Security Engineer
Security Architect Job 15 miles from Portland
Required Skills and Experience
3-4+ years of experience as a Security Engineer or similar
Experience with Cloud Security: Cloud Compliance, Cloud computing, Azure Security Experience preferred
Broad diverse security experience; exposure to multiple different security domains (network, DevOps, application, cloud)
Familiar with Security Frameworks
Nice to Have Skills and Experience
Experience with IAC (Infrastructure as code)
Experience with API connections
Job Description
A client in the Vancouver, WA area is looking for a Security Engineer to join their team! This is a permanent direct hire opening that is a hybrid on-site environment. In this role you will be working on a team alongside other Security Engineers and analysts supporting IT for this organization. This company has a growing security group and has a security framework in place for their organization. As a Security Engineer you will have exposure to a few different cybersecurity domains which include, but are not limited to: Network Security (end point security, managed network detection), Application Security, and Cloud security. Other areas you would be exposed to in this role include: Infrastructure as code (vulnerability management), Cloud computing in Azure, data security, email security, PCI/SOC compliance. This is a great opportunity for someone to take their skills to the next level, learn more, and have a team to support them. If this sounds like a position of interest, please apply today!
Information Security Analyst
Security Architect Job 3 miles from Portland
Title: Information Security Analyst
Employment Type: 7+ Month W2 Contract (No C2C or Sponsorship Available)
Are you looking to grow your career in cybersecurity and gain hands-on experience in a dynamic, Microsoft-forward environment? Talent Groups is hiring an Information Security Analyst on behalf of a growing financial services client. This front-line, triage-focused role on the Information Security Operations team is perfect for someone eager to make meaningful contributions while learning from senior InfoSec engineers.
Responsibilities:
• Monitor and analyze security logs, incidents, alerts, and threat intelligence feeds
• Triage and respond to escalated tickets from our MDR partner and internal users
• Support daily and weekly InfoSec operational tasks driven by compliance needs
• Perform initial vulnerability assessments and log reviews
• Manage and track tickets using ServiceNow (low ticket volume)
• Document SOPs, incident response actions, and technical processes
• Stay informed on evolving threats, tools, and security best practices
• Utilize tools such as Microsoft Defender, Arctic Wolf, Entra ID, Fortra, and Tenable.io
• Collaborate with infrastructure and business teams across the organization
• Participate in internal audits and support policy enforcement activities
Tech Environment:
• Microsoft Defender (Endpoint & Server), Azure/Entra ID, ServiceNow
• Arctic Wolf (MDR), Tenable.io, Fortra (phishing protection)
• Hybrid infrastructure: on-prem data center and Azure Cloud
• PowerShell familiarity is a plus, but scripting is not required
• No on-call responsibilities
What We're Looking For:
• 1-3+ years in Information Security roles (triage, operations, SOC, etc.)
• Strong interest in cybersecurity and a desire to grow your skills
• Experience with SIEMs, endpoint protection, IAM, and vulnerability tools
• Comfortable with log analysis, incident response, and basic system hygiene
• Entry- to mid-level candidates with certifications (CompTIA, ISACA, ISC2, Microsoft, etc.) are encouraged to apply
• Exposure to PCI, FFIEC, SOC 2, or ISO 27001 is a plus
• MSSP or Arctic Wolf experience is a bonus
Note: We appreciate all applicants, but only those selected for an interview will be contacted. Talent Groups is an equal opportunity employer.
Principal Information Security Architect
Security Architect Job 38 miles from Portland
Lumen connects the world. We are igniting business growth by connecting people, data and applications - quickly, securely, and effortlessly. Together, we are building a culture and company from the people up - committed to teamwork, trust and transparency. People power progress.
We're looking for top-tier talent and offer the flexibility you need to thrive and deliver lasting impact. Join us as we digitally connect the world and shape the future.
**The Role**
Lumen is looking for an experienced technical compliance architect to bolster and drive our compliance programs. Reporting to the Senior Director Security for GRC and Business Enablement, the Compliance Architect will serve as a subject matter expert on technical detective and preventative controls to meet our compliance obligations while balancing the need to be secure. This role will be expected to provide guidance, support the decision-making process, and stay current on technological advancement in compliance solutions and federal cloud offerings.
The Principal Compliance Architect is a senior technical expert responsible for designing, verifying, and validating technical controls to ensure the organization's information systems comply with external regulatory, contractual, and industry obligations (such as NIST, ISO, GDPR, HIPAA, CMMC, PCI DSS, etc.). This role works cross-functionally with IT, Security, Legal, and Business teams to interpret compliance requirements and translate them into effective, auditable technical solutions.
**The Main Responsibilities**
+ **Compliance Solution Design:** Analyze external compliance requirements and architect technical controls, processes, and solutions to meet or exceed these obligations.
+ **Control Implementation:** Lead and coordinate the deployment of security and privacy controls across systems, applications, and cloud environments. Assure alignment with Security and Lumen stakeholders to meet the compliance control objectives.
+ **Gap Analysis:** Conduct technical risk and gap assessments against regulatory frameworks and contractual requirements; recommend and drive remediation.
+ **Documentation & Evidence:** Develop and maintain detailed documentation of technical controls, architectures, and compliance evidence for audits and assessments.
+ **Audit Support:** Serve as a technical subject matter expert during internal and external audits, assessments, and regulatory reviews.
+ **Continuous Monitoring:** Design and implement monitoring solutions to ensure ongoing compliance and rapid detection of control failures or deviations.
+ **Stakeholder Collaboration:** Work closely with business, IT, and legal stakeholders to ensure compliance objectives are met without impeding innovation or operations.
+ **Training & Awareness:** Provide guidance and training to technical teams on compliance requirements and secure architecture best practices.
+ **Change Management:** Assess the compliance impact of technology changes and ensure controls remain effective as systems evolve.
+ **Regulatory Intelligence:** Stay current on emerging regulations, standards, and best practices; proactively update controls and architectures as needed.
**What We Look For in a Candidate**
+ Bachelor's degree in information security, Computer Science, Engineering, or related field (Master's preferred)
+ 8+ years of experience in information security, compliance, or risk management roles
+ Deep knowledge of industry frameworks and regulations (e.g., NIST, ISO,CMMI, CMMC, FAR, and DFARS)
+ Proven experience designing and implementing technical controls in complex IT environments including Gov Cloud offerings
+ Strong understanding of security architecture, network security, identity management, and data protection technologies
+ Experience with compliance automation tools and GRC platforms
+ Excellent communication skills, with the ability to explain complex technical concepts to non-technical stakeholders
+ Analytical thinker with a proactive, problem-solving mindset
+ Strong organizational and project management skills
+ Ability to work independently and collaboratively in a fast-paced environment
+ High attention to detail and commitment to quality
+ Relevant certifications strongly preferred (e.g., CISSP, CISA, CISM, CRISC, CCSP, AWS/Azure Security, CMMC RPA, CMMC CCA, CMMC CCP, etc.)
**Compensation**
This information reflects the anticipated base salary range for this position based on current national data. Minimums and maximums may vary based on location. Individual pay is based on skills, experience and other relevant factors.
Location Based Pay Ranges:
$149,084 - $198,779 in these states: AL, AR, AZ, FL, GA, IA, ID, IN, KS, KY, LA, ME, MO, MS, MT, ND, NE, NM, OH, OK, PA, SC, SD, TN, UT, VT, WI, WV, and WY.
$156,539 - $208,718 in these states: CO, HI, MI, MN, NC, NH, NV, OR, and RI.
$163,993 - $218,657 in these states: AK, CA, CT, DC, DE, IL, MA, MD, NJ, NY, TX, VA, and WA.
Lumen offers a comprehensive package featuring a broad range of Health, Life, Voluntary Lifestyle benefits and other perks that enhance your physical, mental, emotional and financial wellbeing. We're able to answer any additional questions you may have about our bonus structure (short-term incentives, long-term incentives and/or sales compensation) as you move through the selection process.
Learn more about Lumen's:
\#GSS
+ Benefits (****************************************************
+ Bonus Structure
**What to Expect Next**
Requisition #: 338017
**Background Screening**
If you are selected for a position, there will be a background screen, which may include checks for criminal records and/or motor vehicle reports and/or drug screening, depending on the position requirements. For more information on these checks, please refer to the Post Offer section of our FAQ page (************************************* . Job-related concerns identified during the background screening may disqualify you from the new position or your current role. Background results will be evaluated on a case-by-case basis.
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
**Equal Employment Opportunities**
We are committed to providing equal employment opportunities to all persons regardless of race, color, ancestry, citizenship, national origin, religion, veteran status, disability, genetic characteristic or information, age, gender, sexual orientation, gender identity, gender expression, marital status, family status, pregnancy, or other legally protected status (collectively, "protected statuses"). We do not tolerate unlawful discrimination in any employment decisions, including recruiting, hiring, compensation, promotion, benefits, discipline, termination, job assignments or training.
**Disclaimer**
The job responsibilities described above indicate the general nature and level of work performed by employees within this classification. It is not intended to include a comprehensive inventory of all duties and responsibilities for this job. Job duties and responsibilities are subject to change based on evolving business needs and conditions.
In any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information.
Please be advised that Lumen does not require any form of payment from job applicants during the recruitment process. All legitimate job openings will be posted on our official website or communicated through official company email addresses. If you encounter any job offers that request payment in exchange for employment at Lumen, they are not for employment with us, but may relate to another company with a similar name.
**Application Deadline**
04/30/2025
Specialist, Information Security Architect
Security Architect Job 15 miles from Portland
Vacant Teck is a leading Canadian resource company focused on responsibly providing the metals essential for global development and the energy transition while caring for the people, communities and land that we love.
