities and recommend appropriate mitigating controls.
* Partner with enterprise and line-of-business architects to integrate security seamlessly into designs and processes.
* Translate complex technical security concepts into clear, actionable insights for C-level executives, business leaders, non-technical stakeholders, and technical engineering teams.
* Recommend mitigating controls, security tools, and remediation strategies to address security gaps and minimize risk.
* Stay current on security threats, vulnerabilities, and technologies to enhance the organization's security posture.
* Promote a security-first culture by mentoring technical teams, educating stakeholders, and embedding security best practices into organizational workflows.
Skills and Qualifications
* 7+ years of hands-on experience in infrastructure, systems, networks, applications, or cloud security.
* 5+ years of enterprise architecture experience required.
* Ability to create and review diagrams using tools such as Visio or Lucidchart.
* Familiarity with secure architecture patterns, reference architectures, and frameworks.
* Expertise in SaaS, PaaS, and IaaS environments, including platforms like AWS, Azure, M365, and Salesforce.
* Experience working with various identity and access management (IAM) solutions such as CyberArk, Okta, Ping Identity, Entra ID/Azure AD, and other tools supporting SSO, MFA, and PAM.
* Familiarity with tools like Jira, Confluence, and ServiceNow for workflow management and documentation.
* Expertise in threat modeling, vulnerability management, and risk assessments.
* Working knowledge of regulatory requirements and compliance standards such as NYDFS, CCPA, GLBA, PCI-DSS, HIPAA, SOX, and GDPR.
* Relevant certifications such as CISSP, CCSP, or equivalent.
* Ability to work independently or collaboratively in a team-oriented environment.
* Bachelor's degree in a relevant field or proven record of experience in Information Technology and Cyber Security roles.
Technical Skills
* Familiarity with protocols such as SAML, OAuth, OIDC, FIDO, PKI, JWT, LDAP, and Kerberos.
* Strong knowledge of common network protocols, including TCP/IP, HTTP/HTTPS, DNS, SMTP, SNMP, SSH, and VPN technologies.
* Expertise in encryption technologies (e.g., TLS, AES, RSA) and key management practices (e.g., KMS, HSM, PKI).
* Familiarity with firewalls, IDS/IPS, WAF, VPN, Routers, Switches, Load Balancers, Zero-Trust, microsegmentation, and SD-WAN security solutions, CASB, Proxy, SSE.
* Experience with SIEM tools such as Splunk, QRadar, or ArcSight and logging/monitoring best practices.
* Knowledge of Docker, Kubernetes, EKS, ECS, and OCP, including their security considerations.
* Proficiency in integrating security into DevOps pipelines with tools such as Jenkins, GitHub, Artifactory, Terraform, and Vault.
Common Security and Architecture Frameworks
* Security Frameworks:
* NIST Cybersecurity Framework (CSF)
* ISO 27001 and 27002
* CSA CCM (Cloud Controls Matrix)
* CIS Controls
* Architecture Frameworks:
* SABSA (Sherwood Applied Business Security Architecture)
* TOGAF (The Open Group Architecture Framework)
* AWS Well-Architected Framework
Preferred Certifications
* TOGAF (The Open Group Architecture Framework)
* SABSA Foundation or Practitioner
* CISSP-ISSAP (Concentration in Security Architecture)
* Certified Cloud Security Professional (CCSP)
* GIAC Security Architecture (GDSA)
* AWS Certified Solutions Architect - Associate or Professional
* AWS Certified Security - Specialty
* Microsoft Certified: Azure Solutions Architect Expert
Soft Skills
* Strong analytical and problem-solving abilities.
* Excellent interpersonal and collaboration skills.
* Strong organizational and time management skills.
* Adaptability and a commitment to continuous learning of new technologies and methodologies.
* Attention to detail and dedication to delivering high-quality results.
* High level of integrity and ethical conduct.
Industry-Specific Experience
* Experience in financial services, insurance, or other regulated environments.
* Proven ability to design and implement security controls that align with industry regulations and standards.
* Experience conducting security assessments and audits in regulated industries.
* Familiarity with industry-specific threats and vulnerabilities to tailor security solutions.
Compensation
The actual compensation offered will ultimately be dependent on multiple factors, which may include the candidate's geographic location, skills, experience and other qualifications.
In addition, the position is eligible for a discretionary bonus in accordance with the terms of the applicable incentive plan.
Corebridge also offers a range of competitive benefits as part of the total compensation package, as detailed below.
Work Location
This position is based in Corebridge Financial's Houston, TX or Durham, NC office and is subject to our hybrid working policy, which gives colleagues the benefits of working both in an office and remotely.
#LI-SAFG #LI-CW1 #LI-Hybrid
Why Corebridge?
At Corebridge Financial, we prioritize the health, well-being, and work-life balance of our employees. Our comprehensive benefits and wellness program is designed to support employees both personally and professionally, ensuring that they have the resources and flexibility needed to thrive.
Benefit Offerings Include:
* Health and Wellness: We offer a range of medical, dental and vision insurance plans, as well as mental health support and wellness initiatives to promote overall well-being.
* Retirement Savings: We offer retirement benefits options, which vary by location. In the U.S., our competitive 401(k) Plan offers a generous dollar-for-dollar Company matching contribution of up to 6% of eligible pay and a Company contribution equal to 3% of eligible pay (subject to annual IRS limits and Plan terms). These Company contributions vest immediately.
* Employee Assistance Program: Confidential counseling services and resources are available to all employees.
* Matching charitable donations: Corebridge matches donations to tax-exempt organizations 1:1, up to $5,000.
* Volunteer Time Off: Employees may use up to 16 volunteer hours annually to support activities that enhance and serve communities where employees live and work.
* Paid Time Off: Eligible employees start off with at least 24 Paid Time Off (PTO) days so they can take time off for themselves and their families when they need it.
Eligibility for and participation in employer-sponsored benefit plans and Company programs will be subject to applicable law, governing Plan document(s) and Company policy.
We are an Equal Opportunity Employer
Corebridge Financial, is committed to being an equal opportunity employer and we comply with all applicable federal, state, and local fair employment laws. All applicants will be considered for employment based on job-related qualifications and without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, disability, neurodivergence, age, veteran status, or any other protected characteristic. The Company is also committed to compliance with all fair employment practices regarding citizenship and immigration status. At Corebridge Financial, we believe that diversity and inclusion are critical to building a creative workplace that leads to innovation, growth, and profitability. Through a wide variety of programs and initiatives, we invest in each employee, seeking to ensure that our colleagues are respected as individuals and valued for their unique perspectives.
Corebridge Financial is committed to working with and providing reasonable accommodations to job applicants and employees, including any accommodations needed on the basis of physical or mental disabilities or sincerely held religious beliefs. If you believe you need a reasonable accommodation in order to search for a job opening or to complete any part of the application or hiring process, please send an email to ******************************************. Reasonable accommodations will be determined on a case-by-case basis, in accordance with applicable federal, state, and local law.
We will consider for employment qualified applicants with criminal histories, consistent with applicable law.
To learn more please visit: ***************************
Functional Area:
IT - Information Technology
Estimated Travel Percentage (%): Up to 25%
Relocation Provided: No
American General Life Insurance Company
Auto-ApplyOffensive Security Researcher
Security architect job in Durham, NC
NVIDIA is looking for security researchers passionate about offensive research across different platforms. Do you have experience with identifying hardware and software vulnerabilities, developing PoC, and tools for automation in vulnerability research? Are you creative and devious in your offensive approach? We want to hear from you!
You should demonstrate ability to excel in an environment with innovative and fast paced development on the worlds most powerful integrated software and hardware computing platform.
What you'll be doing:
* Core job duties will identify vulnerabilities in our embedded firmware and critical system software, building proof of concepts, and collaborating with development teams to remediate them.
* Candidates will invest in improving current tools and offensive practices for bug discovery and evaluation while supporting remediation efforts. We expect team members to exercise modern tools for modeling new attack vectors on unreleased and emerging technology platforms.
* The most impactful candidates can simulate real attacker behaviors, break systems by exploiting design assumption and effectively communicate their findings for action. Focus will be to increase resilience of the end products against all forms of attack through close collaboration with extended SW and HW offensive security teams.
* Products targets span HPC data centers, consumer electronics, autonomous platforms, AI/cloud solutions, and a variety of embedded/IOT platforms providing a rich and complex target space to exercise your skills.
What we need to see:
* We'd like to see proven experience and offensive security research (CVE's, publications, patents, tools, bounties) with demonstrated responsible disclosure practices.
* Strong skills in reverse engineering and automation (IDA, Ghidra), fuzzing (AFL, WinAFL, Syzcaller) and exploitation (ROP, memory corruption) are important to success; as well as understanding of modern embedded cryptography and common security issues.
* Experience with ARM/X86/RISCV assembly (include shellcode development) and low-level C programming paired with understanding and experience with micro-architectural attacks (side channels, fault injection, etc) is critical.
* Demonstrated skill for secure code reviews of complex source projects, and exposure to code quality practices (SDL, threat modeling) that support development goals.
* Candidates should be comfortable working collaboratively and remotely with others to accomplish complex team goals, enabling delivery of outstanding security for our products.
