The Cybersecurity Engineer is responsible for the technical implementation and management of cybersecurity measures. This role involves extensive hands-on work with security technologies, developing and maintaining security protocols, and ensuring the protection of sensitive data. The Cybersecurity Engineer collaborates within the various IT teams to integrate security solutions into business projects and solutions, while supporting overall compliance with HIPAA regulations.
Technical Implementation:
Architect, deploy, and maintain enterprise-grade security technologies, including firewalls, intrusion detection/prevention systems, encryption platforms, and vulnerability management tools.
Implement and support security controls for network infrastructure such as routers, switches, and wireless access points.
Configure, administer, and secure Active Directory and Azure AD environments.
Deploy and oversee endpoint protection platforms and Security Information and Event Management (SIEM) solutions.
Manage Microsoft 365 security capabilities, including conditional access, data loss prevention (DLP), and advanced threat protection.
Evaluate, test, and recommend new security tools, processes, and technologies to strengthen the organization's security posture.
Security Operations:
Continuously monitor systems for security events, investigate alerts, and respond to incidents with appropriate documentation.
Perform ongoing risk assessments and vulnerability scans to identify exposures and drive remediation efforts.
Lead technical response efforts during security incidents or breaches in coordination with the incident response team.
Administer and monitor Identity and Access Management (IAM) systems to ensure secure and appropriate access.
Conduct routine vulnerability assessments and threat analysis to support continual improvement.
Perform digital forensics and incident response activities as needed.
Compliance:
Ensure adherence to HIPAA and all applicable regulatory and security standards.
Design and implement technical safeguards that protect sensitive information and support organizational objectives.
Collaboration:
Partner with IT and business teams to embed security controls into systems, applications, and workflows.
Educate and support staff on cybersecurity awareness, best practices, and evolving threats.
Documentation:
Create and maintain accurate documentation for security configurations, procedures, and incident activity.
Remain informed on current cybersecurity trends and recommend enhancements to existing controls.
Security Audits:
Plan and conduct scheduled and ad-hoc security audits to validate adherence to security policies and standards.
Security Standards and Policies:
Develop, review, and update security policies and standards in alignment with industry best practices and regulatory requirements.
Security Infrastructure Maintenance and Monitoring:
Configure, troubleshoot, and maintain security-related hardware and software.
Implement and manage monitoring tools to detect intrusions and potential security breaches.
Security Strategy Development:
Support the planning, execution, and ongoing refinement of the organization's information security strategy.
Adhere to organizational policies, procedures, and safety standards; complete required training annually; contribute to performance goals and quality improvement initiatives.
Perform additional duties as assigned.
Minimum Education:
Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related discipline required.
Minimum Experience:
Ten (10) years of overall IT experience, including at least five (5) years of hands-on cybersecurity leadership with demonstrated success designing, engineering, and deploying security solutions in an enterprise environment.
Certifications:
Relevant industry certifications such as CISSP, CISM, CISA, CCSP, CEH, Microsoft Azure Engineer, or equivalent are required.
$65k-87k yearly est. 2d ago
Looking for a job?
Let Zippia find it for you.
Architect
Compass Ventures
Security architect job in Sevierville, TN
Compass is looking for an Architect to join our team!
Pay Range: $75,000-$100,000 per year
Schedule: Full-time, Monday-Friday
About Compass:
At Compass, "Development with Direction" is our purpose and passion. We are dedicated to making a positive impact in the Smoky Mountain region through initiatives like solving the workforce housing crisis, creating premier lodging opportunities, and revitalizing Sevierville's Downtown Historic District.
Our Values:
Walk the Walk
Living Fully
Be Intentional
Driven for Excellence
Grit
Who We're Looking For:
Someone who embodies our values, has strong leadership skills, enjoys working with communities, and thrives in a dynamic and collaborative environment.
Role Summary:
We're seeking a creative and technically skilled Architect to design and guide the development of residential, hospitality, and mixed-use projects. This role involves working closely with stakeholders, engineers, and builders to deliver functional and visually compelling spaces aligned with our mission and vision.
Key Responsibilities:
Develop architectural plans, elevations, and construction documents
Lead design meetings and collaborate with internal teams and consultants
Conduct site visits and ensure construction aligns with approved designs
Stay up to date on codes, zoning laws, and building regulations
Incorporate sustainability and local character into designs
Support permitting processes and municipal approvals
Contribute to project timelines, budgets, and documentation
Qualifications:
Degree in Architecture and valid architect's license
2+ years of experience in architectural design or drafting
Proficiency in AutoCAD, Revit, and rendering software
Strong visualization and technical drawing skills
Ability to manage multiple projects and deadlines
Benefits:
Health insurance
Retirement plan
Paid time off
Collaborative team environment
Opportunities for professional development
Apply Today: Join our team and make a difference in the Smoky Mountain region. If you are passionate about making an impact and share our commitment to excellence, we would love to hear from you.
$75k-100k yearly 2d ago
Staff AI Security Architect
Datavant
Security architect job in Frankfort, KY
Datavant is a data platform company and the world's leader in health data exchange. Our vision is that every healthcare decision is powered by the right data, at the right time, in the right format. Our platform is powered by the largest, most diverse health data network in the U.S., enabling data to be secure, accessible and usable to inform better health decisions. Datavant is trusted by the world's leading life sciences companies, government agencies, and those who deliver and pay for care.
By joining Datavant today, you're stepping onto a high-performing, values-driven team. Together, we're rising to the challenge of tackling some of healthcare's most complex problems with technology-forward solutions. Datavanters bring a diversity of professional, educational and life experiences to realize our bold vision for healthcare.
**What We're Looking For**
As a Staff AI SecurityArchitect at Datavant, you will lead the design, evolution, and adoption of secure by design principles across our AI and Machine Learning (ML) systems. This role sits at the intersection of AI innovation and securityarchitecture. You will define and operationalize AI security strategy, embed security into the AI/ML development lifecycle, and partner deeply with data science, engineering, product, legal, and compliance teams to ensure our AI systems are secure, trustworthy, and scalable.
**What You Will Do**
+ Establish AI securityarchitectural standards, design patterns, and best practices adopted across engineering teams.
+ Architect and advise on secure end-to-end AI systems, including data pipelines, model training, evaluation, deployment, runtime monitoring, and agentic workflows.
+ Lead threat modeling, architecture reviews, and risk assessments for AI-driven products, including LLMs, agent frameworks, and multi-agent systems.
+ Define and evolve a comprehensive AI/ML secure development lifecycle integrated into existing SDLC practices.
+ Develop reference architectures, documentation, and reusable security components to accelerate secure AI adoption.
+ Collaborate with legal, privacy, compliance, and responsible AI stakeholders to align security controls with regulatory and ethical requirements.
+ Act as a trusted advisor to senior leadership on AI security risks, trade-offs, and long-term strategy.
**What You Need to Succeed**
+ 8+ years of experience in securityarchitecture, application security, or product security, with meaningful focus on AI/ML systems.
+ Hands-on experience securing AI/ML or LLM-based systems, including familiarity with modern AI architectures and agentic workflows.
+ Strong understanding of AI threat models, including adversarial ML, prompt injection, data poisoning, model theft, and abuse scenarios.
+ Proven ability to design and influence securityarchitectures for large-scale, distributed systems.
+ Strong communication skills with the ability to translate complex technical concepts to both technical and non-technical stakeholders.
+ Have a strong understanding of security controls, both those that exist in audit standards as well as practical controls that can help reduce risk and increase safety.
**What Helps You Stand Out**
+ Hands-on experience building, testing, or tinkering with agentic AI workflows, with an understanding of the security risks they introduce.
+ Experience securing AI/ML workloads in Databricks, with a deep understanding of its platform-specific security risks.
+ You have experience with security in healthcare or other highly regulated space. Examples: HIPAA, HITRUST, SOC 2, PCI, FedRamp experience from an operational response standpoint.
We are committed to building a diverse team of Datavanters who are all responsible for stewarding a high-performance culture in which all Datavanters belong and thrive. We are proud to be an Equal Employment Opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity, religion, national origin, disability, veteran status, or other legally protected status.
At Datavant our total rewards strategy powers a high-growth, high-performance, health technology company that rewards our employees for transforming health care through creating industry-defining data logistics products and services.
The range posted is for a given job title, which can include multiple levels. Individual rates for the same job title may differ based on their level, responsibilities, skills, and experience for a specific job.
The estimated total cash compensation range for this role is:
$224,000-$280,000 USD
To ensure the safety of patients and staff, many of our clients require post-offer health screenings and proof and/or completion of various vaccinations such as the flu shot, Tdap, COVID-19, etc. Any requests to be exempted from these requirements will be reviewed by Datavant Human Resources and determined on a case-by-case basis. Depending on the state in which you will be working, exemptions may be available on the basis of disability, medical contraindications to the vaccine or any of its components, pregnancy or pregnancy-related medical conditions, and/or religion.
This job is not eligible for employment sponsorship.
Datavant is committed to a work environment free from job discrimination. We are proud to be an Equal Employment Opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity, religion, national origin, disability, veteran status, or other legally protected status. To learn more about our commitment, please review our EEO Commitment Statement here (************************************************** . Know Your Rights (*********************************************************************** , explore the resources available through the EEOC for more information regarding your legal rights and protections. In addition, Datavant does not and will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay.
At the end of this application, you will find a set of voluntary demographic questions. If you choose to respond, your answers will be anonymous and will help us identify areas for improvement in our recruitment process. (We can only see aggregate responses, not individual ones. In fact, we aren't even able to see whether you've responded.) Responding is entirely optional and will not affect your application or hiring process in any way.
Datavant is committed to working with and providing reasonable accommodations to individuals with physical and mental disabilities. If you need an accommodation while seeking employment, please request it here, (************************************************************** Id=**********48790029&layout Id=**********48795462) by selecting the 'Interview Accommodation Request' category. You will need your requisition ID when submitting your request, you can find instructions for locating it here (******************************************************************************************************* . Requests for reasonable accommodations will be reviewed on a case-by-case basis.
For more information about how we collect and use your data, please review our Privacy Policy (**************************************** .
$224k-280k yearly 25d ago
Cloud Security Architect
Elevance Health
Security architect job in Nashville, TN
**Location:** This role requires associates to be in-office 1 - 2 days per week, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life balance. This approach combines structured office engagement with the autonomy of virtual work, promoting a dynamic and adaptable workplace. Alternate locations may be considered if candidates reside within a commuting distance from an office.
Please note that per our policy on hybrid/virtual work, candidates not within a reasonable commuting distance from the posting location(s) will not be considered for employment, unless an accommodation is granted as required by law.
The **Cloud SecurityArchitect** is responsible for enabling, maturing, and operationalizing cyber defense capabilities across Elevance Health's enterprise and subsidiary cloud environments.
This role partners closely with Cloud Infrastructure, Application Engineering, Detection Engineering, and Security Operations to ensure cloud-native security telemetry, detection, and response capabilities are deployed, monitored, and continuously improved.