Teck's two regional business units, North America and Latin America, oversee Teck's assets through all phases of safe, sustainable development, operation and closure. The business units are supported by enterprise-wide functions that set strategic direction, establish standards and provide governance, as well as supporting the business through shared services, centers of excellence and business partnering.
Reporting to the Manager, Cyber Threat Prevention, the Specialist, Information Security Architect is responsible for the design, implementation, and continuous improvement of the organization's information security architecture. This outstanding role requires translating business objectives and risk management strategies into specific and measurable security outcomes for corporate environments! Further responsibilities include the secure integration of such outcomes with required industrial and external systems.
Don't miss out on this outstanding opportunity to be part of one of Canada's leading mining companies and join our team!
ResponsibilitiesBe a courageous safety leader, adhere to and sponsor safety and environmental rules and procedures Risk Management: Champion the three lines of defense model for risk management and act as a second line of defense facilitator, regularly interacting with the first line of defense Partner Collaboration: Collaborate with IT, OT, and business partners to manage and integrate security requirements into each phase of the solution delivery lifecycle Architecture Development: Build and maintain security architecture frameworks and standards. Perform threat modeling and exposure assessments to set architectural priorities and assess their adoption and efficiency
QualificationsUndergraduate education or equivalent experience in science, technology engineering or math5+ years of demonstrable experience in information security architecture and continuous professional development in the realm Demonstrable understanding of security frameworks (e.g., NIST CSF, ISO 27001) and control standards (e.g. CIS CSC, NIST 800-53, ISO 27002) General security certification (e.g. GSEC, CISSP, CISA, etc) Proven specialized training in architecture frameworks (e.g. TOGAF, SABSA, etc) You live the Teck values in your daily activities by being responsible and courageous, respectful and inclusive, and both humble and driven Knowledge towards the ability to increase maturity by building on context The desire to keep Teck safe by anticipating company needs The capacity to manage risk while assessing trade-offs Ability to standardize processes through writing and reviewing Demonstrated personal accountability, transparency and a overall growth mindset Collaborative engagement style and effective communication with diverse groups
$103,000 - $127,000 a year
The actual base salary offered is determined based on the successful candidate's relevant experience, skills, and competencies and considers internal equity.
Why Join Us?
At Teck, we offer more than just a job - we provide a pathway to personal and professional enrichment. With captivating projects set against stunning backdrops, a culture of inclusivity and collaboration, and boundless opportunities to learn and grow, joining us means embracing a fulfilling and dynamic career adventure.
Teck employees receive access to our total rewards program and comprehensive benefits package that promote physical, mental, financial, and emotional well-being. This includes but is not limited to:
• Annual Performance Bonus
• Profit Share Plan
• Health Spending Account
• Personal Spending Account
• Extended Health Care
• Dental and Vision Care
• Employer Paid Pension Plan
• Life Insurance and Disability Coverage
• Paid Sick Leave, Vacation and Holidays
• Virtual Telemedicine and additional support for overall well-being
• Employee and Family Assistance Program (EFAP)
Secure Systems Engineer - Platform Architecture
Security Architect Job 3 miles from Portland
**Beaverton, Oregon, United States** **Hardware** Role Number: **200587712** Are you a big-picture visionary who understands how each element affects all the others? At Apple, our Platform Architecture group is responsible for connecting our hardware, software, and servers into one unified system. You'll join a team of architects who are dedicated to securing the world's most advanced consumer devices. Our products are trusted for storing personal data, and our goal is to better safeguard our users. We're looking for dedicated and inspired individuals to help raise the bar on the security of Apple's products.
**Description**
In this role, you will define the architecture and oversee the operation of distributed web services that set and enforce security policy for the development, manufacture, deployment, and operation of Apple products, ultimately driving continuous security improvements for these products. Together, our work will be instrumental in maintaining the trust millions of customers place in their devices every day. As a member of Platform Architecture, you will:
- Lead cross-functional teams throughout the product development cycle to resolve system-level issues without sacrificing product security or impacting world class product design.
- Identify emerging threats, develop threat models, and define security architectures for exciting new Apple products and technologies. Derive system security requirements, and design balanced and novel mitigations in creative collaboration with iconic product and engineering teams.
- Develop detailed system-level specifications to guide product development, integration, and quality assurance teams in the creation of golden unit tests, reference data, and sample libraries to aid integration of our security technologies across team boundaries (e.g. client/server).
- Drive security requirements and architecture into web application services that play a pivotal role in the development, manufacture, deployment, and operation of Apple Products.
- Use a wide range of interpersonal and technical skills to champion adoption of our industry leading security technologies across multiple product categories.
**Minimum Qualifications**
+ BS and 10+ years of relevant industry experience.
+ Experience in designing, developing, and deploying backend web services including API design or scalable infrastructures for highly available applications.
+ Experience with common programming languages such as Python, Go or C/C++.
+ Experience in implementing and managing DevOps practices. Such as continuous integration/continuous deployment (CI/CD), infrastructure as code (IaC), or automation of development, testing, and deployment pipelines.
**Preferred Qualifications**
+ Masters in EE/CE.
+ Ability to effectively lead cross-functional initiatives and to provide architectural guidance to teams lacking resident security expertise.
+ Breadth to work cross-functionally with Infrastructure, Privacy, Safety, Service, Manufacturing, Software, and Product Development teams to resolve system-level security issues.
+ Strong written and oral communications skills across multiple levels.
+ Ability to critically analyze security properties of web service architectures, hardware, and software systems in order to build a comprehensive threat model. (e.g. familiarity with common threat modeling methodologies such as STRIDE)
+ Knowledge of basic cryptographic principles (e.g., symmetric vs asymmetric crypto, encryption vs authentication, secure boot, and PKI frameworks) and familiarity with HSM-based security applications and/or data center management and security expertise.
Apple is an equal opportunity employer that is committed to inclusion and diversity. We seek to promote equal opportunity for all applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, Veteran status, or other legally protected characteristics.Learn more about your EEO rights as an applicant (*********************************************************************************************** .
Apple is an equal opportunity employer that is committed to inclusion and diversity. We seek to promote equal opportunity for all applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, Veteran status, or other legally protected characteristics.Learn more about your EEO rights as an applicant (*********************************************************************************************** .
Apple will not discriminate or retaliate against applicants who inquire about, disclose, or discuss their compensation.
Apple participates in the E-Verify program in certain locations as required by law.Learn more about the E-Verify program (******************************************************** .
Apple is committed to working with and providing reasonable accommodation to applicants with physical and mental disabilities. Reasonable Accommodation and Drug Free Workplace policy Learn more .
Apple is a drug-free workplace. Reasonable Accommodation and Drug Free Workplace policy Learn more .
Apple will consider for employment all qualified applicants with criminal histories in a manner consistent with applicable law. If you're applying for a position in San Francisco, review the San Francisco Fair Chance Ordinance guidelines applicable in your area.
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Sr. Incident Response Analyst, Information Security
Security Architect Job 5 miles from Portland
The Group You'll Be A Part Of The Global Information Systems Group is dedicated to the success of Lam through providing best-in-class and innovative information system solutions and services. Together, we support users globally with data, information, and systems to achieve their business objectives.
The Impact You'll Make
Lam Research seeks a Sr. Incident Response Analyst to lead technical responses to cybersecurity incidents and drive proactive security monitoring to protect Information Technology (IT) and Operational Technology (OT) infrastructure. This role ensures timely threat identification, containment, and remediation, guiding incidents through the full incident response lifecycle (detection to post-incident analysis). The Analyst will collaborate globally with regional teams, mentor junior responders, and enhance Lam's security posture through process optimization and automation. The role reports to the Sr. Manager of Incident Response and requires expertise in incident management, threat detection tools, and cross-functional coordination.
What You'll Do
* Lead Incident Response: Manage complex incidents end-to-end through the lifecycle, from initial detection to post-incident review, ensuring alignment with organizational cybersecurity goals.
* Tier 1 Mentorship: Provide escalation support for Tier 1 CSOC analysts, guiding containment strategies, investigation techniques, and resolution oversight.
* Threat Intelligence: Research emerging threats, vulnerabilities, and exploit trends; apply findings to improve detection and response strategies.
* Process Improvement: Lead automation initiatives, refine standard operating procedures (SOPs), and optimize workflows to reduce manual effort and improve efficiency.
* Global Collaboration: Serve as a liaison between the CSOC and Incident Response Team, ensuring seamless cross-functional communication and information sharing.
* CSOC Support: Contribute to on-call shift rotations and maintain continuous threat monitoring in fast-paced environments.
* Post-Incident Analysis: Lead reviews to document lessons learned, recommend process enhancements, and strengthen overall security resilience.
Who We're Looking For
Required Qualifications:
* Experience:
* 5+ years in Information Security, with 2+ years in a Security Operations Center (SOC).
* Proven success leading incident response for complex cyber incidents across the full lifecycle.
* Hands-on experience with SIEM platforms (e.g., Azure Sentinel, Splunk, QRadar) and security tools (e.g., Microsoft Defender, Cloud App Security).
* Technical Expertise:
* Proficiency in networking, firewalls, OS security (Windows/Linux), cloud computing, and information security best practices.
* Strong understanding of endpoint security, DFIR, threat hunting, and intrusion detection/prevention.
* Experience with Kusto Query Language (KQL), scripting (Python, PowerShell, Bash), and automation.
* Skills:
* Excellent verbal/written communication to translate technical details for diverse audiences.
* Analytical problem-solving skills with creativity in investigative work.
Preferred Qualifications
* Experience:
* Global enterprise-scale (Fortune 500) or semiconductor manufacturing/high-tech industry exposure.
* Familiarity with OT environments, penetration testing, malware analysis, or reverse engineering.