* BS/BA degree or equivalent experience
* 12+ years in a security related field
Ways to stand out from the crowd:
* Navigating complex platform concerns and ability to analyze composed systems to identify high risk components and established testing targets and objectives.
* Practical skills using Hex-Rays IDA Pro and plugin/loaders development (or similar experience with Ghidra) is valuable
* Leveraging innovative strategies and AI advancements to accelerate discovery and resolution of security risks.
* Experience with enclave models such as NVIDIA CC, ARM TEE, Intel SGX/TDX, AMD SEV-SNP and other isolation technologies.
* Development and integration of AI tooling and skills to accelerate and improve activities and or experience with offensive actions targeting AI models (LLM or other) components within those platforms.
NVIDIA has continuously reinvented itself over two decades. Our invention of the GPU in 1999 fueled the growth of the PC gaming market, redefined modern computer graphics, and revolutionized parallel computing. More recently, GPU deep learning ignited modern AI - the next era of computing. NVIDIA is a "learning machine" that constantly evolves by adapting to new opportunities that are hard to solve, that only we can pursue, and that matter to the world. This is our life's work, to amplify creativity and intelligence. Make the choice to join us today!
Your base salary will be determined based on your location, experience, and the pay of employees in similar positions. The base salary range is 224,000 USD - 356,500 USD for Level 5, and 272,000 USD - 425,500 USD for Level 6.
You will also be eligible for equity and benefits.
Applications for this job will be accepted at least until October 5, 2025.
NVIDIA is committed to fostering a diverse work environment and proud to be an equal opportunity employer. As we highly value diversity in our current and future employees, we do not discriminate (including in our hiring and promotion practices) on the basis of race, religion, color, national origin, gender, gender expression, sexual orientation, age, marital status, veteran status, disability status or any other characteristic protected by law.
Auto-ApplySenior Cloud Security Architect (26185)
Security architect job in Durham, NC
NetApp is the data authority for hybrid cloud. We provide a full range of hybrid cloud data services that simplify management of applications and data across cloud and on-premises environments to accelerate digital transformation. Together with our partners, we empower global organizations to unleash the full potential of their data to expand customer touchpoints, foster greater innovation and optimize their operations.
NetApp Data Fabric simplifies and integrates data management across cloud and on-premises to accelerate digital transformation. It delivers consistent and integrated data management services and applications for data visibility and insights, data access and control, and data protection and security. And unleashes the power of data to achieve a new competitive advantage.
If you ask anyone at NetApp why they work here, the answer is inevitably the same: it's the people. At NetApp, we place trust, integrity, teamwork, and caring at the heart of what we do. As such, we've created a culture where people feel empowered to make a difference; where we're passionate about innovation and collaboration; and where we take care of each other, our customers, our partners, and our communities simply because it's the right thing to do.
We provide comprehensive medical, dental, wellness and vision plans for you and your family. We also offer financial savings programs to help you plan for your future. We work hard but also recognize the importance of work-life balance for our employees. We offer educational assistance, legal services, access to discounts and fitness centers. Our volunteer time off program is best in class because what's important to our employees is important to us! Join us, and we'll help you do your best work.
Interested in working at NetApp? Search our open jobs - **************************
Job Description
Are you data-driven? We at NetApp believe in the transformative power of data - to expand customer touchpoints, to foster greater innovation, and to optimize operations. We are designed for simplicity, optimized to protect, created to embrace future opportunity, and open to enrich choice. We are the data authority for hybrid cloud, and we are helping our customers realize the full potential of their data.
We've built a Data Fabric for a data-driven world - to simplify and integrate data management across the resources that are best for the business. With the Data Fabric, our customers can harness the power of cloud data services, build cloud infrastructures, and modernize storage through data management.
By harnessing the power of hybrid cloud data services, customers gain the freedom of choice to securely manage and move data - anywhere, on any cloud. Only NetApp can help organizations deliver data-rich customer experiences when they rapidly test and deploy new applications that easily use data and services regardless of where they reside or in what form.
Qualifications
The Senior Security Architect is responsible for determining security requirements; planning, implementing, and testing security systems; preparing security standards, policies, and procedures; and mentoring team members. He/she also is responsible for designing, building, testing and implementing security systems across NetApp's networks, infrastructure, and cloud based architecture. The Senior Security Architect is expected to have a thorough understanding of complex IT systems and stay up to date with the latest security standards, systems and authentication protocols, as well as best practice security products.
Job Requirements
Interpret compliance and security requirements to design implementable and repeatable controls
Identify gaps in existing and proposed architectures and security controls and provide recommendations for resolution
Contribute to creation and maintenance of Enterprise Information Security policies, standards, and process documentation
Coordinate with Enterprise Information Security leadership to create and maintain overall short- and long-term roadmaps
Conduct reviews for projects related to infrastructure and general information security to ensure they meet requirements and target-state architectures
Participate in risk assessment activities as subject matter expert for infrastructure and general information security concerns
Determines security requirements by evaluating business strategies and requirements; researching information security standards; conducting system security and vulnerability analyses and risk assessments; studying architecture/platform; identifying integration issues; preparing cost estimates
Plans security systems by evaluating network and security technologies; developing requirements for local area networks (LANs), wide area networks (WANs), virtual private networks (VPNs), routers, firewalls, and related security and network devices; designs public key infrastructures (PKIs), including use of certification authorities (CAs) and digital signatures as well as hardware and software; adhering to industry standards
Implements security systems by specifying intrusion detection methodologies and equipment; directing equipment and software installation and calibration; preparing preventive and reactive measures; creating, transmitting, and maintaining keys; providing technical support; completing documentation
Verifies security systems by developing and implementing test scripts
Maintains security by monitoring and ensuring compliance to standards, policies, and procedures; conducting incident response analyses; developing and conducting training programs
Upgrades security systems by monitoring security environment; identifying security gaps; evaluating and implementing enhancements
Prepares system security reports by collecting, analyzing, and summarizing data and trends
Updates job knowledge by tracking and understanding emerging security practices and standards; participating in educational opportunities; reading professional publications; maintaining personal networks; participating in professional organizations
Enhances department and organization reputation by accepting ownership for accomplishing new and different requests; exploring opportunities to add value to job accomplishments
Skills and Education
Skills:
Experience developing enterprise class security architectures in both traditional data center and public / private cloud environments
Working knowledge of industry best practices for information security
2+ years working with one or more cloud service models (Infrastructure as a Service, Platform as a Service, and Software as a Service) and deployment models (public, private, hybrid)
2+ years direct experience designing and implementing security solutions for one or more leading cloud providers (AWS, Azure, Google Cloud Platform)
2+ years direct experience with leading firewall, VPN, IDS/IPS, endpoint security, and DLP solutions
Working knowledge of DevOps Security concepts for Continuous Integration/Continuous Delivery environments
Working knowledge of risk assessments, configuration management, change control, and security baselines and frameworks (NIST CSF, NIST SP 800-171, CIS)
Vulnerability management experience with Common Vulnerability Scoring System (CVSS), Common Vulnerabilities and Exposures (CVE), and Open Web Application Secure Project (OWASP)
Expert knowledge of federated identity management, role and access management, and privileged administrative access best practices
Ability to communicate verbally and in writing with audience appropriate content
Education:
Desired: a minimum of 12 years of related experience with a Bachelor's degree; or 8 years and a Master's degree; or a PhD with 5 years experience; or equivalent experience. Certifications such as CISSP, CCSP, CISM, CCIE Security, and AWS Certified Solutions Architect are a plus
So get ready to tap into the data visionary within, and join us as we accelerate digital transformation and empower our customers to change the world with data!
If you ask a NetApp employee why they work here, the answer is inevitably the same: the people. At NetApp, our culture is at the heart of what we do. We place importance in trust, integrity, teamwork, and caring above all else. NetApp is a place where people are empowered to make a difference. Empowered to innovate. Empowered to collaborate. Empowered to help ourselves and others be data-driven and change the world. We take care of each other, our customers, our partners, and our communities simply because it's the right thing to do.
We work hard but also recognize the importance of work-life balance for our employees because what's important to them is important to us! Recently we implemented Family First, which encourages employees to take paid time off to bond with a new child (through birth or adoption) or to care for a family member with a serious health condition. Our volunteer time off program is best in class, offering employees 40 hours of paid time off per year to donate their time with their favorite organizations. We provide comprehensive medical, dental, wellness and vision plans for you and your family. We offer educational assistance, legal services, and access to discounts and fitness centers. We also offer financial savings programs to help you plan for your future.
Join us and see what empowerment can do.
Additional Information
All your information will be kept confidential according to EEO guidelines.
Enterprise IS Security Engineer
Security architect job in Morrisville, NC
Reporting to the Cybersecurity Manager, the Enterprise Security Engineer, will join our growing security team. This role will be responsible for designing, implementing, and maintaining security measures that protect our systems, network, and data from cyber threats. You will play a critical role in identifying vulnerabilities, responding to incidents, and ensuring compliance with industry standards and regulations
The responsibilities encompass, but are not limited to:
* Implement, manage and monitor M365 and Cloud services security tools and controls.
* Implement, manage and monitor appropriate identity and access management tools and controls.
* Implement, manage, and monitor security measures that support Zero Trust Architecture.
