Security Architect / Head of Security
Security architect job in Draper, UT
Redo is building the most comprehensive platform for ecommerce growth. We help merchants personalize every step of the buyer journey to maximize profit and lifetime value. From returns to warranties, order tracking, post-purchase comms, and beyond, our AI-native suite replaces fragmented point solutions with a unified platform that boosts customer experience, retention, and revenue.
Position Overview
We are seeking a talented Head of Security to join our team at Redo. This role will lead security strategy across the organization, from executive-level risk management and compliance to technical security operations and architecture. In this role, you will take ownership of designing and growing our security architecture, security compliance, and risk management strategy. You will champion security best practices across engineering, product, and legal functions, and lead efforts to ensure threats are proactively identified and mitigated.
Responsibilities:
Lead company-wide security strategy, including building and maintaining a risk register, conducting security training and phishing campaigns, and enabling sales through security questionnaires and customer engagement
Establish and maintain security operations including threat detection, monitoring, SIEM implementation, and penetration testing programs to proactively identify vulnerabilities
Own all security compliance efforts, maintaining existing certifications (SOC 2, GDPR) and achieving new compliance requirements in alignment with sales priorities
Establish and evolve Redo's security architecture across infrastructure, applications, and data flows
Partner with infrastructure and platform engineering teams to drive security improvements including monitoring/remediation of security tooling findings (e.g., Wiz), WAF, IAM, and related infrastructure security
Define and drive secure coding standards, development workflows, and security automation to detect and prevent security issues earlier in the pipeline
Lead threat modeling, risk assessments, and architectural reviews for new features and systems
Design and implement tools and processes for security monitoring, incident detection, response, and prevention
Educate and coach teams across the company on security principles and secure development practices
Qualifications:
4+ years experience in security leadership or security architecture roles, with proven ability to build and manage security programs including compliance, security operations, and technical security architecture in cloud-native environments (e.g., AWS, GCP, Azure)
Proven track record of building security programs and practices in high-growth product companies
Experience with SaaS-relevant compliance frameworks (e.g. SOC 2, GDPR, ISO 27001)
Deep knowledge of threat modeling, system hardening, incident response, and security tooling
Excellent communication and collaboration skills, able to work effectively with product, legal, and engineering partners
Demonstrated ability to operate autonomously while offering mentorship and guidance to others
Preferred Qualifications:
Security leadership experience in early-stage or fast-growing startup environments
Strong programming or scripting skills to directly contribute to security tooling and code reviews
Experience driving security improvements across infrastructure and application teams, including infrastructure security (WAF, IAM) and application security practices
Direct experience with security tooling such as Wiz, SIEM platforms, or bug bounty programs
Experience securing IaC and CI/CD pipelines with infrastructure security best practices
Familiarity with infrastructure-as-code tools such as Terraform or CDK
Contributions to open-source security tooling or industry security standards initiatives
Redo benefits and perks:
Opportunity to work with a dynamic and innovative team in the fast-growing e-commerce industry
Career growth and advancement
On-site gym with showers, pickleball, and basketball
Flexible PTO & company holidays
Redo perks, monthly allowance to make purchases from ecommerce stores to support both existing and potential customers
Company HSA contributions
Weekly lunches & fully stocked break room
$100 monthly babysitting perk reimbursement
Office is minutes from biking and running trails
Google Cloud Security Architect
Security architect job in Salt Lake City, UT
Who You'll Work With As a modern technology company, our Slalom Technologists are disrupting the market and bringing to life the art of the possible for our clients. We have passion for building strategies, solutions, and creative products to help our clients solve their most complex and interesting business problems. We surround our technologists with interesting challenges, innovative minds, and emerging technologies
As a Consultant or Senior Consultant, you will collaborate with cross-functional teams, including IT, security, and business units, to design and implement Google Cloud-based application innovation solutions. You will work alongside experienced cloud architects, data scientists, and other specialists, ensuring the successful delivery of scalable, cloud-native applications and AI-powered solutions.
What You'll Do
* Stay current with security trends, technologies, and best practices around Google Cloud solutions, leveraging tools like Cloud IAM, Cloud Security Command Center, BeyondCorp, and Cloud Armor.
* Define and guide transformational security strategies for Google Cloud environments, ensuring alignment with Google's Zero Trust and BeyondCorp principles.
* Translate complex regulatory requirements (e.g., GDPR, SOC 2, HIPAA) and technology standards into actionable functional and technical requirements for cloud and hybrid environments, ensuring security and compliance.
* Lead teams through various phases of gap analyses, including security assessments, remediation planning, roadmap development, and implementation of remediation actions using Google Cloud-native tools.
* Deliver on the vision, architecture, execution, and quality assurance of security projects on Google Cloud, driving initiatives that secure enterprise workloads and data.
* Guide stakeholders and senior leaders on aligning security solutions with broader business goals, ensuring the architecture follows Google Cloud's security best practices and roadmap.
* Establish security architecture patterns based on Google Cloud security frameworks and industry standards to meet the unique needs of enterprise clients.
* Collaborate with other Google Cloud architects and security teams to continuously improve security knowledge assets and best practices, ensuring the most effective security solutions for clients.
* Design and architect solutions to secure Generative AI models and applications against adversarial attacks, prompt injection, and their potential misuse for malicious cyber activities.
What You'll Bring
* Proven experience with Google Cloud security architecture, with hands-on experience in tools like Cloud IAM, VPC Service Controls, Cloud DLP, and Cloud Armor.
* Strong background in defining and implementing Zero Trust and BeyondCorp security models within Google Cloud environments.
* Familiarity or direct experience with Identity and Access Management (IAM), Data Protection, Vulnerability Management, and Cloud Security solutions in Google Cloud.
* Extensive experience with security design patterns specific to Google Cloud, as well as hybrid and multi-cloud security architecture.
* Experience in security and risk advisory consulting, particularly related to cloud security transformations.
* Ability to lead the development and implementation of cloud security roadmaps aligned with business goals and compliance needs.
* Familiarity with Google Cloud's Artificial Intelligence (AI) capabilities (e.g., Vertex AI, Generative AI services, Model Armor) including their applications, associated security risks (e.g., prompt injection, data poisoning, privacy concerns), and proven strategies for implementing security controls, governance, and responsible AI practices.
* Relevant certifications are strongly desired, including (but not limited to):
* GCP Professional Security Engineer
* GCP Professional Cloud Architect
* CISSP
* Security+
About Us
Slalom is a fiercely human business and technology consulting company that leads with outcomes to bring more value, in all ways, always. From strategy through delivery, our agile teams across 52 offices in 12 countries collaborate with clients to bring powerful customer experiences, innovative ways of working, and new products and services to life. We are trusted by leaders across the Global 1000, many successful enterprise and mid-market companies, and 500+ public sector organizations to improve operations, drive growth, and create value. At Slalom, we believe that together, we can move faster, dream bigger, and build better tomorrows for all.
Compensation and Benefits
Slalom prides itself on helping team members thrive in their work and life. As a result, Slalom is proud to invest in benefits that include meaningful time off and paid holidays, parental leave, 401(k) with a match, a range of choices for highly subsidized health, dental, & vision coverage, adoption and fertility assistance, and short/long-term disability. We also offer yearly $350 reimbursement account for any well-being-related expenses, as well as discounted home, auto, and pet insurance.
Slalom is committed to fair and equitable compensation practices. For this position the base salary pay ranges are listed below. In addition, individuals may be eligible for an annual discretionary bonus. Actual compensation will depend upon an individual's skills, experience, qualifications, location, and other relevant factors. The salary pay range is subject to change and may be modified at any time.
East Bay, San Francisco, Silicon Valley:
* Consultant: $120,000-$177,000
* Senior Consultant: $140,000-$203,000
San Diego, Los Angeles, Orange County, Seattle, Houston, New Jersey, New York City, Westchester, Boston, Washington DC:
* Consultant: $110,000-$162,000
* Senior Consultant: $130,000-$186,000
All other locations:
* Consultant: $105,000-$148,000
* Senior Consultant: $115,000-$171,000
EEO and Accommodations
Slalom is an equal opportunity employer and is committed to inclusion, diversity, and equity in the workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veterans' status, or any other characteristic protected by federal, state, or local laws. Slalom will also consider qualified applications with criminal histories, consistent with legal requirements. Slalom welcomes and encourages applications from individuals with disabilities. Reasonable accommodations are available for candidates during all aspects of the selection process. Please advise the talent acquisition team if you require accommodations during the interview process.
We are accepting applications until 12/31.
Product Security Engineer, Instagram
Security architect job in Salt Lake City, UT
The Instagram Security Ecosystems team is seeking a product-focused security engineer interesting in enabling Instagram product teams to develop features with a focus on security and user safety. You will be relied upon to directly work with Instagram engineers, hardening both product features and our protective frameworks that make life harder for bad actors on the Instagram platform.
**Required Skills:**
Product Security Engineer, Instagram Responsibilities:
1. Threat Modeling and Security Architecture: Work directly with product managers and technical leads on threat models and security architecture for novel Instagram features or products
2. Security Reviews: Perform manual design and implementation reviews of web, mobile, and native code
3. Developer Guidance: Provide guidance and education to developers that help prevent the authoring of vulnerabilities
4. Automated Analysis and Secure Frameworks: Work with other security teams to improve Instagram's static and dynamic analysis and frameworks to scale coverage
5. Bug Bounty: Help provide technical guidance to our world class bug bounty program and independent security researchers
6. Industry Impact: Push the industry forward through conference talks and open source projects to contribute broadly to security for the world
**Minimum Qualifications:**
Minimum Qualifications:
7. B.S. or M.S. in Computer Science, Cybersecurity, or related field, or equivalent experience
8. 8+ years of experience finding vulnerabilities in interpreted languages (Python, PHP)
9. Extensive, proven experience in threat modeling and secure systems design
10. Experience with exploiting common security vulnerabilities
**Preferred Qualifications:**
Preferred Qualifications:
11. Product software engineering or product management experience
12. Experience in security consulting or other leadership-facing security advisory roles
13. Familiarity with cybersecurity investigations, abuse operations, and/or security incident response
14. Contributions to the security community (public research, blogging, presentations, bug bounty, etc.)
**Public Compensation:**
$177,000/year to $251,000/year + bonus + equity + benefits
**Industry:** Internet
**Equal Opportunity:**
Meta is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Meta participates in the E-Verify program in certain locations, as required by law. Please note that Meta may leverage artificial intelligence and machine learning technologies in connection with applications for employment.
Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at accommodations-ext@fb.com.
Sentinel - Systems Security Engineer - 16416
Security architect job in Roy, UT
RELOCATION ASSISTANCE: Relocation assistance may be available CLEARANCE TYPE: SecretTRAVEL: Yes, 10% of the TimeDescriptionAt Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work - and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history.
Join Northrop Grumman on our continued mission to push the boundaries of possible across land, sea, air, space, and cyberspace. Enjoy a culture where your voice is valued and start contributing to our team of passionate professionals providing real-life solutions to our world's biggest challenges. We take pride in creating purposeful work and allowing our employees to grow and achieve their goals every day by Defining Possible. With our competitive pay and comprehensive benefits, we have the right opportunities to fit your life and launch your career today.
Northrop Grumman Defense Systems is seeking a Systems Security Engineer, (Level 2), that will support the Sentinel (GBSD) program performing Hardware Assurance.
This position will be located in Roy, UT and will support the Ground Based Strategic Deterrent (GBSD) program.
The Mission Defense Team (MDT) is seeking a highly motivated and qualified system engineer to serve as a Hardware Assurance Engineer, Level 2. You will be responsible for assessing and prioritizing a broad spectrum of hardware security threats. Key protection activities will involve vendor research, hardware assurance, program protection, counterfeit prevention, and supply chain security.
Additional Responsibilities include:
Assessment and analysis of threats, vulnerabilities, and risk for identified mission-critical functions and critical components
Support courses of action based on knowledge and experience, initiative, guidance, and established regulations and policies
Research, analyze data, and derive facts per identified vulnerabilities
Participate in a variety of working groups and customer meetings; ensure communication of risk environment with stakeholders
Contributes to program plans, goals, objectives, and milestones to for Hardware Assurance
Review technical security assessments of SSE environments to identify points of vulnerability, non-compliance with established standards and regulations and recommended mitigation strategies
Execute completion Statement of Work requirements, Program Milestone Exit Criteria, and program maturity commitments
Ensure the architecture and design of systems are functional and secure; support the design, development, implementation, and integration of security systems and system components
Self-starters compelled to take action in the workplace without requiring prompting from supervisors
Support MDT with other duties as assigned
In addition to technical skills, you will be a self-starter with strong time management skills. Your organizational skills and ability to anticipate future challenges will serve you well
Basic Qualifications
Must be a US Citizen with an active DoD Secret Clearance, at time of application, current and within scope, with an investigation date within the last 6 years
Must have the ability to obtain and maintain Special Access Program (SAP) approval within a reasonable period of time, as determined by the company to meet its business need
Requires a bachelor's degree in a STEM (Science, Technology, Engineering or Mathematics) discipline from an accredited university and 2 years of related experience; or a master's degree with 1 year
Minimum 2 years of applying and understanding Systems Security Engineering principles applicable to US Government Defense Programs
Minimum 2 years in showing the ability to communicate effectively and clearly present technical approaches and findings
Experience in any of the full product life cycles of: ASIC Design, FPGA Design
Experience in HDL (VHDL/Verilog), implementing designs using RTL
Ability to show self as team player, able to multi-task, able to generate quality work products independently, able to make excellent judgement and show interpersonal skills
Preferred Qualifications
Degree in Aerospace Engineering, Systems Engineering, Mechanical Engineering, Software Engineering, or similar
ICBM Experience
Experience developing Systems Security Engineering requirements for hardware and software assurance
Evaluating program processes and compliance strategies for large, complex multi-site programs
Demonstrated experience and familiarity with vulnerability management
Experience with Model-based Systems Engineering (MBSE) concepts and tools
A solid understanding of Program Protection applicable to US Government Defense Programs and applied knowledge in the application of SSE principles across a broad spectrum of security measures (Cybersecurity, Counterfeit Awareness, Anti-Tamper, HW/SW Assurance, OPSEC, etc.) to protect critical program information (CPI)
Top Secret clearance
Position Benefits
As a full-time employee of Northrop Grumman, you are eligible for our robust benefits package including:
Medical, Dental & Vision coverage
401k
Educational Assistance
Life Insurance
Employee Assistance Programs & Work/Life Solutions
Paid Time Off
Health & Wellness Resources
Employee Discounts
******************************************************************
This position's standard work schedule is a 9/80. The 9/80 schedule allows employees who work a nine-hour day Monday through Thursday to take every other Friday off.
This role may offer a competitive relocation assistance package.
#Sentinelsystems
Primary Level Salary Range: $77,200.00 - $115,800.00The above salary range represents a general guideline; however, Northrop Grumman considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills and current market conditions.Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. Annual bonuses are designed to reward individual contributions as well as allow employees to share in company results. Employees in Vice President or Director positions may be eligible for Long Term Incentives. In addition, Northrop Grumman provides a variety of benefits including health insurance coverage, life and disability insurance, savings plan, Company paid holidays and paid time off (PTO) for vacation and/or personal business.The application period for the job is estimated to be 20 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates.Northrop Grumman is an Equal Opportunity Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. For our complete EEO and pay transparency statement, please visit *********************************** U.S. Citizenship is required for all positions with a government clearance and certain other restricted positions.
Auto-ApplyInformation System Security Manager SME
Security architect job in Clearfield, UT
has an exciting opportunity for a Information System Security Manager (ISSM) SME to support the Advanced Training Capabilities (AFLCMC/WNR) at Hill AFB in Ogden, Utah. WNR functions as the Air Force's technical, acquisition, and sustainment experts, providing unique and comprehensive support to the warfighter. The ADE Division is responsible for a vast array of USAF systems, including Electronic Warfare, Range Systems, Range Instrumentation, Air Combat Training and Aircrew Readiness, Command and Control Systems, Advanced Radar Threat Systems, Combat Survivor Evader Locator, P5 Combat Training Systems, Black Switch and Legacy Voice Systems. Furthermore, the ADE Division provides support to depot-level sustainment and maintenance efforts, FMS, U.S. Army, Navy, Pacific Air Forces, Air Combat Command (ACC), Air Force Materiel Command (AFMC), and Air Education and Training Command (AETC) on a continuous basis.
Responsibilities:
Responsibilities may include but are not limited to:
Ensures the integration of cybersecurity into, and throughout the lifecycle of the IT, on behalf of the AO and IAW DoDI 8510.01
Completes and maintains required cybersecurity certification IAW AFMAN17-1303. Individuals in this position must be U.S. citizens
Ensures all AF IT cybersecurity-related documentation is current and accessible to properly authorized individuals. AFI17-101 6 FEBRUARY 2020 15
Supports the PM or ISO in maintaining current authorization to operate, and approval to connect and in implementing corrective actions identified in the plan of action and milestones
Coordinates, with the PM and AO staffs, development of an ISCM strategy and monitor any proposed or actual changes to the system and its environment
Continuously monitors the IT and environment for security-relevant events, assess proposed configuration changes for potential impact to the cybersecurity posture, and assess the quality of security controls implementation against performance indicators
Ensures cybersecurity-related events or configuration changes that impact AF IT authorization or adversely impact the security posture are formally reported to the AO and other affected parties, such as IOs and stewards and AOs of interconnected IT
Appoints IS Security Officers (ISSOs) and provides oversight to ensure ISSOs follow established cybersecurity policies and procedures IAW DoDI 8500.01
Ensures all ISSOs receive necessary technical training and obtain cybersecurity certification IAW AFMAN 17-1301, Computer Security (COMPUSEC), AFMAN 17-1303 and maintain proper clearances IAW DoDI 8500.01
Ensures the AF IT is acquired, documented, operated, used, maintained, and disposed of properly and IAW DoDI 5000.02 and DoDI 8510.01
Requirements
Qualifications:
Minimum Required Qualifications
Citizenship: Must be a US citizen
Clearance: Top Secret
Education: Bachelor's Degree in a related field and 25 years of experience in the respective technical/professional discipline being performed, 15 years of which must be in the DoD
Preferred Qualifications
Master's or Doctorate Degree in a related field and at least 20 years of experience in the respective technical / professional discipline being performed, 12 years of which must be in the DoD
Additional Information
Location: Hill AFB, UT
Travel: 10%
Remote, Onsite, or Hybrid: On-Site
Information Systems Security Officer
Security architect job in Clearfield, UT
**MANTECH** seeks a motivated, career and customer-oriented **Information Systems Security Officer (ISSO)** to join our Air Force / Space team at **Hill AFB** . The ISSO's primary function is to support the United States Air Force's 53rd Wing Technical Support Services (53rd WTSS) contract.
**Responsibilities include, but are not limited to:**
+ Perform ISSO duties in support of in-house and external customers
+ Notify ISSM when changes occur that might affect the authorization determination of the information system(s)
+ Conduct periodic reviews of information systems to ensure compliance with the security authorization package
+ Coordinate any changes or modifications to hardware, software, or firmware of a system with the ISSM and AO/DAO prior to the change
+ Ensure all IS security-related documentation is current and accessible to properly authorized individuals
+ Execute the cyber security portion of the self-inspection, to include provide security coordination and review of all system assessment plans
+ Identify cyber security vulnerabilities and assist with the implementation of the countermeasures for them
+ Conduct security impact analysis activities and provide to the ISSM on all configuration management changes to the authorization boundaries
**Minimum Qualifications:**
+ Bachelor's degree in related discipline from an accredited college or university. 2 additional years of experience may be substituted for a degree.
+ 4+ years direct/related experience
+ Active / valid DoD 8570.01-M IAT-II certification
+ Experience with DoD/USAF information security policy background with practical / hands-on experience applying RMF processes and principles.
+ Experience developing and/or contributing to an RMF body of evidence composition, applicable artifacts, and associated control families.