* Technical Knowledge:
* Advanced proficiency with Microsoft security tools (Defender for Endpoint, Azure Sentinel).
* Cloud expertise (AWS, Azure, or GCP) and familiarity with ATT&CK frameworks or Cyber Kill Chain.
* Certifications:
* At least one of: Security+, CISSP, SANS GCIH or GMON, CEH, OSCP, or Azure Security Engineer.
* Tools:
* Experience with memory forensics tools (e.g., Volatility) or digital forensics software (e.g., Magnet AXIOM, FTK Imager).
Our Commitment
We believe it is important for every person to feel valued, included, and empowered to achieve their full potential. By bringing unique individuals and viewpoints together, we achieve extraordinary results.
Lam Research ("Lam" or the "Company") is an equal opportunity employer. Lam is committed to and reaffirms support of equal opportunity in employment and non-discrimination in employment policies, practices and procedures on the basis of race, religious creed, color, national origin, ancestry, physical disability, mental disability, medical condition, genetic information, marital status, sex (including pregnancy, childbirth and related medical conditions), gender, gender identity, gender expression, age, sexual orientation, or military and veteran status or any other category protected by applicable federal, state, or local laws. It is the Company's intention to comply with all applicable laws and regulations. Company policy prohibits unlawful discrimination against applicants or employees.
Lam offers a variety of work location models based on the needs of each role. Our hybrid roles combine the benefits of on-site collaboration with colleagues and the flexibility to work remotely and fall into two categories - On-site Flex and Virtual Flex. 'On-site Flex' you'll work 3+ days per week on-site at a Lam or customer/supplier location, with the opportunity to work remotely for the balance of the week. 'Virtual Flex' you'll work 1-2 days per week on-site at a Lam or customer/supplier location, and remotely the rest of the time.
IND123 #LI-FC1 #LI-Hybrid
Our Perks and Benefits
At Lam, our people make amazing things possible. That's why we invest in you throughout the phases of your life with a comprehensive set of outstanding benefits.
Discover more at
Security Engineer (Builder)
Security Architect Job 38 miles from Portland
The Meta security organization is seeking an experienced Security Engineer who loves to build their way out of security problems. We strive to go beyond just identifying security vulnerabilities and flaws. We want to 'treat security as an engineering problem,' solving problems through clever, scalable, automated solutions. We want to knock down whole swaths of vulnerabilities at once and eliminate classes of problems so that they never recur in the future. If you love security but also love spending tons of time coding, this might be the ideal role for you!
**Required Skills:**
Security Engineer (Builder) Responsibilities:
1. Work with teams of security engineers and developers to architect scalable solutions to complex problems
2. Build out proofs of concept, tools, and/or platforms to address security problems at scale
3. Lead other engineers in creating solutions
4. Eliminate classes of security problems by shifting the detection and preventions left into the developer workflow
5. Partner with cross-functional teams to ensure security maturity work is being prioritized and addressed in ways both timely and durable
6. Provide architectural, design, and threat-based guidance to software development teams to improve security maturity before code is created
**Minimum Qualifications:**
Minimum Qualifications:
7. BS or MS in Computer Science or a related field, or equivalent experience
8. 5+ years work experience securing enterprise-scale software and services
9. 5+ years work experience writing code in Python, PHP, Java, Ruby, Go, Rust, C/C++ (or similar languages)
10. Experience addressing security problems via building scaled engineering solutions
11. Experience in reviewing distributed systems design and conducting threat model assessment of software and services
**Preferred Qualifications:**
Preferred Qualifications:
12. Background in security-focused software engineering, security engineering, and/or building internal-facing security products
13. Broad knowledge of security domains
14. Contributions to the security community (eg, OSS contributions, public research, blogging, presentations, bug bounty, etc.)
**Public Compensation:**
$147,000/year to $208,000/year + bonus + equity + benefits
**Industry:** Internet
**Equal Opportunity:**
Meta is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Meta participates in the E-Verify program in certain locations, as required by law. Please note that Meta may leverage artificial intelligence and machine learning technologies in connection with applications for employment.
Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at accommodations-ext@fb.com.
Senior Information Security & Risk Engineer
Security Architect Job 38 miles from Portland
Headquartered in Dublin, Ohio, Cardinal Health, Inc. (NYSE: CAH) is a global, integrated healthcare services and products company, providing customized solutions for hospitals, health systems, pharmacies, ambulatory surgery centers, clinical laboratories and physician offices worldwide.
The company provides clinically-proven medical products and pharmaceuticals and cost-effective solutions that enhance supply chain efficiency from hospital to home. Cardinal Health connects patients, providers, payers, pharmacists and manufacturers for integrated care coordination and better patient management. Backed by nearly 100 years of experience, with approximately 50,000 employees in 46 countries, Cardinal Health ranks among the top 20 on the Fortune 500.
We currently have a full-time career opening within Information Security to support the growth of our Navista Application Suite and the Integrated Oncology Network (IoN).
**Department overview**
The Information Security department at Cardinal Health enables Cardinal Health to securely deliver healthcare products and solutions that improve the lives of people every day by ensuring security practices and controls are embedded into Cardinal Health's people, process and technology. We are a remote-first team and are excited to offer full-time remote opportunities.
**Functional Overview**
The Senior Information Security & Risk Engineer is a new capability for Cardinal Health and will be executed by the Product Security team. The primary goal of this position is to ensure delivery of best-in-class cybersecurity, risk management, and compliance for Navista, an oncology Managed Service Offering hosted by Cardinal Health.
**Job Overview**
The Information Security & Risk Engineer will be responsible for day-to-day activities in implementing the corporate information security and compliance program. The individual will be a front-line partner to technical teams and work across the organization to deliver security and compliance initiatives aligning to corporate policies, standards, procedures and audit activities. Success in the role will be measured by the effectiveness of the implementation of information security, risk management and compliance directives.
This role will work with various IT and business teams to drive both information security and compliance initiatives. The individual will assist with internal and external security compliance monitoring activities, review client audits, IT control audits, architecture reviews, threat modeling and security risk assessments. Good interpersonal and relationship building skills are essential for success.
**Job Responsibilities Include:**
+ Maintain governance program that ensures that the security policies, standards and process are in place
+ Serve as liaison to other Cardinal Health teams to ensure knowledge share and best practices
+ Partner with the engineering, architecture and operations teams to ensure delivery of infrastructure design and threat models which prove security requirements
+ Monitor security trends and drive security best practices throughout the organization via threat models and risk analysis
+ Evaluate, design, test, and recommend new or improved controls
+ Work with third party firms and consultants to conduct independent security audits, vulnerability scans, and penetration tests
+ Partner with developers to mentor and advise on secure coding and SDLC practices, define test cases and ensure appropriate testing, remediations, and mitigations
+ Investigate, drive resolution and document security incidents
+ Travel to various Integrated Oncology Network (IoN) sites may be required
**Qualifications**
+ Bachelors Degree in related field, or equivalent work experience leading cybersecurity or information security initiatives
+ Have 5+ years information security related work experience, preferably within the healthcare industry
+ Extensive experience with network and infrastructure design and security, ideally within the Azure cloud
+ Experience in vulnerability management programs, vulnerability assessments and advanced understanding of risk management
+ Familiarity with at least one common programming language, software development pipelines, and system lifecycles
+ Familiarity with standards such as HIPAA/HITECH, ISO, ITIL, NIST, PCI DSS, & SOX, CCPA, OWASP
+ Professional security certification (CISSP or CISM preferred)
+ Experience advising and mentoring diverse teams where you do not have direct authority
+ Strong written and verbal communication skills
**Anticipated salary range:** $121,600 - $182,385
**Bonus eligible:** Yes
**Benefits:** Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
+ Medical, dental and vision coverage
+ Paid time off plan
+ Health savings account (HSA)
+ 401k savings plan
+ Access to wages before pay day with my FlexPay
+ Flexible spending accounts (FSAs)
+ Short- and long-term disability coverage
+ Work-Life resources
+ Paid parental leave
+ Healthy lifestyle programs
**Application window anticipated to close:** 4/7/2025 *if interested in opportunity, please submit application as soon as possible.
The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.
_Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply._
_Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal_ _Opportunity/Affirmative_ _Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law._
_To read and review this privacy notice click_ here (***************************************************************************************************************************
Security Systems Estimator/Engineer
Security Architect Job In Portland, OR
Job Opportunity: Security Systems Construction Estimator/Engineer Reports to: Technologies Preconstruction Manager (Portland, OR Office) Salary Range: $95,000-$115,000 (depending upon experience & knowledge) About Cochran Join Cochran, a trailblazer in the Pacific Northwest's electrical and technology
construction scene. We are at the forefront of fostering innovation in the
Pacific Northwest and beyond. As one of the largest Woman-owned contractors in
the Pacific Northwest, our success hinges on our extraordinary team. We set the
bar high and seek outstanding talent from diverse backgrounds.
Summary
Cochran is currently seeking a Security Systems Construction Estimator/Engineer
to join our Portland team. They will be interfacing with internal engineering,
installation staff and customers at the jobsite. Candidate must be able to take
security systems from inception to completion, starting with customer needs
analysis, bid/specification review, pre-sales engineering/estimating, proposal
writing and submission, and subsequent post-sales engineering support of the
construction team upon project award. These systems will include the potential
need to integrate access control systems, video surveillance systems, intercom
systems and intrusion systems for seamless utilization by end users.
Essential Duties & Responsibilities
The following are the duties associated with being a Cochran Security Systems
Estimator/Engineer. Other duties may be assigned.
Ability to work autonomously as well as part of a team where applicable.
Specification and plan review of bid documents, including the ability to
read blue prints, schematics, interpret project schedules and understand project
requirements set forth in bid documents.