* Implement, manage and monitor Endpoint Security systems (application whitelisting, device control, Anti-Virus, encryption).
* Create, maintain and implement Active directory Group Policy Objects related to cybersecurity.
* Management over the patch rollout system and process.
* Manage the end user security awareness training platform.
* Management of Password Management tools
* Architect and implement enhanced Domain Security structures.
* Enhance and maintain Pyxus Cybersecurity Framework plans and documentation.
* Ensure Security/Cybersecurity best practices are being followed.
* Implement, manage and monitor enterprise IDS and IPS systems.
* Manage Internal Certificate infrastructure.
* Manage External Certificates.
* Manage monthly network vulnerability tests and the remediation process
* Assist as required regarding any legal or audit issues requiring IS resources for investigative or forensic data analysis efforts.
* Implement, maintain and monitor Data Loss Prevention tools.
* Work with application development teams to ensure application security.
* Monitor Internet Security sites for information on new threats (Microsoft, Cisco, CERT & SANS).
* Keep abreast of emerging IS security threats.
* Keep abreast of best practices and new technologies for mitigating IS security threats.
* Provide upfront cybersecurity guidance and input into IS projects and policies so that security is not an afterthought.
* Contribute content to cybersecurity updates for C-level executives.
* On call 24X7 for suspected intrusions and incident response.
* 4 year Degree in Information Technology or Business related field.
* Certification in industry recognized cybersecurity qualifications (e.g. CompTIA Security+, CISSP)
* Minimum of 4 years experience in Cybersecurity.
* Strong working knowledge of TCP/IP, DNS, Active Directory, IP Address Management
* Working knowledge of Firewalls (ISA, CISCO ASA, Palo Alto)
* Experience with Endpoint Security and SIEM systems.
* Experience with Infrastructure related Security tools and procedures - perimeter and internal.
* Experience with securing Cloud based workloads, services and resources.
* Strong Knowledge of encryption and certificate infrastructure.
* Project Management Experience beneficial.
* Experience in Cloud Architecture and design in a multi-forest and domain environment.
* Knowledge and experience in Windows Server OS and hardware.
* Excellent Oral and Written Communication skills.
* Excellent Documentation skills.
* Consistency and attention to detail.
* Ability to work well with others while maintaining a high degree of confidentiality, honesty and integrity.
* Able to do international and/or domestic travel as required
Auto-ApplyDirector, Information Security & End User Computing (EUC)
Security architect job in Durham, NC
At Alcami, we deliver reliable solutions that unlock the potential of transformative medicines from discovery to commercialization, through trusted partnership with our clients, recognized industry expertise and proven regulatory track record.
Are you interested in joining our team?
Job Summary
The Director, Information Security & End User Computing (EUC) is a senior IT leader responsible for safeguarding Alcami's information assets, overseeing enterprise security programs, and managing all end-user computing services and support functions. This role leads teams across security operations, infrastructure protection, and EUC support, ensuring reliable, secure, and high-quality technology experiences for all employees. The Director is expected to coach, develop, and grow technical talent while driving operational excellence, resilience, and continuous improvement across their areas of responsibility.
On-Site Expectations
100% on-site position.
1st Shift: Monday - Friday, 8:30am - 5:30pm.
Responsibilities
Information Security Leadership
Serve as Alcami's Information Systems Security Officer (ISSO) and lead enterprise security governance, assessments, and compliance programs.
Manage security risk assessments across applications, cloud environments, and infrastructure.
Maintain continuous security monitoring, vulnerability management, and incident response readiness.
Oversee documentation and controls aligned with NIST RMF, ISO standards, and applicable regulatory frameworks.
Partner closely with the CIO, CISO (if applicable), and other business leaders to strengthen Alcami's security posture.
Contribute to COOP/DR strategy and ensure security considerations are embedded across all technology operations.
End User Computing (EUC) Leadership
Lead the EUC function, including Service Desk, desktop support, endpoint management, mobile devices, and collaboration tools.
Oversee deployment, configuration, and lifecycle management of laptops, desktops, mobile devices, peripherals, printers, and standard office applications.
Ensure timely, high-quality support for all users, with strong SLAs, KPI tracking, and a culture of ownership.
Manage endpoint security controls, patching, and compliance across all devices.
Drive standardization of images, device configurations, and application delivery.
Strengthen ITIL-aligned service processes, change management discipline, and incident/problem management routines.
Oversee Microsoft 365 administration in partnership with relevant infrastructure teams.
People Leadership & Operations
Recruit, develop, mentor, and retain high-performing teams across Security and EUC.
Establish a culture of accountability, continuous learning, partnership, and proactive communication.
Build operational roadmaps, establish strategic objectives, and manage departmental performance against goals.
Develop and manage annual budgets for Security and EUC.
Represent IT in cross-functional meetings and partner with customers across the organization to drive value.
Continuous Improvement & Technical Leadership
Drive innovation, process optimization, and automation across both Security and EUC operations.
Provide technical guidance for troubleshooting complex security, infrastructure, and EUC issues.
Maintain strong knowledge of emerging technologies, vulnerabilities, and best practices.
Support audits, client assessments, and regulatory inspections.
Qualifications
Bachelor's degree in a related field; equivalent experience considered.
12+ years of experience in IT, including significant experience in Information Security and EUC operations.
6+ years of leadership experience managing technical teams.
CISSP or equivalent security certification preferred.
Deep expertise in security architecture, risk assessment, vulnerability management, and cloud security.
Experience managing enterprise EUC environments, endpoint security, and Microsoft 365.
Strong communication, customer engagement, and cross-functional collaboration skills.
Proven ability to build high-performing teams and drive operational excellence.
The ability to obtain and maintain a U.S. government issued security clearance is required. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance.
Knowledge, Skills, and Abilities
Must have experience with the following:
Cloud expertise, and the ability to teach
Mobile experience
SCADA, infrastructure protection, and/or engineering experience
Must be eligible to obtain a sensitive clearance - Position of Public Trust - and may be required to obtain a higher security clearance.
Ability to manage responsibility for security assessments of a variety of applications or domains, to include cloud computing, and to manage several project/initiatives of large size, complexity, and risk.
Demonstrated proficiency in implementing security controls, conducting risk assessments, and documenting compliance measures based on NIST RMF and ISO standards to meet organizational and regulatory requirements.
Demonstrated proficiency in successfully evaluating and supporting documentation, validation, and accreditation processes necessary to assure that new and existing information technology (IT) systems meet the organization's information assurance (IA) and security requirements.
Demonstrated proficiency in ensuring appropriate treatment of risk, compliance, and assurance from internal and external perspectives.
Demonstrated ability to support development of actionable security blueprints, principles, models, designs, standards, and guidelines to ensure enterprise IT architecture and support is consistent, usable, secure and adds value to the business.
Experience with network and vulnerability scanning tools and technologies to interrogate systems for configuration and status.
In-depth understanding of security architecture principles and best practices to design, implement, and maintain secure IT infrastructures in alignment with corporate policies and compliance standards.
Experience in computer forensic techniques.
Excellent technical knowledge of mainstream security technologies and understands operation of them, such as network security appliances, Intrusion Detection Policies, identity and access management (IAM) systems, anti-malware solutions, antivirus solutions, automated policy compliance tools, desktop security tools, CASB, Email Protection, DNS filtering, IPS/IDS, XDR, and Vulnerability Management.
Expert knowledge of Microsoft product-based systems.
Strong knowledge of Service Now administration.
Strong knowledge of application deployment, OS deployment, OS patching, and inventory management.
Demonstrated experience in advanced troubleshooting of computer hardware and software.
Excellent communication and interpersonal skills.
Strong technical skills for area managing.
Strong business acumen.
Strong understanding of company SOPs, and regulatory guidance documents.
Strong knowledge of safety procedures and quality compliance for assigned area.
Strong knowledge of cGMP requirements.
Strong experience with client audits.
Excellent analytical and problem-solving skill, with the ability to think strategically.
Strong attention to detail as well as time and resource management.
Good presentation skills.
Strong personnel and professional integrity and trustworthiness with strong work ethics and the ability to work independently with some direction.
Promote a safe environment for work.
Comply with the general policy of the company.
High level of personnel and professional integrity and trustworthiness with strong work ethics and the ability to work independently with minimal direction.
Ability to develop and manage a high-performance team focused on quality, accountability, and meeting and exceeding expectations.
Communicate well orally both for internal customers and team members as well as external customers.
Ability to write reports and business correspondence.
Ability to listen and respond well to external customers, partners, and colleagues at all levels.
Highly goal and result oriented.
Prioritizes tasks according to business objectives and can pursue several objectives simultaneously.
Can work independently with a high degree of self-motivation.
Knows how to obtain support from different collaborations.
Tackles problems with enthusiasm and curiosity.
Treats colleagues at all levels with respect.
Very effective listening skills with the ability to hear attentively and process information correctly.
Travel Expectations
Up to 25% travel expected including training.
Physical Demands and Work Environment
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. While performing the duties of this job, the employee may be required to use hands to finger, handle, or feel and to reach with hands and arms. The employee is required to talk and hear. The employee is frequently required to stand, walk and sit. The employee may be occasionally required to climb or balance. The employee may be required to regularly lift and/or move up to 10 pounds, frequently lift and/or move up to 25 pounds and occasionally lift and/or move up to 50 pounds. Specific vision abilities required by this job include close vision, distance vision, and peripheral vision.