**How You Will Make an Impact:**
+ Lead efforts to integrate cyber defense and security operations capabilities into enterprise and subsidiary cloud environments (AWS, Azure, GCP, and OCI), ensuring consistent visibility and detection coverage across platforms.
+ Partner with cloud infrastructure and application teams to ensure security controls, logging, and telemetry are properly enabled, validated, and operational for cloud services and workloads.
+ Work with app, platform and engineering teams to ensure the appropriate level of logging is enabled within their respective environments.
+ Define roadmap and strategy for the future of cloud cyber defense, including CSPM, threat detection, logging pipelines, and incident response integration. Develop an approach that is tailored to the organization and keeps us out in front of developing threats.
+ Propose and develop cloud threat monitoring use cases. Train SOC analysts on how to properly triage, investigate and remediate alerts based on those use cases.
+ Collaborate with security operations and incident response teams to investigate complex cloud security events (e.g. threat detection events, misconfigurations, exposed resources) and support remediation efforts.
+ Infuse automation and AI-driven capabilities into cloud threat management operations.
+ Work with vendors to evaluate, select, and onboard technologies. Partner with vendor contacts to ensure product roadmaps address evolving business and technical requirements.
+ Support pursuit of new business by designing new cloud architectures that are compliant with FedRAMP or other regulatory requirements.
+ Participate in and contribute to governance review for new cloud services, AI-enabled platforms, and SaaS offerings, ensuring security requirements, logging, and guardrails are defined before approval.
+ Act as Subject Matter Expert in all aspects of cloud cyber defense. Advise executive leadership on matters relating to cloud security. Train and mentor junior team members.
+ Draft business-level presentations that garner executive and stakeholder support for cloud cyber defense initiatives.
+ Develop policies, technical standards and other foundational documentation.
+ Support regulatory and audit initiatives by validating cloud security controls, evidence collection, and alignment with frameworks such as SOC2, PCI, HITRUST, and FedRAMP.
**Minimum Requirements:**
Requires BS/BA in Information Technology or related field of study and a minimum of 10 years experience in systems administration and security aspects of information systems, access management and network security technologies, network communications, computer networking, telecommunications, systems development and management, hardware, software, data, and people; experience with multiple technical and business disciplines required; or any combination of education and experience, which would provide an equivalent background.
**Preferred Skills, Capabilities & Experiences:**
+ Fluency with all 3 major cloud service providers: AWS, Azure & Google Cloud Platform.
+ Experience designing, implementing or operating cloud security programs in an enterprise environment.
+ Cloud security certifications such as CCSP or CSP-specific security certifications .
+ Experience with Oracle Cloud Infrastructure.
Please be advised that Elevance Health only accepts resumes for compensation from agencies that have a signed agreement with Elevance Health. Any unsolicited resumes, including those submitted to hiring managers, are deemed to be the property of Elevance Health.
Who We Are
Elevance Health is a health company dedicated to improving lives and communities - and making healthcare simpler. We are a Fortune 25 company with a longstanding history in the healthcare industry, looking for leaders at all levels of the organization who are passionate about making an impact on our members and the communities we serve.
How We Work
At Elevance Health, we are creating a culture that is designed to advance our strategy but will also lead to personal and professional growth for our associates. Our values and behaviors are the root of our culture. They are how we achieve our strategy, power our business outcomes and drive our shared success - for our consumers, our associates, our communities and our business.
We offer a range of market-competitive total rewards that include merit increases, paid holidays, Paid Time Off, and incentive bonus programs (unless covered by a collective bargaining agreement), medical, dental, vision, short and long term disability benefits, 401(k) +match, stock purchase plan, life insurance, wellness programs and financial education resources, to name a few.
Elevance Health operates in a Hybrid Workforce Strategy. Unless specified as primarily virtual by the hiring manager, associates are required to work at an Elevance Health location at least once per week, and potentially several times per week. Specific requirements and expectations for time onsite will be discussed as part of the hiring process.
The health of our associates and communities is a top priority for Elevance Health. We require all new candidates in certain patient/member-facing roles to become vaccinated against COVID-19 and Influenza. If you are not vaccinated, your offer will be rescinded unless you provide an acceptable explanation. Elevance Health will also follow all relevant federal, state and local laws.
Elevance Health is an Equal Employment Opportunity employer and all qualified applicants will receive consideration for employment without regard to age, citizenship status, color, creed, disability, ethnicity, genetic information, gender (including gender identity and gender expression), marital status, national origin, race, religion, sex, sexual orientation, veteran status or any other status or condition protected by applicable federal, state, or local laws. Applicants who require accommodation to participate in the job application process may contact ******************************************** for assistance.
Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state, and local laws, including, but not limited to, the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act.
$98k-145k yearly est. 3d ago
Principal Cloud Security Architect
Labelbox 4.3
Security architect job in Nashville, TN
Role OverviewThe Principal Cloud SecurityArchitect evaluates cloud architectures, identity models, permissions, and security controls across large-scale environments. This role focuses on identifying architectural risks, misconfigurations, and long-term security design gaps.
What You'll Do- Assess cloud architectures (AWS, Azure, GCP) for security gaps - Review IAM configurations, network segmentation, and resource policies - Identify misconfigurations, privilege risks, and insecure patterns - Summarize architectural flaws and provide structured mitigation guidance - Validate alignment with security frameworks and best practices - Support recurring assessments of cloud environments and deployment patterns What You BringMust-Have:- Deep experience in cloud securityarchitecture - Strong understanding of IAM, network design, and cloud service models - Ability to document complex architectures in clear, structured form Nice-to-Have:- Experience with multi-cloud, zero-trust, or high-compliance environments
$102k-145k yearly est. Auto-Apply 38d ago
Google Cloud Security Architect
Slalom 4.6
Security architect job in Nashville, TN
Who You'll Work With As a modern technology company, our Slalom Technologists are disrupting the market and bringing to life the art of the possible for our clients. We have passion for building strategies, solutions, and creative products to help our clients solve their most complex and interesting business problems. We surround our technologists with interesting challenges, innovative minds, and emerging technologies.
Join the Slalom Cloud Team -a team of trailblazers ensuring we achieve our strategic goals through innovation and investment in the future. You'll collaborate with local market teams, niche experts, and global partners to drive cloud solution sales and empower clients on their cloud transformation journey. As a key member of Slalom's Google Cloud Center of Excellence, you'll leverage our award-winning partnerships and multidisciplinary teams to deliver business value and technical excellence for high-impact security and infrastructure solutions.
What You'll Do
* Stay current with security trends, technologies, and best practices around Google Cloud solutions, leveraging tools like Cloud IAM, Cloud Security Command Center, BeyondCorp, and Cloud Armor.
* Define and guide transformational security strategies for Google Cloud environments, ensuring alignment with Google's Zero Trust and BeyondCorp principles.
* Translate complex regulatory requirements (e.g., GDPR, SOC 2, HIPAA) and technology standards into actionable functional and technical requirements for cloud and hybrid environments, ensuring security and compliance.
* Lead teams through various phases of gap analyses, including security assessments, remediation planning, roadmap development, and implementation of remediation actions using Google Cloud-native tools.
* Deliver on the vision, architecture, execution, and quality assurance of security projects on Google Cloud, driving initiatives that secure enterprise workloads and data.
* Guide stakeholders and senior leaders on aligning security solutions with broader business goals, ensuring the architecture follows Google Cloud's security best practices and roadmap.
* Establish securityarchitecture patterns based on Google Cloud security frameworks and industry standards to meet the unique needs of enterprise clients.
* Collaborate with other Google Cloud architects and security teams to continuously improve security knowledge assets and best practices, ensuring the most effective security solutions for clients.
* Design and architect solutions to secure Generative AI models and applications against adversarial attacks, prompt injection, and their potential misuse for malicious cyber activities.
What You'll Bring
* Proven experience with Google Cloud securityarchitecture, with hands-on experience in tools like Cloud IAM, VPC Service Controls, Cloud DLP, and Cloud Armor.
* Strong background in defining and implementing Zero Trust and BeyondCorp security models within Google Cloud environments.
* Familiarity or direct experience with Identity and Access Management (IAM), Data Protection, Vulnerability Management, and Cloud Security solutions in Google Cloud.
* Extensive experience with security design patterns specific to Google Cloud, as well as hybrid and multi-cloud securityarchitecture.
* Experience in security and risk advisory consulting, particularly related to cloud security transformations.
* Ability to lead the development and implementation of cloud security roadmaps aligned with business goals and compliance needs.
* Familiarity with Google Cloud's Artificial Intelligence (AI) capabilities (e.g., Vertex AI, Generative AI services, Model Armor) including their applications, associated security risks (e.g., prompt injection, data poisoning, privacy concerns), and proven strategies for implementing security controls, governance, and responsible AI practices.
* Relevant certifications are strongly desired but not required, including (but not limited to):
* GCP Professional Security Engineer
* GCP Professional Cloud Architect
* CISSP
* Security+
About Us
Slalom is a fiercely human business and technology consulting company that leads with outcomes to bring more value, in all ways, always. From strategy through delivery, our agile teams across 52 offices in 12 countries collaborate with clients to bring powerful customer experiences, innovative ways of working, and new products and services to life. We are trusted by leaders across the Global 1000, many successful enterprise and mid-market companies, and 500+ public sector organizations to improve operations, drive growth, and create value. At Slalom, we believe that together, we can move faster, dream bigger, and build better tomorrows for all.
Compensation and Benefits
Slalom prides itself on helping team members thrive in their work and life. As a result, Slalom is proud to invest in benefits that include meaningful time off and paid holidays, parental leave, 401(k) with a match, a range of choices for highly subsidized health, dental, & vision coverage, adoption and fertility assistance, and short/long-term disability. We also offer yearly $350 reimbursement account for any well-being-related expenses, as well as discounted home, auto, and pet insurance.
Slalom is committed to fair and equitable compensation practices.
Slalom is committed to fair and equitable compensation practices. For this role, we are targeting the following levels and salary ranges:
East Bay, San Francisco, Silicon Valley:
* Senior Consultant: $131,000-$196,500
San Diego, Los Angeles, Orange County, Seattle, Houston, New Jersey, New York City, Westchester, Boston, Washington DC:
* Senior Consultant: $120,000-$180,000
All other locations:
* Senior Consultant: $110,000-$165,000
In addition, individuals may be eligible for an annual discretionary bonus. Actual compensation will depend upon an individual's skills, experience, qualifications, location, and other relevant factors. The salary pay range is subject to change and may be modified at any time.
EEO and Accommodations
Slalom is an equal opportunity employer and is committed to inclusion, diversity, and equity in the workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veterans' status, or any other characteristic protected by federal, state, or local laws. Slalom will also consider qualified applications with criminal histories, consistent with legal requirements. Slalom welcomes and encourages applications from individuals with disabilities. Reasonable accommodations are available for candidates during all aspects of the selection process. Please advise the talent acquisition team if you require accommodations during the interview process.