Conduct meetings with end users to develop a security needs assessment for
estimating purposes.
Conduct periodic site visits to confirm estimating approach is consistent
with construction means and methods.
Accurate quantity take-off and entry into estimating software for the
generation of detailed estimates from conceptual design information, including
the ability to generate large multi-scope estimates.
Participate in estimate/bid reviews with the technologies team
Creation of proposals and scope narratives, including preparation and review
of vendor/subcontractor bid packages.
Able to collaborate with the CAD/BIM/construction departments to produce
project installation documentation.
Understands system technical requirements as well as general networking
protocols.
Understanding of TCP/IP network routing, switching, and wireless
technologies.
General knowledge of security system software for commissioning purposes
(actual commissioning to be completed by field crew).
Ability to design/develop an integrated security systems.
Willing and able to become certified in applicable manufacturers such as
Lenel-S2, Motorola/Avigilon, Genetec, Milestone, Axis-2N, Milestone, Hanwha,
Bosch (this is not an all-encompassing manufacturer list).
Ability to quickly learn and grasp new technologies as well as stay up to
date with latest technologies.
Competency
To perform the job of Estimator successfully, an individual should demonstrate
the following competencies.
Problem Solving - Identifies and resolves problem in a timely manner;
Technical Skills - Pursues ongoing training and development.
Communication - Speaks clearly and persuasively in positive or negative
situations. Writes clearly and informatively. Fluently and clearly speaks
and writes in English.
Quality Management - Demonstrates accuracy and thoroughness. Looks for way
to improve and promote quality.
Team Work - Contributes to building a positive team spirit.
Customer Service - Responds promptly and politely to customer needs.
Responds to requests for bids and meets commitments and deadlines.
Organization - Displays a high level of organizational skills, including
the ability to multi-task effectively due to nature of the role and the need to
be able to shift focus between tasks associated with multiple projects and/or
bid opportunities that this role could be involved with at any given moment.
Dependability - Follows instructions, responds to management direction and
meets commitments. Is consistently at work and on time.
Qualifications
To perform this job successfully, an individual must be able to perform each
essential duty satisfactorily. The requirements listed below are
representative of the knowledge, skill, and/or ability required. Reasonable
accommodations may be made to enable individuals with disabilities to perform
the essential functions.
Education/Experience
Minimum of 3 years of experience in the Security System installation industry
with various systems, including access control, intrusion detection, CCTV/video
surveillance and intercoms. Although not required, additional preference is
given to those with another three or more years of actual hands-on, field
installation experience. Strong understanding of integrated security systems is
preferred.
Language Ability
Ability to read, analyze and interpret general business periodicals,
professional journals, technical procedures or governmental regulations.
Ability to write reports and business correspondence.
Math Ability
Ability to add, subtract, multiply and divide in all units of measure, using
whole numbers, common fractions and decimals.
Reasoning Ability
Ability to apply common sense and understanding to carry out instructions
furnished in written, oral, or diagram form.
Computer Skills
To perform this job successfully, an individual should have intermediate to
expert knowledge of Microsoft Word processing software, spreadsheet software and
estimating software. Working knowledge of Bluebeam, Visio drawing and CAD and
Accubid Anywhere a plus.
Code Knowledge
Working knowledge of the National Electrical Code (NEC) and applicable local
building codes preferred.
Certificates and Licenses
Preference will be given to those candidates already certified on the
manufacturer platforms listed above.
Supervisory Responsibilities
This job has no supervisory responsibilities.
Work Environment
The work environment characteristics described here are representative of those
an employee encounters while performing the essential functions of this job.
Reasonable accommodations may be made to enable individuals with disabilities to
perform the essential functions.
The noise level in the work environment is usually moderate but may vary.
Physical Demands
The physical demands described here are representative of those that must be met
by an employee to successfully perform the essential functions of this job.
Reasonable accommodations may be made to enable individuals with disabilities to
perform the essential functions.
The employee must frequently lift and/or move up to 10 pounds and occasionally
lift and/or move up to 25 pounds. Specific vision abilities required by this
job include Close vision, Peripheral vision, Depth perception and Ability to
adjust focus. While performing the duties of this job, the employee is
frequently required to walk, stand, sit; use hands to finger, handle, or feel;
reach with hands and arms; talk or hear. The employee is occasionally required
to stoop, kneel, crouch, or crawl.
Infrastructure Security Engineer
Security Architect Job In Portland, OR
Western Partitions, Inc. (WPI) is one of the largest and most reputable interior and exterior contracting firms in the US. WPI provides superior contracting services for drywall, prefabrication, metal studs, acoustical systems, wall panels, fireproofing, firestopping, stucco, claddings, painting, windows, doors/frames/hardware, and more.
Since WPI's inception in 1972, we have provided award-winning construction without sacrificing integrity, safety, or efficiency. We are proud that a significant percentage of our business comes from repeat customers. Our service-oriented, fast-track approach, coupled with an attention to detail has resulted in a superior reputation within our industry. We work hard every day to earn our customers' trust and confidence.
Throughout our history, our dedication to our employees, quality of work, and customers has set us apart. The strongest characteristic of our organization is the prominent level of pride we take in every job we complete. Our employees are driven to do the job right the first time without compromise. Lastly, our customers choose WPI based on the emphasis we place on communication, trust, and respect.
WPI is a forward-thinking enterprise committed to protecting our customers and business by successfully applying rigorous compliance standards. As an Infrastructure Security Engineer, you'll lead security initiatives impacting our organization's risk posture and operational resilience. You can shape our security strategy alongside a dedicated, dynamic team that values continuous innovation.
Key Responsibilities
Compliance & Risk Management
Spearhead and maintain compliance standards adoption, including NIST and CMMC
Design and implement security controls satisfying multiple compliance frameworks
Facilitate external audits and maintain evidence of security controls
Maintain knowledge of security sector trends, technologies, and regulations
Coordinate vulnerability assessments and penetration testing
Define operating standards, monitor and refine benchmarks
Develop security policies and operational documentation
Operational Security
Collaborate with senior staff and subject matter experts to ensure that best security practices are in place
Contribute to the design, management, and operation of a Fortinet secure network fabric with zero-trust capabilities
Provide staff training and guidance regarding security protocols and practices
Architect zero-trust network solutions and least-privilege isolation strategies in private and public cloud environments
Design, implement, and refine security controls throughout the enterprise
Evaluate and lead the integration of new security tools and technologies
Develop automated security controls and monitoring solutions
Threat Detection & Response
Implement, optimize, and manage SIEM, XDR, and MDR services to neutralize threats
Build and maintain security automation workflows for rapid incident response and remediation
Conduct threat-hunting exercises and improve detection engineering practices
Lead security incident investigations and drive continuous improvement of response processes
Required Experience:
Bachelor's degree in computer science, information technology, or related field
3+ years of hands-on experience securing enterprise infrastructure
Strong background in SDN/NFV and underlay network engineering
Experience with private and public cloud security architecture
Experience with security tools and frameworks: SIEM, EDR/XDR, SOAR
Experience with NIST, CMMC, ISO, and compliance programs
Proficiency in automation scripting (e.g., PowerShell, Python)
Excellent problem-solving skills and attention to detail
Strong communication and teamwork preference
Preferred Qualifications:
Active CISSP, CISM, CEH, or equivalent security certification
Experience rooted in SecOps and networking
Proficiency with PKI infrastructure
This role is not eligible for visa sponsorship.
Benefits
At WPI our employees are our greatest asset. We put our people first and are proud to provide a comprehensive benefits package designed to meet the needs of our employees at every stage of life.
In our commitment to fostering an environment where everyone can thrive personally and professionally, we offer:
Competitive pay
Incentive bonus plan
401(k) retirement savings plan with match
Medical, prescription drug, dental and vision insurance plans with flexible spending account option
Life insurance, accidental death, and disability benefits
Flexible paid time off policy and paid holidays
Professional development opportunities and certifications
WPI provides equal employment and affirmative action opportunities to applicants and employees without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability.
WPI is a background screening, drug-free workplace.
This job description is intended to outline the general nature and level of work being performed by employees. It is not designed to cover or contain a comprehensive list of responsibilities, duties, or skills required of the employee of this job. Furthermore, this description is subject to change at the discretion of the company, with or without notice.
Revised 2-20-25
Information System Security Officer
Security Architect Job 20 miles from Portland
At PLEXSYS, our teams design, build and deliver Live, Virtual, and Constructive (LVC) innovation and training solutions to customers around the world. With over 200 employees in seventeen states and four foreign countries, we contribute our success to enabling better training…everyday…across the globe.
As an employee of PLEXSYS, you'll find a culture that empowers you to achieve your professional objectives, give your personal best, and work with other highly passionate individuals. Our core values of integrity, excellence, teamwork and agility drive our daily decisions, identify our focus areas, and inspire our organizational culture.
GENERAL DESCRIPTION
The Information System Security Officer (ISSO) is responsible for ensuring the appropriate operational security
posture for information systems and as such, works in close collaboration with the ISSM, CPSO, and FSO. The
ISSO must have detailed knowledge and expertise required to manage the security aspects of an information
system and is assigned the day-to-day responsibility for assigned systems. Responsibilities include
implementation of the requirements of Risk Management Framework, including the Joint Special Access
Program (SAP) Implementation Guide (JSIG), NIST 800-53, or other security requirements as assigned.
This position will report to the Corporate Information Assurance Manager and work in close collaboration with
the AFSO and FSO. The ISSO is responsible for developing and updating the security authorization package, managing and controlling changes to the system, and assessing the security impact of those changes.
Ensure systems are operated, maintained, and disposed of following security policies and procedures as outlined
in the security authorization package.
Report all security-related incidents to the ISSM.
Conduct periodic reviews of information systems to ensure compliance with the security authorization package.