While performing the duties of this job, the employee may be occasionally exposed to moving mechanical parts, high precarious places and vibration. The noise level in the work environment is usually quiet. The employee may be required to gain access to lab, manufacturing or clinical areas for inspections or work discussions. The employee is required to wear the appropriate personal protective equipment to perform the job duties. Such personal protective equipment may include but is not limited to safety eyewear, various types of respirators/breathing apparatus, lab coats, gloves, etc.
Auto-ApplyData Security Engineer
Security architect job in Durham, NC
This role has been designed as ''Onsite' with an expectation that you will primarily work from an HPE office. Who We Are: Hewlett Packard Enterprise is the global edge-to-cloud company advancing the way people live and work. We help companies connect, protect, analyze, and act on their data and applications wherever they live, from edge to cloud, so they can turn insights into outcomes at the speed required to thrive in today's complex world. Our culture thrives on finding new and better ways to accelerate what's next. We know varied backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good. If you are looking to stretch and grow your career our culture will embrace you. Open up opportunities with HPE.
Job Description:
The data security engineer is responsible for designing, implementing, and maintaining the organization's data security. This role involves working closely with IT, DevOps, and other business units to implement and operate Data Loss Prevention and other data security programs.
Responsibilities:
* Lead the design and deployment of enterprise data protection capabilities like DLP, encryption, SSPM, and CASB
* Lead the evaluation and adoption of new security tools and technologies, ensuring they are effectively integrated and managed.
* Manage and fine tune data security policies with the changing requirements
* Contribute to security policies, standards, and procedures to ensure compliance with industry best practices and regulatory requirements.
* Collaborate with IT and DevOps teams to integrate security into the software development lifecycle (SDLC), infrastructure as code (IaC), and cloud environments.
* Collaborate with data warehouse team to feed data into SIEM and long term storage solutions
* SME for the technical response of high-severity security incidents, coordinating efforts across multiple teams and ensuring rapid containment and resolution.
* Contribute to playbooks and procedures.
* Collaborate with key stakeholders, including IT, DevOps, legal, and compliance teams, to ensure that security initiatives align with business goals.
* Provide expert guidance on emerging threats, technologies, and regulatory requirements, contributing to the development of the organization's cybersecurity strategy.
Education and Experience Required:
* Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field. Or equivalent experience.
* 8 years of experience in cybersecurity, with at least 5 years focused on DLP
* Hands-on experience with tools like Zscaler DLP, Microsoft IPG, or equivalent
* Strong understanding of data protection regulations (HIPPA, PCI, SOX) and enterprise compliance frameworks
* Required: Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or equivalent.
* Preferred: Certified Information Systems Professional (CISSP), or other advanced certifications relevant to cybersecurity engineering.
* Knowledge of the NIST 800-53, ISO 27001, and Zero Trust.
* Strong analytical and problem-solving skills, with the ability to assess complex security challenges and develop effective solutions.
* Excellent communication and leadership skills, with the ability to influence technical and non-technical stakeholders at all levels of the organization.
* Ability to manage multiple high-impact projects simultaneously, working effectively in a fast-paced, high-pressure environment
Additional Skills:
Accountability, Accountability, Action Planning, Active Learning, Active Listening, Agile Methodology, Bias, Business, Coaching, Creativity, Critical Thinking, Cybersecurity, Data Analysis Management, Data Collection Management (Inactive), Data Controls, Design Thinking, Development Methodologies, Empathy, Follow-Through, Growth Mindset, Implementation Methodologies, Infrastructure Design, Intellectual Curiosity (Inactive), Long Term Planning, Managing Ambiguity {+ 4 more}
What We Can Offer You:
Health & Wellbeing
We strive to provide our team members and their loved ones with a comprehensive suite of benefits that supports their physical, financial and emotional wellbeing.
Personal & Professional Development
We also invest in your career because the better you are, the better we all are. We have specific programs catered to helping you reach any career goals you have - whether you want to become a knowledge expert in your field or apply your skills to another division.
Unconditional Inclusion
We are unconditionally inclusive in the way we work and celebrate individual uniqueness. We know varied backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good.
Let's Stay Connected:
Follow @HPECareers on Instagram to see the latest on people, culture and tech at HPE.
#unitedstates
#cybersecurity
Job:
Information Technology
Job Level:
TCP_04
States with Pay Range Requirement
The expected salary/wage range for a U.S.-based hire filling this position is provided below. Actual offer may vary from this range based upon geographic location, work experience, education/training, and/or skill level. If this is a sales role, then the listed salary range reflects combined base salary and target-level sales compensation pay. If this is a non-sales role, then the listed salary range reflects base salary only. Variable incentives may also be offered. Information about employee benefits offered can be found at *******************************************************
USD Annual Salary: $106,000.00 - $243,000.00
HPE is an Equal Employment Opportunity/ Veterans/Disabled/LGBT employer. We do not discriminate on the basis of race, gender, or any other protected category, and all decisions we make are made on the basis of qualifications, merit, and business need. Our goal is to be one global team that is representative of our customers, in an inclusive environment where we can continue to innovate and grow together. Please click here: Equal Employment Opportunity.
Hewlett Packard Enterprise is EEO Protected Veteran/ Individual with Disabilities.
HPE will comply with all applicable laws related to employer use of arrest and conviction records, including laws requiring employers to consider for employment qualified applicants with criminal histories.
No Fees Notice & Recruitment Fraud Disclaimer
It has come to HPE's attention that there has been an increase in recruitment fraud whereby scammer impersonate HPE or HPE-authorized recruiting agencies and offer fake employment opportunities to candidates. These scammers often seek to obtain personal information or money from candidates.
Please note that Hewlett Packard Enterprise (HPE), its direct and indirect subsidiaries and affiliated companies, and its authorized recruitment agencies/vendors will never charge any candidate a registration fee, hiring fee, or any other fee in connection with its recruitment and hiring process. The credentials of any hiring agency that claims to be working with HPE for recruitment of talent should be verified by candidates and candidates shall be solely responsible to conduct such verification. Any candidate/individual who relies on the erroneous representations made by fraudulent employment agencies does so at their own risk, and HPE disclaims liability for any damages or claims that may result from any such communication.
Auto-ApplyOfficer, Senior Information Security Engineer
Security architect job in Durham, NC
**BANC OF CALIFORNIA AND YOUR CAREER** Banc of California, Inc. (NYSE: BANC) is a bank holding company headquartered in Los Angeles with one wholly-owned banking subsidiary, Banc of California (the "bank"). Banc of California is one of the nation's premier relationship-based business banks focused on providing banking and treasury management services to small, middle-market, and venture-backed businesses. Banc of California offers a broad range of loan and deposit products and services, with full-service branches throughout California and Denver, Colorado, as well as full-stack payment processing solutions through its subsidiary, Deepstack Technologies. The bank is committed to its local communities by supporting organizations that provide financial literacy and job training, small business support, affordable housing, and more.
At Banc of California, our success is driven by our people, and we take pride in fostering an environment where everyone can reach their full potential. We embrace a culture of empowerment, progressive thinking, and entrepreneurial spirit, ensuring our team members have an opportunity to make an impact and play an important role in the future of Banc of California. Our core values - Entrepreneurialism, Operational Excellence, and Superior Analytics - empower us in creating a dynamic and inclusive workplace. We are committed to supporting your growth and well-being with comprehensive benefits, career development programs, a variety of employee resource groups, and more. TOGETHER WE WIN
**THE OPPORTUNITY**
Responsible for all aspects of cyber security operations including architecture, design, configuration, deployment, operation and management of cyber security tools, systems and processes. The position is involved with the implementation and maintenance of data security systems in both on premise and cloud environments. Performs all duties in accordance with the Company's policies and procedures, all U.S. state and federal laws and regulations, wherein the Company operates.
**HOW YOU'LL MAKE A DIFFERENCE**
+ Builds, supports, monitors and enforces the security posture of the Bank using next-gen firewall, IDS/IPS, endpoint protection, DLP, encryption, SIEM, vulnerability management and other technologies and processes.
+ Conducts / coordinates security control audits, identifies potential gaps/risks and participates in the remediation of same.
+ Establishes and maintains Security Operations team triage and incident response playbooks to protect and recover information assets from unauthorized access, modification or destruction.
+ Assist in developing and implementing technical security standards to support the Bank's security needs and regulatory requirements including ISO2700x, CFPB, SOX, GLBA, NIST, FFIEC and PCI.
+ Provide subject matter expertise in all areas of Information Security technical operations, including analysis of computing environment, security testing and documentation, as well as investigations, software research, emerging technology research, vendor security analysis and participation in periodic audits.
+ Execute a reliable first-line-of defense via documented processes, controls, templates, and rigors.
+ Evaluate effectiveness of security testing and training, including penetration testing, security awareness training, and phishing campaigns.
+ Keeps abreast of the latest security and privacy legislation, regulations, advisories, alerts, and vulnerabilities pertaining to the Bank, and modify security control structure as required.
+ Maintains advanced knowledge and awareness of information security trends within the financial industry.
