IT Senior Microsoft Security Engineer
Security Architect Job 28 miles from Centerville
This role requires expert skills in Microsoft Security, Microsoft Tenant/M365, Azure, and Purview platform to adapt to the needs of our dynamic digital workplace. As a Security Engineer, you will provide strategic thinking and functional support to enhance capabilities in the areas of tenant management of our M365 Tenant, AAD/EntraID, Intune, and Purview service configuration, feature implementation and support. You will work with IT engineers, Applications Team and Vendors from other disciplines to develop strategies to deploy new security services, Microsoft M365, Zero Trust and Azure services with the goal of improving internal collaboration, productivity and knowledge sharing. You will help shape and deliver the future of our secured M365 tenant, Zero Trust and Purview. You must have a strong knowledge of the Microsoft M365 Ecosystem, defender security, DLP monitoring and device management aspects that are essential to meeting our business demands.
Position based in Draper, Utah or San Diego California with eligibility for a hybrid work schedule.
SUPERVISORY RESPONSIBILITIES
No supervisory responsibilities for this role. / This position has supervisory responsibilities.
ESSENTIAL DUTIES AND RESPONSIBILITIES
Manage Systems Security at all levels, IAM, Client, and work with the policies in governance. Security expertise in configuring, creating, deploying, and monitoring Microsoft environments and software while ensuring optimized performance.
Administer, manage, and optimize via Microsoft for Cloud Apps external SAS application (example; Smartsheet, etc), SharePoint, Mail, Teams and computer policies in tandem with governance and compliance to ensure seamless collaboration across the organization.
Adherence to best practices for secure and efficient security of M365 Applications and SAS apps through Microsoft defender. Manage and administer the Microsoft Tenant environment, including site collections, permissions, and content management, ensuring high availability and performance.
Strive to deliver Microsoft cloud technology and products within our roadmap on schedule, and with the highest quality.
Provide advice, guidance, and direction to carry out plans and procedures, ensuring schedule attainment, product development, process adherence, and performance.
Provide vendor tier support for operations and support teams, including root cause analysis and preventative analysis.
Provide technical support with expert knowledge and act as the escalation point for the Client Support Services Team.
Facilitate support for anything related to Computing environment, focusing on our Security Protection, and application protection management.
Contribute to ITSM Knowledge Base IT and ISO procedures. Solid understanding ITIL principles.
Participate in the design and implementation of secured Microsoft deployments that increase productivity or enhance overall business operations.
Documentation and Reporting: prepare and maintain comprehensive documentation, including information and service management plans, service agreement reports, system operational service agreements, and compliance reports.
PREFERRED
Possessing expert knowledge of Microsoft Tenants, M365 security, AAD/EntraID and Purview is a plus.
Possess Microsoft cloud support experience in an enterprise environment.
Proven experience with Windows, Azure Directory, Systems Security and Managing Policies.
Experience developing secure solutions using Microsoft cloud services.
Proven skills managing Defender Platform (Defender for Cloud Apps and Purview setup is a Plus).
Good knowledge level experience within Microsoft platform Protection Engineering.
Manage Intune mobile device management solutions, specifically Microsoft Intune and Apple Business Manager.
Open to work on other assigned towards the users benefit within the organization.
QUALIFICATIONS AND EXPERIENCE
Bachelor's degree in related engineering, computer science, or a related field. Experience in lieu of a degree may be considered.
Minimum of 10 Years of Professional experience with 8+ years specifically as a Microsoft Engineer.
Understanding of the Microsoft Azure, Azure Active Directory management, M365 platforms, Email relays, Networking, and a plus on MSFT Sentinel monitoring baseline.
Must have proven experience with PowerShell scripting and automation tools.
Certifications in Microsoft technologies (e.g., Microsoft Certified: Azure Administrator Associate, Microsoft 365 Certified: Security Administrator Associate) are highly desirable.
Up-to-date knowledge of emerging Microsoft trends and related technologies.
Ability to research and recommend innovative and where possible, automated approaches for systems administration and IT related tasks.
Proven history of Teamwork, problem solving, coaching, influence, analytical thinker.
Strong collaboration skills, with ability to train and support non-technical users.
PHYSICAL DEMANDS
While performing the duties of this job the employee is regularly required to remain in an office at a computer workstation and access information from a computer. The employee is required to be mobile to, from, and within the office. The employee may occasionally move up to 25 pounds.
WORK ENVIORMENT AND EXPECTATIONS
Draper Utah Office or San Deigo CA -based position with the potential for hybrid work within the Utah State or San Diego, CA only, subject to approval.
Employees must maintain the same level of performance, engagement, and availability in hybrid settings as in-office roles.
If you're passionate about IT Security, thrive in a fast-paced environment, apply today!
LifeWave is committed to creating an inclusive workplace that values diversity and promotes equal opportunities for all. We embrace the principles of the Americans with Disabilities Act (ADA) and strive to provide reasonable accommodations to qualified individuals with disabilities.
In our pursuit of building a diverse and talented team, we encourage candidates of all abilities to apply for positions at LifeWave. If you require accommodation during the application or interview process, please inform our HR department, and we will work with you to ensure your needs are met.
Blockchain Security Engineer
Security Architect Job 11 miles from Centerville
Ready to be pushed beyond what you think you're capable of? At Coinbase, our mission is to increase economic freedom in the world. It's a massive, ambitious opportunity that demands the best of us, every day, as we build the emerging onchain platform - and with it, the future global financial system.
To achieve our mission, we're seeking a very specific candidate. We want someone who is passionate about our mission and who believes in the power of crypto and blockchain technology to update the financial system. We want someone who is eager to leave their mark on the world, who relishes the pressure and privilege of working with high caliber colleagues, and who actively seeks feedback to keep leveling up. We want someone who will run towards, not away from, solving the company's hardest problems.
Our work culture is intense and isn't for everyone. But if you want to build the future alongside others who excel in their disciplines and expect the same from you, there's no better place to be.
At Coinbase, security isn't just a priority. It's the foundation of everything we do. In the fast-evolving world of digital currency, where trust is paramount, security breaches can mean the difference between success and failure. That's why we've made security a cornerstone of our mission, setting the standard for protecting millions of customers and billions of dollars in assets.
As a Blockchain Security Engineer on the Decentralized Financial Security Team, you will work closely with engineers, technical product managers and senior leadership on designing secure products from the ground up. You will be responsible for performing secure design reviews, threat modeling, vendor reviews and secure code reviews for upcoming Coinbase products or features that will be used by millions of customers. You will have an opportunity to work on the latest technology and provide leadership visibility of the current risk posture. You'll also have an opportunity to pitch, lead and participate in cross-functional initiatives that uplevel the security of all Coinbase products and services.
What you'll be doing (ie. job duties): To be completed by all business teams except Eng.
Perform design reviews, threat modeling and code reviews of upcoming features and products.
Identify top product risk areas and lead risk-reduction initiatives with cross-functional teams.
Improve and/or automate existing processes to increase efficiency.
Participate in the team on-call rotation to support engineering teams through timely design consultations, vulnerability analysis, bug fix verification, etc.
What we look for in you (ie. job requirements): To be completed by all business teams except Eng.
Bachelor's degree in Computer Science
Expertise in Application Security and fundamental knowledge of cryptography
2+ years of threat modeling/design review experience
Strong communication skills with the ability to translate technical security requirements and risks into terms that anyone can understand.
Ability to work independently and unblock yourself.
Nice to haves:
MS or PhD in Computer Science or related field.
Experience in at least one of: Go, Ruby or Python.
Experience automating manual processes or carrying out process improvements.
Experience in Blockchain, Exchange, or Decentralized Exchange Security.
ID: P69496
Pay Transparency Notice: Depending on your work location, the target annual salary for this position can range as detailed below. Full time offers from Coinbase also include target bonus + target equity + benefits (including medical, dental, vision and 401(k)).
Pay Range:
$152,405-$179,300 USD
Please be advised that each candidate may submit a maximum of four applications within any 30-day period. We encourage you to carefully evaluate how your skills and interests align with Coinbase's roles before applying.
Commitment to Equal Opportunity
Coinbase is committed to diversity in its workforce and is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, sex, gender expression or identity, sexual orientation or any other basis protected by applicable law. Coinbase will also consider for employment qualified applicants with criminal histories in a manner consistent with applicable federal, state and local law. For US applicants, you may view the Know Your Rights notice here. Additionally, Coinbase participates in the E-Verify program in certain locations, as required by law.
Coinbase is also committed to providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please contact us at accommodations[at]coinbase.com to let us know the nature of your request and your contact information. For quick access to screen reading technology compatible with this site click here to download a free compatible screen reader (free step by step tutorial can be found here).
Global Data Privacy Notice for Job Candidates and Applicants
Depending on your location, the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) may regulate the way we manage the data of job applicants. Our full notice outlining how data will be processed as part of the application procedure for applicable locations is available here. By submitting your application, you are agreeing to our use and processing of your data as required. For US applicants only, by submitting your application you are agreeing to arbitration of disputes as outlined here.
Benefits at Coinbase
Medical Plan, Dental and Vision Plan with generous employee contributions
Health Savings Account with company contributions each pay period
Disability and Life Insurance
401(k) plan with company match
Wellness Stipend
Mobile/Internet Reimbursement
Connections Stipend
Volunteer Time Off
Fertility Counseling and Benefits
Generous Time off/Leave Policy
The option of getting paid in digital currency
Learn more about our mission
Principal Cloud Security Architect - #9096
Security Architect Job 25 miles from Centerville
Principal Cloud Security Architect - Utah or Tempe, Az.
Our clients are the game changers, leaders and investors who fuel the global innovation economy. They're the businesses behind the next medical breakthroughs. And the visionaries whose new technologies could transform the way people live and work. They come to the Company for our expertise, deep network and 30+ years of experience in the industries we serve, and to partner with diverse teams of passionate, enterprising the Company, dedicated to an inclusive approach to helping them grow and succeed at every stage of their business.
Join us at the Company and be part of bringing our clients' world-changing ideas to life. At The Company, we have the opportunity to grow and collectively make an impact by supporting the innovative clients and communities the Company serves. We pride ourselves in having both a diverse client roster and an equally diverse and inclusive organization. And we work diligently to encourage all with different ways of thinking, different ways of working, and especially those traditionally underrepresented in technology and financial services, to apply.