Monitor system recovery processes to ensure security features and procedures are properly restored and
functioning correctly.
Ensure audit records are collected, reviewed, and documented.
Duties also include physical and environmental protection, personnel security, and incident handling.
DUTIES & RESPONSIBILITIES
Lead the information system security program for their assigned location to include implementation and
validation of automated informational security, ensuring security requirements as contracted are
satisfied
Maintain and establish the accreditation of classified information systems
Establish and implement security procedures and practices in support of Corporate goals and current
DoD Regulations
Ensure all security procedures are being followed such as patching, AV updates, continuous monitoring,
trainings, and self-inspections
Develop, implement and maintain security emergency action plans
Provide security education and training to local employees
Maintain administrative security records and documents for local employees
Conduct self-inspections to ensure current security measures and policies are effective
Conduct random security inspections to ensure regulations and procedures are being adhered to by
local employees
Conduct system audits in accordance with security accreditation package requirement
Lead the information system security program for their assigned location to include implementation and validation of automated informational security, ensuring security requirements as contracted are satisfied
Maintain and establish the accreditation of classified information systems
Establish and implement security procedures and practices in support of Corporate goals and current DoD Regulations
Ensure all security procedures are being followed such as patching, AV updates, continuous monitoring, trainings, and self-inspections
Develop, implement and maintain security emergency action plans
Provide security education and training to local employees
Maintain administrative security records and documents for local employees
Conduct self-inspections to ensure current security measures and policies are effective
Conduct random security inspections to ensure regulations and procedures are being adhered to by local employees
Conduct system audits in accordance with security accreditation package requirements
Conduct vulnerability scans and analysis
Conduct maintenance on the networks, systems, and hardware
Perform software upgrades on networks, systems, and hardware
Perform security assignments in accordance with the Automated Information System requirements and local regulations
Understand and follow NISPOM/ODAA/RMF/JAFAN/ICD/NIST/JSIG classified system accreditation and certification requirements
Other duties as assigned
REQUIREMENTS
Bachelor's degree in related field or 4 years' experience in related field
DoD 8570 compliant, IAT Level II
Experience with Windows based administration of Information Systems
Ability to work within compliance standards; previous experience with RMF, HIPAA , PCI DSS, or
equivalent compliance standard preferred
Strong experience in networking, active directory, centralized logging solutions, vulnerability scanning
and anti-virus solutions
Experience with security audits for information systems
Strong communication and problem-solving skills
Ability to work in both a team environment as well as independently
Must be organized and detail oriented
Ability to obtain and maintain Top Secret clearance with the ability to obtain approval for SAP/SCI access
DESIRABLE
Have previous experience with DoD Security Regulations and Policies
PERKS
As a PLEXSYS employee, you can expect certain advantages; such as advancement based on performance, competitive wages, valuable benefits and a great working environment. Our team is committed to ensuring an environment that empowers individuals to realize their full potential by providing opportunities and necessary support to achieve personal and professional goals.
Medical/Vision/Prescription/Dental Benefits
Life, AD&D and Long Term Disability Coverage
Paid Holidays, Military Leave, and Paid Time Off
401k Plan with eligibility from first day of employment
Education reimbursement for job-related courses for full-time employees
PriceClub/COSTCO/Sam's Club annual membership
Application Security Engineer
Security Architect Job 38 miles from Portland
Evaluates application security in all phases of the software development life cycle. Works closely with team members to define application security best practices, performs software architecture and design reviews, and supports the identification, interpretation, and remediation of vulnerabilities across a variety of applications, programming languages, and platforms.
+ Supports the development of security procedures and methods to ensure the safety of information systems and to protect the system from intentional (unauthorized) or accidental (inadvertent) access or destruction.
+ Works with Web development, network administration, and corporate security teams, to actively identify, and analyze risks and develop plans that drive security improvements for the project/program.
+ Serves as a liaison between development teams and stakeholders to understand and formulate security requirements for project/program.
+ Defines, maintains, and enforces application security best practices.
+ Explains and demonstrates vulnerabilities to application owners, and provide recommendations for mitigation.
+ Conducts and coordinates vulnerability assessments of software application under development.
+ Identifies additional application security related tools, conducts tool analysis, and provided recommendations.
+ Performs and conducts penetration tests and manual/automated code reviews.
+ Trains developers and other relevant team members on Secure Code Development as well as other security protocols as needed.
**Minimum Qualifications**
+ Bachelor's Degree in Computer Science, Engineering, or other Engineering or Technical discipline or equivalent relevant experience.
+ 5-10 years of experience as an Application Security Developer, Application Security Analyst, or equivalent.
**Other Job Specific Skills**
+ Expertise with application server technologies such as Spring Framework, Spring Security, Web Services, REST, and Hibernate.
+ In-depth knowledge of and experience with security technologies, single-sign-on and identity management technologies.
+ Expertise with web system security concepts, including authentication, authorization (RBAC), encryption/hashing, SAML, and LDAP.
+ Knowledge of web application vulnerabilities such as cross-site scripting (XSS), sessions hijacking, SQL injection, CSRF (Cross-Site Request Forgery), OWASP Top 10, and other attack vectors.
+ Hands-on experience with encryption, hashing, secure random number generation, key derivation, digital signatures, etc.
+ Knowledge of network based, system level and application layer attacks and mitigation methods, and TCP/IP, HTTP/S, and related protocols.
+ Experience with static code analysis tools including HP Fortify.
+ Familiarity with JavaScript, NodeJS, or other scripting languages and BurpSuite or other intercepting proxy tools.
+ Experience working with GIT source code management.
+ Must have solid working experience and knowledge of Unix/Linux operating system.
+ Experience with one or more of the following technologies: Vagrant, Chef, Rake, Gradle, Jenkins, and Cache DB is preferred.
+ Understanding of Agile/Scrum methodologies is preferred.
+ Experience with Axiomatics is a plus.
**Compensation Ranges**
Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.
**EEO Requirements**
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.
All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.
Physical Requirements
The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.
**Disclaimer**
The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.
114200 to 142200
EEO Requirements
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, gender identity, veteran status, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.
All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, veteran status, disability, gender identity, or age. All decisions on employment are made to abide by the principle of equal employment.
Security Engineer 4 - FedRAMP Compliance Architect
Security Architect Job 38 miles from Portland
PagerDuty, Inc. (NYSE:PD) is a global leader in digital operations management. Half of the Fortune 500 and nearly 70% of the Fortune 100 trust PagerDuty as essential infrastructure. Join us. (******************************* At PagerDuty, you'll tackle complex problems, collaborate with kind and ambitious people, and help build a more equitable world-all in a flexible, award-winning workplace.
PagerDuty is seeking a **Security Engineer 4 - FedRAMP Compliance Architect** to join our diverse, customer-focused team! This **Security Engineer 4 - FedRAMP Compliance Architect** will design, implement, and maintain secure architectures that meet FedRAMP requirements in a multi-tenant cloud environment. This role combines deep technical expertise with FedRAMP compliance knowledge to create scalable, secure solutions. You'll be the glue between security compliance requirements and technical implementation, ensuring our cloud infrastructure meets federal security standards while enabling business objectives.
**Key Responsibilities:**
+ Design, implement, and maintain system architectures to align with FedRAMP requirements.
+ Serve as the subject matter expert (SME) on FedRAMP, advising internal teams on security best practices, control implementations, and risk mitigation strategies.
+ Collaborate with engineering, operations, product, and corporate IT teams to develop secure cloud-based architectures that meet federal compliance mandates.
+ Implement governance strategy on technical security controls, including access management, configuration, encryption, logging, monitoring, and vulnerability management.
+ Support annual assessments, security control reviews, and audits, coordinating with third-party assessors (3PAO) and government sponsors.
+ Technical support for external stakeholders on customer responsibilities.
+ Key contributor to the development and maintenance of the System Security Plan (SSP), Policies and Procedures, Configuration Management Plan, Secure System Development Life Cycle, and other FedRAMP documentation
+ Partner with the GRC (Governance, Risk, and Compliance) team to efficiently track and resolve security findings.
**Basic Qualifications:**
+ 5+ years of experience in cloud security architecture, compliance, or cybersecurity engineering, with at least 3 years of experience supporting FedRAMP Moderate or High authorization.
+ Deep expertise in FedRAMP, NIST 800-53, FISMA, and cloud security best practices.
+ Strong ability to assess security risks and recommend technical and procedural mitigations.
+ Experience working with AWS GovCloud, Azure Government, or other federal cloud environments.
+ Experience with audit preparation, risk assessments, and working with third-party assessors (3PAOs).
+ Exceptional written and verbal communication skills for creating and managing FedRAMP documentation.
**Preferred Qualifications:**
+ Experience supporting DoD IL 4 or 5 environments.
+ Experience with data governance frameworks, secure data storage, and data lifecycle management in multi-tenant cloud environments.
+ Understanding of NIST AI Risk Management Framework (AI RMF) and its implications for secure AI adoption in government environments.
+ Familiar with SaaS security tools (such as Sumo Logic, Datadog, Crowdstrike, Wiz, Lucidchart, Snyk, and Qualys).
+ Familiarity with Cloud Native and SaaS constructs, including architectures, DevOps, CI/CD, and SecOps disciplines.
+ Relevant certifications, such as:
+ Certified Information Systems Security Professional (CISSP)
+ AWS Security Specialty, or equivalent
+ CompTIA Advanced Security Practitioner (CASP+)
+ Certificate of Cloud Security Knowledge (CCSK)]]
The successful applicant will be performing work in FedRAMP environments, and therefore, must be a U.S. Person (i.e. U.S. citizen, U.S. national, lawful permanent resident, asylee, or refugee). **This position may also perform work that the U.S. government has specified can only be performed by a U.S. citizen on U.S. soil.**
The base salary range for this position is 172,000 - 289,000 USD. This role may also be eligible for bonus, commission, equity, and/or benefits.