+ High level of personal integrity, the ability to professionally handle confidential matters, and project the appropriate level of urgency, judgment, and maturity.
+ Treat people with respect; keep commitments; inspire the trust of others; work ethically and with integrity; uphold organizational values; accept responsibility for own actions.
+ Demonstrates knowledge of and adherence to EEO policy; shows respect and sensitivity for cultural differences; educates others on the value of diversity; promotes working environment free of harassment of any type; builds a diverse workforce and supports affirmative action.
+ Follows policies and procedures; completes tasks correctly and on time; supports the company's goals and values.
+ Performs the position safely, without endangering the health or safety to themselves or others and will be expected to report potentially unsafe conditions. The employee shall comply with occupational safety and health standards and all rules, regulations and orders issued pursuant to the OSHA Act of 1970, which are applicable to one's own actions and conduct.
+ Performs other duties and projects as assigned.
**WHAT YOU'LL BRING**
+ Demonstrates knowledge of, adherence to, monitoring and responsibility for compliance with state and federal regulations and laws as they pertain to this position including but not limited to the following: Regulation Z (Truth in Lending Act), Regulation B (Equal Credit Opportunity Act), Fair Housing Act (FHA), Home Mortgage Disclosure Act (HMDA), Real Estate Settlement Procedures Act (RESPA), Fair Credit Reporting Act (FCRA), Bank Secrecy Act (BSA) in conjunction with the USA PATRIOT Act, Anti-Money Laundering (AML) and Customer Information Program (CIP), Right to Financial Privacy Act (RFPA, state and federal) and Community Reinvestment Act (CRA).
+ Security generalist, someone that thrives in fast-paced environments with diverse technologies, but can dive deep on your domain(s) expertise.
+ Interested in solving security challenges through partnership, technical awareness and assurance.
+ Adept at influence and driving change within the organization.
+ Self-starter with a hands-on style, a high level of energy, stamina and drive.
+ Able to present ideas clearly and gain agreement and group consensus.
+ Strong team player.
+ Ability to work with little to no supervision while performing duties
+ Bachelor's Degree, Information Systems, Computer Science, Information Security or related field desired.
+ Security Operations experience in financial services, healthcare, or other highly-regulated sector desired.
+ 5+ years IT security or Information Security experience with a proven ability to engage with business units and technical peers.
+ Experience and knowledge of Palo Alto firewalls
+ Highschool diploma or equivalent required
**HOW WE'LL SUPPORT YOU**
+ **Financial Security:** You will be eligible to participate in the company's 401k plan which includes a company match and immediate vesting.
+ **Health & Well-Being:** We offer comprehensive insurance options including medical, dental, vision, AD&D, supplemental life, long-term disability, pre-tax Health Savings Account with employer contributions, and pre-tax Flexible Spending Account (FSA).
+ **Building & Supporting Your Family:** Banc of California partners with providers that offeradoption, surrogacy, and fertility assistance as well as paid parental leave and family support solutions including care options for your family.
+ **Paid Time Away:** Eligible team members receive paid vacation days, holidays, and volunteer time off.
+ **Career Growth Opportunities:** To support career growth of our team members, we offer tuition reimbursement, an annual mentorship program, leadership development resources, access to LinkedIn Learning, and more.
**SALARY RANGE**
The full-time base salary range for this position is $100,000.00 - $150,000.00 a year. The base salary ultimately offered is determined through a review of education, industry experience, training, knowledge, skills, abilities of the applicant in alignment with market data and other factors.
Banc of California is an equal opportunity employer committed to creating a diverse workforce. All qualified applicants will receive consideration for employment without regard to age (40 and over), ancestry, color, religious creed (including religious dress and grooming practices), denial of Family and Medical Care Leave, disability (mental and physical) including HIV and AIDS, marital status, medical condition (cancer and genetic characteristics), genetic information, military and veteran status, national origin (including language use restrictions), race, sex (which includes pregnancy, childbirth, breastfeeding and medical conditions related to pregnancy, childbirth or breastfeeding), gender, gender identity, gender expression, and sexual orientation. If you require reasonable accommodation as part of the application process, please contact Talent Acquisition.
Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws.
For further information, please review the Know Your Rights (**************************** notice from the Department of Labor.
Equal Opportunity Employer
PacWest Bancorp and its affiliates are fully committed to the principles of equal opportunity and diversity. We take pride in building a workplace culture where all employees feel supported and respected, and have equal access to career and development opportunities without regard to race, religion/creed, color, national origin, age, marital status, ancestry, sex, gender (including pregnancy, childbirth, breastfeeding or related medical conditions), gender identity/expression, sexual orientation, veteran status, physical or mental disability, medical condition, military status, genetic information, or any other characteristic protected by federal, state or local laws.
Security Engineer - Secure Software Development
Security architect job in Greensboro, NC
By joining Sedgwick, you'll be part of something truly meaningful. It's what our 33,000 colleagues do every day for people around the world who are facing the unexpected. We invite you to grow your career with us, experience our caring culture, and enjoy work-life balance. Here, there's no limit to what you can achieve.
Newsweek Recognizes Sedgwick as America's Greatest Workplaces National Top Companies
Certified as a Great Place to Work
Fortune Best Workplaces in Financial Services & Insurance
Security Engineer - Secure Software Development
Security Engineer - Secure Software Development
**PRIMARY PURPOSE OF THE ROLE:** To manage the implementation of security measures to protect company data, networks, and computer systems. To focus on executing security fundamentals for threat detection, investigation, and response efforts.
**ARE YOU AN IDEAL CANDIDATE?** We are looking for enthusiastic candidates who thrive in a collaborative environment, who are driven to deliver great work, are customer-oriented and are naturally empathetic.
**ESSENTIAL RESPONSIBLITIES MAY INCLUDE**
+ Engineers, implements and monitors security measures for the protection of computer systems, networks and information.
+ Identifies and defines system security requirements.
+ Designs computer security architecture and develops detailed cyber security designs.
+ Prepares and documents standard operating procedures and protocols.
+ Configures and troubleshoots security infrastructure devices.
+ Develops technical solutions and new security tools to assist in mitigating security vulnerabilities and automating repeatable tasks.
+ Leads IT groups and business units as necessary in troubleshooting compatibility issues between security tools and business or productivity programs.
+ Performs analysis of suspected malicious code and other software or programs and provides written or verbal analysis to management.
+ Analyzes client and customer needs as required and provides clear and concise reports to leadership.
+ Works closely with management on assigned projects from inception through implementation ensuring adequate internal communication and user involvement is maintained.
**QUALIFICATIONS**
Eight (8) years of encryption technologies/algorithms, digital forensics, network topologies, and access controls experience or equivalent combination of educated and experience required.
**Skills & Knowledge**
+ Knowledge of TCP/IP services
+ Knowledge of audit and compliance
+ Knowledge of vulnerability management
+ Knowledge of penetration testing
+ Knowledge of various operating systems
+ Knowledge of desktop productivity software
+ Knowledge of Carbon Black Protection
+ Knowledge of Symantec Endpoint Protection and host data loss prevention
+ Knowledge of information technology security frameworks
+ Excellent oral and written communication skills, including presentation skills
+ PC literate, including Microsoft Office products
+ Analytical and interpretive skills
+ Strong organizational skills
+ Excellent interpersonal skills
+ Ability to create and complete comprehensive, accurate and constructive written reports
+ Ability to work in a team environment
+ Ability to meet or exceed Performance Competencies
**Proficient in Snyk for Application Security:** Demonstrated expertise in integrating Snyk into CI/CD pipelines to proactively identify and remediate vulnerabilities in open-source dependencies, container images, and infrastructure as code. Skilled in leveraging Snyk's developer-first tools to maintain secure codebases, enforce security policies, and ensure compliance with industry standards. Experienced in configuring automated scans, interpreting results, and collaborating with development teams to implement effective remediation strategies, contributing to a robust DevSecOps culture.
**TAKING CARE OF YOU**
+ Career development and promotional growth opportunities
+ A diverse and comprehensive benefits offering including medical, dental vision, 401K, PTO and more
\#LI-TS1
Work environment requirements for entry-level opportunities include -
Physical: Computer keyboarding
Auditory/visual: Hearing, vision and talking
Mental: Clear and conceptual thinking ability; excellent judgement and discretion; ability to meet deadlines
Travels as required
The statements contained in this document are intended to describe the general nature and level of work being performed by a colleague assigned to this description. They are not intended to constitute a comprehensive list of functions, duties, or local variances. Management retains the discretion to add or to change the duties of the position at any time.
Sedgwick is an Equal Opportunity Employer and a Drug-Free Workplace.
**If you're excited about this role but your experience doesn't align perfectly with every qualification in the job description, consider applying for it anyway! Sedgwick is building a diverse, equitable, and inclusive workplace and recognizes that each person possesses a unique combination of skills, knowledge, and experience. You may be just the right candidate for this or other roles.**
**Sedgwick is the world's leading risk and claims administration partner, which helps clients thrive by navigating the unexpected. The company's expertise, combined with the most advanced AI-enabled technology available, sets the standard for solutions in claims administration, loss adjusting, benefits administration, and product recall. With over 33,000 colleagues and 10,000 clients across 80 countries, Sedgwick provides unmatched perspective, caring that counts, and solutions for the rapidly changing and complex risk landscape. For more, see** **sedgwick.com**
information Security Engineer
Security architect job in Greensboro, NC
Locus is a nimble, experienced consulting team specializing in information security, cloud computing, networking, and infrastructure. We have extensive experience delivering technology solutions in the Network, Cloud, and Security arenas to some of the largest companies in the world. Candidates are treated like unique individuals, not a commodity, and our career experts are committed to understanding all aspects of a candidate's wants and needs in order to find the best possible fit.