Job Description
Cloud Security Architect provides cyber security advisory services to business units at the Company, and supports IT initiatives and business projects by recognizing security risks and implementing security controls within public and private cloud environments, in adherence to the Company security policies and standards.
The Cloud Security Architect directly engages The Company IT teams to integrate new and existing security solutions.
The Architect will be assigned to large, enterprise and mission critical projects and implement security strategy and architecture, in order to protect the Company assets, manage risk, and maintain compliance.
Knowledge:
· Deep understanding of security architectures, defense in depth, cloud and on-prem security models and concepts
· Proficient in designing and deploying IaaS security solutions, preferably in AWS public cloud.
· Experience and working knowledge of network architecture, subnetting, and TCP/IP protocols, and OSI model layers and protocols at each model layer
· Understanding of international and United States laws and regulations impacting cyber security and personal data privacy, including GLBA, SOX, and the FFIEC Information Security requirements
· Working knowledge of security frameworks and control references such as NIST CSF, CIS 20, COBIT, PCI DSS, OWASP, ISO 27000 family and NIST SP 800 series.
· Familiar with various security architectures and methodologies (Defense in Depth, Segmentation, Least Privilege, Zero-Trust, Kill-Chain, etc.)
Skills:
· Excellent analytical and problem solving skills
· Ability to demonstrate empathy while seeking common interests; effective problem and conflict resolution skills
· Scripting skills (Shell, Python, Java, PHP, PowerShell, etc.) preferred but not required
· Familiar with government security standards and regulations including GLBA, SOX, PCI, COBIT, ITIL - Familiar with various security architectures and methodologies (Defense in Depth, Kill-Chain, NIST, Critical Controls, OWASP, etc.)
· Leadership qualities, desire to influence horizontally and vertically, and mentor team members.
· Excellent written and verbal communication skills
Education/Experience:
· Bachelor's degree in management Information Systems, Computer Science, and/or Business, or equivalent work experience
· 7+ years working in IT security domain
· Experience implementing, supporting, or defining requirements for security tools such as WAF, SIEM, IPS, CASB, EDR
· Experience with AWS public cloud services and security tools - Experience with SIEM technologies.
· Experience with cloud technologies specifically AWS. - Experience with AWS in a security environment preferred. -
· Experience working with Windows and Linux operating systems
· Experience working with firewalls and network IDS/IPS
· Experience doing vulnerability assessments, risk assessments and penetration testing
Certifications:
One or more of the following professional certifications: CISSP, CISM, SANS GIAC, CISA, Security+, AWS Solutions Architect, AWS Security Specialist (or willingness to obtain within 6 months) Strong demonstrated knowledge of networking and TCP/IP protocol or networking certification (CCNA)
For more than 35 years, The Company and its subsidiaries have helped innovative companies and their investors move bold ideas forward, fast. The Company Financial Group's businesses, including The Company, offer commercial and private banking, asset management, private wealth management, brokerage and investment services and funds management services to companies in the technology, life science and healthcare, private equity and venture capital,, The Company operates in centers of innovation around the world.
Client Security Engineer
Security Architect Job 11 miles from Centerville
Meta's Client Security team is seeking experienced Security Engineer who have a track record of solving complex security problems at scale. Client Security Engineers design and develop solutions to ensure Meta's data and systems can only be accessed by trusted devices, and that applicable security policies are enforced on devices.
**Required Skills:**
Client Security Engineer Responsibilities:
1. Drive Meta's trusted devices strategy by building tools that enable connectivity to our infrastructure only from Meta owned and managed devices
2. Build machine attestation and secure certificate storage solutions to enable provable client identity
3. Deploy systems that help mitigate security risks by understanding and controlling what software is allowed to execute on our client devices
4. Develop, validate, and enforce our client security policies
5. Build and deploy tools and automation that proactively detect and respond to security risks and threats to internal corporate services
6. Advise and collaborate with other teams
**Minimum Qualifications:**
Minimum Qualifications:
7. 5+ years of combined experience designing and deploying security infrastructure (such as PKI, key management, and certificate management)
8. 2+ years of software development experience in PHP, Golang, Python, C\C++, Rust, or Ruby
9. Experience applying fundamental security concepts to systems
10. B.S. in Computer Science or a related field, or equivalent experience
**Preferred Qualifications:**
Preferred Qualifications:
11. Mobile Security Experience on iOS and Android platforms including MDM, security policy
12. OS development experience (Windows, Mac, Linux)
13. Experience managing PKI for client devices
**Public Compensation:**
$147,000/year to $208,000/year + bonus + equity + benefits
**Industry:** Internet
**Equal Opportunity:**
Meta is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Meta participates in the E-Verify program in certain locations, as required by law. Please note that Meta may leverage artificial intelligence and machine learning technologies in connection with applications for employment.
Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at accommodations-ext@fb.com.
Sentinel STPA-Sec Systems Security Engineer T3 -14407
Security Architect Job 18 miles from Centerville
RELOCATION ASSISTANCE: Relocation assistance may be available CLEARANCE TYPE: SecretTRAVEL: Yes, 10% of the TimeDescriptionAt Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work - and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history.
The Sentinel Mission Defense Team (MDT) is seeking a highly motivated and qualified system engineer to serve as a System-Theoretic Process Analysis for Security (STPA-Sec) Engineer, Level 2 or Level 3. You will be combining traditional Systems Engineering skills, with a holistic system analyses approach in order to uncover any potential security, safety, or availability features using the existing STPA handbook guidelines, industry security frameworks (NIST, ISO, NISPOM), and Model Based Systems Engineering (MBSE) workspace. You will be generating structured requirements, decomposition strategies, and mitigations within STPA principles. This position will be located in Roy, Utah and may offer a competitive relocation package.
Additional Responsibilities include:
Execute combined traditional Systems Engineering principles, with a holistic system analyses approach in order to uncover any potential safety, security, or availability features using the existing STPA handbook guidelines, and Model Based Systems Engineering (MBSE) workspace
Ability to understand and decompose systems to identify causal scenarios; aptitude to construct control structures and identify unsafe control actions
Assessment and analysis of threats, vulnerabilities, and risk for identified mission-critical functions and critical components
Lead and execute completion Statement of Work requirements, Program Milestone Exit Criteria, and program maturity commitments
Lead in a variety of working groups and customer meetings; ensure communication of risk environment with stakeholders
Self-starters compelled to take action in the workplace without requiring prompting from supervisors
Support MDT with other duties as assigned
Basic Qualifications:
Must be a US Citizen with an active DoD Secret Clearance with an investigation date within the last 6 years
Must be able to be successfully screened for Enhanced Security Clearances, within a reasonable amount of time as determined by the company to meet its business needs
For Level 3 Principal Systems Engineer
Bachelor's degree in a STEM (Science, Technology, Engineering or Mathematics) discipline from an accredited university and 5 years of related experience, or a Master's degree in a STEM discipline and 3 years of related experience, or a PhD in a STEM discipline and 1 year of related experience.
Minimum 2 years of applying and understanding Systems Security Engineering principles applicable to US Government Defense Programs.
Minimum 2 years' experience demonstrating the ability to communicate effectively and clearly present technical approaches and findings.
Minimum 2 years' experience in applying safety thinking to a complex system in a rapidly changing product or technology.
Minimum 2 years' experience in applying analytical methodologies to raw data in order to determine and present clear and precise findings and recommendations.
Minimum 2 years' experience performing against schedule.
Preferred Qualifications:
Active Top-Secret clearance with SAP Access.
Direct experience with ICBM Systems
Experience applying Program Protection principles to US Government Defense Programs and applied knowledge in the application of SSE principles across a broad spectrum of security measures (Cybersecurity, Counterfeit Awareness, Anti-Tamper, HW/SW Assurance, OPSEC, etc.) to protect critical program information (CPI)
Experience developing Systems Security Engineering requirements for hardware and software assurance
Experience with Risk Management (identification and development of risks) and driving risk mitigations to closure.
Experience with assessment and analysis of threats, vulnerabilities, and risk for identified mission-critical functions and critical components.
Direct experience with Model-based Systems Engineering (MBSE) concepts and tools (CAMEO, DOORS)
Position Benefits:
As a full-time employee of Northrop Grumman, you are eligible for our robust benefits package including
Medical, Dental & Vision coverage
Educational Assistance
Life Insurance
Employee Assistance Programs & Work/Life Solutions
Paid Time Off
Health & Wellness Resources
Employee Discounts
This positions standard work schedule is a 9/80. The 9/80 schedule allows employees who work a nine-hour day Monday through Thursday to take every other Friday off. This role may offer a competitive relocation assistance package.
#Sentinelsystems
Salary Range: $81,300.00 - $130,900.00The above salary range represents a general guideline; however, Northrop Grumman considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills and current market conditions.Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. Annual bonuses are designed to reward individual contributions as well as allow employees to share in company results. Employees in Vice President or Director positions may be eligible for Long Term Incentives. In addition, Northrop Grumman provides a variety of benefits including health insurance coverage, life and disability insurance, savings plan, Company paid holidays and paid time off (PTO) for vacation and/or personal business.The application period for the job is estimated to be 20 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates.Northrop Grumman is an Equal Opportunity Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. For our complete EEO and pay transparency statement, please visit *********************************** U.S. Citizenship is required for all positions with a government clearance and certain other restricted positions.
Senior Staff Information Security Engineer
Security Architect Job 11 miles from Centerville
It all started in sunny San Diego, California in 2004 when a visionary engineer, Fred Luddy, saw the potential to transform how we work. Fast forward to today - ServiceNow stands as a global market leader, bringing innovative AI-enhanced technology to over 8,100 customers, including 85% of the Fortune 500 . Our intelligent cloud-based platform seamlessly connects people, systems, and processes to empower organizations to find smarter, faster, and better ways to work. But this is just the beginning of our journey. Join us as we pursue our purpose to make the world work better for everyone.
The ServiceNow Security Organization delivers world-class, innovative security solutions to reduce risk and protect the company and our customers. We enable our customers to migrate their most sensitive data and workloads to the cloud, accelerating our business so that we are the most trusted SaaS provider. We create an environment where our employees are proud to work and can make a positive impact.
**Team**
This position reports to the Director, Security Engineering. The Enterprise Security Engineering team targets building state-of-the-art technology that will help reduce the risk surrounding the sensitive assets of the company with the least impact possible on operations, acts as guidance and facilitator to the security operations teams and helps shifting Security perception from blocker to enabler by building a relationship of trust with the other teams.