Our base salary ranges are determined by role, level, and location. The range, which is subject to change based on primary work location, reflects the minimum and maximum base salary we expect to pay newly hired employees for the position. Within the range, we determine pay for an individual based on a number of factors including market location, job-related knowledge, skills/competencies and experience.
Your recruiter can share more about the specific offerings for this role, as well as the salary range for your primary work location during the hiring process.
**Hesitant to apply?**
We encourage you to submit your resume even if you don't meet every requirement. We value potential and consider each candidate's full professional story. Whether you're exploring a career change or taking your next step, we look forward to reviewing your application. If this just isn't the right role or time - sign up for job alerts (**************************************** !
**Where we work**
PagerDuty currently has offices (**************************************** in Atlanta, Lisbon, London, San Francisco, Santiago, Sydney, Tokyo, and Toronto. We offer a hybrid, flexible environment. We also provide ample opportunities for connection, like team offsites and volunteering events.
**How we work**
Our values (************************************** guide how we support customers, collaborate with colleagues, develop products, and foster a culture of belonging. They define not just our actions, but what it means to be Dutonian.
**What we offer**
As a global organization, our total rewards approach is competitive with industry standards and aligned with local laws and regulations. Learn more, including country-specific offerings, on our benefits site (********************************************** .
**Your package may include:**
- Competitive salary
- Comprehensive benefits package from day one
- Flexible work arrangements
- Company equity*
- ESPP (Employee Stock Purchase Program)*
- Retirement or pension plan*
- Generous paid vacation time
- Paid holidays and sick leave
- Dutonian Wellness Days & HibernationDuty - companywide paid days off in addition to PTO
- Paid parental leave: 22 weeks for pregnant parent, 12 weeks for non-pregnant parent (some countries have longer leave standards and we comply with local laws)*
- Paid volunteer time off: 20 hours per year
- Company-wide hack weeks
- Mental wellness programs
*Eligibility may vary by role, region, and tenure
**About PagerDuty**
PagerDuty, Inc. (NYSE:PD) is a global leader in digital operations management, enabling customers to achieve operational efficiency at scale with the PagerDuty Operations Cloud. The PagerDuty Operations Cloud combines AIOps, Automation, Customer Service Operations and Incident Management with a powerful generative AI assistant to create a flexible, resilient and scalable platform to increase innovation velocity, grow revenue, reduce cost, and mitigate the risk of operational failure. Half of the Fortune 500 and nearly 70% of the Fortune 100 rely on PagerDuty as essential infrastructure for the modern enterprise.
PagerDuty is Great Place to Work-certified, a Fortune Best Workplace for Millennials, a Fortune Best Medium Workplace, a Fortune Best Workplace in Technology, and a top rated product on TrustRadius and G2.
Go behind-the-scenes on our careers site (*********************************** and @pagerduty on Instagram.
**Additional Information**
PagerDuty is committed to creating a diverse environment and is an equal opportunity employer. PagerDuty does not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, parental status, veteran status, or disability status.
PagerDuty is committed to providing reasonable accommodations for qualified individuals with disabilities in our job application process. Should you require accommodation, please email accommodation@pagerduty.com and we will work with you to meet your accessibility needs.
PagerDuty uses the E-Verify employment verification program.
Security Engineer
Security Architect Job 15 miles from Portland
A client in the Vancouver, Wa area is looking for a Sr. Security Engineer to join their team! This is a permanent direct hire opening. In this role you will be working on a team alongside a small team composed of Security Engineers and Analysts to support IT for this organization. This company has a growing security group and has security frameworks in place. As a Sr. Security Engineer you will have exposure to a few different cybersecurity domains which include, but are not limited to: Network Security (end point security, managed network detection), Application Security, and Cloud security. Other areas you would be exposed to in this role include: Infrastructure as code (vulnerability management), Cloud computing in Azure, data security, and email security. This position is a team oriented role that is more hands on keyboard verse compliance. This is a great opportunity for someone to take their skills to the next level, learn more, and have a team to support them. If this sounds like a position of interest, please apply today!
Requirements:
4+ years of experience as a Security Engineer, System Engineer with Cloud Experience, DevSecOps Engineer, Security Analyst or similar
Experience with Application Security and/or Cloud Security: Cloud Compliance, Cloud computing, Azure Security Experience preferred
Broad diverse security experience; exposure to multiple different security domains (Application Development, Network, DevOps, cloud)
Plusses:
Experience with IAC (Infrastructure as code)
Experience with API connections
Benefits Overview + Compensation:
The Company offers the following benefits for this position, subject to applicable eligibility requirements: medical insurance, health savings account, flexible savings account, dental insurance, vision insurance, 401(k) retirement plan, accidental death and dismemberment, life insurance, voluntary life insurance, voluntary disability insurance, voluntary accident, voluntary critical care, voluntary hospital indemnity, legal, identity and fraud protection, commuter benefits, pet insurance, employee stock purchase program, and an employee assistance program.
$110,000-$130,000 per year annual salary. Bonus eligible.
Secure Systems Engineer - Platform Architecture
Security Architect Job 3 miles from Portland
Are you a big-picture visionary who understands how each element affects all the others? At Apple, our Platform Architecture group is responsible for connecting our hardware, software, and servers into one unified system. You'll join a team of architects who are dedicated to securing the world's most advanced consumer devices. Our products are trusted for storing personal data, and our goal is to better safeguard our users. We're looking for dedicated and inspired individuals to help raise the bar on the security of Apple's products.In this role, you will define the architecture and oversee the operation of distributed web services that set and enforce security policy for the development, manufacture, deployment, and operation of Apple products, ultimately driving continuous security improvements for these products. Together, our work will be instrumental in maintaining the trust millions of customers place in their devices every day. As a member of Platform Architecture, you will:
* Lead cross-functional teams throughout the product development cycle to resolve system-level issues without sacrificing product security or impacting world class product design.
* Identify emerging threats, develop threat models, and define security architectures for exciting new Apple products and technologies. Derive system security requirements, and design balanced and novel mitigations in creative collaboration with iconic product and engineering teams.
* Develop detailed system-level specifications to guide product development, integration, and quality assurance teams in the creation of golden unit tests, reference data, and sample libraries to aid integration of our security technologies across team boundaries (e.g. client/server).
* Drive security requirements and architecture into web application services that play a pivotal role in the development, manufacture, deployment, and operation of Apple Products.
* Use a wide range of interpersonal and technical skills to champion adoption of our industry leading security technologies across multiple product categories.Masters in EE/CE.
Ability to effectively lead cross-functional initiatives and to provide architectural guidance to teams lacking resident security expertise.
Breadth to work cross-functionally with Infrastructure, Privacy, Safety, Service, Manufacturing, Software, and Product Development teams to resolve system-level security issues.
Strong written and oral communications skills across multiple levels.
Ability to critically analyze security properties of web service architectures, hardware, and software systems in order to build a comprehensive threat model. (e.g. familiarity with common threat modeling methodologies such as STRIDE)
Knowledge of basic cryptographic principles (e.g., symmetric vs asymmetric crypto, encryption vs authentication, secure boot, and PKI frameworks) and familiarity with HSM-based security applications and/or data center management and security expertise.Array
Insider Threat Security Engineer 5
Security Architect Job 5 miles from Portland
The Group You'll Be A Part Of The Global Resilience, Security and Transformation/Infosec Group is dedicated to the success of Lam through providing best-in-class and innovative information system solutions and services. Together, we support users globally with data, information, and systems to achieve their business objectives.
Who We're Looking For
As an Insider Threat Security Engineer at Lam Research, you will play a critical role in helping manage insider threat and helping to build out our insider threat capabilities. Your responsibilities will include driving tooling requirements to determine anomalous user activities, indicators, and providing support to active incidents alongside our most valuable stakeholders. You may be asked to support cross-functional opportunities across Lam Research to help identify security trends and metrics, develop innovative use cases designed to detect anomalous events, and support education and awareness campaigns for insider risk and threat. You will use sophisticated technology and robust partnerships to enhance our insider risk posture against nation-state actors, negligent and malicious employee activity, and support high-risk populations from potential compromise. You will play a vital role in taking the Lam Research Insider Threat program to the next level by levering both, your critical thinking and technical expertise.
What You'll Do
* Implement and Maintain Security Solutions: Ensure the effective operation, implementation, and troubleshooting of Insider Risk Management (IRM) technologies, policies, and rules across Lam.
* Collaborate with InfoSec & Other Partners: Work closely with Lam's Cybersecurity Engineering team and other cross-functional teams, such as IT, HR, and Legal- to define and refine policies that protect sensitive data and to ensure IRM implementation is in line with Lam's infrastructure and environment.
* Drive Continuous Improvement: fine tune IRM rules and work with Cybersecurity Engineering to fine tune DLP rules to minimize false positives, while regularly assessing and maturing the Insider Threat Engineering function to identify areas of improvement.
* Be the Insider Threat Technical Expert: Serve as an escalation point for colleagues and collaborators, providing guidance and support as needed.
* Reporting & Metrics: Contribute to regular management reporting, offering insights on the performance and effectiveness of the IRM ecosystem.
* *Must be able to maintain confidentiality and always use sound discretion and judgment*
Minimum Qualifications
* Bachelor's degree in Computer Science, Cybersecurity, Information Security, Information Technology, Counterintelligence, or related discipline.
* 5+ years of experience as a security engineer in an Insider Threat role.
* Proven experience in implementing, troubleshooting, and administering Insider Threat and DLP technologies in a global enterprise.