**Clearance Requirements:**
+ Active Top Secret Clearance
+ Must be able to obtain and maintain a DoD TS/SCI-eligible clearance (i.e. DCID 6/4 eligibility)
+ Eligibility for access to Special Access Program Information
+ Willingness to submit to a Polygraph.
**Physical Requirements:**
+ Must be able to remain in a stationary position 50%
+ Needs to occasionally move about inside the office to access file cabinets, office machinery, etc.
+ Constantly operates a computer and other office productivity machinery, such as a calculator, copy machine and computer printer.
+ Frequently communicates with co-workers, management and customers, which may involve delivering presentations. Must be able to exchange accurate information in these situations
MANTECH International Corporation considers all qualified applicants for employment without regard to disability or veteran status or any other status protected under any federal, state, or local law or regulation.
If you need a reasonable accommodation to apply for a position with MANTECH, please email us at ******************* and provide your name and contact information.
Engineer, Information Security and Risk
Security architect job in Salt Lake City, UT
Cardinal Health, Inc. (NYSE: CAH) is a global healthcare services and products company. We provide customized solutions for hospitals, healthcare systems, pharmacies, ambulatory surgery centers, clinical laboratories, physician offices and patients in the home. We are a distributor of pharmaceuticals and specialty products; a global manufacturer and distributor of medical and laboratory products; an operator of nuclear pharmacies and manufacturing facilities; and a provider of performance and data solutions. Working to be healthcare's most trusted partner, our customer-centric focus drives continuous improvement and leads to innovative solutions that improve the lives of people every day. With approximately 50,000 employees worldwide, Cardinal Health ranks among the top fifteen in the Fortune 500.
**_Department Overview:_**
**Information Technology** oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value.
**Information Security and Risk** develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure, or destruction. This job family develops system back-up and disaster recovery plans, conducts incident responses, threat management, vulnerability scanning, virus management and intrusion detection as well as completes risk assessments.
Lead IAM work for new customer onboardings and migrations. Collaborate with CAH Account Management, Application Teams, and Customers to design, implement, and test federated SSO solution based on customer login requirements. Provide technical guidance and act as primary point of contact for business partners and customer related to IAM work for onboarding. Additional responsibilities include supporting application integrations and enhancing SSO self service application onboarding.
**Responsibilities:**
+ **Customer Onboarding IAM Efforts - Strategy & Execution :** Lead the planning, design, and execution for Customer Onboarding via federated SSO, ensuring alignment with overall business and security objectives. This includes assessing multiple Cardinal Health e-commerce applications, understanding login requirements for new/existing customers, designing, testing and implementing solutions etc to ensure top notch user login experience and enhancing Cardinal Health's security posture.
+ **Collaboration & Communication:** Coordinate cross-functional teams, including Customer Business and IT teams, Cardinal Health's Account Management/Sales and Application teams, Information Security and others to ensure effective IAM implementation and seamless integration with business processes. Communicate complex security concepts to technical and non-technical internal and external stakeholders.
+ **Application Integration Leadership:** Lead the integration of various enterprise applications (SaaS, on-premise, custom-built) with our core IAM infrastructure, ensuring secure authentication, authorization, and user provisioning/de-provisioning.
+ **User Lifecycle Management:** Streamline and automate user provisioning, de-provisioning, and periodic access reviews for employees, contractors, and partners across all integrated systems, ensuring smooth onboarding and offboarding during M&A transitions.
+ **Solution Design & Implementation:** Design, implement, and maintain IAM solutions including Single Sign-On (SSO), Multi-Factor Authentication (MFA), and Role-Based Access Control (RBAC) frameworks.
+ **Technical Troubleshooting & Support:** Troubleshoot, identify, and resolve technical identity and access management-related issues, providing expert support to internal teams and end-users during and after integration.
+ **Documentation & Best Practices:** Develop, review, and maintain comprehensive technical documentation, including architecture diagrams, configuration guides, and operational procedures. Stay up-to-date with IAM best practices, regulatory requirements, and security trends.
**Qualifications:**
+ **Education:** Bachelor's degree in Computer Science, Information Technology, Information Security, or a related field, or equivalent practical experience.
+ **Experience:** 5+ years of progressive experience as an IAM Engineer, designing and implementing enterprise scale solutions with significant experience in supporting M&A integration projects preferred.
+ **Technical Expertise:**
+ Extensive knowledge and experience with authentication standards and technologies such as SSO (SAML, OAuth, OpenID Connect), MFA
+ Proficiency in directory services (e.g., Active Directory, Azure AD, LDAP).
+ Hands-on experience with leading IAM platforms (e.g., Okta, Microsoft Azure AD, CyberArk, ForgeRock, Ping Identity, SailPoint).
+ Strong understanding of security principles, risk management, and access control models (e.g., RBAC).
+ Familiarity with Zero Trust architecture principles.
+ Familiarity with AI/ML concepts and their practical application in security and risk management, especially in IAM context.
+ Strong communication and interpersonal skills to collaborate effectively with various teams and stakeholders.
+ Detail-oriented mindset to ensure precise access control configurations and compliance.
+ Excellent problem-solving and analytical abilities to troubleshoot access issues and design solutions for unique business requirements
+ Must be a self-starter who takes full ownership of projects from inception to completion , holding oneself accountable for the security and operation integrity of IAM platform.
+ Ability to manage multiple priorities and meet tight deadlines in a fast-paced M&A environment.
**Anticipated salary range:** $94,900 - $135,600
**Bonus eligible:** No
**Benefits:** Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
+ Medical, dental and vision coverage
+ Paid time off plan
+ Health savings account (HSA)
+ 401k savings plan
+ Access to wages before pay day with my FlexPay
+ Flexible spending accounts (FSAs)
+ Short- and long-term disability coverage
+ Work-Life resources
+ Paid parental leave
+ Healthy lifestyle programs
**Application window anticipated to close:** 12/20/2025 *if interested in opportunity, please submit application as soon as possible.
The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.
_Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply._
_Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal_ _Opportunity/Affirmative_ _Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law._
_To read and review this privacy notice click_ here (***************************************************************************************************************************
Senior Security Engineer
Security architect job in Salt Lake City, UT
Who We Are
Legato Security is an information security firm founded upon the belief that every organization has the right to keep its data private and secure. Our mission is to build close partnerships with our clients, serving them not as just a vendor, but as trusted advisors helping to build effective, proactive plans. Our focus is always on both the technical and human elements within an organization. We believe in comprehensive strategies designed to harden networks, deflect attackers, and rapidly recover from any accidents. As technology progresses, so do our tactics, ensuring our experts are always prepared to serve forward-looking leaders eager to stay ahead of emerging threats.
Position Overview
Legato Security is seeking a Security Engineer to join our MSSP engineering team with a primary focus on Microsoft 365 security engineering. You will lead and support security configuration and management across Entra ID (Azure AD), Intune, Conditional Access, and the Microsoft Defender suite, while also operating and optimizing SIEM, EDR, and Email Security platforms for our customers. You will mentor junior team members, collaborate directly with clients, and drive continuous improvement in reliability, visibility, and detection outcomes.
Specific Job Responsibilities
Design, implement, and maintain secure configurations across Entra ID (Identity Protection, MFA, Conditional Access, PIM), Intune (device compliance, configuration profiles, app protection, endpoint security baselines), and Microsoft 365 Defender (Defender for Endpoint/Identity/Office 365; DLP) to reduce risk and improve posture.
Perform tenant health reviews, roadmap recommendations, and architecture guidance aligned to best practices.
Independently resolve complex platform issues; escalate critical problems with comprehensive analysis.
Develop and refine queries, dashboards, and reports across various SIEM and EDR solutions to improve visibility and meet customer requests.
Manage log source onboarding and tuning, parser normalization, licensing and ingestion health to maintain accuracy and performance.
Administer updates, patches, and configurations on managed security systems.
Manage and optimize RBAC with least privilege and auditing; maintain separation of duties.
Perform monthly health checks to validate uptime, data quality, and control effectiveness; proactively remediate issues.
Provide actionable recommendations on security configurations; act as a trusted advisor to clients.
Work client requests end-to-end in the ticketing system, populating required fields, documenting findings, linking related tickets, and closing issues promptly.
Ensure all activities comply with organizational policies and regulatory requirements (e.g., CMMC, GDPR, HIPAA, PCI-DSS).
Contribute to cross-functional projects; stay current with emerging threats, technologies, and compliance standards; implement security best practices.
Qualifications
Required Qualifications:
Bachelor's degree (or equivalent experience) in cybersecurity, information technology, computer science, or a related field.
Hands-on administration of Microsoft 365 security: Entra ID (Azure AD), Intune, Conditional Access, and Microsoft Defender products (Endpoint, Identity, Office 365).
Proven experience administering SIEM, EDR, and email security solutions in an MSSP or enterprise environment.
Ability to create complex queries, detections, dashboards, and reports in SIEM/EDR solutions.
Strong troubleshooting skills for agent issues and policy configurations at both global and local levels.
Proficiency across Windows, Unix/Linux, and mac OS operating environments.
Scripting familiarity with PowerShell, Python or Bash.
Strong knowledge of firewalls/UTMs, IDS/IPS, VPNs; excellent log analysis capabilities.
Preferred Qualifications:
Microsoft security certifications (e.g., SC-300, SC-200, AZ-500, MD-102) or equivalent.
Experience administering Splunk Enterprise and Splunk Cloud (content management, data onboarding, search head/indexer administration, basic performance tuning).
Experience with Cribl (e.g., Cribl Stream) or similar observability pipelines.
Vendor-specific certifications such as Sumo Logic Cloud SIEM Administrator, CrowdStrike CCFA/CCFR/CCFH, Google Associate Cloud Engineer, Microsoft Azure Security Engineer Associate, AWS Cloud Practitioner.
Strong written and verbal communication skills with direct client-facing experience.