**Role**
The Senior Staff Information Security Engineer will serve as a technical subject matter expert within the Infrastructure Security team, responsible for engineering solutions that secure ServiceNow's core enterprise infrastructure. This includes network, server, authentication systems, certificates, and operational tooling. You will drive strategic initiatives that prevent threats, reduce operational risk, and enhance resilience across infrastructure services.
**What you get to do in this role:**
+ Define and execute the technical strategy for securing infrastructure, aligned to risk and business needs
+ Lead efforts to harden network and server infrastructure against unauthorized access, misconfigurations, and malware
+ Architect and implement scalable and automated security controls across authentication, system configurations, and monitoring pipelines
+ Drive secure deployment and management of on-prem containerized environments (e.g., Kubernetes)
+ Establish controls and visibility to manage certificate lifecycle and prevent expiration-related risks
+ Champion operational excellence through automation, outage reduction, and service resilience improvements
+ Represent Infrastructure Security in architecture reviews, incident response, and compliance initiatives
+ Mentor and develop other engineers, influencing secure engineering practices across teams
+ Stay current with industry threats, trends, and mitigation techniques related to infrastructure security
**To be successful in this role you have:**
**Required Skills:**
+ Experience in leveraging or critically thinking about how to integrate AI into work processes, decision-making, or problem-solving. This may include using AI-powered tools, automating workflows, analyzing AI-driven insights, or exploring AI's potential impact on the function or industry.
+ Master's degree in computer science; engineering, or information technology or equivalent industry experience
+ 10+ years of relevant hands-on engineering experience
+ Deep experience with operating system and server security (Linux, Windows)
+ Advanced knowledge of enterprise networking and secure network architectures
+ Proficiency in scripting and automation (Python, Bash, Go, etc.)
**Desirable Skills:**
+ Experience in working with web and database services (REST APIs, JSON, XML, SQL)
+ Experience in working with Splunk and SPL (or other SIEM/Log management systems)
+ Experience in working with cryptography (PKI, TLS, VPNs, secure credential management, disk encryption, certificate and code signing)
+ Experience with infrastructure-as-code and configuration management tools such as Puppet and Ansible to automate system hardening and policy enforcement.
+ Experience in working with hardware virtualization (bare metal servers, storage, load balancing, virtual networking using VMware, Citrix, Hyper-V, etc.)
+ Planning hardware and software system upgrades and configuration changes
+ Automating operations and capacity planning
+ System performance tuning and service monitoring
+ System and software debugging experience with strong troubleshooting skills
+ Familiarity with regulatory and industry certifications (FedRAMP, NIST 800-53, NIST CSF, SOC 2, SOX and GDPR)
+ Ability to analyze and assess complex problems quickly and efficiently
+ Growth mindset approach: hungry and humble with the ability to lead and train others
+ Ability to thrive in a dynamic, driven, fast-paced environment
\#SecurityJobs
**Work Personas**
We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work. Learn more here (************************************************************************************************************************************* .
**Equal Opportunity Employer**
ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, national origin or nationality, ancestry, age, disability, gender identity or expression, marital status, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements.
**Accommodations**
We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact ***************************** for assistance.
**Export Control Regulations**
For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities.
From Fortune. ©2024 Fortune Media IP Limited. All rights reserved. Used under license.
Senior Information Security & Risk Engineer
Security Architect Job 11 miles from Centerville
Headquartered in Dublin, Ohio, Cardinal Health, Inc. (NYSE: CAH) is a global, integrated healthcare services and products company, providing customized solutions for hospitals, health systems, pharmacies, ambulatory surgery centers, clinical laboratories and physician offices worldwide.
The company provides clinically-proven medical products and pharmaceuticals and cost-effective solutions that enhance supply chain efficiency from hospital to home. Cardinal Health connects patients, providers, payers, pharmacists and manufacturers for integrated care coordination and better patient management. Backed by nearly 100 years of experience, with approximately 50,000 employees in 46 countries, Cardinal Health ranks among the top 20 on the Fortune 500.
We currently have a full-time career opening within Information Security to support the growth of our Navista Application Suite and the Integrated Oncology Network (IoN).
**Department overview**
The Information Security department at Cardinal Health enables Cardinal Health to securely deliver healthcare products and solutions that improve the lives of people every day by ensuring security practices and controls are embedded into Cardinal Health's people, process and technology. We are a remote-first team and are excited to offer full-time remote opportunities.
**Functional Overview**
The Senior Information Security & Risk Engineer is a new capability for Cardinal Health and will be executed by the Product Security team. The primary goal of this position is to ensure delivery of best-in-class cybersecurity, risk management, and compliance for Navista, an oncology Managed Service Offering hosted by Cardinal Health.
**Job Overview**
The Information Security & Risk Engineer will be responsible for day-to-day activities in implementing the corporate information security and compliance program. The individual will be a front-line partner to technical teams and work across the organization to deliver security and compliance initiatives aligning to corporate policies, standards, procedures and audit activities. Success in the role will be measured by the effectiveness of the implementation of information security, risk management and compliance directives.
This role will work with various IT and business teams to drive both information security and compliance initiatives. The individual will assist with internal and external security compliance monitoring activities, review client audits, IT control audits, architecture reviews, threat modeling and security risk assessments. Good interpersonal and relationship building skills are essential for success.
**Job Responsibilities Include:**
+ Maintain governance program that ensures that the security policies, standards and process are in place
+ Serve as liaison to other Cardinal Health teams to ensure knowledge share and best practices
+ Partner with the engineering, architecture and operations teams to ensure delivery of infrastructure design and threat models which prove security requirements
+ Monitor security trends and drive security best practices throughout the organization via threat models and risk analysis
+ Evaluate, design, test, and recommend new or improved controls
+ Work with third party firms and consultants to conduct independent security audits, vulnerability scans, and penetration tests
+ Partner with developers to mentor and advise on secure coding and SDLC practices, define test cases and ensure appropriate testing, remediations, and mitigations
+ Investigate, drive resolution and document security incidents
+ Travel to various Integrated Oncology Network (IoN) sites may be required
**Qualifications**
+ Bachelors Degree in related field, or equivalent work experience leading cybersecurity or information security initiatives
+ Have 5+ years information security related work experience, preferably within the healthcare industry
+ Extensive experience with network and infrastructure design and security, ideally within the Azure cloud
+ Experience in vulnerability management programs, vulnerability assessments and advanced understanding of risk management
+ Familiarity with at least one common programming language, software development pipelines, and system lifecycles
+ Familiarity with standards such as HIPAA/HITECH, ISO, ITIL, NIST, PCI DSS, & SOX, CCPA, OWASP
+ Professional security certification (CISSP or CISM preferred)
+ Experience advising and mentoring diverse teams where you do not have direct authority
+ Strong written and verbal communication skills
**Anticipated salary range:** $121,600 - $182,385
**Bonus eligible:** Yes
**Benefits:** Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
+ Medical, dental and vision coverage
+ Paid time off plan
+ Health savings account (HSA)
+ 401k savings plan
+ Access to wages before pay day with my FlexPay
+ Flexible spending accounts (FSAs)
+ Short- and long-term disability coverage
+ Work-Life resources
+ Paid parental leave
+ Healthy lifestyle programs
**Application window anticipated to close:** 4/7/2025 *if interested in opportunity, please submit application as soon as possible.
The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.
_Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply._
_Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal_ _Opportunity/Affirmative_ _Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law._
_To read and review this privacy notice click_ here (***************************************************************************************************************************
Senior Security Engineer
Security Architect Job 11 miles from Centerville
Why join Pave?
At Pave, our vision is simple - unlock a labor market built on trust.
How are we going to get there? By building a compensation platform powered by the largest real-time compensation dataset on earth, we give you confidence in every compensation decision.
We partner with our customers to help them build and retain world-class teams through planning, communicating, and benchmarking their team's compensation in real time. And you don't have to just hear it from us - you can hear it from our customers: Affirm, Airtable, Ancestry, Clio, Credit Karma, Dropbox, Hover, Hubspot, Grammarly, Ramp, Workato, and (8,500+) more!
If playing to win, building with intellectual honesty, and focusing on the Pave platinum standard sounds like fun, we highly encourage you to reach out. We'd love to partner with you on our journey to change the world of compensation!
Security @ Pave
Security is part of everything we do at Pave. With amazing growth comes amazing engineering and security challenges. This is an opportunity to have a huge impact and run programs at a company that doesn't need to be convinced why security is important. Our customers count on us to secure some of their most sensitive data, and that trust is central to Pave. It's the only way we can unlock a labor market built on trust, and change the world of compensation.
What You'll Bring
5+ years of application security experience as part of a blue team
Expert knowledge of OWASP Top 10 and application security
Security design review experience
Experience in running bug bounty programs and pentesting
Outstanding communication and partnership skills with software engineers
Ideally, experience in Google Cloud Security best practices
Compensation, It's What We Do.
This salary range may include multiple levels. Your level is based on our assessment of your interview performance and experience, which you can always ask the hiring manager about to understand in more detail. Salary is just one component of Pave's total compensation package for employees. Your total rewards package at Pave will include equity, top-notch medical, dental, and vision coverage, an unlimited PTO policy, and many other region-specific benefits.
Our compensation ranges are structured into geographic tiers (1, 2, and 3) based on local market conditions and cost of living, read more about tiers here!!
Salt Lake City pay bands$140,250—$189,750 USDUnderstand our DNA
At Pave, we embrace a relentless pursuit of excellence - we're committed to being in the top tier of our industry in everything we deliver. If you're seeking standard hours and conventional challenges, this might not align with your goals. If you're eager to push boundaries and elevate your potential beyond what you thought possible, we want to hear from you!
Our Compensation Philosophy
We've built our compensation framework to recognize and reward exceptional talent while fostering authentic connections with candidates who share our vision. Our approach emphasizes pay for performance, ensuring that your growth and impact are reflected in your rewards. We continuously innovate our compensation practices to maintain efficiency and fairness over time, creating alignment between candidate aspirations and company success.
FAQ's:
How big is Pave today?
We were founded in 2019 in San Francisco and have grown to 150 employees across the US and the UK.
Where are the Pave offices?
We're headquartered in San Francisco's FiDi neighborhood, with additional offices in New York City and regional hubs in Salt Lake City and the United Kingdom. We embrace a high-energy, collaborative in-person work environment at these locations, operating on a hybrid schedule that brings teams together in-office on Mondays, Tuesdays, and Fridays.