* Experience with cloud security and cloud-based applications.
* Excellent problem-solving skills and the ability to work independently.
* Outstanding communication skills, with the ability to collaborate effectively across different teams and stakeholders.
Preferred Qualifications
* Certifications in cybersecurity, such as CISSP, CISM, or CEH.
* Formal education and training in insider threat and counterintelligence.
* Knowledge and experience with Microsoft E5 security products, specifically Purview DLP, IRM, and Defender.
* Experience with data analytics and visualization tools.
* Knowledge of behavioral analysis and psychology.
* Experience within a global semiconductor company or equivalent industry experience preferred.
* Ability to breakdown and understand complex problems and the ability to develop a plan and innovative ways to address them.
Our Commitment
We believe it is important for every person to feel valued, included, and empowered to achieve their full potential. By bringing unique individuals and viewpoints together, we achieve extraordinary results.
Lam Research ("Lam" or the "Company") is an equal opportunity employer. Lam is committed to and reaffirms support of equal opportunity in employment and non-discrimination in employment policies, practices and procedures on the basis of race, religious creed, color, national origin, ancestry, physical disability, mental disability, medical condition, genetic information, marital status, sex (including pregnancy, childbirth and related medical conditions), gender, gender identity, gender expression, age, sexual orientation, or military and veteran status or any other category protected by applicable federal, state, or local laws. It is the Company's intention to comply with all applicable laws and regulations. Company policy prohibits unlawful discrimination against applicants or employees.
Lam offers a variety of work location models based on the needs of each role. Our hybrid roles combine the benefits of on-site collaboration with colleagues and the flexibility to work remotely and fall into two categories - On-site Flex and Virtual Flex. 'On-site Flex' you'll work 3+ days per week on-site at a Lam or customer/supplier location, with the opportunity to work remotely for the balance of the week. 'Virtual Flex' you'll work 1-2 days per week on-site at a Lam or customer/supplier location, and remotely the rest of the time.
IND123 #LI-FC1 #LI-Hybrid
Our Perks and Benefits
At Lam, our people make amazing things possible. That's why we invest in you throughout the phases of your life with a comprehensive set of outstanding benefits.
Discover more at
Security Engineer - Surface Coverage, Detection Engineering
Security Architect Job 38 miles from Portland
Meta Security is looking for a Security Engineer with experience in threat modeling, TTP identification, and detection engineering. You'll work alongside Software Engineers and Offensive Security Engineers to identify critical assets, assess the top risks, and evaluate potential attacks against Meta systems. You will be working across engineering teams supporting Production and Corporate systems to develop detection and response automation leveraging both industry-standard and custom detection and response platforms. You'll generate detection ideas utilizing some of the world's largest data sets and build on top of hyper-scale data pipelines.
**Required Skills:**
Security Engineer - Surface Coverage, Detection Engineering Responsibilities:
1. Lead cross-functional projects to improve our capabilities to effectively detect and respond to security incidents
2. Review security architecture of large-scale custom and commercial systems and independently propose logging, detection and prevention controls
3. Perform TTP-based Threat Modeling for a wide variety of assets including endpoints, mobile, servers, internal services, public & private cloud environments and networking equipment
4. Perform analysis against logs from a variety of sources (e.g., individual host logs, network traffic logs) to identify potential threats and detection ideas
5. Build response workflows and actions that auto-resolve false positives and provide context scaling our investigators
6. Support security incident response in a cross-functional environment and drive incident resolution
7. Design and implement attack testing automation to validate detection coverage
8. Build logging pipelines using our custom datasets and infrastructure
**Minimum Qualifications:**
Minimum Qualifications:
9. 6+ years of experience in Detection & Response Engineering or similar Security Engineering role
10. Experience building complex automations and integrations using SOAR platforms
11. Bachelor's degree in computer science or related field or equivalent experience in Security
12. Experience designing systems used for responding to both external and insider threats
13. Experience analyzing network and host-based security events
14. Knowledge of networking technologies, specifically TCP/IP and the related protocols
15. Knowledge of operating systems, file systems, and memory structures on Windows, MacOS and Linux
16. Coding/scripting experience in one or more general purpose languages
17. Experience with attacker tactics, techniques, and procedures
**Preferred Qualifications:**
Preferred Qualifications:
18. Background in security-focused software engineering, designing large scale systems and data pipelines, or offensive security
19. Experience in threat hunting including leveraging intelligence data to proactively identify and iteratively investigates suspicious behavior across networks and systems
20. Broad knowledge across the Security domain, as well as focus in one (or more) areas such as Logs and events processing, Incident Management, Digital Forensics, Offensive Security Testing, Detection and/or Response tooling development
**Public Compensation:**
$147,000/year to $208,000/year + bonus + equity + benefits
**Industry:** Internet
**Equal Opportunity:**
Meta is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Meta participates in the E-Verify program in certain locations, as required by law. Please note that Meta may leverage artificial intelligence and machine learning technologies in connection with applications for employment.
Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at accommodations-ext@fb.com.
Senior Security Engineer, Cyber Risk Management
Security Architect Job 38 miles from Portland
Headquartered in Dublin, Ohio, Cardinal Health, Inc. (NYSE: CAH) is a global, integrated healthcare services and products company, providing customized solutions for hospitals, health systems, pharmacies, ambulatory surgery centers, clinical laboratories and physician offices worldwide.
The company provides clinically-proven medical products and pharmaceuticals and cost-effective solutions that enhance supply chain efficiency from hospital to home. Cardinal Health connects patients, providers, payers, pharmacists and manufacturers for integrated care coordination and better patient management. Backed by nearly 100 years of experience, with approximately 50,000 employees in 46 countries, Cardinal Health ranks among the top 15 on the Fortune 500.
We currently have a full-time job opening for a Senior Security Engineer of Cyber Risk Management
_Department overview:_
Information Security and Risk Management (ISRM) at Cardinal Health enables Cardinal Health to securely deliver healthcare products and solutions that improve the lives of people every day by ensuring security and controls are embedded into Cardinal Health's people, process and technology. The Cyber Risk and Customer Security Assurance team fulfils our mission to strengthen our shield against cyber threats by providing a framework of processes and methodologies to manage Cardinal Health's cybersecurity risks through issue and exception management, cyber risk management, and customer third party risk assessment engagement.
Job Summary
Sr. Engineer, Cyber Risk Management, applies knowledge of Information Security, Risk Management, and Information Technology to lead the maturity of our Cyber Risk program. The primary responsibility of this role is to collaborate across the enterprise to measure the impact and likelihood of a variety of Cyber Risks.
This role is a senior position within the team and will work with all members of the Information Security team as well as Senior Leadership, Enterprise Risk Management, Business leaders, and IT teams.
Responsibilities:
+ Provide senior leaders and executives with information summarized at the correct level to make efficient, cost-effective, risk management decisions about the technology and information processing supporting their business functions
+ Work with all members of the Information Security team to drive information risk governance processes throughout the Cardinal Health enterprise
+ Implement the information risk management framework and related governance processes to cover not just the IT function, but all technology and information processing regardless of where the processing is in the enterprise (e.g., "shadow IT", manufacturing systems, operational technology, etc.)
+ Leverage and integrate with existing IT risk management and risk escalation / approval processes
+ Create an information risk register that catalogs key IT risks through an ongoing "top-down" risk assessment process
+ Define processes for summarizing "bottom-up" risk identified throughout various risk and compliance activities to add to risk register
+ Define and measure risk metrics that can be used to evaluate risk trends
_Qualifications:_
+ Excellent written and verbal communication skills
+ Experience in Information Technology, Information Security, and Risk Management
+ Experience implementing and maintaining processes at large enterprises
+ Experience with IT security principles, practices, technologies, programs and procedures, accompanied by an understanding of risk management methodologies and cybersecurity assessment frameworks
+ High-quality analytical skills, relationship management competencies
+ Relevant Information Security Certifications
**Anticipated salary range:** $121,600 - $182,385
**Bonus eligible:** Yes
**Benefits:** Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
+ Medical, dental and vision coverage
+ Paid time off plan
+ Health savings account (HSA)
+ 401k savings plan
+ Access to wages before pay day with my FlexPay
+ Flexible spending accounts (FSAs)
+ Short- and long-term disability coverage
+ Work-Life resources
+ Paid parental leave
+ Healthy lifestyle programs
**Application window anticipated to close:** 4/27/2025 *if interested in opportunity, please submit application as soon as possible.
The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.
_Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply._
_Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal_ _Opportunity/Affirmative_ _Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law._
_To read and review this privacy notice click_ here (***************************************************************************************************************************
Security Engineer 5 - Product & Application Security
Security Architect Job 38 miles from Portland
PagerDuty, Inc. (NYSE:PD) is a global leader in digital operations management. Half of the Fortune 500 and nearly 70% of the Fortune 100 trust PagerDuty as essential infrastructure. Join us. (******************************* At PagerDuty, you'll tackle complex problems, collaborate with kind and ambitious people, and help build a more equitable world-all in a flexible, award-winning workplace.
PagerDuty is seeking a **Staff Security Engineer 5** to join our diverse, customer-focused team! As a **Staff Security Engineer 5** , you will bring your rich technical experience securing applications in a cloud native environment. You will be a part of an amazing team that's intensely focused on securing our products, improving our security processes, and building the future of security at PagerDuty.
This is an exciting opportunity to build security solutions that make developers and customers happy. The ideal candidate will have a blend of experiences across large enterprise environments and small or mid-size environments and will have focused on establishing security standards, coordinating with product development teams, developing strategies for secure-by-default architectures, and corresponding process and tooling selection and implementation. Things that make you smile: secure product architectures, providing an engaging Developer Experience for security adoption, and cute animal memes.