Perks
· Start-up company in a growth phase with opportunity for advancement based on performance
· Start-up culture with an office in downtown Salt Lake City, UT
· Competitive medical and dental benefits for employee and family members
· Other company-provided benefits such as short-term disability, basic life insurance, children's orthodontia, with additional voluntary benefits available, and 401K match
· Flexible Paid Time Off policy
· Professional Development opportunities specific to role
Auto-ApplySr. Android Engineer, Security
Security architect job in Salt Lake City, UT
Salt Lake City Utah Exp 2-5 yrs Deg Bachelors Relo Bonus Occasional Travel Job Description • Mobile application development using Java running on Android, with special emphasis on security system integration and monitoring features. • Working in a fast-pace environment with a cross-functional group of HW, FW, SW engineers.
• Working within the agile SW development model, using Scrum methodology.
ITEMIZED DESCRIPTION OF DUTIES:
• Android application development on multiple devices, screen sizes and layouts.
• Research, development and debugging of security areas of home control application.
• Develop and coordinate design tasks and schedules with the cross functional design teams.
• Branching and merging of code using a modern source code repository.
• Conduct cross functional design reviews, develop and conduct validation testing routines needed to insure highly reliable best in class quality products.
• Participate in the development processing and scheduling for predictable and accurate on time delivery of products.
NEEDED SKILLS AND EXPERIENCE:
• Android development in Java.
• C++ development and accessing via JNI.
• Debugging and testing, including unit testing, of your own code.
• Video streaming experience is desirable.
• Experience with embedded scripting languages is desirable. Bonus for Lua experience.
• Experience with other mobile platforms, specifically iOS, is a plus.
MINIMUM QUALIFICATIONS:
• Bachelor's degree in computer science or computer engineering.
• 2 years Android application development
Additional Information
All your information will be kept confidential according to EEO guidelines.
Direct Staffing Inc
Sr. Security Analyst
Security architect job in South Jordan, UT
Lightspeed is a leading provider of cloud-based software for dealerships and Original Equipment Manufacturers (OEMs), serving the Powersport, Marine, RV, Trailer, Outdoor Power Equipment, and Golf Cart industries. Lightspeed's Dealer Management Solution (DMS) enables dealerships to optimize their end-to-end business operations, including sales, parts, service, rentals, accounting, and Customer Relationship Management (CRM). When implemented into their daily operations, Lightspeed helps dealers increase their profitability by selling more units, service, and parts, all while creating a more streamlined experience for customers. For nearly 40 years, Lightspeed has been empowering 4,500+ dealers across North America with the tools and technology they need to manage their dealerships.
The Senior Security Analyst is responsible for team lead activities, such as monitoring, analyzing, and responding to security incidents across enterprise systems, cloud environments, and networks. This role ensures the confidentiality, integrity, and availability of organizational information through proactive detection, incident response, and continuous improvement. The ideal candidate will have a strong technical background in leading threat analysis, SIEM integration and management, vulnerability management, and incident handling.
What you'll do:
Monitor and investigate security alerts and events across SIEM, EDR, and network systems.
Conduct root cause analysis and coordinate remediation of security incidents.
Lead vulnerability assessments and ensure timely patching and mitigation.
Develop and maintain incident response playbooks and escalation procedures.
Collaborate with IT, DevOps, and Development teams to strengthen overall security posture.
Lead proactive threat hunting and continuous tuning of detection mechanisms.
Support internal and external audits (e.g., SOC 2) and risk assessments by providing evidence and guidance.
Perform firewall management, including rule changes, troubleshooting, and SOP development for hybrid cloud/on-prem environments.
Lead to red/blue team exercises and implement findings to improve defenses.
Coordinate and assist with enterprise pen-tests, risk assessments, and compliance initiatives.
Serve as a lead security advisor to business and technical teams, providing guidance on secure design, risk mitigation, and compliance using industry frameworks and best practices.
What you should have:
Qualifications:
Bachelor's degree in Cybersecurity, Information Technology, or a related field, or equivalent experience.
8+ years of experience in information security, incident response, or SOC operations.
Proven hands-on experience with SIEM tools (Splunk, Sentinel, QRadar, etc.) and EDR/XDR platforms (CrowdStrike, Darktrace, Microsoft Defender).
Strong experience securing and monitoring cloud environments (AWS, Azure).
Deep knowledge of security frameworks (NIST CSF, ISO 27001, SOC 2).
Advanced scripting and automation proficiency (Python, PowerShell, Terraform).
Excellent analytical, problem-solving, and communication skills.
Preferred Qualifications:
Relevant certifications such as AWS Security, CISSP, GCIH, GCIA, GPEN, GWAPT preferred.
Experience integrating AI and automation into security operations workflows.
Hands-on experience performing dynamic application security testing and red team exercises across endpoint and cloud environments.
Expert-level networking and firewall expertise with platforms such as Palo Alto, Cisco, or Checkpoint.
Master's degree in Cybersecurity, Information Technology, or a related field.
Inclusion and Diversity at Lightspeed:
At Lightspeed, we celebrate the uniqueness of every individual and encourage diverse perspectives. We believe that inclusion drives innovation and fosters meaningful connections. We are committed to building an environment where everyone feels valued and empowered to make an impact.
Equal Employment Opportunity Statement:
Lightspeed is an Equal Opportunity Employer and is dedicated to building a diverse and inclusive workforce. All qualified applicants will be considered for employment without regard to race, color, creed, ancestry, national origin, gender, sexual orientation, gender identity, gender expression, marital status, religion, age, disability, veteran status, or any other protected category.
Important Note:
Applicants must be authorized to work in the U.S.
Ready to apply?
Take the next step in your career-apply today and join a team where your skills will make an impact!
Auto-ApplyApplication Security Engineer
Security architect job in Salt Lake City, UT
Job Details 110 S. REGENT STREET SUITE 500 - SALT LAKE CITY, UTDescription
Here at Priority Dispatch, we know that protecting lives starts with the right protocols, training, and ensuring systems are safe and reliable. We're looking to hire a full time Application Security Engineer to use their expertise to build and defend secure systems that support our mission of delivering life saving dispatch systems! This is your chance to join an award winning company while having your work contribute and make a direct impact for good in communities around the world.
We offer benefits that include medical, dental, vision, legal, and pet insurance, 401K and company contributions, PTO, short and long term disability and life insurance, and more while having meaningful work at a company that's been voted as a top place to work in Utah for the past 5 years running! Come see why our teams love to work here!
Job Summary
We are seeking an experienced Application Security Engineer to secure our web and desktop applications by implementing and managing SAST, DAST, and SCA processes. This role partners with developers, QA, and DevOps to embed security into CI/CD pipelines, conduct code reviews, and promote secure coding practices. The ideal candidate has deep expertise in OWASP Top Ten risks, API security, and threat modeling, with experience addressing unique challenges in desktop applications where automation is limited. Familiarity with cloud-native and AI-driven systems is essential, along with knowledge of compliance frameworks such as ISO 27001, NIST, CMMC, and Cyber Essentials. This position reports to the Director of Enterprise Solutions and Technology and plays a critical role in strengthening the organization's overall security posture. This is a hybrid role based in Salt Lake City, Utah.
Major Responsibilities
Ensure all application code is thoroughly tested and scanned for risks, vulnerabilities, and third-party dependencies using SAST, DAST, and SCA tools.
Provide additional attention to desktop applications where automated security tooling may be limited, developing custom solutions as needed.
Conduct penetration testing on core products, as well as other web applications and public-facing websites.
Design and implement security controls for APIs, including secure authentication, authorization, and protection against common threats such as cross-site request forgery (CSRF).
Collaborate with development teams to integrate Identity and Access Management (IAM) solutions aligned with least privilege and zero trust principles.
Serve as a key contributor to the security architecture and design of software systems, working closely with engineering teams to embed security into technical decisions.
Participate in the internal Security Council, contributing to strategic decisions and security governance.
Lead training initiatives for developers, QA, and DevOps teams to promote secure design principles and a security-first mindset.
Collaborate with engineering teams to integrate security into the software development lifecycle (SDLC).
Perform threat modeling and risk assessments to identify and mitigate potential vulnerabilities early in the development process.
Stay current with evolving security regulations, compliance standards, and emerging threats, ensuring organizational alignment and readiness.
Qualifications
Qualifications
Bachelor's degree in Computer Science, Information Security, or a related field.
3-5 years of experience in application security, software development, or related technical roles.
Strong understanding of secure coding practices, OWASP Top Ten, and software security testing methodologies.
Hands-on experience with SAST, DAST, and SCA tools and techniques.
Ability to develop custom scripts and automation to support security scanning, especially for desktop applications where tooling may be limited.
Familiarity with penetration testing, threat modeling, and secure architecture design.
Knowledge of API security, IAM, authentication and authorization protocols, and common web vulnerabilities such as CSRF and XSS.
Experience working with cloud-native applications and modern development environments.
Familiarity with security regulations and compliance frameworks such as ISO 27001, SOC 2, and GDPR.
CISSP or other relevant security certifications (e.g., OSCP, CSSLP) preferred.
Excellent communication skills and ability to collaborate across engineering, QA, and DevOps teams.
Physical Requirements/Essential Job Functions
Design and implement security controls to ensure all application code is tested and up to security standards
Conducting testing on core products, web applications, and other public facing websites to identify and reduce security threats
Collaborate closely with development teams to provide security guidance into technical decisions
Ability to multi-task technical problems efficiently
Ability to communicate technical concepts to both users and programmers effectively.
Problem-solving
Frequent computer and telephone use
Sitting for long periods of time
Concentrating for long periods of time.
Occasional travel of less than 10% may be required.