What do employee benefits at Pave look like?
We offer comprehensive medical, dental, and vision coverage, plus mental health support and wellness perks. You'll grow with our quarterly learning stipend, and enjoy daily lunch, dinner, and delicious snacks when you're in the office.
What can I expect in interviewing at Pave?
At Pave, we value intellectual honesty and transparency, and we bring this to our interview process. Throughout your time interviewing with us, we will be evaluating where you can best make an impact through multiple conversations with your recruiter, hiring manager, peers, cross-functional partners, and leadership. We also use our interviews to determine leveling, which is finalized at the end of your interview process by your hiring manager. The majority of our roles have 3-5 interview rounds. You can expect to hear back from our team within 2 days after each interview round. Once we extend an offer, we hope to hear back from you within 3 days. It is extremely important to us that we find a great mutual fit - we're excited to get to know you!
More Questions? Check out our candidate resources page!
Pave is committed to a diverse and inclusive workforce. We are an equal opportunity employer and do not discriminate on the basis of race, ethnicity, gender, gender identity, sexual orientation, protected veteran status, disability, age, or another legally protected status. For individuals with disabilities who would like to request accommodation, please email *******************. Sponsorship for work visas or other permits may be available for certain positions, subject to Pave's policies and legal requirements.
Principal, Microsoft Security Engineer - Purview
Security Architect Job 11 miles from Centerville
Who You'll Work With As a modern technology company, our Slalom Technologists are disrupting the market and bringing to life the art of the possible for our clients. We have passion for building strategies, solutions, and creative products to help our clients solve their most complex and interesting business problems. We surround our technologists with interesting challenges, innovative minds, and emerging technologies.
The Global Technology Microsoft Center of Excellent (MCoE) drives strategic direction and enablement. We accelerate innovation and learning, advance sales and delivery excellence by amplifying Slalom's proven local model with high-caliber Microsoft technology expertise. Our focus is Microsoft's six go-to-market solution areas: Modern Work, Security, Azure Infrastructure, Digital & Application Innovation, Data & AI, and Business Applications.
Slalom is targeting a Principal hire for this role.
What You'll Do
* Implement and manage security solutions for Microsoft environments.
* Focus on enhancing the end user experience across secure solution architectures.
* Deploy tailored M365 Compliance configurations with Purview Information Protection, Data Loss Prevention (DLP), data lifecycle management, and records management.
* Implement and manage Azure data governance solutions.
* Collaborate with IT and security teams to ensure compliance with security policies.
* Conduct security audits and assessments.
* Provide technical support and guidance on security matters.
* Develop and maintain security policies, standards, and guidelines.
* Stay current with emerging security threats and technologies.
Who You Are
* Experience as a Microsoft Security Engineer or similar role.
* Proficiency in Microsoft security technologies and tools, including Purview Information Protection, DLP, data lifecycle management, records management, and Azure data governance.
* Strong troubleshooting and problem-solving skills.
* Excellent communication and teamwork skills.
* Ability to work independently and as part of a team.
* Strong understanding of security best practices and regulatory requirements.
* Experience with security frameworks such as NIST, ISO 27001, and CIS Controls.
About Us
Slalom is a fiercely human business and technology consulting company that leads with outcomes to bring more value, in all ways, always. From strategy through delivery, our agile teams across 52 offices in 12 countries collaborate with clients to bring powerful customer experiences, innovative ways of working, and new products and services to life. We are trusted by leaders across the Global 1000, many successful enterprise and mid-market companies, and 500+ public sector organizations to improve operations, drive growth, and create value. At Slalom, we believe that together, we can move faster, dream bigger, and build better tomorrows for all.
Compensation and Benefits
Slalom prides itself on helping team members thrive in their work and life. As a result, Slalom is proud to invest in benefits that include meaningful time off and paid holidays, parental leave, 401(k) with a match, a range of choices for highly subsidized health, dental, & vision coverage, adoption and fertility assistance, and short/long-term disability. We also offer yearly $350 reimbursement account for any well-being-related expenses, as well as discounted home, auto, and pet insurance.
Slalom is committed to fair and equitable compensation practices. For this position at the Principal level the base salary pay range is $122,000 to $225,000. In addition, individuals may be eligible for an annual discretionary bonus. Actual compensation will depend upon an individual's skills, experience, qualifications, location, and other relevant factors. The salary pay range is subject to change and may be modified at any time.
EEO and Accommodations
Slalom is an equal opportunity employer and is committed to inclusion, diversity, and equity in the workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veterans' status, or any other characteristic protected by federal, state, or local laws. Slalom will also consider qualified applications with criminal histories, consistent with legal requirements. Slalom welcomes and encourages applications from individuals with disabilities. Reasonable accommodations are available for candidates during all aspects of the selection process. Please advise the talent acquisition team if you require accommodations during the interview process.
We are accepting applicants until 5/7/2025..
Information Systems Security Officer (ISSO) III
Security Architect Job 21 miles from Centerville
div class="mt-5" div class="redactor-styles" strong Top Secret Clearance Jobs/strong is dedicated to helping those with the most exclusive security clearance find their next career opportunity and get interviews within 48 hours.br/br/strongstrong :br/br//strong/strongstrong Type of Requisition:br/br//strong Regularbr/br/strongstrong Clearance Level Must Currently Possess:br/br//strong/strong Top Secret/SCIbr/br/strongstrong Clearance Level Must Be Able To Obtain:br/br//strong/strong Top Secret SCI + Polygraphbr/br/strongstrong Suitability:br/br//strong/strongstrong Public Trust/Other Required:br/br//strong Nonebr/br/strongstrong Job Family:br/br//strong/strong Information Securitybr/br/strongstrong Skills:br/br//strong/strongstrong Job Qualifications:br/br//strong Information Security, Information Security Management, Information System Securitybr/br/strongstrong Certifications:br/br//strong/strong Cisco Certified Network Associate (CCNA) Security - Cisco, GICSP: Global Industrial Cyber Security Professional - Global Information Assurance Certification (GIAC), GSEC: GIAC Security Essentials Certification - Global Information Assurance Certification (GIAC)br/br/strongstrong Experience:br/br//strong/strong5 + years of related experiencebr/br/strongstrong US Citizenship Required:br/br//strong/strong Yesbr/br/strongstrong Job Description:br/br//strong/strong The Information Systems Security Officer (ISSO) II is responsible for ensuring the appropriate operational security posture is maintained for an information system and as such, works in close collaboration with the ISSM and ISO. The position shall have the detailed knowledge and expertise required to manage the security aspects of an information system and, in many organizations, is assigned responsibility for the day-to-day security operations of a system.br/br/This will include physical and environmental protection, personnel security, incident handling, and security training and awareness. It will be required to work in close coordination with the ISSM and ISO in monitoring the information system(s) and its environment of operation to include developing and updating the authorization documentation, implementing configuration management across authorization boundaries. This will include assessing the security impact of those changes and making recommendation to the ISSM. The primary function is working within Special Access Programs (SAPs) supporting Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense (OSD) and Military Compartments efforts. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities.br/br/strongstrong Performance Shall Include:br/br//strong/strongulli Assist the ISSM in meeting their duties and responsibilities./lili Prepare, review, and update authorization packages./lili Ensure approved procedures are in place for clearing, sanitizing, and destroying various types of hardware and media./lili Notify ISSM when changes occur that might affect the authorization determination of the information system(s)./lili Conduct periodic reviews of information systems to ensure compliance with the security authorization package./lili Coordinate any changes or modifications to hardware, software, or firmware of a system with the ISSM and AO/DAO prior to the change./lili Monitor system recovery processes to ensure security features and procedures are properly restored and functioning correctly./lili Ensure all IS security-related documentation is current and accessible to properly authorized individuals./lili Ensure audit records are collected, reviewed, and documented (to include any anomalies)/lili Attend required technical and security training (e.g., operating system, networking, security management) relative to assigned duties./lili Execute the cyber security portion of the self-inspection, to include security coordination and review of all system assessment plans./lili Identify cyber security vulnerabilities and assist with the implementation of the countermeasures for them./lili Prepare reports on the status of security safeguards applied to computer systems./lili Perform ISSO duties in support of in-house and external customers./lili Conduct continuous monitoring activities for authorization boundaries under your preview./lili Assist Department of Defense, National Agency and Contractor organizations with the development of assessment and authorization (Aamp;A) efforts.br/br//li/ulstrongstrong Experience:br/br//strong/strongulli5+ years related experience./lili2+ years SAP experience required./lili Prior performance in roles such as System, Network Administrator or ISSO.br/br//li/ulstrongstrong Education:br/br//strong/strongulli Bachelor's degree in a related area or equivalent experience (4 years)br/br//li/ulstrongstrong Certifications:br/br//strong/strongulli IAT Level II ( Security+ CE, CCNA Security, etc) or IAM Level II - with in 6 months of hirebr/br//li/ulstrongstrong Clearance Required To Start:br/br//strong/strongulli TS/SCI required/lili Must be able to Attain - TS/SCI with CI Polygraphbr/br//li/ul#AirforceSAPOpportunities #ISSO IIIbr/br/The likely salary range for this position is $92,331 - $121,785. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.br/br/strongstrong Scheduled Weekly Hours:br/br//strong/strong40br/br/strongstrong Travel Required:br/br//strong/strong10-25%br/br/strongstrong Telecommuting Options:br/br//strong/strong Onsitebr/br/strong Work Location:br/br//strong USA UT Ogdenbr/br/strong Additional Work Locations:br/br//strongstrongstrong Total Rewards At GDIT:br/br//strong/strong Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.br/br/We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 30 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.br/br/We connect people with the most impactful client missions, creating an unparalleled work experience that allows them to see their impact every day. We create opportunities for our people to lead and learn simultaneously. From securing our nation's most sensitive systems, to enabling digital transformation and cloud adoption, our people are the ones who make change real.br/br/GDIT is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status, or any other protected class.
/div
/div
Information Systems Security Officer (ISSO)
Security Architect Job 21 miles from Centerville
Dark Wolf Solutions is looking for an Information Systems Security Officer (ISSO) to provide support to the USG to ensure industrial information systems are in compliance with current industrial security regulations and governing policies, to ensure that the systems have the proper safeguards to protect classified data. The ISSO will inspect information systems at contractor sites nationwide and assist with assessment and accreditation (A&A). This position will use industrial security policy guidance to include ICD 503, ICD 705, and SEAD 4 (replaced ICD 704) as well as the National Industrial Security Program Operating Manual (NISPOM) and its supplement. This position will require a Top Secret security clearance and is located in Ogden, UT.