$131k-196.5k yearly 27d ago
Principal Security Architect
First Horizon Bank 3.9
Security architect job in Memphis, TN
**Weekly Schedule:** Monday- Friday: 9am-5pm **Primary Responsibilities** + Manages solution design from conception, through ARB, to delivery + Primarily responsible for producingarchitecture documentation forsecurityapplications as assigned and as projects and programs of work dictate
+ Maintains First Horizon'sSecurityArchitecture Pattern Inventory (across identity, data, application, network, and cloud) as a member of the Core EnterpriseArchitecture Team
+ Leadssecuritydesign workshops and POC efforts for new (security) capabilities
+ Validates 3rd Party/Vendor Solutions forsecurityconcerns
+ Aligns InformationSecurityTechnology strategy and planning with First Horizon's business goals and objectives
+ Promotes the use of a shared infrastructure and application roadmap to reduce costs and improve how assets are secured
+ Builds and maintains technical trusted advisor relationships with influential technical decision makers within Technology
+ Works with engineers to ensure that technical solutions as delivered align with InformationSecurityStandards and Policies
+ Works with Portfolio technology leaders to include IT Risk and SecurityException initiatives in portfolio roadmap
+ Manage Encryption Standards: key management, tokenization for payments, DLP/classification/handling;architect PCI DSS segmentation boundaries and compensating controls.
+ Manage Network/Zero Trust Standards: microsegmentation across Azure and colocation; secure branch/office connectivity; define workload identity and continuous verification patterns; enforce least privilege.
+ Detection/telemetry: Publish Splunk logging schema, retention, and correlation strategies; onboard logs from Azure, Colo, API Gateways, IAM, CyberArk, MFaaS, and core platforms; drive ATT&CK‑aligned detections and forensic readiness.
+ Secure SDLC and supply chain: Operationalize threat modeling; collaboratively define CI/CD control overlays with DevOps; establish artifact signing/SBOM standards; ensure secrets handling and container/Kubernetes baselines where applicable.
+ Governance and risk: Maintain control overlays mapped to FFIEC/GLBA/PCI/NIST; lead design reviews; manage exceptions with remediation timelines; produce audit-ready decision records in partnership with the CISO team.
+ Payments and third-party/SaaS: Define intake andsecurityrequirements for MFaaS, Salesforce, ServiceNow, FIS/Fiserv/Bottomline integrations-identity, logging, data handling, and PCI scoping.
+ Physicalsecurityintegration: Align building access, video, and visitor systems with identity and logging patterns; coordinate incident playbooks with Corporate/PhysicalSecurity.
+ Enablement and influence: Mentor seniorarchitects and engineering associates; lead communities of practice; communicate strategy, benefits, and trade-offs to executives and delivery teams.
**Requirements**
+ Bachelor's degree in Computer Science, Management Information Systems, or related field
+ (12+) years of InformationSecurityexperience
+ (7+) years of SecurityArchitecture
+ Experience in regulated financial services
+ Experience with Azuresecurityarchitecture across multi-tenant/region and hybrid environments; strong Zero Trust and network segmentation expertise
+ Regulatory fluency: FFIEC, GLBA, PCI DSS; practical NIST CSF/800-53 mapping; MITRE ATT&CK‑aligned detection design.
+ Experience with technical documentation like interaction diagrams, process diagrams, network topologies and otherarchitectural content
+ Experience with Agile/SAFe methodologies
+ Experience with EnterpriseArchitecture Governance: ARB/design councils, exception handling, and audit narratives; ability to set and harmonize enterprise standards.
**Certifications/Licensures**
+ Strongly preferred: CISSP or CompTIASecurity+ Microsoft AzureSecurityEngineer or Azure SolutionsArchitectExpert
+ Preferred: CCSP; CISM or CRISC; SANS GCSA or GCLD; PCI Professional (PCIP) or equivalent GIAC enterprise defense/IR certifications
**Skills And Competencies**
+ Ability to adapt to new technologies and learn quickly
+ Enterprisearchitectural leadership across identity, cloud, application, data, and networksecurity.
+ IAM for associates (Entra ID, Active Directory) and clients (TransmitSecurity, ForgeRock/Ping, or Okta); OAuth/OIDC; phishing-resistant MFA/passkeys; PAM integration and privileged pathway design.
+ IntegrationSecurity: FAPI, OAuth2.0, FDX, mTLS, rate limiting, schema validation, abuse/bot mitigation, CIAM integration, OWASP, and high-quality telemetry to Splunk.
+ Secure SDLC and supply chain: threat modeling, pipelinesecurity, artifact signing/SBOM, dependency hygiene, and secrets management.
+ Communication, influence, and enablement: ability to translate risk to business impact, drive adoption, and coach peers and engineers.
+ Ownership and execution: measurable risk reduction, pattern adoption, and cross‑team collaboration.
**About Us**
First Horizon Corporation is a leading regional financial services company, dedicated to helping our clients, communities and associates unlock their full potential with capital and counsel. Headquartered in Memphis, TN, the banking subsidiary First Horizon Bank operates in 12 states across the southern U.S. The Company and its subsidiaries offer commercial, private banking, consumer, small business, wealth and trust management, retail brokerage, capital markets, fixed income, and mortgage banking services. First Horizon has been recognized as one of the nation's best employers by Fortune and Forbes magazines and a Top 10 Most Reputable U.S. Bank. More information is available at ******************** (https://urldefense.com/v3/\_\_https:/********************/\_\_;!!Cz2fjcuE!hpq9hPnrucZCPIAVPojVESItIq-FPzhurNdCrQ3JE8Rkx3gMd70nIk6\_kmPxl66\_oJCEsXs0gNunPowMAMHCmBYPOtUxUGI$) .
**Benefit Highlights**
- Medical with wellness incentives, dental, and vision
- HSA with company match
- Maternity and parental leave
- Tuition reimbursement
- Mentor program
- 401(k) with 6% match
- More -- FirstHorizon.com/First-Horizon-National-Corporation/Careers/Our-Benefits
Follow Us
Facebook (******************************************
X formerly Twitter
LinkedIn (***************************************************
Instagram
YouTube (**********************************************************
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws.
For further information, please review the Know Your Rights (**************************** notice from the Department of Labor.
$108k-134k yearly est. 31d ago
Director of Information Security
SRM Concrete 4.1
Security architect job in Smyrna, TN
Director of Information Security Job Summary Smyrna Ready Mix (SRM) is seeking an accomplished and forward-thinking Director of Information Security to lead the strategy, implementation, and continuous improvement of SRM's cybersecurity posture across a rapidly growing enterprise environment. This leadership role will oversee all aspects of information security governance, risk management, compliance, and operations, ensuring that SRM's systems, data, and infrastructure remain secure, resilient, and aligned with business objectives. The Director of Information Security will collaborate with IT Leadership and operational teams to develop scalable security policies, incident response capabilities, and proactive defense measures across both on[1]premises and cloud (Azure/OCI) environments. This role requires a balance of technical expertise, leadership acumen, and business insight to protect SRM's expanding digital footprint. This position reports directly to the Chief Information Officer (CIO) and partners closely with senior IT and business leadership. The Director of Information Security will play a pivotal role in safeguarding SRM's operations and empowering the company's continued growth through secure, reliable, and innovative technology practices.
Responsibilities
• The Director of Information Security is responsible for the full lifecycle of SRM's cybersecurity program - from strategic planning and design through implementation, monitoring, and continuous improvement.
• Develop and execute SRM's enterprise-wide information security strategy, roadmap, and governance framework, ensuring consistent control design, secure system integration, and architectural alignment with Zero Trust principles.
• Lead and mentor the information security team, fostering a culture of collaboration, accountability, and ongoing professional development.
• Establish and maintain cybersecurity policies, standards, and procedures in alignment with industry best practices (NIST, CIS, ISO 27001).
• Design and oversee the implementation of security controls across network, system, application, and cloud infrastructures (Azure, OCI, O365).
• Collaborate with IT leadership to integrate security into all technology projects, ensuring secure design, configuration, and deployment practices.
• Manage risk assessments, vulnerability management, and remediation activities, prioritizing mitigation efforts based on business impact.
• Oversee identity and access management (IAM) strategy, ensuring proper integration with Microsoft Entra ID (Azure AD), Active Directory, and role-based access controls, as well as other identity strategies to be evaluated and implemented.
• Oversee enterprise security operations and incident response, leveraging SIEM, threat intelligence, and analytics to detect and mitigate risks, while leading disaster recovery planning, simulation exercises, periodic threat assessments and penetration testing, and post-incident reviews to strengthen organizational resilience.
• Coordinate audits and compliance efforts related to security, privacy, and data protection (SOX, PCI, GDPR, etc. as applicable).
• Define and track risk metrics on key cybersecurity performance indicators (KPIs) including health, incidents, and strategic initiatives and provide executive reports to CIO and IT leadership regularly and C-suite as needed.
• Partner with CIO and IT Leadership, along with Legal and HR teams to ensure adherence to evolving data privacy and regulatory requirements.
• Develop security strategies for operational technology (OT) and industrial IoT environments, including plant networks, weigh systems, and telemetry.
• Develop and manage enterprise-wide security awareness and training programs to promote a strong security culture.
• Evaluate emerging threats and technologies, recommending appropriate security solutions and investments.
• Establish and oversee third-party and supply-chain risk management processes, ensuring that vendor systems and services meet SRM's security and privacy requirements.
• Collaborate across IT disciplines (systems, networking, applications) to ensure end-to-end resilience, visibility, and alignment of security priorities with operational needs.
Qualifications / Requirements
• Bachelor's degree in Information Security, Computer Science, or related field (Master's preferred).
• 10+ years of progressive experience in IT and information security, including at least 5 years in a leadership or management role.
• Strong technical foundation in network, system, and cloud security, including firewalls, SIEM, endpoint protection, identity management, and incident response.
• Proven experience implementing and managing security programs across hybrid (on-prem/cloud) infrastructures.
• Deep understanding of various security suites for endpoint management and security (Defender, Entra ID, Intune, SentinelOne, Avanon, Azure Security Center and similar).
• Knowledge of risk management frameworks such as NIST CSF, ISO 27001, and CIS Controls.
• Demonstrated success developing policy, governance, and compliance programs.
• Strong analytical and strategic thinking skills with the ability to translate complex security issues into business terms.
• Excellent communication, leadership, and interpersonal skills; able to influence across technical and executive levels.
• Relevant certifications such as CISSP, CISM, CISA, or CRISC.
• Experience with industrial or operational technology (OT) environments is a plus.
• Experience with Zero Trust architecture and cloud-native security solutions.
• Experience leading incident response teams or managing security operations centers (SOC).
• Knowledge of data loss prevention (DLP), MFA, SIEM/SOAR, and endpoint detection and response (EDR) platforms.
• Proven ability to develop, budget for, and manage information security projects ensuring strategic investment in technologies, tools, and personnel are implemented timely and with minimal service impact.