Our Company: Priority Dispatch Corp. is an Equal Opportunity Employer. We are a small, fast-growing provider of consulting, training, and software products for the public safety market. Priority Dispatch is based in the U.S. in downtown Salt Lake City, Utah. We offer a comprehensive benefits package including medical, dental, and matching 401(k) programs, etc. Priority Dispatch Corp. (PDC) provides comprehensive, integrated solutions for Police, Fire, and Medical emergency dispatching. We incorporate the Priority Dispatch System approved by the International Academies of Emergency Dispatch in all our products. PDC offers multi-agency emergency dispatching ProQA software, as well as a card-set version, AQUA quality improvement software, training, consulting, and Academy accreditation support. ************************
Security Engineer II
Security architect job in Salt Lake City, UT
Trustmark's mission is to improve wellbeing - for everyone. It is a mission grounded in a belief in equality and born from our caring culture. It is a culture we can only realize by building trust. Trust established by ensuring associates feel respected, valued and heard. At Trustmark, you'll work collaboratively to transform lives and help people, communities and businesses thrive. Flourish in a culture of diversity and inclusion where appreciation, mutual respect and trust are constants, not just for our customers but for ourselves. At Trustmark, we have a commitment to welcoming people, no matter their background, identity or experience, to a workplace where they feel safe being their whole, authentic selves. A workplace made up of diverse, empowered individuals that allows ideas to thrive and enables us to bring the best to our colleagues, clients and communities.
We are seeking a highly skilled Cyber Security Engineer to join our team and play a pivotal role in safeguarding our organization's digital assets. The ideal candidate will possess a deep understanding of cybersecurity principles, a strong technical background, and a passion for protecting sensitive information.
You will be responsible for engineering, implementing and monitoring security measures for the protection of Trustmark's computer systems, networks and information. The role helps identify and define system security requirements as well as develop detailed cyber security designs.
**Responsibilities:**
+ Design, implement, and maintain security architectures, systems, and solutions to protect critical infrastructure and data.
+ Conduct vulnerability assessments and penetration testing to identify and mitigate risks.
+ Develop and implement security policies, standards, and procedures.
+ Monitor security systems and respond to incidents promptly and effectively.
+ Stay up-to-date with the latest cybersecurity threats and trends.
+ Collaborate with cross-functional teams to ensure security is integrated into all aspects of the business.
+ Provide technical guidance and support to internal stakeholders.
**Qualifications:**
+ Bachelor's degree in Computer Science, Information Technology, or a related field or
+ 3-5 Years of network engineering or cyber engineering experience
+ Strong understanding of cybersecurity frameworks and standards (e.g., NIST, ISO 27001).
+ Proficiency in network security, systems security, application security, and data security.
+ Hands-on experience with security tools and technologies (e.g., firewalls, intrusion detection systems, encryption, SIEM).
+ Excellent problem-solving and analytical skills.
+ Strong communication and interpersonal skills.
+ Ability to work independently and as part of a team.
**Preferred Qualifications:**
+ Certifications such as CISSP, CISA, or CEH.
+ Experience with cloud security (e.g., AWS, Azure, GCP).
+ Knowledge of scripting and programming languages (e.g., Python, PowerShell).
Brand: Trustmark
Come join a team at Trustmark that will not only utilize your current skills but will enhance them as well. Trustmark benefits include health/dental/vision, life insurance, FSA and HSA, 401(k) plan, Employee Assistant Program, Back-up Care for Children, Adults and Elders and many health and wellness initiatives. We also offer a Wellness program that enables employees to participate in health initiatives to reduce their insurance premiums.
**For the fourth consecutive year we were selected as a Top Workplace by the Chicago Tribune.** The award is based exclusively on Trustmark associate responses to an anonymous survey. The survey measured 15 key drivers of engaged cultures that are critical to the success of an organization.
All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, sex, sexual orientation, sexual identity, age, veteran or disability.
Join a passionate and purpose-driven team of colleagues who contribute to Trustmark's mission of helping people increase wellbeing through better health and greater financial security. At Trustmark, you'll work collaboratively to transform lives and help people, communities and businesses thrive. Flourish in a culture where appreciation, mutual respect and trust are constants, not just for our customers but for ourselves.
Introduce yourself to our recruiters and we'll get in touch if there's a role that seems like a good match.
When you join Trustmark, you become part of an organization that makes a positive difference in people's lives. You will play a vital role in delivering on our mission of helping people increase wellbeing through better health and greater financial security. Our customers tell us they simply appreciate the personal attention and knowledgeable service. Others tell us we've changed their lives.
At Trustmark, you'll be part of a close-knit team. You'll enjoy abundant opportunities to grow your career. That's why so many of our associates stay at Trustmark and thrive. Trustmark benefits from more than 100 years of experience but pairs that rich history with a palpable sense of optimism, growth and excitement for what's ahead - and beyond. This is a place where associates bring their whole selves to work each day. A place where you can be yourself. Whatever your beyond is, you can achieve it at Trustmark.
Information Security Engineers
Security architect job in Salt Lake City, UT
Bookmark this Posting Print Preview | This posting does not accept online applications. Please contact your Human Resource Office for instructions on how to apply. Announcement Details Open Date 11/17/2025 Requisition Number PRN43601B Job Title Information Security Engineers Working Title Information Security Engineer Career Progression Track P00 Track Level FLSA Code Computer Employee Patient Sensitive Job Code? No Standard Hours per Week 40.00 Full Time or Part Time? Full Time Shift Day Work Schedule Summary VP Area President Department 00954 - UIT Systems & Security Location Campus City Salt Lake City, UT Type of Recruitment External Posting Pay Rate Range 88,000 to 131,300 Close Date 02/17/2026 Priority Review Date (Note - Posting may close at any time) Job Summary
The Information Security Engineer position in the Information Security Office (ISO) is
responsible for leading and supporting security initiatives which mitigate risk and ensure system and data integrity at the University of Utah and University Health Care. This includes providing security guidance and technical risk assessments of new or ongoing projects, responding to and analyzing security incidents, and implementing new security technologies or processes. This is a highly collaborative position which requires strong analytical and communication skills.
This position is hybrid, requiring the selected candidate to either reside in or be willing to move to the Salt Lake City area.
Responsibilities
* Assist the University in meeting Information Security compliance obligations.
* Contribute to incident response procedures, participate in incident response activities, and help develop strategies to prevent future occurrences.
* Analyze indicators of compromise from endpoints, servers, and cloud environments to identify the root cause of breaches, malware infections, or other security issues.
* Provide security evaluations and guidance regarding new technologies or processes.
* Assist in legal discovery, evidence acquisition, and preservation.
* Support the Security Operations Center (SOC) with tools, data, and guidance.
* Stay up-to-date concerning emerging threats, vulnerabilities, and security solutions through research and industry sources.
This job description is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of employees assigned to the job.
Minimum Qualifications
EQUIVALENCY STATEMENT: 1 year of higher education can be substituted for 1 year of directly related work experience (Example: bachelor's degree = 4 years of directly related work experience).
Department may hire employee at one of the following job levels:
Information Security Engineer, I: Requires a bachelor's (or equivalency) + 2 years of directly related work experience or a master's (or equivalency) degree.
Information Security Engineer, II: Requires a bachelor's (or equivalency) + 4 years or a master's (or equivalency) + 2 years of directly related work experience.
Information Security Engineer, III: Requires a bachelor's (or equivalency) + 6 years or a master's (or equivalency) + 4 years of directly related work experience.
Information Security Engineer, IV: Requires a bachelor's (or equivalency) + 8 years or a master's (or equivalency) + 6 years of directly related work experience.
Information Security Engineer, V: Requires a bachelor's (or equivalency) + 10 years or a master's (or equivalency) + 8 years of directly related work experience.
Information Security Engineer, VI: Requires a bachelor's (or equivalency) + 12 years or a master's (or equivalency) + 10 years of directly related work experience.
Information Security Engineer, VII: Requires a bachelor's (or equivalency) + 14 years or a master's (or equivalency) + 12 years of directly related work experience.
Preferences
* A thorough understanding of security industry standards (i.e. NIST 800-53, ISO/IEC 27001, CIS Controls, etc.)
* Experience with compliance standards including HIPAA, FISMA, PCI, and FERPA
* Experience with information security in a higher-education or healthcare setting.
* One or more security-specific certifications (CISSP, CISA, etc.)
One or more of the following:
a.) Experience with Data Security Posture Management, both on-premises and Cloud/SaaS
b.) Microsoft Purview Sensitivity Labels, Email, SharePoint, and OneDrive access controls
c.) Data Loss Prevention tools, tactics, and procedures
d.) Data cataloging, classification, discovery, and governance; overall data security
Type Benefited Staff Special Instructions Summary Additional Information
The University is a participating employer with Utah Retirement Systems ("URS"). Eligible new hires with prior URS service, may elect to enroll in URS if they make the election before they become eligible for retirement (usually the first day of work). Contact Human Resources at ************** for information. Individuals who previously retired and are receiving monthly retirement benefits from URS are subject to URS' post-retirement rules and restrictions. Please contact Utah Retirement Systems at ************** or ************** or University Human Resource Management at ************** if you have questions regarding the post-retirement rules.
This position may require the successful completion of a criminal background check and/or drug screen.
The University of Utah values candidates who have experience working in settings with students and possess a strong commitment to improving access to higher education.
Veterans' preference is extended to qualified applicants, upon request and consistent with University policy and Utah state law. Upon request, reasonable accommodations in the application process will be provided to individuals with disabilities.
Consistent with state and federal law, the University of Utah does not discriminate based upon race, ethnicity, color, religion, national origin, age, disability, sex, sexual orientation, gender, gender identity, gender expression, pregnancy, pregnancy-related conditions, genetic information, or protected veteran's status. The University does not discriminate on the basis of sex in the education program or activity that it operates, as required by Title IX and 34 CFR part 106. The requirement not to discriminate in education programs or activities extends to admission and employment. Inquiries about the application of Title IX and its regulations may be referred to the Title IX Coordinator, to the Department of Education, Office for Civil Rights, or both.
To request a reasonable accommodation for a disability or if you or someone you know has experienced discrimination or sexual misconduct including sexual harassment, you may contact the Director/Title IX Coordinator in the Office of Equal Opportunity and Title IX (OEO). More information, including the Director/Title IX Coordinator's office address, electronic mail address, and telephone number can be located at: ***************************************
Online reports may be submitted at oeo.utah.edu
************************************ This report includes statistics about criminal offenses, hate crimes, arrests and referrals for disciplinary action, and Violence Against Women Act offenses. They also provide information about safety and security-related services offered by the University of Utah. A paper copy can be obtained by request at the Department of Public Safety located at 1658 East 500 South.