Required Qualifications:
2+ years of experience with A&A process, ICD 503, and NIST Risk Management Framework (RMF)
2+ years of experience writing technical reports related to A&A, System Security Plans (SSP), security policies and/or guidance
2+ years of demonstrated knowledge and technical skills in: network architecture, configuration of a local area network (LAN), and securing operating systems
5+ years of experience with Microsoft Windows Server, Windows 7, Windows 8, Windows 10, Microsoft Office Suite (Word, Excel, PowerPoint), Apple/MAC OS, Unix/Linus systems, and virtualization software (VMware, Hyper-V, Virtual Box)
Experience using vulnerability and compliance assessment tools such as Nessus, SCAP, or App Detective
At least one (1) of the following cyber security certifications: Security+ CE, SSCP, CAP, CISM, CASP, CISSP, GSEC, GICSP, GSLC, CEH, CDNA, CSSLP
Ability to communicate on technical subjects using clear, concise, non-technical language to include strong written communications, ability to provide written feedback on documents, and ability to prepare briefings
Ability to travel domestically (20% to 40% of the time)
HS Diploma
US Citizenship and an active Top Secret security clearance with SCI eligibility.
Desired Qualifications:
Bachelor's Degree preferred
Two (2) or more of the following certifications: Security+ CE, SSCP, CAP, CISM, CASP, CISSP, GSEC, GICSP, GSLC, CEH, CDNA, CSSLP
Demonstrated experience giving technical guidance to system administrators
Three (3) or more years of experience with the IC Community's/Sponsor's A&A process, ICD 503, and NIST Risk Management
Any additional certifications relevant to system and cyber security not previously listed
This position is located in Ogden, UT.
We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories.
In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.
Application Security Engineer
Security Architect Job 11 miles from Centerville
Evaluates application security in all phases of the software development life cycle. Works closely with team members to define application security best practices, performs software architecture and design reviews, and supports the identification, interpretation, and remediation of vulnerabilities across a variety of applications, programming languages, and platforms.
+ Supports the development of security procedures and methods to ensure the safety of information systems and to protect the system from intentional (unauthorized) or accidental (inadvertent) access or destruction.
+ Works with Web development, network administration, and corporate security teams, to actively identify, and analyze risks and develop plans that drive security improvements for the project/program.
+ Serves as a liaison between development teams and stakeholders to understand and formulate security requirements for project/program.
+ Defines, maintains, and enforces application security best practices.
+ Explains and demonstrates vulnerabilities to application owners, and provide recommendations for mitigation.
+ Conducts and coordinates vulnerability assessments of software application under development.
+ Identifies additional application security related tools, conducts tool analysis, and provided recommendations.
+ Performs and conducts penetration tests and manual/automated code reviews.
+ Trains developers and other relevant team members on Secure Code Development as well as other security protocols as needed.
**Minimum Qualifications**
+ Bachelor's Degree in Computer Science, Engineering, or other Engineering or Technical discipline or equivalent relevant experience.
+ 5-10 years of experience as an Application Security Developer, Application Security Analyst, or equivalent.
**Other Job Specific Skills**
+ Expertise with application server technologies such as Spring Framework, Spring Security, Web Services, REST, and Hibernate.
+ In-depth knowledge of and experience with security technologies, single-sign-on and identity management technologies.
+ Expertise with web system security concepts, including authentication, authorization (RBAC), encryption/hashing, SAML, and LDAP.
+ Knowledge of web application vulnerabilities such as cross-site scripting (XSS), sessions hijacking, SQL injection, CSRF (Cross-Site Request Forgery), OWASP Top 10, and other attack vectors.
+ Hands-on experience with encryption, hashing, secure random number generation, key derivation, digital signatures, etc.
+ Knowledge of network based, system level and application layer attacks and mitigation methods, and TCP/IP, HTTP/S, and related protocols.
+ Experience with static code analysis tools including HP Fortify.
+ Familiarity with JavaScript, NodeJS, or other scripting languages and BurpSuite or other intercepting proxy tools.
+ Experience working with GIT source code management.
+ Must have solid working experience and knowledge of Unix/Linux operating system.
+ Experience with one or more of the following technologies: Vagrant, Chef, Rake, Gradle, Jenkins, and Cache DB is preferred.
+ Understanding of Agile/Scrum methodologies is preferred.
+ Experience with Axiomatics is a plus.
**Compensation Ranges**
Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.
**EEO Requirements**
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.
All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.
Physical Requirements
The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.
**Disclaimer**
The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.
86,200 to 127,500
EEO Requirements
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, gender identity, veteran status, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.
All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, veteran status, disability, gender identity, or age. All decisions on employment are made to abide by the principle of equal employment.
Triage Security Engineer 3
Security Architect Job 40 miles from Centerville
At Arctic Wolf, we're not just navigating the cybersecurity landscape - we're redefining it. Our global team of dedicated Pack members is driving innovation and setting new industry standards every day. Our impact speaks for itself: we've earned recognition on the Forbes Cloud 100, CNBC Disruptor 50, Fortune Future 50, and Fortune Cyber 60 lists, and we recently took home the 2024 CRN Products of the Year award. We're proud to be named a Leader in the IDC MarketScape for Worldwide Managed Detection and Response Services and earning a Customers' Choice distinction from Gartner Peer Insights. Our Aurora Platform also received CRN's Products of the Year award in the inaugural Security Operations Platform category. Join a company that's not only leading, but also shaping, the future of security operations.
Our mission is simple: End Cyber Risk. We're looking for a Triage Security Engineer to be part of making this happen.
The Triage Security Engineer will contribute to our Security Services department by supporting our customers through our Security Operations Centre.
About the Role:
As part of the Security Services team, the Triage Security Engineer (TSE) is a role that leverages your security expertise to identify, detect, and notify customers of security events ongoing within their environment. The TSE will be expected to have a deep knowledge of various threats and forms of attack while having demonstrated experience in highly technical security roles.
The successful candidate will be working shifts in a 24x7 environment with focus on security investigations, security related task work, and improvement activities to better the triage function.
This role will have a high technical aspect and limited customer relationship function, in that you will managing security incidents and working with Concierge Security Teams to provide the post-incident remediation activities.
Arctic Wolf TSEs are accountable for the detection and notification of security incidents to our customers.
As a Triage Security Engineer you will get to:
Analyze incoming security events based on different data points; network, endpoint, and log sources expediently, consistently, and accurately
Prioritize incoming events exceptionally well
Willingness to run a security incident to completion; detect, work with team members, and communicate effectively with internal and external team parties throughout the process.
Steer complex investigations within your area of expertise, and leverage your security knowledge to engage the other experts within other disciplines appropriately
Prioritize task work according to understood and implied priorities
Conduct quality reviews on outgoing tickets, security engagements, and at a system level looking for areas of improvement
Contribute your security expertise using the development platform to elevate more precise signal with minimal noise
Ability to coach and mentor other team members to share knowledge and expertise
Continuously broaden your security expertise and depth within a set competency
Arctic Wolf is a fast-growing company, and all TSE candidates should expect to work with many teams within Arctic Wolf, including engineering, operations, sales, marketing, and executive management. A positive can-do attitude is a must. A willingness to learn and continuous self-improvement is critical. An ability to deal with uncertainty is a positive.
We are looking for someone who might have:
5+ years Industry experience; Information Security, Network Security, or Cyber Security roles focusing on threat hunting, incident response, or security analysis.
Threat Intelligence Analysis experience: Staying updated on the latest cyber threats, attack vectors, and industry trends through threat intelligence sources and analyzing threat data to identify potential risks to the organization.
Proactive Threat Hunting experience: Utilizing security tools, techniques, and methodologies to proactively search for signs of compromise and malicious activity within the network environment.
Incident Response experience: Collaborating with incident response teams to investigate and respond to security incidents promptly. Taking necessary actions to contain and eradicate threats, minimizing their impact on organizational assets.
Forensic Analysis experience: Conducting forensic analysis of security incidents to gather evidence, understanding attack methodologies, and improving threat detection capabilities.
Have deep technical competency in the following:
Networking - common protocols, server/client infrastructure, routers, switches, WAPs, etc
Perimeter - firewalls, IDS, IPS, UTM, WAF, Gateways, Proxys, Mail Servers, etc
Authentication - AD, SSO, MFA, etc
IaaS - cloud services, AWS, Azure, GCP
End Point - MDM, EDR, EPP, AV
SaaS - collaboration tools including O365, GSuite, Box, Salesforce, Workday, etc
Assist in the incident Response life cycle for Analysis; Containment, and Eradication
Ability to advise and coach clients during an active breach on how to remediate and secure their environment.
Create and audit new and existing detections for malicious activity
Analyze incoming security events in a SIEM based on network, endpoint, firewall, cloud, DNS and others as needed expediently, consistently, and accurately to determine if an event is malicious
Experience working in a Security Operation Center, security incident response teams, or in roles with security forensics or malware analysis disciplines.
Analyze log and system data from the above list and other IT systems
Know how to use one or more scripting tools and languages such as Python, Bash, and Power Shell
Great writing and speaking skills
A positive “can-do” attitude
A willingness to learn and continuous self-improvement
There are no specific degree or certification requirements but degrees in engineering or technology are a plus.
Relevant certifications (e.g., CISSP, GIAC, CEH) are a plus.
You will be required to attend trainings, seminars, or webinars relevant to job role to enhance current knowledge base and skill set in order to improve job performance and efficiency. Attend at least one event in a year and should not impact job/project deliverables.
At Arctic Wolf, we foster a collaborative and inclusive work environment that thrives on diversity of thought, background, and culture. This is reflected in our multiple awards, including Top Workplace USA (2021-2024), Best Places to Work - USA (2021-2024), Great Place to Work - Canada (2021-2024), Great Place to Work - UK (2024), and Kununu Top Company - Germany (2024). Our commitment to bold growth and shaping the future of security operations is matched by our dedication to customer satisfaction, with over 7,000 customers worldwide and more than 2,000 channel partners globally. As we continue to expand globally and enhance our technology, Arctic Wolf remains the most trusted name in the industry.