About SRM
Smyrna Ready Mix (SRM) is a growing leader in the ready-mix concrete industry, recognized for excellence, integrity, and innovation. Our IT department supports a fast-paced, technology-driven environment, ensuring reliable systems and connectivity across all SRM locations nationwide. Joining SRM IT means becoming part of a collaborative, forward-thinking team that values accountability, growth, and teamwork. We leverage modern infrastructure solutions to support SRM's mission-building better communities with reliable service and sustainable growth.
$102k-144k yearly est. 6d ago
IT Security Engineer SR
Dollar General Corporation 4.4
Security architect job in Goodlettsville, TN
The Senior Security Engineer is responsible for designing and leading advanced security solutions to safeguard Dollar General's digital infrastructure, with a focus on cloud, network, and system security in a dynamic retail environment. This role drives layered security integration, mentors junior team members, and utilizes tools such as Palo Alto Networks, Splunk, and F5 ASM to address complex security risk. The ideal candidate brings a balance of technical depth, critical thinking, and pragmatism to strengthen Dollar General's overall security posture.
Job Details
Duties & Responsibilities: What major responsibilities does this position have and what percentage of time is spent on completing them? (Typically 5 - 7)
* Design and implement securityarchitectures across on-premises and cloud environments (Google GCP, Azure) utilizing tools such as Palo Alto firewalls, F5 ASM, and Akamai App & API Protector.
* Promote modern security fundamentals by embedding security into CI/CD pipelines using Terraform and championing secure design practices for applications and APIs.
* Perform advanced risk analysis and vulnerability management, leveraging tools such as ExtraHop RevealX, Palo Alto Cortex XDR, and Sysdig Secure to identify and mitigate threats.
* Manage and respond to security incidents and perform forensic analysis using Splunk and Proofpoint Email Security while leveraging CyberArk for privileged access control.
* Develop and enforce security policies related to network security (Palo Alto, Fortinet), DNS (Akamai), and identity management (Clearpass), with emphasis on PKI and conditional access frameworks.
* Mentor junior security engineers, fostering critical thinking and hands-on problem-solving skills while collaborating with IT and business units to embed security into organizational processes.
* Research emerging threats and evaluate technologies to inform and enhance Dollar General's security strategy and posture.
Knowledge, Skills and Abilities (KSAs): What KSAs are required to perform this job?
* Deep expertise in network security (Palo Alto, Fortinet, Meraki MX), application firewalls (F5 ASM, Akamai App & API Protector, Cloud Armor), and data protection (Digital Guardian DLP, Microsoft DLP).
* Advanced proficiency in cloud security (GCP, Azure) and container security (Sysdig Secure), including tools such as VPC Service Controls and Cloud Armor.
* Strong scripting skills in Python, Bash, or PowerShell, and hands-on experience in Terraform for automating security infrastructure.
* In-depth understanding of PKI, VPN/remote access technologies (CyberArk Alero, GlobalProtect), and DNS security (Akamai DNS, Akamai GLB).
* Exceptional analytical and critical thinking skills with the ability to solve complex security challenges in a pragmatic and business-aligned manner.
* Proven leadership and communication skills, with the ability to mentor team members and influence cross-functional stakeholders.
* Excellent written, oral, and inter-personal communications skills with the ability to clearly communicate complex topics across technical and non-technical audiences.
* Capability to adapt to rapidly changing technologies and threat landscapes, with occasional availability for non-standard hours or travel (up to 5%).
Qualifications
Work Experience &/or Education: What are the minimum education and/or experience requirements necessary to perform this job?
* Bachelor's degree in Computer Science, Information Security, or a related field; or equivalent combination of education and relevant experience.
* Minimum 7 years of experience in information security, including at least 2 years in a senior or leadership capacity.
* Advanced hands-on experience with at least five of the following:
* Palo Alto Networks firewalls and Panorama
* Akamai App/API Protector
* F5 Application Security Manager (ASM)
* Sysdig Secure (or equivalent)
* Google Cloud Platform (GCP) native security tools
* Microsoft Azure native security tools
* Microsoft Defender
* CyberArk Privileged Access
* HCL BigFix
* Splunk Enterprise and Enterprise Security
* Data security methodologies
* DLP technologies
* Proven track record in risk analysis, mitigation planning, and implementing secure configurations across cloud, network, and application layers.
* Preferred certifications: CISSP, CISM, CISSP-ISSAP, Palo Alto PCNSE, Splunk Certified Architect, or GCP Cloud Security Engineer.
$91k-114k yearly est. 20d ago
Sr. Information Security Engineer
North Star Staffing Solutions
Security architect job in Goodlettsville, TN
Job Requirements & Qualifications: •Designs, put into practice, administers, and supports multiple information security platforms, systems, and applications. Supports a variety of technologies in a hands-on manner. •Performs internal security risk assessments, security risk assessments of third party business partners, and detailed security risk assessments of various technologies. (Examples include directory services, database platforms, client and server operating systems, programming languages, web services, firewalls, remote access technologies, messaging platforms, encryption solutions, wireless technologies, internally-hosted applications, externally-hosted applications, and cloud services).
•Supports defined Company operating principles via effective, pragmatic information security controls. Analyzes, defines, implements, and administers efficient business processes related to information security programs. Represents the information security function through pragmatic consultation and participation in a defined SDLC.
•Maintains knowledge of current and up-and-coming security, compliance, and technical developments. Identifies present and prospective future vulnerabilities and collaborates with suitable leaders to identify, recommend, and develop risk remediation plans, ad to track remediation outcomes and timelines.
•Works with the information security management team to administer, maintain, and continuously improve HIPAA, PCI DSS, SOX, and internal controls compliance programs, investigate known or suspected security incidents, support internal and external audits, and assist in the development of appropriate audit response Management Action Plans.
•Promotes security best practices via awareness, example, and compliance with policies and regulatory requirements.
•Uses project management best practices to initiate, manage, and close projects, often simultaneously across a variety of projects. Creates and maintains a variety of documents related to projects and information security.
•Guide and cross-train junior department team members lead meetings construct and uphold strong partnerships with multiple departments coordinate vendor support engagements etc.
Knowledge, Skills, and Abilities
•Knowledgeable with and ability to apply time-proven, generally-accepted security management concepts, techniques, and methodologies.
•Strong understanding of pragmatic implementation of information security controls, holistic defense-in-depth strategies, protocols used to interconnect networks, and publish application resources.
•Strong, efficient written and verbal communication skills that enables effective communications to multiple audiences.
•Ability to occasionally work unscheduled shifts and in an on-call capacity and be available for occasional travel (up to 25%).
•Strong internal (security recommendations) and external (vendor support) negotiation skills.
•Ability to influence and encourage others.
•Strong understanding of PCI, HIPAA, and SOC regulatory requirements.
•Development/analysis proficiency in one or more scripting languages.
•Development/analysis proficiency in TSQL.
•Capability to learn and preserve new skills required to adapt to growing business and technical environments.
•Strong perceptive of present and emergent information security technologies and trends.
Qualifications
Work Experience and/or Education
•Bachelor's and/or Master's degree in information security or computer information systems.
•6+ years of information security generalist experience (broad and deep in data, application, system, and network security domains) with complex technical initiatives.
•Active CISA, CISSP, or CISM certification.
•Experience identifying and addressing security risks associated with host and network operating systems (e.g. Windows, Linux, AS400, PAN OS, AIX, Cisco IOS, etc.) enterprise services (e.g. directory services, email, web publishing, database, virtualization, etc.) content management, client-server, and collaboration, thin-client, and web-based applications enterprise applications (e.g. Lawson) cloud services (e.g. SaaS, IaaS, etc.) data storage, etc.
•Hands-on SME/lead experience with the design, implementation, and administration of at least 5 of the following technologies: Palo Alto Networks, IBM Tivoli Endpoint Manager (BigFix), IBM QRadar (SIEM), Qualys Vulnerability Scanning Solutions, Tenable Nessus, Juniper SSL VPN GlobalScape EFT Server Symantec Data Loss Prevention (Vontu), RSA SecurID, and CyberArk Password Management.
Additional Information
$88k-117k yearly est. 10h ago
Senior Security Engineer, Detection and Response
Acadia Healthcare Inc. 4.0
Security architect job in Franklin, TN
Senior Security Engineer - Detection and Response Candidates must be local or willing to relocate at their own expense Our Mission Acadia Healthcare's purpose is to Lead Care With Light and our mission is to be a world-class organization that sets the standard for excellence in the treatment of mental health and addiction concerns. We strive to maintain our standing as a thought leader in the behavioral healthcare industry, providing treatment that is synonymous with compassion and innovation.
About the Role
The Sr. Security Engineer - Detection and Response position is instrumental in the safeguarding and preservation of Acadia's crucial IT infrastructure and sensitive patient data. This role is entirely committed to upholding the most stringent cybersecurity standards within a healthcare environment, ensuring full compliance with industry regulations, and promptly addressing security incidents. Through the adept utilization of state-of-the-art security technologies, automation, and strong partnerships with third-party MSSPs, the Healthcare Security Engineer assumes a pivotal role in the delivery of superior patient care, the nurturing of patient trust, and the unwavering preservation of integrity and confidentiality within our healthcare systems.
The first 90 days in this role will be fully in-person to ensure comprehensive onboarding and training. After the initial period, the position will transition to a hybrid model, with 2 days remote and 3 days in the office each week.
Compensation & Benefits
We value your expertise and dedication-and we invest in your success.
* Competitive Base Salary commensurate with experience
* Comprehensive Medical, Dental, and Vision Insurance
* 401(k) Plan with Company Match
* Paid Time Off (PTO) and recognized holidays
* Company-paid Basic Life and AD&D Insurance
* Employee Assistance Program (EAP) and mental wellness resources
* Opportunities for professional growth and advancement within Acadia's nationwide network
Key Responsibilities
* Security Operations:
* Implement and manage security tools
* Continuously monitor for malicious activities and vulnerabilities
* Develop comprehensive threat detection and alerting procedures
* Incident Response:
* Lead and coordinate incident response, collaborating with IT and compliance teams
* Tailor incident response plans for healthcare settings
* Investigate and assess security incidents, with forensic analysis
* Develop containment and remediation strategies for risk mitigation
* Security Infrastructure and Compliance:
* Maintain and optimize security tools and systems
* Ensure compliance with healthcare regulations and standards
* Assist in external compliance audits
* MSSP and Threat Intelligence:
* Collaborate with MSSP for security tools and configurations
* Define SLAs and KPIs to align with security objectives
* Share threat intelligence with MSSP for unified threat response
* Coordinate incidents and create incident response playbooks with MSSP's expertise
* Continuous Improvement and Automation:
* Enhance security through scripting and automation
* Develop custom security solutions
* Automate incident response with scripting
* Stay current with scripting languages and automation frameworks
* Operational Metrics and SLOs:
* Define operational metrics and KPIs
* Establish quantifiable performance indicators
* Regularly review and refine operational metrics
* Develop and monitor service level objectives (SLOs) to ensure operational excellence
Other Responsibilities
* Performs other tasks as assigned
Standard Expectations
* Complies with organizational policies, procedures, performance improvement initiatives and maintains organizational and industry policies regarding confidentiality
* Communicate clearly and effectively to person(s) receiving services and their family members, guests and other members of the health care team
* Develops constructive and cooperative working relationships with others and maintains them over time
* Encourages and builds mutual trust, respect and cooperation among team members
Education/Experience/Skill Requirements
* Education: A bachelor's degree or equivalent work experience
* Experience: Minimum of 5 years of cybersecurity experience, with a preference for at least 4 years in detection and response
* Expertise: Strong knowledge of cybersecurity principles, technologies, and best practices. Proven experience in healthcare security and knowledge of industry regulations, such as HIPAA and HITECH
* Communication: Excellent communication and collaboration skills to work with diverse teams and vendors
* Compliance: Knowledge and understanding of relevant legal and regulatory requirements, such as: Sarbanes-Oxley Act (SOX), Health Insurance Portability and Accountability Act (HIPAA) and Payment Card Industry/Data Security Standard (PCI)
* Frameworks: Proficiency in common information security management frameworks, such as ITIL, Center for Internet Security (CIS) Critical Security Controls (CSC), and NIST, including 800-53 and MITRE ATT&CK Framework
* Problem-Solving: Strong problem-solving and analytical abilities
* Technology Proficiency: Candidates must be capable of effectively evaluating and implementing technical alternatives, staying up to date with emerging technologies, risk assessment methodologies, and incident response
* Self-Motivation: Self-motivated with strong organizational skills and exceptional attention to detail
* Multitasking: Ability to manage multiple tasks/projects simultaneously within strict time frames and adapt to frequent priority changes
* Adherence: Capability to work within established policies, procedures, and practices set by the organization
* Language Skills: Proficient in English to provide and receive instructions and directions effectively.