We are laser-focused on winning together and supporting both our internal team and clients alike for long-term shared success. We take a full-service approach with our process, understanding our clients and candidates needs to find the right fit from a skillset and a cultural perspective. People are at the cornerstone of what we do, and we'd love to hear from you.
Locus is currently searching for an Information Security Engineer for our client. This is a full time perm exempt role.
SUMMARY: Responsible for protecting the organization's computers, networks, and data against threats, such as security breaches, computer viruses, or attacks by cyber criminals. This position oversees the planning, development, coordination, implementation, and management of all Information Security functions and measures to regulate access and usage of Customer Information Systems in accordance with established company policies, standards and procedures. The Information Security Manager regularly interfaces with other department heads in matters pertaining to information security awareness and keeps abreast of changes in regulatory and compliance issues, which affect all phases of information security and Customer. This position is also responsible for administration of corporate Business Continuity Program.
ESSENTIAL JOB FUNCTIONS:
Develops Information Security (IS) architecture/designs, plans, controls, processes, standards, policies, and procedures to ensure alignment with IS standards and overall IS security strategy
Develop, implement, and manage security measures for information systems to regulate access to computer data files and prevent unauthorized modification, destruction, or disclosure of information
Determines user requirements, plans projects, establishes priorities, and monitors progress
Manages the evaluation and testing of hardware, firmware, and software for possible impact on systems security
Maintains and monitors user access control for bank systems
Coordinates with other managers to integrate IS project components with other projects including application delivery, network, server, and hosted solutions
Manages and coordinates the enterprise Vendor Risk Management Program
Manages and coordinates Corporate Business Continuity Program
Communicate best practices and risks to Customer
Perform a risk assessment of Customer's vulnerabilities in the cybersecurity landscape and develop Customer's risk appetite for Information Security
Develop key risk indicators and dashboard metrics reporting to both the management team and the Board of Directors
JOB REQUIREMENTS:
Bachelor's Degree from an accredited university in the field of Audit, MIS, Computer Science or related field of study
Prior Information Security experience at a Financial Services company
Familiarity with Financial Services regulations
Familiarity with Federal Financial Institution Examination Council (FFIEC) guidance
Prior management experience
Certified Secure Software Lifecycle Professional (CSSLP) and/or Certified Information Security Manager (CISM) certification
KNOWLEDGE/SKILLS REQUIRED:
Knowledge of financial services industry and all applicable regulations and industry standards
Advanced ability to engineer security solutions
Intermediate relationship management skills
Intermediate knowledge of cybersecurity strategy management
Advanced cybersecurity monitoring and reporting skills
Advanced knowledge of security incident handling
Advanced knowledge of security risk assessment methodologies
Excellent customer service skills
Strong verbal and written communication skills
High level of attention to detail, with strong problem solving & organizational skills
Ability to perform effectively in fast-paced environment
PHYSICAL AND MENTAL QUALIFICATIONS:
Standing, walking, bending and stooping required
Must be able to sit at a desk for long periods of time and use a computer
Must be able to occasionally move or lift up to 10 pounds
May be asked to work supplemental hours periodically
Limited travel required during and after business hours
The above statements are intended to describe the general nature and level of work being performed by the incumbent assigned to this classification. They are not intended to be construed as an exhaustive list of all responsibilities, duties, and/or skills required of all personnel so classified. NOT A CONTRACT
Network Security Analyst
Security architect job in Durham, NC
Established in 1991, Collabera is one of the fastest growing end-to-end information technology services and solutions companies globally. As a half a billion dollar IT company, Collabera's client-centric business model, commitment to service excellence and Global Delivery Model enables its global 2000 and leading mid-market clients to deliver successfully in an increasingly competitive marketplace.
With over 8200 IT professionals globally, Collabera provides value-added onsite, offsite and offshore technology services and solutions to premier corporations. Over the past few years, Collabera has been awarded numerous accolades and Industry recognitions including.
Collabera awarded Best Staffing Company to work for in 2012 by SIA. (hyperlink here)
Collabera listed in GS 100 - recognized for excellence and maturity
Collabera named among the Top 500 Diversity Owned Businesses
Collabera listed in GS 100 & ranked among top 10 service providers
Collabera was ranked:
32 in the Top 100 Large Businesses in the U.S
18 in Top 500 Diversity Owned Businesses in the U.S
3 in the Top 100 Diversity Owned Businesses in New Jersey
3 in the Top 100 Privately-held Businesses in New Jersey
66th on FinTech 100
35th among top private companies in New Jersey
***********************************************
Collabera recognizes true potential of human capital and provides people the right opportunities for growth and professional excellence. Collabera offers a full range of benefits to its employees including paid vacations, holidays, personal days, Medical, Dental and Vision insurance, 401K retirement savings plan, Life Insurance, Disability Insurance.
Job Description
Work Location: Durham NC 27703
Job Title: Network Security Analyst
Duration: 24 Months
Roles & Responsibilities:
• Primary job responsibility will be to perform Intrusion Detection Sensor Threat Analysis.
• Support for any one of McAfee IDS, Sourcefire IDS, Cisco IDS, Tipping Point IDS, Enterasys IDS, Juniper IDP and Fortinet IDS strongly desired.
• The Operations team supports 24x7 and an off shift work schedule may be required.
Qualifications
IDS/IPS
"Network analyst jobs" ; "Network security" ; "firewall analyst"; "network security position"; "network engineer"; "security engineer"
Additional Information
Should you have any questions, please feel free to call:
************
Aditika Sithta
Lead Information Security Architect / Engineer
Security architect job in Durham, NC
EmTacq specializes in EMployer Talent ACQuisitions, matching the most qualified candidates with the most competitive positions available. We pride ourselves on not just putting bodies in seats, rather matching professionals to their careers. We are headquartered in the Raleigh / Durham, NC area. However, as a recruiting agency we service companies and candidates across the United States. We are your best source for professional, value driven low cost recruitment services.
Job Description
The Lead Information Security Engineer will be responsible for designing and implementing a process to analyze the design of technology solutions for threats, attacks, and vulnerabilities that could affect the control environment. Must be a subject matter expert (SME) with strong collaboration skills to work with cross functional teams to ensure the design of technology solutions complies with information security policies, and regulatory obligations.
The Lead Information Security Engineer must have the ability to identify, document, and recommend security safeguards and configurations in a highly complex environment with a demonstrated ability to recognize, and appropriately incorporate layered security safeguards within the network, application, and data layers from a defender's perspective. In this role you must be a positive professional, adaptable, pragmatic, and who is comfortable in delivering clear and concise information at both a technical and managerial level.
Responsibilities:
Design and implement a process to analyze the design of technology solutions for threats, attacks, and vulnerabilities that could affect the client's control environment. Review and approve security configuration checklists (e.g., hardening or lockdown guides) for technology platforms and solutions (e.g., operating systems, databases, firewalls, etc.) Provide security consulting services internally to the engineering organization by giving guidance and functioning as an information security SME. Must have the ability to identify, document, and recommend security safeguards and configurations in a highly complex environment with a demonstrated ability to recognize, and appropriately incorporate layered security safeguards within the network, application, and data layers from a defender's perspective.
Qualifications
Required Experience
*5+ years of experience in one or more of the following information security domains: access management, cryptography, data loss prevention (DLP), emerging technologies (i.e., cloud, mobile, etc.), endpoint security, incident response, malware analysis and protection, network and perimeter security, or web and mobile application security.
*5+ years of experience analyzing the design of technology solutions using common industry frameworks such as DREAD, SSE-CMM (ISO/IEC 21827), STRIDE, or other risk assessment models.
*5+ years of working knowledge of various industry security standards and frameworks including: ISO 27001, ISF Standard of Good Practice (SoGP), NIST Special Publications, etc.
*5+ years of working knowledge of modern enterprise and security architectures, their challenges, common approaches to overcome their challenges, and their inherent security strengths and weaknesses.
*Teamwork and communication skills, both written and verbal.
Preferred Experience
*Bachelor's degree in Computer Science, Information Systems, or related field. 8+ years of equivalent work experience required in lieu of degree is acceptable.
*Professional certifications such as: CISSP, CISA, CISM, GIAC, CGEIT, CRISC, CEH, or other relevant industry certification strongly preferred.
Additional Information
Equal Employment Opportunity
Our client is proud to be an equal opportunity/affirmative action employer. We are committed to attracting, retaining and maximizing the performance of a diverse and inclusive workforce. It is their policy to ensure equal employment opportunity without discrimination or harassment on the basis of race, color, creed, religion, national origin, alienage or citizenship status, age, sex, sexual orientation, gender identity or expression, marital or domestic/civil partnership status, disability, veteran status, genetic information or any other basis protected by law.