Our Values
Arctic Wolf recognizes that success comes from delighting our customers, so we work together to ensure that happens every day. We believe in diversity and inclusion, and truly value the unique qualities and unique perspectives all employees bring to the organization. And we appreciate that-by protecting people's and organizations' sensitive data and seeking to end cyber risk- we get to work in an industry that is fundamental to the greater good.
We celebrate unique perspectives by creating a platform for all voices to be heard through our Pack Unity program. We encourage all employees to join or create a new alliance. See more about our Pack Unity here.
We also believe and practice corporate responsibility, and have recently joined the Pledge 1% Movement, ensuring that we continue to give back to our community. We know that through our mission to End Cyber Risk we will continue to engage and give back to our communities.
All wolves receive compelling compensation and benefits packages, including:
Equity for all employees
Flexible time off and paid volunteer days
RRSP and 401k match
Training and career development programs
Comprehensive private benefits plan including medical, mental health, dental, disability, life and AD&D, and value-added services
Robust Employee Assistance Program (EAP) with mental health services
Fertility support and paid parental leave
Arctic Wolf is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under federal, provincial, or local law. Arctic Wolf is committed to fostering a welcoming, accessible, respectful, and inclusive environment ensuring equal access and participation for people with disabilities. As such, we strive to make our entire employee experience as accessible as possible and provide accommodations as required for candidates and employees with disabilities and/or other specific needs where possible. Please let us know if you require any accommodations by emailing *************************.
Security Requirements
Conducts duties and responsibilities in accordance with AWN's Information Security policies, standards, processes and controls to protect the confidentiality, integrity and availability of AWN business information (in accordance with our employee handbook and corporate policies).
Background checks are required for this position.
This position may require access to information protected under U.S. export control laws and regulations, including the Export Administration Regulations (“EAR”). Please note that, if applicable, an offer for employment will be conditioned on authorization to receive software or technology controlled under these U.S. export control laws and regulations.
Security Engineer 5 - Product & Application Security
Security Architect Job 11 miles from Centerville
PagerDuty, Inc. (NYSE:PD) is a global leader in digital operations management. Half of the Fortune 500 and nearly 70% of the Fortune 100 trust PagerDuty as essential infrastructure. Join us. (******************************* At PagerDuty, you'll tackle complex problems, collaborate with kind and ambitious people, and help build a more equitable world-all in a flexible, award-winning workplace.
PagerDuty is seeking a **Staff Security Engineer 5** to join our diverse, customer-focused team! As a **Staff Security Engineer 5** , you will bring your rich technical experience securing applications in a cloud native environment. You will be a part of an amazing team that's intensely focused on securing our products, improving our security processes, and building the future of security at PagerDuty.
This is an exciting opportunity to build security solutions that make developers and customers happy. The ideal candidate will have a blend of experiences across large enterprise environments and small or mid-size environments and will have focused on establishing security standards, coordinating with product development teams, developing strategies for secure-by-default architectures, and corresponding process and tooling selection and implementation. Things that make you smile: secure product architectures, providing an engaging Developer Experience for security adoption, and cute animal memes.
**Key Responsibilities**
+ Responsible for leading, designing, implementing, and configuring security controls for SaaS applications in a cloud-based infrastructure environment.
+ Lead complex projects that require in-depth knowledge across technical, solutions, and business, and collaborate across the broader engineering organization.
+ Identify threats and vulnerabilities, security gaps, and recommend enhancements and changes to increase product and infrastructure security posture.
+ Support security operations to provide the protection of the confidentiality, availability, and integrity of customer data and building/maintaining customer trust.
+ Partner with product/engineering, corporate operations, and employees to build and maintain a security-aware culture where everyone understands and plays their part
+ Provide thought leadership on modern security operations and help lead our infrastructure security organization in creating trust through security.
+ Participating in our team's on-call rotation, triaging and addressing security issues as they arise.
+ Mentor and grow application security engineers.
+ You have a desire to stay ahead of the latest industry trends and technologies, a track record of sharing contributions to the wider security engineering community and a commitment to continuous learning.
+ You believe security should make it easy to do the right thing.
+ You are an expert at leading collaborative efforts involving large groups.
+ Expert at building consensus within and across engineering teams.
**Minimum Requirements**
+ 7+ years of experience in infrastructure securing infrastructure, securing infrastructure including IaaS, PaaS, SaaS, including network security.
+ 5+ years experience with cloud-native security experience, cloud-native based application security best practices.
+ Experience with Linux operating systems, scripting languages such as Python, configuration languages like YAML, JSON and technologies such as Terraform and/or Cloudformation, configuration tools such as Chef or Ansible.
+ Experience with AWS cloud security best practices, and AWS security technologies such as AWS IAM, AWS Organizations, AWS Shield, AWS GuardDuty.
+ Excellent written and verbal communication skills.
+ The ability to compress intricate security challenges into concise descriptions.
+ The ability to solve security problems without saying "No".
+ You have a track record of stepping up and leading successful security engineering projects.
+ Past experience with application security, security testing, code reviews and identity and access management
+ Past experience with threat analysis, threat hunting, proactive security practices
+ Prior experience with Application Security, Secure SDL for cloud native services.
+ Experience with containerized applications, and technologies, such as Docker and Kubernetes.
+ Experience working in a continuous delivery/continuous deployment environment.
**Preferred Qualifications**
+ Certifications such as AWS Security Speciality, (ISC)2 Certified Cloud Security Professional (CCSP), (ISC)2 CISSP (Certified Information Systems Security Professional).
The base salary range for this position is 192,000 - 319,000 USD. This role may also be eligible for bonus, commission, equity, and/or benefits.
Our base salary ranges are determined by role, level, and location. The range, which is subject to change based on primary work location, reflects the minimum and maximum base salary we expect to pay newly hired employees for the position. Within the range, we determine pay for an individual based on a number of factors including market location, job-related knowledge, skills/competencies and experience.
Your recruiter can share more about the specific offerings for this role, as well as the salary range for your primary work location during the hiring process.
**Hesitant to apply?**
We encourage you to submit your resume even if you don't meet every requirement. We value potential and consider each candidate's full professional story. Whether you're exploring a career change or taking your next step, we look forward to reviewing your application. If this just isn't the right role or time - sign up for job alerts (**************************************** !
**Where we work**
PagerDuty currently has offices (**************************************** in Atlanta, Lisbon, London, San Francisco, Santiago, Sydney, Tokyo, and Toronto. We offer a hybrid, flexible environment. We also provide ample opportunities for connection, like team offsites and volunteering events.
**How we work**
Our values (************************************** guide how we support customers, collaborate with colleagues, develop products, and foster a culture of belonging. They define not just our actions, but what it means to be Dutonian.
**What we offer**
As a global organization, our total rewards approach is competitive with industry standards and aligned with local laws and regulations. Learn more, including country-specific offerings, on our benefits site (********************************************** .
**Your package may include:**
- Competitive salary
- Comprehensive benefits package from day one
- Flexible work arrangements
- Company equity*
- ESPP (Employee Stock Purchase Program)*
- Retirement or pension plan*
- Generous paid vacation time
- Paid holidays and sick leave
- Dutonian Wellness Days & HibernationDuty - companywide paid days off in addition to PTO
- Paid parental leave: 22 weeks for pregnant parent, 12 weeks for non-pregnant parent (some countries have longer leave standards and we comply with local laws)*
- Paid volunteer time off: 20 hours per year
- Company-wide hack weeks
- Mental wellness programs
*Eligibility may vary by role, region, and tenure
**About PagerDuty**
PagerDuty, Inc. (NYSE:PD) is a global leader in digital operations management, enabling customers to achieve operational efficiency at scale with the PagerDuty Operations Cloud. The PagerDuty Operations Cloud combines AIOps, Automation, Customer Service Operations and Incident Management with a powerful generative AI assistant to create a flexible, resilient and scalable platform to increase innovation velocity, grow revenue, reduce cost, and mitigate the risk of operational failure. Half of the Fortune 500 and nearly 70% of the Fortune 100 rely on PagerDuty as essential infrastructure for the modern enterprise.
PagerDuty is Great Place to Work-certified, a Fortune Best Workplace for Millennials, a Fortune Best Medium Workplace, a Fortune Best Workplace in Technology, and a top rated product on TrustRadius and G2.
Go behind-the-scenes on our careers site (*********************************** and @pagerduty on Instagram.
**Additional Information**
PagerDuty is committed to creating a diverse environment and is an equal opportunity employer. PagerDuty does not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, parental status, veteran status, or disability status.
PagerDuty is committed to providing reasonable accommodations for qualified individuals with disabilities in our job application process. Should you require accommodation, please email accommodation@pagerduty.com and we will work with you to meet your accessibility needs.
PagerDuty uses the E-Verify employment verification program.
Sentinel STPA-Sec Systems Security Engineer T2 - 8104-1
Security Architect Job 18 miles from Centerville
At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work - and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history.
The Sentinel Mission Defense Team (MDT) is seeking a highly motivated and qualified system engineer to serve as a System-Theoretic Process Analysis for Security (STPA-Sec) Engineer, Level 2. You will be combining traditional Systems Engineering skills, with a holistic system analyses approach in order to uncover any potential security, safety, or availability features using the existing STPA handbook guidelines, industry security frameworks (NIST, ISO, NISPOM), and Model Based Systems Engineering (MBSE) workspace. You will be generating structured requirements, decomposition strategies, and mitigations within STPA principles. This position will be located in Huntsville, Alabama or Roy, UT and may offer a competitive relocation package.
**Additional Responsibilities include:**
+ Execute combined traditional Systems Engineering principles, with a holistic system analyses approach in order to uncover any potential safety, security, or availability features using the existing STPA handbook guidelines, and Model Based Systems Engineering (MBSE) workspace
+ Ability to understand and decompose systems to identify causal scenarios; aptitude to construct control structures and identify unsafe control actions
+ Assessment and analysis of threats, vulnerabilities, and risk for identified mission-critical functions and critical components
+ Lead and execute completion Statement of Work requirements, Program Milestone Exit Criteria, and program maturity commitments
+ Lead in a variety of working groups and customer meetings; ensure communication of risk environment with stakeholders
+ Self-starters compelled to take action in the workplace without requiring prompting from supervisors
+ Support MDT with other duties as assigned
**Basic Qualifications:**
+ Bachelor's degree in a STEM (Science, Technology, Engineering or Mathematics) discipline from an accredited university and 2 years of related experience, or a Master's degree in a STEM discipline and 0 years of related experience
+ Must be a US Citizen with an active U.S. Government DoD Secret security clearance at time of application with an investigation completed within the last 6 years.