License/Designations/Certifications
* Certifications: Desired by not required: Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), CompTIA Security + or Network +, GIAC Certified Incident Handler Certification (GCIH), GIAC Certified Intrusion Analyst Certification (GCIA), Certified Cloud Security Professional (CCSP), Certified Intrusion Analyst (GCIA), Certified Information Security Incident Handler (CIHI), Certified Incident Handler (EC-Council ECIH), Certified Ethical Hacker (CEH), or other similar credentials.
Supervisory Requirements
This position is an Individual Contributor
While this job description is intended to be an accurate reflection of the requirements of the job, management reserves the right to add or remove duties from particular jobs when circumstances (e.g. emergencies, changes in workload, rush jobs or technological developments) dictate.
#LI-JS1
$90k-116k yearly est. 5d ago
Manager, Information Security Policy and Controls Governance
Unum Group 4.4
Security architect job in Chattanooga, TN
Our Fortune 500 company is driving a digital transformation and looking for forward-thinking innovators to disrupt how our industry thinks about and uses technology. As one of the world's leading employee benefits providers, we help millions of people gain affordable access to benefits that help them protect their families, their finances and their futures.
Are you an asker of questions, a solver of problems, and a challenger of the status quo? Our mission is to provide a differentiated customer experience and exceed the expectations people have of technology at any company - not just insurers.
We are seeking individuals to join our team of talented IT professionals who share never-ending passion and an unwavering focus on our customer experience. Team members comfortable working in an agile, fast-paced, and delivery-focused environment thrive in our environment where we value an entrepreneurial spirit and those who challenge the status-quo.
Unum is changing, and we're excited about what's next. Join us.
General Summary:The Manager - Information Security Policy and Controls Governance is responsible for strategic enhancement and day-to-day operation of key governance, risk, and compliance capabilities, including policy and standards governance, enterprise and application-level risk assessments, and controls management and attestation programs. This role will oversee the full lifecycle of governing documents, manage policy exceptions, coordinate external and regulatory assessments, and ensure strong alignment between security controls and regulatory requirements. The manager will also drive consistent, timely issues management across all domains. This leader will partner closely with stakeholders across the organization to mature processes, strengthen compliance posture, and ensure effective, repeatable execution of GRC activities. They will manage a small to mid-size team of IT security and risk management professionals.
Job Specifications
Bachelors degree in computer science, or relevant technical experience
Has 5+ years experience in an IT Risk Management field, or equivalent relevant work experience
Has a security technology background with strong knowledge of relevant technical security disciplines
Exhibits courage by taking smart risks and encouraging others to do so; empowers innovative approaches by motivating others to be proactive and resourceful
Able to effectively coach, mentor, identify, and address skills needs and gaps
Proficient in methods and techniques for running effective meetings and for understanding and influencing the roles played by participants
Displays good interpersonal skills at all levels of contact and in a wide variety of situations, able to listen and influence, and to relate to customers in their own language
Demonstrates the ability to champion change and support teams through change.
Demonstrates the ability to think critically, challenge conventional thinking and generate and apply unique business insight to create competitive advantage for the organization
Has solid knowledge of regulations, including, GLPA, HIPAA, GDPR, CCPA, and other cyber security regulatory compliance requirements and related programs
Has in-depth knowledge of security and control frameworks such as the NIST Cyber Security Framework, NIST SP 800-53, ISO 17799/27001, CobIT, and ITIL
CRISC, CISSP, CISM, CISA, and other security related certifications are a plus
Principal Duties and Responsibilities
Oversees and evaluates the delivery and effectiveness of the organizations policy governance, risk assessments, control attestation, and issues management capabilities, taking action to address performance or quality gaps as needed.
Ensures the team maintains a well‑defined, risk‑aligned backlog of work that advances program maturity and meets regulatory, audit, and business needs.
Guides team members in prioritizing assessments, policy lifecycle activities, and control-related work based on risk, business value, and regulatory timelines.
Proactively removes obstacles and operational roadblocks that hinder timely completion of assessments, attestations, and governance processes.
Partners with business and technology stakeholders to translate security, compliance, and risk management objectives into actionable work items.
Ensures best‑practice execution, including structured assessment methodologies, clear control documentation, consistent issue tracking, adherence to policy standards, and high‑quality evidence collection.
Encourages creativity and continuous improvement in maturing governance, assessment, and control processes; fosters a culture of innovation within the team.
Uses operational metrics, assessment cycle data, and workflow insights to understand team performance and drive process efficiency.
Partners with leadership to ensure strong talent is in place to support the organization's governance, risk and compliance obligations.
Mentors, coaches, and motivates team members to elevate their GRC expertise, business partnership skills, and overall performance.
Identifies skill gaps related to risk frameworks, regulatory requirements, control design, and assessment techniques, ensuring development plans address these needs.
Promotes cross‑training and shared ownership of GRC functions to reduce single‑points‑of‑failure and increase team resilience.
While accountable for the team's output, actively cultivates a self‑organizing, autonomous, and collaborative team that consistently demonstrates accountability and continuous improvement.
Conducts regular 1:1s and development discussions to monitor progress, reinforce strengths, and close skill gaps.
Collaborates with peers to evaluate the effectiveness of resourcing models, proposing enhancements to better support team operations.
Maintains a strong understanding of emerging regulatory trends, risk frameworks (e.g., NIST CSF, HIPAA, SOC, ISO), and control expectations to inform program improvements.
Reinforces disciplined prioritization by ensuring the team focuses on the highest‑value, highest‑risk activities and commitments.
Designs and operates GRC processes with partner teams' knowledge and needs in mind, ensuring risk governance activities are clear, intuitive, and easy to complete.
#LI-TO1
#LI-MULTI
IN4
Our company is built on helping individuals and families, and this starts with our employees. We want employees to maintain a positive balance, which is why we provide access to the benefits and resources they need to invest in themselves. From our onsite fitness facilities and generous paid time off to employee professional development programs, we are committed to helping employees live and work their best - both inside and outside the office.
Unum is an equal opportunity employer, considering all qualified applicants and employees for hiring, placement, and advancement, without regard to a person's race, color, religion, national origin, age, genetic information, military status, gender, sexual orientation, gender identity or expression, disability, or protected veteran status.
The base salary range for applicants for this position is listed below. Unless actual salary is indicated above in the job description, actual pay will be based on skill, geographical location and experience.
$89,400.00-$183,500.00
Additionally, Unum offers a portfolio of benefits and rewards that are competitive and comprehensive including healthcare benefits (health, vision, dental), insurance benefits (short & long-term disability), performance-based incentive plans, paid time off, and a 401(k) retirement plan with an employer match up to 5% and an additional 4.5% contribution whether you contribute to the plan or not. All benefits are subject to the terms and conditions of individual Plans.
Company:
Unum
$89.4k-183.5k yearly Auto-Apply 12d ago
Sr. Security Analyst
Maximus 4.3
Security architect job in Bowling Green, KY
Description & Requirements Maximus is seeking a qualified Sr. Technical/Security Analyst for multiple projects, current and upcoming. The qualified candidate will be involved in technical/security planning and assessment projects with potentially multiple state agencies. The position requires the candidate to produce/review security relevant documentation, such as system security plans, POA&Ms, assessment plans, etc., produce technical/security analyses, develop estimates, review and contribute to requirements for large systems-planning efforts in the Child Support, Child Welfare and/or Integrated Eligibility public-sector domains. The individual will report directly to a Senior Manager. Maximus is a matrix-managed organization, which means the individual will have secondary reporting relationships to one or more Project Managers, depending on which projects they are assigned.
*This role is remote but requires working standard business hours in the US time zone of the client.*
Essential Duties and Responsibilities:
- Collaborate with project managers on various initiatives and projects to track progress and provide support as necessary.
- Support leadership in ensuring that the project is delivered to specifications, is on time, and within budget.
- Work closely with management and work groups to create and maintain work plan documents.
- Track the status and due dates of projects.
- Manage relationships with project staff responsible for projects.
- Produce regular weekly and monthly status reports that could include; work plan status, target dates, budget, resource capacity, and other reports as needed.
- Facilitate regular meetings and reviews.
- Adhere to contract requirements and comply with all corporate policies and procedures.
Job Specific Duties and Responsibilities:
-Perform duties independently under the direction of their direct manager and/or Project Managers on specific projects.
-Review project documentation and client materials and provide analysis of technical and security related topics.
-Participate in client meetings and offer observations and insight on technical and security related topics.
-Identify risk areas and potential problems that require proactive attention.
-Review and author artifacts and other project documents and identify potential gaps, inconsistencies, or other issues that may put the project at risk. Such artifacts and documents may include but are not limited to:
*System Security Plan
*Plan of Action and Milestones (POA&M)
*Security Assessment Plan
*Risk Assessment reports
*CMS ARC-AMPE forms and documentation
*Data Conversion and Migration Management Plan
*Deployment and/or roll-out plans
-Perform security assessments, lead security audit and assessment activities, and provide direct security oversight support to assigned clients and projects.
-Identify and escalate to the Senior Manager / Project Manager risks, alternatives, and potential quality issues.
-Attend interviews, focus groups, or other meetings necessary to gather information for project deliverables in accordance with the project scope of work.
-Attend project meetings with the client, subcontractors, project stakeholders, or other Maximus Team members, as requested by the Senior Manager / Project Manager.
-Complete project work in compliance with Maximus standards and procedures.