Sr. Security Analyst
Security architect job in Durham, NC
Procom is a leading provider of professional IT services and staffing to businesses and governments in Canada. With revenues over $500 million, the Branham Group has recognized Procom as the 3rd largest professional services firm in Canada and is now the largest “Canadian-Owned” IT staffing/consulting company.
Procom's areas of staffing expertise include:
• Application Development
• Project Management
• Quality Assurance
• Business/Systems Analysis
• Datawarehouse & Business Intelligence
• Infrastructure & Network Services
• Risk Management & Compliance
• Business Continuity & Disaster Recovery
• Security & Privacy
Specialties• Contract Staffing (Staff Augmentation)
• Permanent Placement (Staff Augmentation)
• ICAP (Contractor Payroll)
• Flextrack (Vendor Management System)
Job Description
Sr. Security Analyst
On behalf of our client, Procom Services is searching for a Sr. Security Analyst for a contract opportunity in Durham, NC.
Sr. Security Analyst Job Details
Responsible for user account administration in a multi-platform environment and ensure that administration procedures are aligned with overall Information Security policies and standards. Assist in the development of access controls to safeguard customer systems against accidental or unauthorized modification, destruction or disclosure.
Maintain user access to securable customer system resources (UNIX, OS390 Mainframe, iSeries, Windows / Active Directory, Outlook Exchange) performing tasks such as: creation / configuration of user logon Ids and updating access control lists, access provisioning and access removals and access terminations.
Perform detailed analysis of access requests/processes and provide recommendations for improvement to senior team members and Information Security management.
Educate information / resource owners in the implementation of necessary information security controls.
Perform standard and non-standard processing of security authorization requests.
Work with resource owners to determine appropriate security policies for securable customer resources.
Provide on-call support for after-hours system access issues and troubleshoot system access problems and failures.
Report suspected information security misuse to manager or director.
Assist resource owners and IT staff in understanding and responding to security access exceptions.
Sr. Security Analyst Mandatory Skills
- Bachelor's degree in Computer Science.
- 2 years of security administration experience, or related technical system administration experience.
- In lieu of degree 5 years of security administration experience.
- Familiarity with audit and risk-related methodologies; such as COBIT and HIPAA.
- Systems administration experience within other aspects of IT
- Demonstrated security administration experience on two or more platforms (UNIX, OS390 Mainframe, iSeries, Windows / Active Directory, Outlook Exchange)
- Demonstrated experience working with a managed services organization.
- Demonstrated experience working with a request ticketing system, such as Triole.
- Strong analytical and problem-solving skills.
- Ability to present and discuss technical information to users with varying technical expertise.
- Proven ability to work under stress in emergencies. Flexibility to handle pressure from many directions simultaneously.
- Must be detail-oriented with a high level of accuracy.
- Excellent written and verbal communication skills.
- Demonstrated ability to develop and maintain collaborative working relationships across multiple teams.
- Strong customer focus and the ability to manage customer expectations.
- Must have strong team-oriented interpersonal skills and the ability to effectively interface with a wide variety of people.
- Demonstrated commitment to continuous process improvement.
- CISSP, CISA, or other security / audit / field related certifications a plus
Sr. Security Analyst Start Date
ASAP
Sr. Security Analyst Assignment Length
7+ months
Additional Information
All your information will be kept confidential according to EEO guidelines. Please send your resume in
Word
format only.
Security Engineer, Level III
Security architect job in Durham, NC
This individual will be responsible for providing tier III support for a Managed Service Security Provider (MSSP). The successful candidate will be an integral member of the security engineering team and will need to be fully cognizant of state-of-the-art network, firewall, and other security technologies, products and solutions as well as industry best practice with regard to the design, implementation and deployment of next generations security devices.
This individual should have hands-on experience configuring, installing and managing Fortigate, Cisco ASA, Checkpoint, SonicWall or Blue Coat security devices. This person must be able to communicate, and document instructions effectively with Tier 1 and 2 support teams. Excellent customer service skills and written communication are required.
This position is located in Durham, NC.
Qualifications:
A Bachelors or Master's degree preferably in Computer Engineering/Networking, international equivalent, or equivalent experience
Minimum of 5 years of experience designing, implementing and deploying next generation firewalls based on Information Security Best Practices
Hands on experience in security systems, including firewalls, intrusion detection systems, anti-virus software, authentication systems, log management, content filtering, etc
Minimum of 7 years experience in networking, troubleshooting, and analysis tools
Expert understanding and working knowledge of TCP/IP, access-control lists, VLANs, VPNs, firewalls, and dynamic routing protocols such as BGP, OSPF and EIGRP
Evaluates and recommends solutions for highly complex security systems according to industry best practices to safeguard internal information systems and databases
Excellent communication skills and experience working collaboratively in cross-functional teams.
On-call Duties
Ability to travel as needed, approximately 1-3 times a quarter. Can be both domestic and global travel.
Desired:
Vender Certification, preferably Fortinet/Cisco/Blue Coat
Security Certifications: CCNA, CCNP-Security
The ability to define security requirements and subsequently reviews complex systems to determine if they have been designed to comply with established standards
The ability to conduct research and inform management of appropriate developments in firewall, IDPS, WCF, DLP, Application Control and VPN and secure networking technologies and products
Compensation:
A competitive package consisting of a base salary, and full company benefits
Company information
We help nations, governments and businesses around the world defend themselves against cybercrime, reduce their risk in the connected world, comply with regulation, and transform their operations. We do this using our unique set of solutions, systems, experience and processes - often collecting and analyzing huge volumes of data. We employ over 4,000 people across 18 countries in the Americas, APAC, UK and EMEA
Sr. Security Engineer
Security architect job in Morrisville, NC
The ideal candidate will have engineering expertise as it relates to endpoint security technologies to include Antivirus: EDR/XDR, Symantec End-point Security Complete (SESC), and other industry end-point toolsets; preferably in a large organization.
Requirements:
Advanced experience of Windows domain, workstation platform, registry, protocols, etc. to include emerging platforms with mobility (iOS, Android)
Ability to implement, configure, and utilize Symantec Antivirus features within Symantec Endpoint Security Complete to implement endpoint security
Ability to utilize Symantec Cyber Defense Manager (CDM) for Endpoint and Enterprise protection
Experience engineering computer builds/security policies
Providing security guidance of technical engineering for endpoint environments, settings, policies, and design configurations
Able to communicate complex issues to other engineers and work with other engineers and/or vendor to debug and/or change configuration to solve systemic configuration problems
Self-motivated; must take ownership of issues
Commitment to following through until complete resolution of problem
Flexible; be able to adapt to changes in the work environment
Ability to multitask
Excellent written and oral communication skills
Ability to find creative solutions to complex problems
This individual must possess well-rounded technology experience in a distributed computing environment.
Candidate must have 3 - 7 years of relevant technology and infrastructure experience.
Desired Skills:
Project planning experience
Excellent writing skills
Windows, mac OS, Linux iOS
Azure, Amazon, and Google Cloud
Microsoft office suite of applications
Apple IOS, Android, MDM services
Auto-ApplyINFO SECURITY ENGINEER 5 (Penetration Testing)
Security architect job in Winston-Salem, NC
Type: Contract Duration: 3 months Job description: • Conduct dynamic application security testing using both manual and automated testing tools. • Review test results from tools • Ensure that automated tests are completed successfully • Configure tools as required to be successful in evaluating VERA (Vendor remote access) applications
• Identify and remove any false positives from automated testing tool reports
• Triage & Disposition results and enforce a Bug Bar
• Verify/validate defect fixes
• Provide application security consulting SME Support to developers
• Assist developers with understanding of security defects and risk
• Assist in defining acceptable solution to fix defects
• Communicate Security risk to ISCs and ORCs to document security issues and controls for security planning purposes
• Help maintain Security Coding Standards and Bug Bar as required
• Assist in the Development of standards as required
• Provide training
• Stay up to speed on 3rd party (inside and outside Wells Fargo) known security vulnerabilities
• Develop and review malicious use cases/threat models
• Maintain a broad understanding of security technologies and products
• Actively participate on improving the security culture and education throughout the organization
Qualifications
Required skills:
• 5+ years of experience in security applications and systems
• Minimum of 5 years of Information Security Engineer/Consultant experience with application penetration testing.
• Minimum of 5 years of demonstrated experience with automated penetration tools
• Minimum of 5 years of demonstrated experience with manual penetration testing tools
• Demonstrated experience with creating and communication of reports regarding web application vulnerabilities to various level of personnel within a large organization
Desired skills:
• Advanced Information Security technical skills
• Ability to manage complex issues and develop solutions
• Excellent verbal and written communication skills
• Knowledge and understanding of application or software security such as: web application penetration testing, secure code review, secure static code analysis
• Knowledge and understanding of banking or financial services industry
• Experience working in a large enterprise environment
• Strong analytical skills with high attention to detail and accuracy
• Knowledge and understanding of information security industry standards and government regulations
• Ability to manage multiple and competing priorities
• Ability to work with limited supervision
• Ability to take on a high level of responsibility, initiative, and accountability
• Good attention to detail and accuracy skills
• Strong collaboration and partnering skills
• Demonstrated experience developing and reviewing malicious use cases/threat models
Job expectations
• Ability to work weekends and holidays as needed or scheduled
Candidate will be required to work onsite at certain facilities in these cities: MN-Minneapolis; AZ-Chandler; NC-Charlotte;NC-Winston Salem; CA - San Francisco
Additional Information
All your information will be kept confidential according to EEO guidelines.