+ Must have the ability to obtain and maintain Special Access Program (SAP) approval within a reasonable period of time, as determined by the company to meet its business need.
+ Minimum 1 years of applying and understanding Systems Security Engineering principles applicable to US Government Defense Programs.
+ Minimum 1 year experience demonstrating the ability to communicate effectively and clearly present technical approaches and findings.
+ Minimum 1 year experience in applying safety principles to a complex system in a rapidly changing product or technology.
+ Minimum 1 year experience in applying analytical methodologies to raw data in order to determine and present clear and precise findings and recommendations.
+ Minimum 1 years of experience performing against schedule.
**Preferred Qualifications:**
+ Active Top-Secret clearance with SAP Access
+ Direct experience with Intercontinental Ballistic Missile Systems
+ Experience applying Program Protection principles to US Government Defense Programs and applied knowledge in the application of SSE principles across a broad spectrum of security measures (Cybersecurity, Counterfeit Awareness, Anti-Tamper, HW/SW Assurance, OPSEC, etc.) to protect critical program information (CPI)
+ Experience developing Systems Security Engineering requirements for hardware and software assurance
+ Experience with Risk Management (identification and development of risks) and driving risk mitigations to closure.
+ Experience with assessment and analysis of threats, vulnerabilities, and risk for identified mission-critical functions and critical components.
+ Direct experience with Model-based Systems Engineering (MBSE) concepts and tools (CAMEO, DOORS)
+ Familiarity with Agile Systems Engineering practices
**Position Benefits:**
As a full-time employee of Northrop Grumman, you are eligible for our robust benefits package including
+ Medical, Dental & Vision coverage
+ Educational Assistance
+ Life Insurance
+ Employee Assistance Programs & Work/Life Solutions
+ Paid Time Off
+ Health & Wellness Resources
+ Employee Discounts
This positions standard work schedule is a 9/80. The 9/80 schedule allows employees who work a nine-hour day Monday through Thursday to take every other Friday off. This role may offer a competitive relocation assistance package.
\#Sentinelsystems
Salary Range: $81,300.00 - $120,900.00
The above salary range represents a general guideline; however, Northrop Grumman considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills and current market conditions.
Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. Annual bonuses are designed to reward individual contributions as well as allow employees to share in company results. Employees in Vice President or Director positions may be eligible for Long Term Incentives. In addition, Northrop Grumman provides a variety of benefits including health insurance coverage, life and disability insurance, savings plan, Company paid holidays and paid time off (PTO) for vacation and/or personal business.
The application period for the job is estimated to be 20 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates.
Northrop Grumman is an Equal Opportunity Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. For our complete EEO and pay transparency statement, please visit *********************************** U.S. Citizenship is required for all positions with a government clearance and certain other restricted positions.
Senior Staff Information Security Engineer
Security Architect Job 11 miles from Centerville
It all started in sunny San Diego, California in 2004 when a visionary engineer, Fred Luddy, saw the potential to transform how we work. Fast forward to today - ServiceNow stands as a global market leader, bringing innovative AI-enhanced technology to over 8,100 customers, including 85% of the Fortune 500. Our intelligent cloud-based platform seamlessly connects people, systems, and processes to empower organizations to find smarter, faster, and better ways to work. But this is just the beginning of our journey. Join us as we pursue our purpose to make the world work better for everyone.
Job Description
The ServiceNow Security Organization delivers world-class, innovative security solutions to reduce risk and protect the company and our customers. We enable our customers to migrate their most sensitive data and workloads to the cloud, accelerating our business so that we are the most trusted SaaS provider. We create an environment where our employees are proud to work and can make a positive impact.
Team
This position reports to the Director, Security Engineering. The Enterprise Security Engineering team targets building state-of-the-art technology that will help reduce the risk surrounding the sensitive assets of the company with the least impact possible on operations, acts as guidance and facilitator to the security operations teams and helps shifting Security perception from blocker to enabler by building a relationship of trust with the other teams.
Role
The Senior Staff Information Security Engineer will serve as a technical subject matter expert within the Infrastructure Security team, responsible for engineering solutions that secure ServiceNow's core enterprise infrastructure. This includes network, server, authentication systems, certificates, and operational tooling. You will drive strategic initiatives that prevent threats, reduce operational risk, and enhance resilience across infrastructure services.
What you get to do in this role:
* Define and execute the technical strategy for securing infrastructure, aligned to risk and business needs
* Lead efforts to harden network and server infrastructure against unauthorized access, misconfigurations, and malware
* Architect and implement scalable and automated security controls across authentication, system configurations, and monitoring pipelines
* Drive secure deployment and management of on-prem containerized environments (e.g., Kubernetes)
* Establish controls and visibility to manage certificate lifecycle and prevent expiration-related risks
* Champion operational excellence through automation, outage reduction, and service resilience improvements
* Represent Infrastructure Security in architecture reviews, incident response, and compliance initiatives
* Mentor and develop other engineers, influencing secure engineering practices across teams
* Stay current with industry threats, trends, and mitigation techniques related to infrastructure security
Qualifications
To be successful in this role you have:
Required Skills:
* Experience in leveraging or critically thinking about how to integrate AI into work processes, decision-making, or problem-solving. This may include using AI-powered tools, automating workflows, analyzing AI-driven insights, or exploring AI's potential impact on the function or industry.
* Master's degree in computer science; engineering, or information technology or equivalent industry experience
* 10+ years of relevant hands-on engineering experience
* Deep experience with operating system and server security (Linux, Windows)
* Advanced knowledge of enterprise networking and secure network architectures
* Proficiency in scripting and automation (Python, Bash, Go, etc.)
Desirable Skills:
* Experience in working with web and database services (REST APIs, JSON, XML, SQL)
* Experience in working with Splunk and SPL (or other SIEM/Log management systems)
* Experience in working with cryptography (PKI, TLS, VPNs, secure credential management, disk encryption, certificate and code signing)
* Experience with infrastructure-as-code and configuration management tools such as Puppet and Ansible to automate system hardening and policy enforcement.
* Experience in working with hardware virtualization (bare metal servers, storage, load balancing, virtual networking using VMware, Citrix, Hyper-V, etc.)
* Planning hardware and software system upgrades and configuration changes
* Automating operations and capacity planning
* System performance tuning and service monitoring
* System and software debugging experience with strong troubleshooting skills
* Familiarity with regulatory and industry certifications (FedRAMP, NIST 800-53, NIST CSF, SOC 2, SOX and GDPR)
* Ability to analyze and assess complex problems quickly and efficiently
* Growth mindset approach: hungry and humble with the ability to lead and train others
* Ability to thrive in a dynamic, driven, fast-paced environment
#SecurityJobs
Additional Information
Work Personas
We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work. Learn more here.
Equal Opportunity Employer
ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, national origin or nationality, ancestry, age, disability, gender identity or expression, marital status, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements.
Accommodations
We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact ***************************** for assistance.
Export Control Regulations
For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities.
From Fortune. 2024 Fortune Media IP Limited. All rights reserved. Used under license.
Senior Information Security Engineer
Security Architect Job 11 miles from Centerville
Directly accountable for safeguarding the organization's information assets. The role involves designing, implementing, and enforcing security protocols and procedures that mitigate risks and ensure compliance. With heavy focus in information security operations, including vulnerability management, incident/event management, compliance management, policy/procedure development and information security awareness.
This responsibility will be carried out through the development of information security requirements, planning, design, implementation, and periodic audit/validation of effectiveness of all security controls.
Accountabilities:
+ Architect, design, and implement security controls for our infrastructure and critical systems.
+ Determine information security requirements by evaluating and researching information security standards; conducting system security and vulnerability analyses and risk assessments; studying architecture/platform; and identifying integration issues.
+ Verify information security systems effectiveness by developing and implementing testing and validation processes to periodically audit systems.
+ Collaborate with managed security service provider (MSSP) to ensure their services are effectively delivered to our organization and validate that alerts are properly acted upon to mitigate identified threats.
+ Support security incident response activities utilizing security tools (SIEM/SOAR)
+ Lead and collaborate in the development of a Business Continuity and Disaster Recovery plan.
+ Prepare system security reports by collecting, analyzing, and summarizing data and trends.
+ Track and understand emerging security practices and threats. Leverage this knowledge to improve security configurations across the enterprise and hunt for potential or active threats.
+ This role will be responsible for monitoring Healthcare industry and regulatory trends to ensure prompt and complete action plans are developed and implemented to address such requirements.
+ Serve as the primary liaison for audit activities related to the areas of information security.
+ This will also include maintaining ongoing cybersecurity risk profile using the recommended industry tools, and being certain that activities which keep us aligned with our target levels are implemented.
+ Demonstrable expertise in implementing, managing, and fine-tuning security controls using a variety of security tools and frameworks. Specific experience with Palo Alto firewalls and Palo Alto suite of security tools.
+ In-depth experience with Identity and Access Management (IAM), specifically in designing and implementing IAM solutions for provisioning, de-provisioning, and role-based access controls within the organization. Familiarity with industry standard IAM solutions and best practices is a must.
+ Familiarity with monitoring and managing security incidents, including the use of Security Information and Event Management (SIEM) tools.
+ Proven track record in working with cross-functional teams to address security and compliance challenges, specifically in a regulated financial environment.
+ Experience in developing and implementing security policies and procedures that align with industry regulations such as PCI-DSS, NCUA, or related financial sector regulations.
+ Previous involvement in handling external and internal audits related to information security, along with remediation of identified issues.
+ A high level of problem-solving skills and the ability to communicate in a clear, concise manner.
+ Must be able to communicate effectively in both oral and written form and explain technical concepts in non-technical terms to staff and prepare clear and concise written communications.
+ Must be able to manage multiple projects/tasks concurrently; and prioritize requests and complete assignments within an estimated timeframe; and organize, schedule, and coordinate a variety of activities and projects.
+ Must have the ability to learn new software and hardware packages and adapt to changes in technology.
Qualifications:
+ Bachelor's Degree in computer science or Equivalent work experience
+ At least 10 years of experience in information security preferred
+ Excellent written communication skills.
+ Strong organizational and planning skills.
+ Demonstrates a high degree of personal integrity and practices ethical standards. Must remain objective and independent when completing assignments, and consistently demonstrate the ability to hold information in confidence.