-Support team to complete assigned responsibilities as outlined in the Project schedule.
-Support all other tasks assigned by Senior Manager / Project Manager.
Minimum Requirements
- Bachelor's degree in related field.
- 7-10 years of relevant professional experience required.
- Equivalent combination of education and experience considered in lieu of degree.
Job Specific Requirements:
-Be available to work during standard client business hours. Projects may involve clients from any US time zone, so it is possible that work outside of the individual's local business hours will be required.
-Bachelor's degree from an accredited college or university, or equivalent work experience.
-7+ years of experience in information security, with at least 3 years of security-compliance work in a regulated industry.
-5+ years of experience working with HIPAA, NIST 800-53 and/or CMS MARS-E or ARC-AMPE security frameworks.
-Familiar with operating systems: Windows, Linux/UNIX, OS/X.
-Familiar with AI tools, capabilities.
-Strong command of cloud computing topics.
-Strong command of agile software development practices as well as waterfall development practices.
-Strong desktop software skills: proficient in MS Office, Excel, Word, Project.
-Ability to explain and communicate technical subjects to non-technical audiences.
-Ability to develop advanced concepts, techniques, and standards requiring a high level of interpersonal and technical skills.
-Ability to work independently.
-Good organizational skills and the ability to manage multiple tasks and deadlines simultaneously.
-Strong interpersonal and team building skills, as well as an understanding of client relationship building are essential.
-Excellent verbal and writing skills and be comfortable working with customers.
-Ability to multi-task with supervision.
-Self-motivated fast learner.
Preferred Skills:
-Prefer a candidate with experience in the Health & Human Services industry, which may include working with programs such as Child Support, Child Welfare, or Integrated Eligibility (SNAP, TANF, and Medicaid).
-Preference for security related certifications, such as the CISSP (Certified Information Systems Security Professional).
EEO Statement
Maximus is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, age, national origin, disability, veteran status, genetic information and other legally protected characteristics.
Pay Transparency
Maximus compensation is based on various factors including but not limited to job location, a candidate's education, training, experience, expected quality and quantity of work, required travel (if any), external market and internal value analysis including seniority and merit systems, as well as internal pay alignment. Annual salary is just one component of Maximus's total compensation package. Other rewards may include short- and long-term incentives as well as program-specific awards. Additionally, Maximus provides a variety of benefits to employees, including health insurance coverage, life and disability insurance, a retirement savings plan, paid holidays and paid time off. Compensation ranges may differ based on contract value but will be commensurate with job duties and relevant work experience. An applicant's salary history will not be used in determining compensation. Maximus will comply with regulatory minimum wage rates and exempt salary thresholds in all instances.
Accommodations
Maximus provides reasonable accommodations to individuals requiring assistance during any phase of the employment process due to a disability, medical condition, or physical or mental impairment. If you require assistance at any stage of the employment process-including accessing job postings, completing assessments, or participating in interviews,-please contact People Operations at **************************.
Minimum Salary
$
120,000.00
Maximum Salary
$
140,000.00
$78k-105k yearly est. Easy Apply 4d ago
Information Security Executive Advisor (Business Information Security Officer- BISO)
Carebridge 3.8
Security architect job in Nashville, TN
Location: This role requires associates to be in-office 1 day per week, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life balance. This approach combines structured office engagement with the autonomy of virtual work, promoting a dynamic and adaptable workplace. Ideal candidates will be able to report to one of our Pulse Point locations in Indianapolis, IN or Nashville, TN. Alternate locations may be considered if candidates reside within a commuting distance from an office.
Please note that per our policy on hybrid/virtual work, candidates not within a reasonable commuting distance from the posting location(s) will not be considered for employment, unless an accommodation is granted as required by law.
The Information Security Executive Advisor (Business Information Security Officer- BISO) develops strategic and tactical plans for a comprehensive enterprise-wide information security program. Leads the development of policies, technical standards, guidelines, procedures, and other elements of an infrastructure necessary to support information security in compliance with established company policies, regulatory requirements, and generally accepted information security controls. Responsible for the selection and delivery of strategic network security, access control and secure transaction/messaging solutions.
How you will make an impact:
* Establishes architecture oversight and planning for information and network security technologies.
* Leads development of an information security risk management program that includes business, regulatory, industry practices and technical environment considerations.
* Establishes strategic vendor relationships for security products and services.
* Develops Enterprise-wide security incident response plans and strategies that includes integration with business, compliance, privacy, and legal constituents and requirements.
* Provides advanced level engineering design functions.
* Provides trouble resolution and serves as point of technical escalation on complex problems.
* Creates presentations and seeks IT and business management approval and acceptance of significant replacements or reconfigurations of major security technologies serving the Enterprise.
* Provides technical guidance and leadership to the technical engineers within the organization.
* Participates in the design of the Enterprise architecture.
* Proposes opportunities to improve results based on targeted or continuous assessment.
* Researches relevant trends and activities in healthcare, business, competition and regulatory environments.
* Recommends strategy adjustments.
* Participates in Enterprise planning activity, including vendor assessment, technology platform selection and retirement, prioritization and integration.
* Serves as a technical merger and acquisition lead.
* Acts as a subject matter expert for executive management.
* Provides top-tier support for 6 or more of the information security technology common body of knowledge skill sets: 1) Access Control, 2) Application Security, 3) Business Continuity and Disaster Recovery Planning, 4) Cryptography, 5) Information Security and Risk Management 6) Legal, Regulations, 7) Compliance and Investigations, 8) Operations Security, 9) Physical (Environmental) Security, 10) SecurityArchitecture and Design, 11) Telecommunications and Network Security.
Minimum Requirements:
Requires BS/BA in Information Technology or related field of study and a minimum of 10 years of experience in systems administration and security aspects of information systems, access management and network security technologies, network communications, computer networking, telecommunications, systems development and management, hardware, software, data, and people; experience with multiple technical and business disciplines required; or any combination of education and experience, which would provide an equivalent background.
Preferred Skills, Capabilities and Experiences:
* Previous experience leading large security projects for individual business units highly preferred.
* Expert Business Information Security Liaison experience highly preferred.
* Ability to operate with ambiguous data to create a strategy and plan preferred.
* Broad-based experience to plan and design highly complex systems preferred.
* Expert knowledge and understanding of industry-accepted data processing controls and concepts preferred.
* Security Certifications such as CISSP and other advanced technical security certifications (e.g. Information Systems SecurityArchitecture Professional, Information Systems Security Engineering Professional, Certification and Accreditation or equivalent certifications) preferred.
Please be advised that Elevance Health only accepts resumes for compensation from agencies that have a signed agreement with Elevance Health. Any unsolicited resumes, including those submitted to hiring managers, are deemed to be the property of Elevance Health.
Who We Are
Elevance Health is a health company dedicated to improving lives and communities - and making healthcare simpler. We are a Fortune 25 company with a longstanding history in the healthcare industry, looking for leaders at all levels of the organization who are passionate about making an impact on our members and the communities we serve.
How We Work
At Elevance Health, we are creating a culture that is designed to advance our strategy but will also lead to personal and professional growth for our associates. Our values and behaviors are the root of our culture. They are how we achieve our strategy, power our business outcomes and drive our shared success - for our consumers, our associates, our communities and our business.
We offer a range of market-competitive total rewards that include merit increases, paid holidays, Paid Time Off, and incentive bonus programs (unless covered by a collective bargaining agreement), medical, dental, vision, short and long term disability benefits, 401(k) +match, stock purchase plan, life insurance, wellness programs and financial education resources, to name a few.
Elevance Health operates in a Hybrid Workforce Strategy. Unless specified as primarily virtual by the hiring manager, associates are required to work at an Elevance Health location at least once per week, and potentially several times per week. Specific requirements and expectations for time onsite will be discussed as part of the hiring process.
The health of our associates and communities is a top priority for Elevance Health. We require all new candidates in certain patient/member-facing roles to become vaccinated against COVID-19 and Influenza. If you are not vaccinated, your offer will be rescinded unless you provide an acceptable explanation. Elevance Health will also follow all relevant federal, state and local laws.
Elevance Health is an Equal Employment Opportunity employer and all qualified applicants will receive consideration for employment without regard to age, citizenship status, color, creed, disability, ethnicity, genetic information, gender (including gender identity and gender expression), marital status, national origin, race, religion, sex, sexual orientation, veteran status or any other status or condition protected by applicable federal, state, or local laws. Applicants who require accommodation to participate in the job application process may contact ******************************************** for assistance.
Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state, and local laws, including, but not limited to, the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act.
$99k-139k yearly est. Auto-Apply 60d+ ago
Information System Security Officer
ITR 4.2
Security architect job in Oak Ridge, TN
Job DescriptionEast Tennessee company is seeking an ISSO to join their growing team. This position requires candidates to currently have or can obtain a federal security clearance so US citizenship is required. This position will be required to work onsite in Oak Ridge Tennessee.
Duties and Responsibilities:The ISSO is a primary stakeholder and facilitator of the continuous monitoring efforts that promote RMF compliance throughout the organization. The ISSO provides direction to IT and infrastructure support personnel on the application of security patches and secure configurations. Routine collaboration and consultation with the ISSM regarding the design, development, integration, and analysis of unclassified information systems. Under general supervision, the candidate is responsible for performing a full range of Information Assurance functions in support of the security needs of the ISSM.Primary Responsibilities:
Provide assistance to the ISSM and CISO in the certification and accreditation (C&A) of systems/networks and implementation of cybersecurity requirements and procedures across the client site.
Ensure systems are operated, maintained, and disposed of in accordance with security policies and procedures and as outlined in applicable System Security Plans (SSPs).
Perform documented procedures for authorizing users to access information systems.
Develop and maintain SSPs for system C&A.
Manage Plans of Action and Milestones to closure for information systems under accreditation.
Provide guidance on policies and controls to support appropriate levels of risk, facilitate risk tolerance discussions and decisions, and recommend controls based on industry standards and practices. Escalate questions/concerns/issues to more senior-level staff as required.
Participate in internal/external compliance audits, reviews, self-assessments, assessments, and data calls.
Identify, promote, and make recommendations for process improvements.
Assist with annual self-inspections, system certification testing, periodic security testing, and functional testing on systems/networks.
Ensure compliance of all network equipment with applicable DOE and ORNL requirements
Other duties as assigned for support within the program.
Basic Qualifications:
Bachelor's degree with 5-7 years of relevant experience (ex. cybersecurity assessments, risk management, cybersecurity policy, and compliance, etc.). An equivalent combination of education and experience may be considered.
Ability to obtain and maintain a DOE Q security clearance or equivalent is required.
Strong analytical and organizational skills as well as problem solving capabilities to understand Cybersecurity risk and exposure (legal, regulatory violations, etc.) to ORNL.
Demonstrated experience implementing compliance frameworks (NIST, etc)
Excellent interpersonal, verbal, written, and presentation communication skills.
Thorough understanding of industry standards and regulations including NIST 800-53, NIST Risk Management Framework, and NIST Cybersecurity Framework (CSF).