Posting Specific Questions
Required fields are indicated with an asterisk (*).
* * What is your highest level of completed education?
* None
* High School Diploma or Equivalent
* Associate Degree
* Bachelor's Degree
* Master's Degree
* Doctorate Degree
* * How many years of related work experience do you have?
* Less than 6 years
* 6 years or more, but less than 9 years
* 9 years or more, but less than 12 years
* 12 years or more, but less than 15 years
* 15 years or more
Applicant Documents
Required Documents
* Resume
Optional Documents
* Cover Letter
Auto-ApplySenior Offensive Security Engineer
Security architect job in Salt Lake City, UT
Who We Are
In today's work environment, employees use a myriad of devices to access IT applications and data over multiple networks to stay productive, wherever and however they work. Ivanti elevates and secures Everywhere Work so that people and organizations can thrive.
While our headquarters is in the U.S., half of our employees and customers are outside the country. We have 36 offices in 23 nations, with significant offices in London, Frankfurt, Paris, Sydney, Shanghai, Singapore, and other major cities around the world.
Ivanti's mission is to be a global technology leader enabling organizations to elevate Everywhere Work, automating tasks that discover, manage, secure, and service all their IT assets. Through diverse and inclusive hiring, decision-making, and commitment to our employees and partners, we will continue to build and deliver world-class solutions for our customers.
Our Culture - Everywhere Work Centered Around You
At Ivanti, our success begins with our people. This is why we embrace Everywhere Work across the globe, where Ivantians and our customers are thriving. We believe in a healthy work-life blend and act on it by fostering a culture where all perspectives are heard, respected, and valued. Through Ivanti's Centered Around You approach, our employees benefit from programs focused on their professional development and career growth.
We align through our core values by locking arms in collaboration, being champions for our customers, focusing on the outcomes that matter most and fighting the good fight against cyber-attacks. Are you ready to join us on the journey to elevate Everywhere Work?
Why We Need You!
The Offensive Security Engineer at Ivanti plays a crucial role in assessing the security of applications, networks, and systems by simulating cyberattacks. Responsibilities include managing responsible disclosure programs, collaborating with internal teams to prioritize and resolve vulnerabilities, and conducting penetration tests. A top candidate would find this role attractive because it offers the opportunity to work with cutting-edge cybersecurity technologies, contribute to enhancing Ivanti's overall security posture, and collaborate with a talented team of professionals. Additionally, the role allows for continuous learning and offers room for growth in a dynamic and fast-paced organization.
Ivanti's Security Department is responsible for implementing and maintaining organization-wide information security policies, standards, guidelines, and procedures. The security team works collaboratively with other business units to document business requirements, then solves for those requirements through a variety of aligned platforms which make up our enterprise architecture. The teams ultimate goal is to keep Ivanti, our data, our customers and employees safe.
As an Offensive Security Engineer, you will be responsible for evaluating the security of applications, networks, and systems by simulating cyberattacks. You will conduct comprehensive security assessments, identify vulnerabilities, and provide recommendations for remediation to enhance the overall security posture of Ivanti products.
Define clear policies and procedures for the responsible disclosure process, including guidelines for researchers, internal stakeholders, and third-party vendors.
Establish and maintain communication channels with the security research community to promote awareness of the responsible disclosure program and encourage participation.
Receive and triage vulnerability reports submitted by external researchers through various channels, such as email, web form, or bug bounty platform.
Collaborate with internal security teams to assess the severity and impact of reported vulnerabilities and prioritize them for resolution based on risk.
Facilitate communication and collaboration between researchers and relevant stakeholders, including development teams, IT operations, and product managers, to ensure timely resolution of identified security issues.
Track the progress of vulnerability remediation efforts and ensure that issues are addressed within agreed-upon timelines.
Maintain detailed records of vulnerability reports, assessments, and resolutions to support compliance requirements and internal reporting.
Develop and maintain metrics to measure the effectiveness of the responsible disclosure program, including response times, resolution rates, and researcher satisfaction.
Monitor industry best practices and emerging trends in responsible disclosure and vulnerability management to identify opportunities for program enhancement and optimization.
Perform penetration tests and vulnerability assessments of applications, network and systems using various tools and techniques to exploit identified vulnerabilities and assess the effectiveness of existing security measures.
Stay abreast of the latest security threats, trends, and technologies through continuous learning and research to enhance penetration testing methodologies and techniques.
Qualifications:
5 years of experience in cybersecurity, with a focus on penetration testing and vulnerability assessment.
Responsible Disclosure Program (VDP) and Bugbounty program management
CEH, Offensive Security Certified Professional (OSCP), or other relevant certifications.
Strong understanding of networking protocols, operating systems, and web applications.
Proficiency in using penetration testing tools such as Metasploit, Nmap, Burp Suite, etc.
Knowledge of common cybersecurity threats and attack vectors.
Excellent analytical and problem-solving skills.
Effective communication skills for writing detailed reports and presenting findings to stakeholders.
Our Employer Commitment
This job posting will remain active until a qualified candidate is identified.
At Ivanti, we are committed to providing an environment of mutual respect where equal employment opportunities are available to all applicants and teammates without regard to race, color, religion, sex, pregnancy (including childbirth, lactation and related medical conditions), national origin, age, physical and mental disability, marital status, sexual orientation, gender identity, gender expression, genetic information (including characteristics and testing), military and veteran status, and any other characteristic protected by applicable law.
We invite individuals of all backgrounds and abilities to apply. If you require assistance to optimize your interview experience, please contact us at *********************.
Auto-ApplyGoogle Cloud Security Architect
Security architect job in Salt Lake City, UT
Who You'll Work With As a modern technology company, our Slalom Technologists are disrupting the market and bringing to life the art of the possible for our clients. We have passion for building strategies, solutions, and creative products to help our clients solve their most complex and interesting business problems. We surround our technologists with interesting challenges, innovative minds, and emerging technologies.
Join the Slalom Cloud Team -a team of trailblazers ensuring we achieve our strategic goals through innovation and investment in the future. You'll collaborate with local market teams, niche experts, and global partners to drive cloud solution sales and empower clients on their cloud transformation journey. As a key member of Slalom's Google Cloud Center of Excellence, you'll leverage our award-winning partnerships and multidisciplinary teams to deliver business value and technical excellence for high-impact security and infrastructure solutions.
What You'll Do
* Stay current with security trends, technologies, and best practices around Google Cloud solutions, leveraging tools like Cloud IAM, Cloud Security Command Center, BeyondCorp, and Cloud Armor.
* Define and guide transformational security strategies for Google Cloud environments, ensuring alignment with Google's Zero Trust and BeyondCorp principles.
* Translate complex regulatory requirements (e.g., GDPR, SOC 2, HIPAA) and technology standards into actionable functional and technical requirements for cloud and hybrid environments, ensuring security and compliance.
* Lead teams through various phases of gap analyses, including security assessments, remediation planning, roadmap development, and implementation of remediation actions using Google Cloud-native tools.
* Deliver on the vision, architecture, execution, and quality assurance of security projects on Google Cloud, driving initiatives that secure enterprise workloads and data.
* Guide stakeholders and senior leaders on aligning security solutions with broader business goals, ensuring the architecture follows Google Cloud's security best practices and roadmap.
* Establish security architecture patterns based on Google Cloud security frameworks and industry standards to meet the unique needs of enterprise clients.
* Collaborate with other Google Cloud architects and security teams to continuously improve security knowledge assets and best practices, ensuring the most effective security solutions for clients.
* Design and architect solutions to secure Generative AI models and applications against adversarial attacks, prompt injection, and their potential misuse for malicious cyber activities.
What You'll Bring
* Proven experience with Google Cloud security architecture, with hands-on experience in tools like Cloud IAM, VPC Service Controls, Cloud DLP, and Cloud Armor.
* Strong background in defining and implementing Zero Trust and BeyondCorp security models within Google Cloud environments.
* Familiarity or direct experience with Identity and Access Management (IAM), Data Protection, Vulnerability Management, and Cloud Security solutions in Google Cloud.
* Extensive experience with security design patterns specific to Google Cloud, as well as hybrid and multi-cloud security architecture.
* Experience in security and risk advisory consulting, particularly related to cloud security transformations.
* Ability to lead the development and implementation of cloud security roadmaps aligned with business goals and compliance needs.
* Familiarity with Google Cloud's Artificial Intelligence (AI) capabilities (e.g., Vertex AI, Generative AI services, Model Armor) including their applications, associated security risks (e.g., prompt injection, data poisoning, privacy concerns), and proven strategies for implementing security controls, governance, and responsible AI practices.
* Relevant certifications are strongly desired but not required, including (but not limited to):
* GCP Professional Security Engineer
* GCP Professional Cloud Architect
* CISSP
* Security+
About Us
Slalom is a fiercely human business and technology consulting company that leads with outcomes to bring more value, in all ways, always. From strategy through delivery, our agile teams across 52 offices in 12 countries collaborate with clients to bring powerful customer experiences, innovative ways of working, and new products and services to life. We are trusted by leaders across the Global 1000, many successful enterprise and mid-market companies, and 500+ public sector organizations to improve operations, drive growth, and create value. At Slalom, we believe that together, we can move faster, dream bigger, and build better tomorrows for all.
Compensation and Benefits
Slalom prides itself on helping team members thrive in their work and life. As a result, Slalom is proud to invest in benefits that include meaningful time off and paid holidays, parental leave, 401(k) with a match, a range of choices for highly subsidized health, dental, & vision coverage, adoption and fertility assistance, and short/long-term disability. We also offer yearly $350 reimbursement account for any well-being-related expenses, as well as discounted home, auto, and pet insurance.
Slalom is committed to fair and equitable compensation practices.
Slalom is committed to fair and equitable compensation practices. For this role, we are targeting the following levels and salary ranges:
East Bay, San Francisco, Silicon Valley:
* Senior Consultant: $131,000-$196,500
San Diego, Los Angeles, Orange County, Seattle, Houston, New Jersey, New York City, Westchester, Boston, Washington DC:
* Senior Consultant: $120,000-$180,000
All other locations:
* Senior Consultant: $110,000-$165,000
In addition, individuals may be eligible for an annual discretionary bonus. Actual compensation will depend upon an individual's skills, experience, qualifications, location, and other relevant factors. The salary pay range is subject to change and may be modified at any time.