**Please let me know if you might someone to refer or if you are interested for the role.
**Please reply with an updated copy of your resume and preferred time for a call.
**You can call me back at
************
.
Network Security Analyst
Security architect job in Durham, NC
Established in 1991, Collabera is one of the fastest growing end-to-end information technology services and solutions companies globally. As a half a billion dollar IT company, Collabera's client-centric business model, commitment to service excellence and Global Delivery Model enables its global 2000 and leading mid-market clients to deliver successfully in an increasingly competitive marketplace.
With over 8200 IT professionals globally, Collabera provides value-added onsite, offsite and offshore technology services and solutions to premier corporations. Over the past few years, Collabera has been awarded numerous accolades and Industry recognitions including.
Collabera awarded Best Staffing Company to work for in 2012 by SIA. (hyperlink here)
Collabera listed in GS 100 - recognized for excellence and maturity
Collabera named among the Top 500 Diversity Owned Businesses
Collabera listed in GS 100 & ranked among top 10 service providers
Collabera was ranked:
32 in the Top 100 Large Businesses in the U.S
18 in Top 500 Diversity Owned Businesses in the U.S
3 in the Top 100 Diversity Owned Businesses in New Jersey
3 in the Top 100 Privately-held Businesses in New Jersey
66th on FinTech 100
35th among top private companies in New Jersey
***********************************************
Collabera recognizes true potential of human capital and provides people the right opportunities for growth and professional excellence. Collabera offers a full range of benefits to its employees including paid vacations, holidays, personal days, Medical, Dental and Vision insurance, 401K retirement savings plan, Life Insurance, Disability Insurance.
Job Description
Work Location: Durham NC 27703
Job Title: Network Security Analyst
Duration: 24 Months
Roles & Responsibilities:
• Primary job responsibility will be to perform Intrusion Detection Sensor Threat Analysis.
• Support for any one of McAfee IDS, Sourcefire IDS, Cisco IDS, Tipping Point IDS, Enterasys IDS, Juniper IDP and Fortinet IDS strongly desired.
• The Operations team supports 24x7 and an off shift work schedule may be required.
Qualifications
IDS/IPS
"Network analyst jobs" ; "Network security" ; "firewall analyst"; "network security position"; "network engineer"; "security engineer"
Additional Information
Should you have any questions, please feel free to call:
************
Aditika Sithta
Lead Information Security Architect / Engineer
Security architect job in Durham, NC
EmTacq specializes in EMployer Talent ACQuisitions, matching the most qualified candidates with the most competitive positions available. We pride ourselves on not just putting bodies in seats, rather matching professionals to their careers. We are headquartered in the Raleigh / Durham, NC area. However, as a recruiting agency we service companies and candidates across the United States. We are your best source for professional, value driven low cost recruitment services.
Job Description
The Lead Information Security Engineer will be responsible for designing and implementing a process to analyze the design of technology solutions for threats, attacks, and vulnerabilities that could affect the control environment. Must be a subject matter expert (SME) with strong collaboration skills to work with cross functional teams to ensure the design of technology solutions complies with information security policies, and regulatory obligations.
The Lead Information Security Engineer must have the ability to identify, document, and recommend security safeguards and configurations in a highly complex environment with a demonstrated ability to recognize, and appropriately incorporate layered security safeguards within the network, application, and data layers from a defender's perspective. In this role you must be a positive professional, adaptable, pragmatic, and who is comfortable in delivering clear and concise information at both a technical and managerial level.
Responsibilities:
Design and implement a process to analyze the design of technology solutions for threats, attacks, and vulnerabilities that could affect the client's control environment. Review and approve security configuration checklists (e.g., hardening or lockdown guides) for technology platforms and solutions (e.g., operating systems, databases, firewalls, etc.) Provide security consulting services internally to the engineering organization by giving guidance and functioning as an information security SME. Must have the ability to identify, document, and recommend security safeguards and configurations in a highly complex environment with a demonstrated ability to recognize, and appropriately incorporate layered security safeguards within the network, application, and data layers from a defender's perspective.
Qualifications
Required Experience
*5+ years of experience in one or more of the following information security domains: access management, cryptography, data loss prevention (DLP), emerging technologies (i.e., cloud, mobile, etc.), endpoint security, incident response, malware analysis and protection, network and perimeter security, or web and mobile application security.
*5+ years of experience analyzing the design of technology solutions using common industry frameworks such as DREAD, SSE-CMM (ISO/IEC 21827), STRIDE, or other risk assessment models.
*5+ years of working knowledge of various industry security standards and frameworks including: ISO 27001, ISF Standard of Good Practice (SoGP), NIST Special Publications, etc.
*5+ years of working knowledge of modern enterprise and security architectures, their challenges, common approaches to overcome their challenges, and their inherent security strengths and weaknesses.
*Teamwork and communication skills, both written and verbal.
Preferred Experience
*Bachelor's degree in Computer Science, Information Systems, or related field. 8+ years of equivalent work experience required in lieu of degree is acceptable.
*Professional certifications such as: CISSP, CISA, CISM, GIAC, CGEIT, CRISC, CEH, or other relevant industry certification strongly preferred.
Additional Information
Equal Employment Opportunity
Our client is proud to be an equal opportunity/affirmative action employer. We are committed to attracting, retaining and maximizing the performance of a diverse and inclusive workforce. It is their policy to ensure equal employment opportunity without discrimination or harassment on the basis of race, color, creed, religion, national origin, alienage or citizenship status, age, sex, sexual orientation, gender identity or expression, marital or domestic/civil partnership status, disability, veteran status, genetic information or any other basis protected by law.
Sr. Security Analyst
Security architect job in Durham, NC
Procom is a leading provider of professional IT services and staffing to businesses and governments in Canada. With revenues over $500 million, the Branham Group has recognized Procom as the 3rd largest professional services firm in Canada and is now the largest “Canadian-Owned” IT staffing/consulting company.
Procom's areas of staffing expertise include:
• Application Development
• Project Management
• Quality Assurance
• Business/Systems Analysis
• Datawarehouse & Business Intelligence
• Infrastructure & Network Services
• Risk Management & Compliance
• Business Continuity & Disaster Recovery
• Security & Privacy
Specialties• Contract Staffing (Staff Augmentation)
• Permanent Placement (Staff Augmentation)
• ICAP (Contractor Payroll)
• Flextrack (Vendor Management System)
Job Description
Sr. Security Analyst
On behalf of our client, Procom Services is searching for a Sr. Security Analyst for a contract opportunity in Durham, NC.
Sr. Security Analyst Job Details
Responsible for user account administration in a multi-platform environment and ensure that administration procedures are aligned with overall Information Security policies and standards. Assist in the development of access controls to safeguard customer systems against accidental or unauthorized modification, destruction or disclosure.
Maintain user access to securable customer system resources (UNIX, OS390 Mainframe, iSeries, Windows / Active Directory, Outlook Exchange) performing tasks such as: creation / configuration of user logon Ids and updating access control lists, access provisioning and access removals and access terminations.
Perform detailed analysis of access requests/processes and provide recommendations for improvement to senior team members and Information Security management.
Educate information / resource owners in the implementation of necessary information security controls.
Perform standard and non-standard processing of security authorization requests.
Work with resource owners to determine appropriate security policies for securable customer resources.
Provide on-call support for after-hours system access issues and troubleshoot system access problems and failures.
Report suspected information security misuse to manager or director.
Assist resource owners and IT staff in understanding and responding to security access exceptions.
Sr. Security Analyst Mandatory Skills
- Bachelor's degree in Computer Science.
- 2 years of security administration experience, or related technical system administration experience.
- In lieu of degree 5 years of security administration experience.
- Familiarity with audit and risk-related methodologies; such as COBIT and HIPAA.
- Systems administration experience within other aspects of IT
- Demonstrated security administration experience on two or more platforms (UNIX, OS390 Mainframe, iSeries, Windows / Active Directory, Outlook Exchange)
- Demonstrated experience working with a managed services organization.
- Demonstrated experience working with a request ticketing system, such as Triole.
- Strong analytical and problem-solving skills.
- Ability to present and discuss technical information to users with varying technical expertise.
- Proven ability to work under stress in emergencies. Flexibility to handle pressure from many directions simultaneously.
- Must be detail-oriented with a high level of accuracy.
- Excellent written and verbal communication skills.
- Demonstrated ability to develop and maintain collaborative working relationships across multiple teams.
- Strong customer focus and the ability to manage customer expectations.
- Must have strong team-oriented interpersonal skills and the ability to effectively interface with a wide variety of people.
- Demonstrated commitment to continuous process improvement.
- CISSP, CISA, or other security / audit / field related certifications a plus
Sr. Security Analyst Start Date
ASAP
Sr. Security Analyst Assignment Length
7+ months
Additional Information
All your information will be kept confidential according to EEO guidelines. Please send your resume in Word format only.