Working knowledge of privacy regulations and impacts.
Ability to work independently, meet deadlines, and uphold high ethical standards.
Preferred Qualifications:
Active DOE Q or TS security clearance or equivalent.
Master's degree in information assurance or related field with 4-6 years of relevant experience working in an information security, information technology or information risk management related field.
Cybersecurity certifications (CISSP, CISA, CISM, CRISC, CCSP, SSCP) and Incident Response Certification
Privacy management, cybersecurity, evaluating security controls, identifying control gaps, and mitigating measures along with a strong understanding of business practices and technology concepts.
Highly motivated individual with an enthusiasm for governance, risk and compliance who can communicate benefits and drive success.
Demonstrated background in governance, risk, and compliance.
Experience in obtaining Authority to Operate (ATO) for DOE government systems.
$63k-83k yearly est. 12d ago
Sr. Cyber Security (Sailpoint) Engineer
Community Health Systems 4.5
Security architect job in Franklin, TN
As a member of the Community Health Systems (CHS) Cyber Security Team, the Cyber Security (IAM) Engineer, Sr will be responsible for design, implementation, and support of IAM integrations, with a strong focus on automating user provisioning lifecycle processes across a wide range of enterprise applications. The engineer role will serve as subject matter expert for Sailpoint ISC environment and work with cross functional teams to mature the platform and ensure it meets business and application needs.
**Essential Functions**
+ Design, develop, implement, and support enterprise Identity and Access Management (IAM) systems and solutions.
+ Serve as a Subject Matter Expert (SME) for SailPoint Identity Security Cloud (ISC), providing guidance and support for integrations across a wide range of applications
+ Lead the implementation of core IAM functions, including Joiner-Mover-Leaver (JML) lifecycle processes, role management, connector integrations, provisioning policies, rules, transforms, and workflows.
+ Work with a variety of applications and systems, including Active Directory, Ping, GSuite, and more, to support identity integrations and access management processes. Knowledge of working with medical applications like Med host, Cerner is desirable
+ Collaborate with enterprise architecture and business stakeholders to drive the strategic growth and maturity of the IAM program.
+ Maintain continuous oversight of the IAM environment to ensure security, system integrity, and operational stability.
+ Proactively identify security vulnerabilities, conduct risk assessments, and implement remediation measures to strengthen the overall identity security posture and reduce exposure to threats.
+ Track and analyze IAM-related metrics, using insights to drive improvements in system performance, access governance, and operational efficiency.
+ Partner with audit, compliance, application owners, and business teams to support ongoing operations and new business initiatives.
+ Work with teams to proactively troubleshoot and resolve critical issues, and performing root cause analysis to maintain system availability, health, and continuous access provisioning/deprovisioning to applications.
+ Work with internal audit and compliance teams to ensure IAM platform aligns with internal policy requirements, respond to audit requests, provide required documentation and evidence reports.
+ Build and review business and technical requirements, solution designs, and use case documentation to support the successful implementation of IAM functionalities.
+ Maintain up-to-date documentation including architecture diagrams, technical specifications, and run books to support onboarding applications, cross-team collaboration, and smooth handoffs across IAM-related projects.
+ Business and Soft Skill expectations:
+ Communicate and interact effectively and professionally with co-workers, management, customers and vendors.
+ Communicate with management regarding development within areas of assigned responsibilities and perform special projects as required or requested.
**Qualifications**
+ Bachelor's Degree in Cyber Security, Computer Science, Information Systems (or other related field) or equivalent work experience
+ 6+ years of Identity and Access Management4+ years of Sailpoint experience2+ years of Sailpoint ISC experience
**Knowledge, Skills and Abilities**
+ Deep knowledge of cyber security tools, techniques, and standards across infrastructure, applications, and cloud environments.
+ Strong understanding of security frameworks including NIST, CIS, and ISO 27001.
+ Ability to analyze complex technical and business problems and develop effective, scalable solutions.
+ Skilled in incident response, forensic analysis, and root cause determination.
+ Excellent written and verbal communication skills, with the ability to clearly convey technical concepts to non-technical audiences.
**Licenses and Certifications**
+ Relevant security certifications such as CISSP, CISM, GIAC, or CEH required
+ Additional technical certifications (e.g., Azure Security Engineer, AWS Security Specialty) preferred
Equal Employment Opportunity
This organization does not discriminate in any way to deprive any person of employment opportunities or otherwise adversely affect the status of any employee because of race, color, religion, sex, sexual orientation, genetic information, gender identity, national origin, age, disability, citizenship, veteran status, or military or uniformed services, in accordance with all applicable governmental laws and regulations. In addition, the facility complies with all applicable federal, state and local laws governing nondiscrimination in employment. This applies to all terms and conditions of employment including, but not limited to: hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training. If you are an applicant with a mental or physical disability who needs a reasonable accommodation for any part of the application or hiring process, contact the director of Human Resources at the facility to which you are seeking employment; Simply go to ************************************************* to obtain the main telephone number of the facility and ask for Human Resources.
$71k-88k yearly est. 30d ago
Product Security Engineer
Ncontracts
Security architect job in Brentwood, TN
Remote | Product and Development | Full-Time
WHO WE ARE
Headquartered in Nashville, Tenn., Ncontracts leads the industry in integrated risk management and compliance solutions, serving over 5,000 financial institutions nationwide. As a seven-time Inc. 5000 Fastest Growing Companies honoree and consistent year-over-year recipient of "Best Places to Work" awards, we offer a thriving, work environment where career growth and life-work balance go hand in hand.
At Ncontracts, you'll join a team of industry experts dedicated to strengthening the financial services sector through innovation and thought leadership. We're seeking creative, collaborative, and self-driven professionals across all areas of our business - from developing cutting-edge solutions to sales, marketing, customer support, and beyond. Join us in our mission to make the financial industry stronger and more resilient, while advancing your career in a supportive, dynamic environment that values your unique skills and perspectives.
THE ROLE
We're looking for a Product Security Engineer to embed security throughout our software development lifecycle. You'll work closely with engineering teams to secure our financial services platform, with particular focus on emerging AI technologies including Agentic AI systems. This role offers the opportunity to shape security practices in a cutting-edge fintech environment.
WHAT YOU DO
Participate in securityarchitecture reviews and threat modeling for new features and systems
Perform code reviews with focus on security vulnerabilities and best practices
Design and implement security controls for cloud infrastructure (AWS, Azure, GCP)
Participate in security assessments of AI/ML systems, including Agentic AI implementations
Contribute to secure coding guidelines and security testing frameworks
Integrate security tools into CI/CD pipelines (SAST, DAST, dependency scanning)
Collaborate with DevOps team on infrastructure-as-code security practices
Investigate and remediate security vulnerabilities across the technology stack
Create security documentation for development teams and architectural decisions
Support penetration testing activities and coordinate remediation efforts
Research emerging threats and security technologies, particularly in AI/ML space
WHAT YOU NEED
2+ years of experience in application security or product security engineering
Bachelor's degree in computer science, Cybersecurity, or related technical field
Strong programming skills in modern languages (Python, Ruby, Java, C#, JavaScript, PowerShell)
Strong database experience with proficiency in SQL and PostgreSQL
Deep understanding of web application security (OWASP Top 10, API security)
Experience with cloud securityarchitectures and containerization (Docker, Kubernetes)
Experience with server administration across Linux and Windows environments
Knowledge of security testing tools and methodologies (SAST, DAST, penetration testing)
Experience applying risk assessment methodologies (DREAD, CVSS) to analyze security findings and establish data-driven remediation priorities
Understanding of secure software development lifecycle (SSDLC) practices
Experience with version control systems (Git) and CI/CD pipelines
Experience with infrastructure automation using Ansible
Demonstrated ability to communicate technical security concepts to diverse stakeholders and influence remediation efforts
Self-motivated with ability to work independently and drive security initiatives to completion
Experience collaborating with development teams to implement security fixes
NICE TO HAVE
Professional certifications (SAA-C03, PJPT, CSSLP, CEH, OSCP, AZ-400, AWS DevOps, or equivalent)
Experience with AI/ML security, including model security and adversarial attacks
Knowledge of financial services security requirements and data protection
Experience with infrastructure-as-code tools (Terraform, CloudFormation)
Background in threat modeling frameworks (STRIDE, PASTA, OCTAVE)
Experience with security orchestration and automation platforms
WE OFFER
A fun, fast-paced work environment
Responsible PTO Plan that meets or exceeds state and local medical and family leave laws
11 paid holidays
Community and social events to keep you connected and engaged
Mental Health Benefits
Medical, Dental and Vision insurance
Company-paid Group Life Insurance, Short- and Long-Term Disability
Flexible Spending Account & Health Savings Account
Aflac Benefits - Critical Illness, Cancer Protection, & Hospital Choice
Pet Insurance
401 (k) with company match with eligibility on Day 1 of employment
2 Paid Volunteer Time Off Days
And much more!
Compensation Information
Pursuant to state and local law disclosure requirements, the pay range for this role, with final offer amount dependent on education, skills, experience and location is $80,000 to $100,000 per year. This position may be eligible for an annual discretionary incentive award. The incentive award amount is dependent upon company performance and your personal performance and is not guaranteed.
AAP/EEO Statement
Ncontracts provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.
This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.
Other Duties
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice.
$80k-100k yearly Auto-Apply 60d+ ago
Security Engineer
Lattimore Black Morgan & Cain, PC and Affiliates
Security architect job in Brentwood, TN
The Security Engineer is responsible for ensuring that technical and procedural security controls are established and maintained within the organization and complies with a variety of security requirements as well as industry best practices. The position works closely with the Information Security Officer, IS leadership, and team members to implement and maintain security and compliance across LBMC.
The Security Engineer will assist in managing Security Systems such as various endpoints, network logging, monitoring, physical access methods, and preventive systems as needed. The Security Engineer must focus on continuous improvement of response capabilities through automation and critical thinking. The professional is responsible for scrutinizing malware, targeted attacks, and intrusion detection. The Security Engineer will identify, investigate, and respond to information security alerts. They play an active role in searching through datasets, alerts, and notifications to detect any threats and anomalies. The security engineer will help resolve any issues related to network perimeter and security infrastructure devices. They must help resolve Windows and other security vulnerabilities.
The Security Engineer must be able to dissect network, host, memory, and other artifacts that are originating from multiple operating systems and applications. The engineer will perform enterprise-wide operations to identify any undetected threats. It is the responsibility of the security engineer to develop alerting and detection strategies to investigate any unusual behavior. They must develop new defensive techniques to recognize any changes in adversary techniques and tactics.
The Security professional must be involved in incident response and investigations. The Information Security Engineer may suggest tools and techniques to achieve security goals. The Security Engineer may perform well-researched security enhancement suggestions to the ISO which meet security standards that protect the organization from possible security breaches.