EEO and Accommodations
Slalom is an equal opportunity employer and is committed to inclusion, diversity, and equity in the workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veterans' status, or any other characteristic protected by federal, state, or local laws. Slalom will also consider qualified applications with criminal histories, consistent with legal requirements. Slalom welcomes and encourages applications from individuals with disabilities. Reasonable accommodations are available for candidates during all aspects of the selection process. Please advise the talent acquisition team if you require accommodations during the interview process.
Security Engineer
Security architect job in Salt Lake City, UT
Meta Platforms, Inc. (Meta), formerly known as Facebook Inc., builds technologies that help people connect, find communities, and grow businesses. When Facebook launched in 2004, it changed the way people connect. Apps and services like Messenger, Instagram, and WhatsApp further empowered billions around the world. Now, Meta is moving beyond 2D screens toward immersive experiences like augmented and virtual reality to help build the next evolution in social technology. To apply, click "Apply to Job" online on this web page.
**Required Skills:**
Security Engineer Responsibilities:
1. Build tools that enable connectivity to our infrastructure only from Meta owned and managed devices.
2. Build machine attestation and secure certificate storage solutions to enable strong client trust.
3. Deploy systems that help mitigate security risks by understanding and controlling what software is allowed to execute on our client devices.
4. Develop, validate, and enforce our client security policies.
5. Build and deploy tools and automation that proactively detect and respond to security risks and threats to internal corporate services.
6. Advise and collaborate with other teams.
7. Telecommuting from anywhere in the U.S. allowed.
**Minimum Qualifications:**
Minimum Qualifications:
8. Requires Bachelor's Degree (or foreign equivalent) in Computer Science, Engineering or a related field and 1 year of experience in the job offered or a computer-related occupation
9. Requires 12 months of experience involving the following:
10. PHP, Golang, Python, C/C++, Rush, or Ruby
11. Designing and deploying security infrastructure such as PKI, key management, and certificate management
12. Endpoint Security & Management
13. Certificate Lifecycle
14. Devices & OS hardening and security policies
15. Identity & Access Management (Authentication & Authorization, SSO)
16. Network Security and
17. Programming and Code Review
**Public Compensation:**
$178,041/year to $200,200/year + bonus + equity + benefits
**Industry:** Internet
**Equal Opportunity:**
Meta is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Meta participates in the E-Verify program in certain locations, as required by law. Please note that Meta may leverage artificial intelligence and machine learning technologies in connection with applications for employment.
Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at accommodations-ext@fb.com.
Information Systems Security Officer
Security architect job in Clearfield, UT
General information Requisition # R64695 Posting Date 12/10/2025 Security Clearance Required Top Secret Remote Type Onsite Time Type Full time Description & Requirements Shape the future of defense with MANTECH! Join a team dedicated to safeguarding our nation through advanced tech and innovative solutions. Since 1968, we've been a trusted partner to the Department of Defense, delivering cutting-edge projects that make a real impact. Dive into exciting opportunities in Cybersecurity, IT, Data Analytics and more. Propel your career forward and be part of something extraordinary. Your journey starts now-protect and innovate with MANTECH!
MANTECH seeks a motivated, career and customer-oriented Information Systems Security Officer (ISSO) to join our Air Force / Space team at Hill AFB.
The ISSO's primary function is to support the United States Air Force's 53rd Wing Technical Support Services (53rd WTSS) contract.
Responsibilities include, but are not limited to:
* Perform ISSO duties in support of in-house and external customers
* Notify ISSM when changes occur that might affect the authorization determination of the information system(s)
* Conduct periodic reviews of information systems to ensure compliance with the security authorization package
* Coordinate any changes or modifications to hardware, software, or firmware of a system with the ISSM and AO/DAO prior to the change
* Ensure all IS security-related documentation is current and accessible to properly authorized individuals
* Execute the cyber security portion of the self-inspection, to include provide security coordination and review of all system assessment plans
* Identify cyber security vulnerabilities and assist with the implementation of the countermeasures for them
* Conduct security impact analysis activities and provide to the ISSM on all configuration management changes to the authorization boundaries
Minimum Qualifications:
* Bachelor's degree in related discipline from an accredited college or university. 2 additional years of experience may be substituted for a degree.
* 4+ years direct/related experience
* Active / valid DoD 8570.01-M IAT-II certification
* Experience with DoD/USAF information security policy background with practical / hands-on experience applying RMF processes and principles.
* Experience developing and/or contributing to an RMF body of evidence composition, applicable artifacts, and associated control families.
Clearance Requirements:
* Active Top Secret Clearance
* Must be able to obtain and maintain a DoD TS/SCI-eligible clearance (i.e. DCID 6/4 eligibility)
* Eligibility for access to Special Access Program Information
* Willingness to submit to a Polygraph.
Physical Requirements:
* Must be able to remain in a stationary position 50%
* Needs to occasionally move about inside the office to access file cabinets, office machinery, etc.
* Constantly operates a computer and other office productivity machinery, such as a calculator, copy machine and computer printer.
* Frequently communicates with co-workers, management and customers, which may involve delivering presentations. Must be able to exchange accurate information in these situations
MANTECH International Corporation considers all qualified applicants for employment without regard to disability or veteran status or any other status protected under any federal, state, or local law or regulation.
If you need a reasonable accommodation to apply for a position with MANTECH, please email us at ******************* and provide your name and contact information.
Auto-ApplyEngineer, Information Security and Risk
Security architect job in Salt Lake City, UT
Cardinal Health, Inc. (NYSE: CAH) is a global healthcare services and products company. We provide customized solutions for hospitals, healthcare systems, pharmacies, ambulatory surgery centers, clinical laboratories, physician offices and patients in the home. We are a distributor of pharmaceuticals and specialty products; a global manufacturer and distributor of medical and laboratory products; an operator of nuclear pharmacies and manufacturing facilities; and a provider of performance and data solutions. Working to be healthcare's most trusted partner, our customer-centric focus drives continuous improvement and leads to innovative solutions that improve the lives of people every day. With approximately 50,000 employees worldwide, Cardinal Health ranks among the top fifteen in the Fortune 500.
**_Department Overview:_**
**Information Technology** oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value.
**Information Security and Risk** develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure, or destruction. This job family develops system back-up and disaster recovery plans, conducts incident responses, threat management, vulnerability scanning, virus management and intrusion detection as well as completes risk assessments.
We are seeking a highly skilled and experienced Identity and Access Management (IAM) Engineer to join our team. In this pivotal role, you will be instrumental in designing, implementing, and managing IAM solutions that secure our enterprise applications and facilitate the secure, efficient, and seamless integration of identity and access systems in context of our rapid growth through Mergers and Acquisitions. You will ensure robust access controls, streamline user experiences, and maintain operational continuity across our diverse IT landscape. The ideal candidate will have deep technical expertise in modern IAM principles, protocols and products along with strong management and communication skills.
**Responsibilities:**
+ **Application Integration Leadership:** Lead the integration of various enterprise applications (SaaS, on-premise, custom-built) with our core IAM infrastructure, ensuring secure authentication, authorization, and user provisioning/de-provisioning.
+ **M&A Integration Strategy & Execution:** Lead the planning, design, and execution of IAM integration strategies for M&A activities, ensuring alignment with overall business and security objectives. This includes assessing the IAM landscapes of merging entities to identify challenges and solutions.
+ **Identity System Merging & Consolidation:** Manage the complex process of merging disparate identity providers, user directories (e.g., Active Directory, Azure AD, LDAP), and access management systems from acquired companies into the existing infrastructure.
+ **User Lifecycle Management:** Streamline and automate user provisioning, de-provisioning, and periodic access reviews for employees, contractors, and partners across all integrated systems, ensuring smooth onboarding and offboarding during M&A transitions.
+ **Solution Design & Implementation:** Design, implement, and maintain IAM solutions including Single Sign-On (SSO), Multi-Factor Authentication (MFA), Privileged Access Management (PAM), and Role-Based Access Control (RBAC) frameworks.
+ **Security & Compliance:** Ensure IAM systems and processes comply with regulatory requirements (e.g., GDPR, HIPAA, SOX) and internal security policies, providing auditable records of access activities. Protect against data breaches by ensuring only authorized personnel can access sensitive information.
+ **Technical Troubleshooting & Support:** Troubleshoot, identify, and resolve technical identity and access management-related issues, providing expert support to internal teams and end-users during and after integration.
+ **Collaboration & Communication:** Coordinate cross-functional teams, including Information Security, IT Operations, HR, and Application Development, to ensure effective IAM implementation and seamless integration with business processes. Communicate complex security concepts to technical and non-technical stakeholders.
+ **Documentation & Best Practices:** Develop, review, and maintain comprehensive technical documentation, including architecture diagrams, configuration guides, and operational procedures. Stay up-to-date with IAM best practices, regulatory requirements, and security trends.
**Qualifications:**
+ **Education:** Bachelor's degree in Computer Science, Information Technology, Information Security, or a related field, or equivalent practical experience.
+ **Experience:** 5+ years of progressive experience as an IAM Engineer, designing and implementing enterprise scale solutions with significant experience in supporting M&A integration projects preferred.
+ **Technical Expertise:**
+ Proficiency in directory services (e.g., Active Directory, Azure AD, LDAP).
+ Extensive knowledge and experience with authentication standards and technologies such as SSO (SAML, OAuth, OpenID Connect), MFA, and privileged access management (PAM).
+ Hands-on experience with leading IAM platforms (e.g., Okta, Microsoft Azure AD, CyberArk, ForgeRock, Ping Identity, SailPoint).
+ Experience with scripting languages (e.g., PowerShell, Python) for automation and integration.
+ Strong understanding of security principles, risk management, and access control models (e.g., RBAC).
+ Understanding of DevOps practices.
+ Familiarity with Zero Trust architecture principles.