**Key Responsibilities**
+ Responsible for leading, designing, implementing, and configuring security controls for SaaS applications in a cloud-based infrastructure environment.
+ Lead complex projects that require in-depth knowledge across technical, solutions, and business, and collaborate across the broader engineering organization.
+ Identify threats and vulnerabilities, security gaps, and recommend enhancements and changes to increase product and infrastructure security posture.
+ Support security operations to provide the protection of the confidentiality, availability, and integrity of customer data and building/maintaining customer trust.
+ Partner with product/engineering, corporate operations, and employees to build and maintain a security-aware culture where everyone understands and plays their part
+ Provide thought leadership on modern security operations and help lead our infrastructure security organization in creating trust through security.
+ Participating in our team's on-call rotation, triaging and addressing security issues as they arise.
+ Mentor and grow application security engineers.
+ You have a desire to stay ahead of the latest industry trends and technologies, a track record of sharing contributions to the wider security engineering community and a commitment to continuous learning.
+ You believe security should make it easy to do the right thing.
+ You are an expert at leading collaborative efforts involving large groups.
+ Expert at building consensus within and across engineering teams.
**Minimum Requirements**
+ 7+ years of experience in infrastructure securing infrastructure, securing infrastructure including IaaS, PaaS, SaaS, including network security.
+ 5+ years experience with cloud-native security experience, cloud-native based application security best practices.
+ Experience with Linux operating systems, scripting languages such as Python, configuration languages like YAML, JSON and technologies such as Terraform and/or Cloudformation, configuration tools such as Chef or Ansible.
+ Experience with AWS cloud security best practices, and AWS security technologies such as AWS IAM, AWS Organizations, AWS Shield, AWS GuardDuty.
+ Excellent written and verbal communication skills.
+ The ability to compress intricate security challenges into concise descriptions.
+ The ability to solve security problems without saying "No".
+ You have a track record of stepping up and leading successful security engineering projects.
+ Past experience with application security, security testing, code reviews and identity and access management
+ Past experience with threat analysis, threat hunting, proactive security practices
+ Prior experience with Application Security, Secure SDL for cloud native services.
+ Experience with containerized applications, and technologies, such as Docker and Kubernetes.
+ Experience working in a continuous delivery/continuous deployment environment.
**Preferred Qualifications**
+ Certifications such as AWS Security Speciality, (ISC)2 Certified Cloud Security Professional (CCSP), (ISC)2 CISSP (Certified Information Systems Security Professional).
The base salary range for this position is 192,000 - 319,000 USD. This role may also be eligible for bonus, commission, equity, and/or benefits.
Our base salary ranges are determined by role, level, and location. The range, which is subject to change based on primary work location, reflects the minimum and maximum base salary we expect to pay newly hired employees for the position. Within the range, we determine pay for an individual based on a number of factors including market location, job-related knowledge, skills/competencies and experience.
Your recruiter can share more about the specific offerings for this role, as well as the salary range for your primary work location during the hiring process.
**Hesitant to apply?**
We encourage you to submit your resume even if you don't meet every requirement. We value potential and consider each candidate's full professional story. Whether you're exploring a career change or taking your next step, we look forward to reviewing your application. If this just isn't the right role or time - sign up for job alerts (**************************************** !
**Where we work**
PagerDuty currently has offices (**************************************** in Atlanta, Lisbon, London, San Francisco, Santiago, Sydney, Tokyo, and Toronto. We offer a hybrid, flexible environment. We also provide ample opportunities for connection, like team offsites and volunteering events.
**How we work**
Our values (************************************** guide how we support customers, collaborate with colleagues, develop products, and foster a culture of belonging. They define not just our actions, but what it means to be Dutonian.
**What we offer**
As a global organization, our total rewards approach is competitive with industry standards and aligned with local laws and regulations. Learn more, including country-specific offerings, on our benefits site (********************************************** .
**Your package may include:**
- Competitive salary
- Comprehensive benefits package from day one
- Flexible work arrangements
- Company equity*
- ESPP (Employee Stock Purchase Program)*
- Retirement or pension plan*
- Generous paid vacation time
- Paid holidays and sick leave
- Dutonian Wellness Days & HibernationDuty - companywide paid days off in addition to PTO
- Paid parental leave: 22 weeks for pregnant parent, 12 weeks for non-pregnant parent (some countries have longer leave standards and we comply with local laws)*
- Paid volunteer time off: 20 hours per year
- Company-wide hack weeks
- Mental wellness programs
*Eligibility may vary by role, region, and tenure
**About PagerDuty**
PagerDuty, Inc. (NYSE:PD) is a global leader in digital operations management, enabling customers to achieve operational efficiency at scale with the PagerDuty Operations Cloud. The PagerDuty Operations Cloud combines AIOps, Automation, Customer Service Operations and Incident Management with a powerful generative AI assistant to create a flexible, resilient and scalable platform to increase innovation velocity, grow revenue, reduce cost, and mitigate the risk of operational failure. Half of the Fortune 500 and nearly 70% of the Fortune 100 rely on PagerDuty as essential infrastructure for the modern enterprise.
PagerDuty is Great Place to Work-certified, a Fortune Best Workplace for Millennials, a Fortune Best Medium Workplace, a Fortune Best Workplace in Technology, and a top rated product on TrustRadius and G2.
Go behind-the-scenes on our careers site (*********************************** and @pagerduty on Instagram.
**Additional Information**
PagerDuty is committed to creating a diverse environment and is an equal opportunity employer. PagerDuty does not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, parental status, veteran status, or disability status.
PagerDuty is committed to providing reasonable accommodations for qualified individuals with disabilities in our job application process. Should you require accommodation, please email accommodation@pagerduty.com and we will work with you to meet your accessibility needs.
PagerDuty uses the E-Verify employment verification program.
Product Security Engineer
Security Architect Job 5 miles from Portland
The Group You'll Be A Part Of The Global Information Systems Group is dedicated to the success of Lam through providing best-in-class and innovative information system solutions and services. Together, we support users globally with data, information, and systems to achieve their business objectives.
The Impact You'll Make
Lam Information Security is looking for a security engineer to work with our software development teams. The application security engineer will specialize in the building security into existing and new CI/CD pipelines for Lam software. We are looking for an engineer who understands best practices and tools utilized in secure development and building security into the application.
The application security engineer will also support the broader information security strategy to safeguard Lams information systems infrastructure, business systems, and Operational Technology (OT) systems in Lam including engineering/manufacturing Labs.
What You'll Do
* Contribute to the overall objectives of the Security Engineering team
* Design and guide the implementation of secure software development life cycle practices including threat modeling, code review, static and dynamic code analysis, secured GIT/CVS/SVN, peer review, and vulnerability assessment
* Develop DevSecOps capabilities including identifying security scanning tools (SAST, DAST, IAST,SCA) to be integrated into SDLC processes
* Guide and evangelize the organization in establishing end to end strong secure SDLC/DevOps policies and standards to foster security of CI/CD pipeline
* Research, evaluate and implement new security prototypes to meet an ever-evolving security risk posture
* Design, implement, deploy and maintain security architectures and countermeasures to protect products
* Assess the security of products to discover potential vulnerabilities on products
* Provide subject matter expertise to product engineering teams, advocating for better security process throughout LAM
Who We're Looking For
* Bachelors degree in Computer Science, Information Security, IT management or related field
* 5+ years of experience in Information Security - related field
* Possess in-depth knowledge of OWASP top 10 and other similar frameworks to lead a team of product security analysts
* Demonstrated experience in product security, including hardware and software
* Experience working with Agile framework
* Ability to drive product and program conversations to negotiate tradeoffs between tactical and strategic goals
* Experience with security activities throughout the software development lifecycle - design reviews, threat modeling, code reviews, tooling, penetration testing
* Experience working with Static/Dynamic/Interactive Application Security Tools and Run-time Application Security Protection tools
* Hands on experience working with tools (Jenkins/Bitbucket/Artifactory)
* CISSP, CompTIA Security+, SANS professional certifications preferred
* Strong people and team/relationship building skills, work with cross functional global teams
Preferred Qualifications
* Experience within a global semiconductor company or equivalent industry experience preferred Breakdown and understand complex problems and the ability to develop a plan and innovative ways to address them
* Experience working in Azure cloud environment, utilizing Microsoft DevOps tools to architect secured coding to protect sensitive data
Our Commitment
We believe it is important for every person to feel valued, included, and empowered to achieve their full potential. By bringing unique individuals and viewpoints together, we achieve extraordinary results.
Lam Research ("Lam" or the "Company") is an equal opportunity employer. Lam is committed to and reaffirms support of equal opportunity in employment and non-discrimination in employment policies, practices and procedures on the basis of race, religious creed, color, national origin, ancestry, physical disability, mental disability, medical condition, genetic information, marital status, sex (including pregnancy, childbirth and related medical conditions), gender, gender identity, gender expression, age, sexual orientation, or military and veteran status or any other category protected by applicable federal, state, or local laws. It is the Company's intention to comply with all applicable laws and regulations. Company policy prohibits unlawful discrimination against applicants or employees.
Lam offers a variety of work location models based on the needs of each role. Our hybrid roles combine the benefits of on-site collaboration with colleagues and the flexibility to work remotely and fall into two categories - On-site Flex and Virtual Flex. 'On-site Flex' you'll work 3+ days per week on-site at a Lam or customer/supplier location, with the opportunity to work remotely for the balance of the week. 'Virtual Flex' you'll work 1-2 days per week on-site at a Lam or customer/supplier location, and remotely the rest of the time.
IND123 #LI-FC1 #LI-Hybrid
Our Perks and Benefits
At Lam, our people make amazing things possible. That's why we invest in you throughout the phases of your life with a comprehensive set of outstanding benefits.
Discover more at