+ Demonstrated proactiveness and an ability to work independently and self-directed in managing multiple concurrent projects.
+ Excellent analytical and problem-solving skills.
**Anticipated salary range:** $103,500 - $147,900
**Bonus eligible:** Yes
**Benefits:** Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
+ Medical, dental and vision coverage
+ Paid time off plan
+ Health savings account (HSA)
+ 401k savings plan
+ Access to wages before pay day with my FlexPay
+ Flexible spending accounts (FSAs)
+ Short- and long-term disability coverage
+ Work-Life resources
+ Paid parental leave
+ Healthy lifestyle programs
**Application window anticipated to close:** 5/28/2025 *if interested in opportunity, please submit application as soon as possible.
The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.
_Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply._
_Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal_ _Opportunity/Affirmative_ _Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law._
_To read and review this privacy notice click_ here (***************************************************************************************************************************
Senior Security Engineer
Security Architect Job 11 miles from Centerville
Security @ Pave Security is part of everything we do at Pave. With amazing growth comes amazing engineering and security challenges. This is an opportunity to have a huge impact and run programs at a company that doesn't need to be convinced why security is important. Our customers count on us to secure some of their most sensitive data, and that trust is central to Pave. It's the only way we can unlock a labor market built on trust, and change the world of compensation.
What You'll Bring
* 5+ years of application security experience as part of a blue team
* Expert knowledge of OWASP Top 10 and application security
* Security design review experience
* Experience in running bug bounty programs and pentesting
* Outstanding communication and partnership skills with software engineers
* Ideally, experience in Google Cloud Security best practices
Senior Information System Security Officer (ISSO)
Security Architect Job 21 miles from Centerville
Top Secret Clearance Jobs is dedicated to helping those with the most exclusive security clearance find their next career opportunity and get interviews within 48 hours. Odyssey Systems has an exciting opportunity for a Information System Security Officer (ISSO)to support the Aerospace Dominance Enabler Division (AFLCMC/HBZ)at Hill AFB in Ogden Utah. HBZ functions as the Air Force's technical, acquisition and sustainment experts providing unique and comprehensive support to the warfighter. The ADE Division is responsible for a vast array of USAF systems to include Electronic Warfare, Range Systems, Range Instrumentation, Air Combat Training and Aircrew Readiness, Command and Control Systems, Advanced Radar Threat Systems, Combat Survivor Evader Locator, P5 Combat Training Systems, Black Switch and Legacy Voice Systems. Furthermore, the ADE Division provides support to depot level sustainment and maintenance efforts, FMS, U.S. Army, Navy, Pacific Air Forces, Air Combat Command (ACC), Air Force Materiel Command (AFMC), and Air Education and Training Command (AETC) on a continuous basis.
This position plays a crucial role in supporting the HBZ Division by contributing to the establishment of a new Top Secret facility and ensuring that all compliance requirements and policies are correctly adhered to.
Responsibilities
In this position you will p rovide ISSO support that will be responsible for ensuring the appropriate operational security posture is maintained for the assigned IT. Including activities to maintain situational awareness and to initiate actions to improve or restore cybersecurity posture.
Duties
Duties includ e, but not limited to:
Implements and enforce all AF cybersecurity policies, procedures, and countermeasures.
Completes and maintains required cybersecurity certification IAW AFMAN17-1303. Individuals in this position must be U.S. citizens
Ensures all users have the requisite security clearances and need-to-know, complete annual cybersecurity training, and are aware of their responsibilities before being granted access to the IT according to AFMAN 17-1301
Maintains all authorized user access control documentation IAW the applicable AF Records Information Management System
Ensures software, hardware, and firmware complies with appropriate security configuration guidelines, e.g., security technical implementation guides /security requirement guides
Ensures proper configuration management procedures are followed prior to implementation and contingent upon necessary approval. Coordinate changes or modifications with the system-level ISSM, SCA, and/or SCAR. 16 AFI17-101 6 FEBRUARY 2020
Initiates protective or corrective measures, in coordination with the ISSM, when a security incident or vulnerability is discovered
Reports security incidents or vulnerabilities to the system-level ISSM.
Initiates exceptions, deviations, or waivers to cybersecurity requirements
Qualifications
Minimum Required Qualifications:
Citizenship: Must be a US citizen
Clearance : Top Secret Clearance
Education: Bachelor's Degree in a related field and 12 years of experience in the respective technical/professional discipline being performed, five of which must be in the DoD OR
15 years of directly related experience with proper certifications as described in the PWS labor category performance requirements, eight of which must be in the DoD
Preferred Education: Master's or Doctorate Degree in a related field and ten years of experience in the respective technical / professional discipline being performed, five years of which must be in the DoD
Additional Information
Location: Hill AFB, Ogden UT
Company Overview
Odyssey Systems Consulting Group, is an innovative small business committed to providing world-class technical, management, and training support services to government and public sector clients. We focus on people, processes, and performance to deliver superior results. Since our inception in 1997, our commitment to mission success and customer satisfaction has been recognized with exponential growth and exceptional past performance ratings. We accept challenging assignments and drive projects from the planning stages, through implementation, and into operations and support.
Please note: Final compensation for this position will be determined by various factors such as the Federal Government contract labor categories and contract wage rates, relevant work experience, specific skills and competencies, geographic location, education, and certifications.
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
Concierge Security Engineer 2
Security Architect Job 40 miles from Centerville
At Arctic Wolf, we're not just navigating the cybersecurity landscape - we're redefining it. Our global team of dedicated Pack members is driving innovation and setting new industry standards every day. Our impact speaks for itself: we've earned recognition on the Forbes Cloud 100, CNBC Disruptor 50, Fortune Future 50, and Fortune Cyber 60 lists, and we recently took home the 2024 CRN Products of the Year award. We're proud to be named a Leader in the IDC MarketScape for Worldwide Managed Detection and Response Services and earning a Customers' Choice distinction from Gartner Peer Insights. Our Aurora Platform also received CRN's Products of the Year award in the inaugural Security Operations Platform category. Join a company that's not only leading, but also shaping, the future of security operations.
Our mission is simple: End Cyber Risk. We're looking for a Concierge Security Engineer 2 to be part of making that happen.
About the Role:
The Concierge Security Engineer 2 (CSE2) is a key member of the Concierge Security Team that delivers world-class Arctic Wolf security services. The CSE2 supports the technical relationship with their assigned customers and leverages their skills and expertise to fulfill key responsibilities.
As a Concierge Security Engineer 2, you will:
Create and maintain an outstanding partnership with customers;
Support the direct delivery of Arctic Wolf network and endpoint security solutions to customers, including tasks such as investigating security events, and configuring, troubleshooting and verifying data sources;
Action or escalate customer requests for guidance, information or support in a timely manner, including coordinating efforts with other teams, as needed.
Proactively interact and communicate with internal and external stakeholders.
The CSE2 role combines aspects of an IT Security Analyst, a Security Architect, and an Incident Response Consultant. A successful CSE2 possesses strong technical aptitude and an ability to communicate, educate, and share information effectively with non-technical people.
Who You Are:
You thrive in fast-paced environments and have a positive can-do attitude. You are a critical thinker that continually learns and can navigate uncertainty. You enjoy working with customers and in a team, are an excellent communicator, and are able to easily interact with a variety of people, personalities and technical skill levels. Above all, your passion for cybersecurity and partnering with customers shows in everything you do!
Your experience could look like:
1-5 years of experience in a hands-on security role with a good knowledge of security architecture
Degree or diploma in a relevant field, or certifications and experience equivalent
Strong partnering and relationship building skills in a professional context
Strong communication skills, both written and verbal
Strong analytical and problem-solving skills
Additional skills and experience:
Security testing and forensics tools
Malware analysis
Scripting/Coding experience
Incident response
Authentication and identity management
Risk management, assessment and common compliance frameworks
Penetration testing and attack simulation
About Arctic Wolf
At Arctic Wolf, we foster a collaborative and inclusive work environment that thrives on diversity of thought, background, and culture. This is reflected in our multiple awards, including Top Workplace USA (2021-2024), Best Places to Work - USA (2021-2024), Great Place to Work - Canada (2021-2024), Great Place to Work - UK (2024), and Kununu Top Company - Germany (2024). Our commitment to bold growth and shaping the future of security operations is matched by our dedication to customer satisfaction, with over 7,000 customers worldwide and more than 2,000 channel partners globally. As we continue to expand globally and enhance our technology, Arctic Wolf remains the most trusted name in the industry.
Our Values
Arctic Wolf recognizes that success comes from delighting our customers, so we work together to ensure that happens every day. We believe in diversity and inclusion, and truly value the unique qualities and unique perspectives all employees bring to the organization. And we appreciate that-by protecting people's and organizations' sensitive data and seeking to end cyber risk- we get to work in an industry that is fundamental to the greater good.
We celebrate unique perspectives by creating a platform for all voices to be heard through our Pack Unity program. We encourage all employees to join or create a new alliance. See more about our Pack Unity here.
We also believe and practice corporate responsibility, and have recently joined the Pledge 1% Movement, ensuring that we continue to give back to our community. We know that through our mission to End Cyber Risk we will continue to engage and give back to our communities.
All wolves receive compelling compensation and benefits packages, including:
· Equity for all employees
· Flexible time off and paid volunteer days
· RRSP and 401k match
· Training and career development programs
· Comprehensive private benefits plan including medical, mental health, dental, disability, life and AD&D, and value-added services
· Robust Employee Assistance Program (EAP) with mental health services
· Fertility support and paid parental leave
Arctic Wolf is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under federal, provincial, or local law. Arctic Wolf is committed to fostering a welcoming, accessible, respectful, and inclusive environment ensuring equal access and participation for people with disabilities. As such, we strive to make our entire employee experience as accessible as possible and provide accommodations as required for candidates and employees with disabilities and/or other specific needs where possible. Please let us know if you require any accommodations by emailing *************************.
Security Requirements
Conducts duties and responsibilities in accordance with AWN's Information Security policies, standards, processes and controls to protect the confidentiality, integrity and availability of AWN business information (in accordance with our employee handbook and corporate policies).
Background checks are required for this position.
This position may require access to information protected under U.S. export control laws and regulations, including the Export Administration Regulations (“EAR”). Please note that, if applicable, an offer for employment will be conditioned on authorization to receive software or technology controlled under these U.S. export control laws and regulations.