+ Familiarity with AI/ML concepts and their practical application in security and risk management, especially in IAM context.
+ **M&A Specific Skills:** Proven track record of managing complex integration projects, including assessing existing IAM capabilities, workflow, systems, and processes of acquired entities. Ability to navigate the complexities of integrating diverse identity infrastructures.
+ Strong communication and interpersonal skills to collaborate effectively with various teams and stakeholders.
+ Detail-oriented mindset to ensure precise access control configurations and compliance.
+ Excellent problem-solving and analytical abilities to troubleshoot access issues and design solutions for unique business requirements
+ Must be a self-starter who takes full ownership of projects from inception to completion , holding oneself accountable for the security and operation integrity of IAM platform.
+ Ability to manage multiple priorities and meet tight deadlines in a fast-paced M&A environment.
+ Adaptability to stay ahead of evolving IAM technologies and security threats.
**Anticipated salary range:** $94,900 - $135,600
**Bonus eligible:** No
**Benefits:** Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
+ Medical, dental and vision coverage
+ Paid time off plan
+ Health savings account (HSA)
+ 401k savings plan
+ Access to wages before pay day with my FlexPay
+ Flexible spending accounts (FSAs)
+ Short- and long-term disability coverage
+ Work-Life resources
+ Paid parental leave
+ Healthy lifestyle programs
**Application window anticipated to close:** 12/20/2025 *if interested in opportunity, please submit application as soon as possible.
The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.
_Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply._
_Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal_ _Opportunity/Affirmative_ _Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law._
_To read and review this privacy notice click_ here (***************************************************************************************************************************
Sr. Security Analyst
Security architect job in South Jordan, UT
Job Description
Lightspeed is a leading provider of cloud-based software for dealerships and Original Equipment Manufacturers (OEMs), serving the Powersport, Marine, RV, Trailer, Outdoor Power Equipment, and Golf Cart industries. Lightspeed's Dealer Management Solution (DMS) enables dealerships to optimize their end-to-end business operations, including sales, parts, service, rentals, accounting, and Customer Relationship Management (CRM). When implemented into their daily operations, Lightspeed helps dealers increase their profitability by selling more units, service, and parts, all while creating a more streamlined experience for customers. For nearly 40 years, Lightspeed has been empowering 4,500+ dealers across North America with the tools and technology they need to manage their dealerships.
The Senior Security Analyst is responsible for team lead activities, such as monitoring, analyzing, and responding to security incidents across enterprise systems, cloud environments, and networks. This role ensures the confidentiality, integrity, and availability of organizational information through proactive detection, incident response, and continuous improvement. The ideal candidate will have a strong technical background in leading threat analysis, SIEM integration and management, vulnerability management, and incident handling.
What you'll do:
Monitor and investigate security alerts and events across SIEM, EDR, and network systems.
Conduct root cause analysis and coordinate remediation of security incidents.
Lead vulnerability assessments and ensure timely patching and mitigation.
Develop and maintain incident response playbooks and escalation procedures.
Collaborate with IT, DevOps, and Development teams to strengthen overall security posture.
Lead proactive threat hunting and continuous tuning of detection mechanisms.
Support internal and external audits (e.g., SOC 2) and risk assessments by providing evidence and guidance.
Perform firewall management, including rule changes, troubleshooting, and SOP development for hybrid cloud/on-prem environments.
Lead to red/blue team exercises and implement findings to improve defenses.
Coordinate and assist with enterprise pen-tests, risk assessments, and compliance initiatives.
Serve as a lead security advisor to business and technical teams, providing guidance on secure design, risk mitigation, and compliance using industry frameworks and best practices.
What you should have:
Qualifications:
Bachelor's degree in Cybersecurity, Information Technology, or a related field, or equivalent experience.
8+ years of experience in information security, incident response, or SOC operations.
Proven hands-on experience with SIEM tools (Splunk, Sentinel, QRadar, etc.) and EDR/XDR platforms (CrowdStrike, Darktrace, Microsoft Defender).
Strong experience securing and monitoring cloud environments (AWS, Azure).
Deep knowledge of security frameworks (NIST CSF, ISO 27001, SOC 2).
Advanced scripting and automation proficiency (Python, PowerShell, Terraform).
Excellent analytical, problem-solving, and communication skills.
Preferred Qualifications:
Relevant certifications such as AWS Security, CISSP, GCIH, GCIA, GPEN, GWAPT preferred.
Experience integrating AI and automation into security operations workflows.
Hands-on experience performing dynamic application security testing and red team exercises across endpoint and cloud environments.
Expert-level networking and firewall expertise with platforms such as Palo Alto, Cisco, or Checkpoint.
Master's degree in Cybersecurity, Information Technology, or a related field.
Inclusion and Diversity at Lightspeed:
At Lightspeed, we celebrate the uniqueness of every individual and encourage diverse perspectives. We believe that inclusion drives innovation and fosters meaningful connections. We are committed to building an environment where everyone feels valued and empowered to make an impact.
Equal Employment Opportunity Statement:
Lightspeed is an Equal Opportunity Employer and is dedicated to building a diverse and inclusive workforce. All qualified applicants will be considered for employment without regard to race, color, creed, ancestry, national origin, gender, sexual orientation, gender identity, gender expression, marital status, religion, age, disability, veteran status, or any other protected category.
Important Note:
Applicants must be authorized to work in the U.S.
Ready to apply?
Take the next step in your career-apply today and join a team where your skills will make an impact!
Engineer, Information Security and Risk
Security architect job in Salt Lake City, UT
Cardinal Health, Inc. (NYSE: CAH) is a global healthcare services and products company. We provide customized solutions for hospitals, healthcare systems, pharmacies, ambulatory surgery centers, clinical laboratories, physician offices and patients in the home. We are a distributor of pharmaceuticals and specialty products; a global manufacturer and distributor of medical and laboratory products; an operator of nuclear pharmacies and manufacturing facilities; and a provider of performance and data solutions. Working to be healthcare's most trusted partner, our customer-centric focus drives continuous improvement and leads to innovative solutions that improve the lives of people every day. With approximately 50,000 employees worldwide, Cardinal Health ranks among the top fifteen in the Fortune 500.
**_Department Overview:_**
**Information Technology** oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value.
**Information Security and Risk** develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure, or destruction. This job family develops system back-up and disaster recovery plans, conducts incident responses, threat management, vulnerability scanning, virus management and intrusion detection as well as completes risk assessments.
**Responsibilities:**
+ **M&A Integration Execution:** Collaborate and engage with IAM Lead and other business partners on planning, design, and execution of IAM integration strategies for M&A activities, ensuring alignment with overall business and security objectives. This includes assessing the IAM landscapes of merging entities to identify challenges and solutions.
+ **Design and Implement Sailpoint IIQ Solutions:** Configure and customize Sailpoint IIQ components (Lifecycel Manager, Compliance Manager etc). Also develop workflows, rules, and connectors for identity governance.
+ **Application integration with Sailpoint IIQ:** Integrate Sailpoint IIQ with enterprise applications, directories and cloud platforms in addition to developing and maintaining connectros for provisioning and de-provisioning.
+ **Sailpoint IIQ Development and Scripting:** Write and maintain BeanShell scripts, Java code and XML configurations, develop customer Sailpoint tasks and workflows.
+ **Identity System Merging & Consolidation:** Manage the complex process of merging disparate identity providers, user directories (e.g., Active Directory, Azure AD, LDAP), and access management systems from acquired companies into the existing infrastructure.
+ **User Lifecycle Management:** Streamline and automate user provisioning, de-provisioning, and periodic access reviews for employees, contractors, and partners across all integrated systems, ensuring smooth onboarding and offboarding during M&A transitions.
+ **Security & Compliance:** Ensure IAM systems and processes comply with regulatory requirements (e.g., GDPR, HIPAA, SOX) and internal security policies, providing auditable records of access activities. Protect against data breaches by ensuring only authorized personnel can access sensitive information.
+ **Technical Troubleshooting & Support:** Troubleshoot, identify, and resolve technical identity and access management-related issues, providing expert support to internal teams and end-users during and after integration.
+ **Collaboration & Communication:** Coordinate cross-functional teams, including Information Security, IT Operations, HR, and Application Development, to ensure effective IAM implementation and seamless integration with business processes. Communicate complex security concepts to technical and non-technical stakeholders.
+ **Documentation & Best Practices:** Develop, review, and maintain comprehensive technical documentation, including architecture diagrams, configuration guides, and operational procedures. Stay up-to-date with IAM best practices, regulatory requirements, and security trends.
**Qualifications**
+ Experience with SailPoint IdentityIQ (IIQ) is a must
+ Experience with SailPoint IIQ Integrations (Workday, Active Directory/LDAP, Webservices, SCIM, JDBC, SAP)
+ Experience implementing Life Cycle Manager (LCM) Configuration workflow tasks that model business functions, including Lifecycle Requests (Role or Entitlement), Lifecycle Events (Joiner, Mover, or Leaver), and LCM Workflow Details (Workflows and Subprocesses)
+ Solid understanding of the SailPoint object model, rules, and policies
+ Experience with both lifecycle manager (LCM) and compliance manager (CM) modules
+ Knowledge of Active Directory, LDAP, Workday, and cloud platforms (GCP, MS Entra ID) is required
+ Proven track record of successful IAM implementations including large scale enterprise deployments.
+ Experience working within regulatory standards and requirements such as, SOX, HIPAA, GDPR etc. is desired.
**Anticipated salary range:** $94,900 - $135,600
**Bonus eligible:** No
**Benefits:** Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
+ Medical, dental and vision coverage
+ Paid time off plan
+ Health savings account (HSA)
+ 401k savings plan
+ Access to wages before pay day with my FlexPay
+ Flexible spending accounts (FSAs)
+ Short- and long-term disability coverage
+ Work-Life resources
+ Paid parental leave
+ Healthy lifestyle programs
**Application window anticipated to close:** 12/20/2025 *if interested in opportunity, please submit application as soon as possible.
The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.
_Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply._
_Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal_ _Opportunity/Affirmative_ _Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law._
_To read and review this privacy notice click_ here (***************************************************************************************************************************