Essential Responsibilities
* Security Alerts: Review, respond, and remediate where applicable;
* Vulnerability remediation (may also be tasked with vulnerability administration, enhancements, scans, and automation development opportunities);
* Phish campaign monitoring and resolution;
* Analyze security systems and seek improvements on a continuous basis;
* Report possible threats or software issues;
* Research weaknesses and determine ways to counter them;
* Understand software, hardware, and internet needs while adjusting them according to our business environment;
* Assist fellow employees with cybersecurity, software, hardware, or IT needs;
* Carry out and support information security plans and policies;
* Respond to, investigate, and assist in recovery efforts related to a security breach;
* Assist in Security Awareness training development and support;
* Troubleshoot security and network problems;
* Ensure the organization's data and infrastructure are protected by enabling and/or recommending appropriate security controls;
* Participate and follow the change management process;
* Daily administrative tasks, reporting, and communication within Information Security as well as relevant departments within the organization, as needed or directed;
* Administer, configure, and troubleshoot security infrastructure devices such as Varonis;
* Test new software and firmware, as needed or directed.
Operational Management
* Work closely with IS Engineering, Security Engineers/Analysts, and other IS departments on corporate technology development to fully secure information, computer, network, and processing systems;
* Recommend and implement changes, where appropriate, related to security policies and practices in accordance with changes in local and federal law;
* Creatively provide resolution to security issues/problems in a cost-effective manner;
* Collaborate with the Information Security Officer to establish and maintain systems for ensuring security and privacy policies are met.
* Other security responsibilities as directed by the Information Security Officer
Other Qualifications
* Minimum of 1 - 3 years progressive experience in Cybersecurity technology development/engineering, with an emphasis on cybersecurity technology installations projects, administration, development, support, and related security tools/technology implementations;
* Position requires a 4-year degree in Information Systems, Computer Science, Information Security or similar. An equivalent combination of education and experience will be considered;
* For those not meeting the minimum education, additional work-related experience will be deemed equivalent;
* CISSP or related certification is an advantage;
* Strong knowledge of core IT and Security infrastructures including Active Directory, Azure AD, Microsoft Windows security controls, SIEM, AV/EDR [specifically Microsoft o365/E5], IPS, PIM, PAM, IAM, Certificate Management, vulnerability scanners, etc.;
* Working knowledge and experience in the following areas:
* Cloud computing security in Azure/Windows environments, security controls, security capabilities identification;
* Experience in working on Microsoft products and can learn new systems quickly;
* Experience with Nessus, Sentinel, Log Analytics, M365 Security stack, penetration testing, security patching, AppLocker, etc.;
* Strong verbal and written communication skills required;
* Must be able to handle multiple, simultaneous tasks effectively and efficiently while maintaining a professional, courteous manner;
* Must be able to work well with others;
* Must be detail oriented and organized;
* High integrity, including maintenance of confidential information;
* Must be able to exercise good judgement and positively influence others, including handling confrontations/conflict with poise and efficiency;
* Focus on continuously improving skillset to meet security changes and challenges;
* Based on business need, ability to work a flexible schedule, including some evenings and weekends as approved in advance or as required to support a security issue;
* Regular and reliable attendance required.
$73k-99k yearly est. 36d ago
Aux Security Personnel PRN
Vanderbilt Health 4.6
Security architect job in Lebanon, TN
Discover Vanderbilt University Medical Center: Located in Nashville, Tennessee, and operating at a global crossroads of teaching, discovery, and patient care, VUMC is a community of individuals who come to work each day with the simple aim of changing the world. It is a place where your expertise will be valued, your knowledge expanded, and your abilities challenged. Vanderbilt Health is committed to an environment where everyone has the chance to thrive and where your uniqueness is sought and celebrated. It is a place where employees know they are part of something that is bigger than themselves, take exceptional pride in their work and never settle for what was good enough yesterday. Vanderbilt's mission is to advance health and wellness through preeminent programs in patient care, education, and research.
Organization:
Security
Job Summary:
JOB SUMMARY
The Auxiliary Security Personnel supports hospital operations by ensuring the safety of patients and hospital employees. The ASP performs crime prevention duties, general security services, and patient de-escalation; enforces Vanderbilt Wilson County Hospital policies and procedures as well as state and local laws. Proactive patrol by means of foot or post as assigned by the requesting department.
.
KEY RESPONSIBILITIES
* Serves the hospital through proactive patrol of assigned area working with zone contacts to identify potential security related situations and develop prevention strategies.
* Identifies potential security related conditions and participates in problem solving through partnerships to develop prevention strategies.
* Coordinates with the Director of Facility Operations personnel on physical security, safety information, and other related crime prevention issues within their area.
* Develops rapport with staff of Vanderbilt Wilson County
* Completes Handle with Care patient de-escalation training and orientation sessions for new employees
* Responder for non-emergency calls to include but not be limited to the following law enforcement or safety and security concerns: Situations that indicate potential for violence or potential volatility.
* Assists medical personnel in the detention of psychiatric patients.
* Appears in court as prosecuting officer or witness and presents testimony.
* Prepares and submits applicable follow-up reports.
TECHNICAL CAPABILITIES
* Communication (Intermediate): Clearly, effectively and respectfully communicates to employees or customers.
* Purchasing (Novice): Understands the concepts behind supplier relations and supply chain management. Handles supplier-related activities, requests for pricing, and purchases of goods and services while ensuring appropriate costs, schedules, quality, deliveries, terms, and conditions.
* Contract Maintenance (Intermediate): The process of ensuring that the intent, requirements, and terms and conditions of a contract are met and continue to be met through the end of the agreement.
* Data Processing (Intermediate): Retrieving, transforming and classifying data to produce meaningful information.
Our professional administrative functions include critical supporting roles in information technology and informatics, finance, administration, legal and community affairs, human resources, communications and marketing, development, facilities, and many more.
At our growing health system, we support each other and encourage excellence among all who are part of our workforce. High-achieving employees stay at Vanderbilt Health for professional growth, appreciation of benefits, and a sense of community and purpose.
Core Accountabilities:
* Organizational Impact: Performs tasks that are typically routine that may impact team's performance with occasional guidance. * Problem Solving/ Complexity of work: Utilizes some discretion and research to solve routine problems. * Breadth of Knowledge: Applies knowledge of standards, established processes and procedure that apply to your own job. * Team Interaction: Provides guidance to entry level co-workers.
Core Capabilities :
Supporting Colleagues : Develops Self and Others: Continuously improves own skills by identifying development opportunities.- Builds and Maintains Relationships: Seeks to understand colleagues' priorities, working styles and develops relationships across areas.- Communicates Effectively: Openly shares information with others and communicates in a clear and courteous manner. Delivering Excellent Services: - Serves Others with Compassion: Invests time to understand the problems, needs of others and how to provide excellent service.- Solves Complex Problems: Seeks to understand issues, solves routine problems, and raises proper concerns in a timely manner. - Offers Meaningful Advice and Support: Listens carefully to understand the issues and provides accurate information and support. Ensuring High Quality: - Performs Excellent Work: Checks work quality before delivery and asks relevant questions to meet quality standards. - Fulfills Safety and Regulatory Requirements: Demonstrates basic knowledge of conditions that affect safety and reports unsafe conditions to the appropriate person or department. Managing Resources Effectively : - Demonstrates Accountability: Takes responsibility for completing assigned activities and thinks beyond standard approaches to provide high-quality work/service. - Stewards Organizational Resources: Displays understanding of how personal actions will impact departmental resources. - Makes Data Driven Decisions: Uses accurate information and good decision making to consistently achieve results on time and without error. Fostering Innovation : - Generates New Ideas: Willingly proposes/accepts ideas or initiatives that will impact day-to-day operations by offering suggestions to enhance them. - Applies Technology: Absorbs new technology quickly; understands when to utilize the appropriate tools and procedures to ensure proper course of action. - Adapts to Change: Embraces changes by keeping an open mind to changing plans and incorporates change instructions into own area of work.
Position Qualifications:
Responsibilities:
Certifications:
Work Experience:
Relevant Work Experience
Experience Level:
Less than 1 year
Education:
Graduate of an approved discipline specific program
Vanderbilt Health is committed to fostering an environment where everyone has the chance to thrive and is committed to the principles of equal opportunity. EOE/Vets/Disabled.
$48k-67k yearly est. Auto-Apply 2d ago
Physical Security Systems Engineer
xAI
Security architect job in Memphis, TN
xAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company's mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All engineers are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates.
About the Role
As a Physical Security Systems Engineer at xAI, you'll design, implement, and maintain advanced security systems to safeguard our facilities, assets, and personnel. Working onsite in Memphis, Tennessee, you'll tackle complex challenges, leveraging your deep expertise in security technologies to strengthen our infrastructure at a fast-scaling company. Expect to dive into system optimization, ensure robust protection, and travel regularly to xAI sites to support our mission of accelerating human scientific discovery through AI.
This is an in-person role based in Memphis, Tennessee, with regular travel required to all xAI sites.
Responsibilities
Develop detailed design plans for the installation of physical security systems including access control, surveillance cameras, intrusion detection, and alarm systems.
Collaborate with InfoSec, IT and facility management teams to integrate security hardware with existing systems across locations.
Manage health and configuration of security network infrastructure
Regularly assess the performance of installed security systems and make necessary adjustments or upgrades.
Conduct preventive maintenance to ensure all security equipment is in optimal working condition.
Diagnose and resolve hardware issues promptly to minimize downtime and security risks.
Keep detailed records of all service and maintenance activities.
Participate in or lead security audits to identify vulnerabilities in physical security measures.
Recommend and implement solutions to address identified security gaps.
Liaise with vendors for procurement of security hardware, ensuring compliance with organizational standards and budget constraints.
Manage relationships with external contractors for installation and maintenance services.
Train security and facility staff on the use of new security systems.
Ensure all security hardware installations meet local, state, and federal regulations.
Maintain up-to-date documentation on system configurations, maintenance schedules, and security incident responses.
Required Qualifications
Minimum of 5 years in a role focused on physical security systems design.
Proven experience with CCTV, access control, and intrusion detection systems.
Experience using CAD software and reading architectural drawings
Experience using Bluebeam software
Preferred Qualifications
Bachelor's degree in Electrical Engineering, Computer Science, or related field; or equivalent experience in security systems.
Ability to interpret security objectives, develop project schedules and manage adherence to established timetables.
Familiarity with Genetec software is a plus.
Proficiency in hardware troubleshooting and system diagnostics.
Experience configuring security and network architecture in integrated security systems.
Familiarity with current security technology trends and innovations.
Certifications such as CPP (Certified Protection Professional) or PSP (Physical Security Professional) are highly desirable.
Excellent problem-solving abilities and attention to detail.
Strong communication skills for effective collaboration with team members and stakeholders.
Ability to work under pressure in a dynamic environment on highly condensed timelines.
Regular sitting at a desk or computer for extended periods, typing and writing. Occasionally walking, around the facility and standing.
xAI is an equal opportunity employer. For details on data processing, view our
Recruitment Privacy Notice.
How much does a security architect earn in Lebanon, TN?
The average security architect in Lebanon, TN earns between $83,000 and $173,000 annually. This compares to the national average security architect range of $92,000 to $179,000.