Information Security Architect
Security architect job in New York, NY
Title: Information Security Architect
On-site/Remote/Hybrid: Hybrid 3 days onsite/2 days remote.
Duration: 12 Months
Work Hours: 37.5 Hours/Week.
Interview Process: 1-2 Rounds
Job Description:
This position is responsible for assisting in the development, implementation, and support of security architectures and solutions including security frameworks and roadmaps within the corporate business and Operational units across the agencies. It also includes securing enterprise information by determining security requirements, planning, implementing, and testing security systems with a team player environment. The following desired knowledge, skills, and abilities are required for this position. Knowledge of and experience in developing and documenting security architecture and plans, including strategic, tactical and project plans. Knowledge of common information security management frameworks. Excellent technical knowledge of mainstream operating systems and a wide range of security technologies, such as network security appliances, identity and access management systems, anti-malware solutions, automated policy compliance tools and desktop security tools. Ability to develop, document and maintain security policies, processes, procedures, and standards. Knowledge of network infrastructure including routers, switches, firewalls and the associated network protocols and concepts. Strong analytical skills required to analyze security requirements and relate such requirements to the appropriate security controls.
Responsibilities include the following.
Determine security requirements by evaluating business strategies and requirements; researching information security standards; conducting system security and vulnerability analyses; studying architecture/platform; identifying integration issues; preparing cost estimates.
Plan security systems by evaluating network and security technologies; developing requirements for local area networks, wide area networks, virtual private networks, routers, firewalls, and related security and network devices; designs public key infrastructures, including use of certification authorities and digital signatures as well as hardware and software; adhering to industry standards.
Implement security systems by specifying intrusion detection methodologies and equipment; directing equipment and software installation and calibration; preparing preventive and reactive measures; creating, transmitting, and maintaining keys; providing technical support; completing documentation.
Upgrade security systems by monitoring security environment; evaluating and implementing enhancements.
Prepare system security reports by collecting, analyzing, and summarizing data and trends. Track and understand emerging security practices and standards by participating in educational opportunities, reading professional publications and participating in professional organisation.
Software Security Engineer
Security architect job in New York, NY
Software Security Engineer (Agentic AI Platform)
We are partnered with a fast moving AI company that recently closed an eight figure seed round and is now building the core technical foundation that will support their next phase of growth. The founders are experienced second time operators moving with serious velocity and they have brought us in to help make a mission critical early hire.
This is a rare opportunity to join at the ground level and take full ownership of the infrastructure, security posture, and enterprise readiness of a product already gaining strong traction with financial and enterprise customers.
What You Will Do
Design build and maintain scalable secure and resilient cloud infrastructure for a high performance AI platform.
Define and implement cloud security standards authentication guardrails and enterprise grade controls such as SSO RBAC and audit logging.
Lead the companies readiness for SOC2 and ISO compliance and partner closely with the founders to navigate enterprise requirements.
Own the technical architecture for any infrastructure or security blockers encountered with large customers.
Build robust observability systems including metrics logging and tracing to support reliability at scale.
Design and ship production systems end to end from concept to architecture to deployment.
Collaborate with AI engineering and product teams to ensure infrastructure supports rapid iteration growth and enterprise expansion.
What We Are Looking For
Three or more years of hands on experience across backend engineering infrastructure or security engineering.
Strong cloud security fundamentals with Azure experience especially helpful.
A proven ability to architect and maintain production grade cloud systems.
Experience building secure scalable services with strong engineering rigor.
Comfort working directly with fast moving founders in an AI native environment.
Experience preparing for or leading SOC2 or ISO compliance efforts is a major plus.
Location
New York City.
Compensation
$200k - $300k Base Salary + Founding Level Equity
At CodeRed Partners we are committed to supporting equal opportunity employers and helping build diverse and inclusive teams. People are at the center of everything we do and we are proud to partner with companies shaping the future of AI through technical excellence trust and authentic collaboration.
Cyber Security Engineer
Security architect job in New York, NY
JOB FUNCTION
The Cybersecurity Engineer will be responsible for implementing and maintaining the firm's cybersecurity technology solutions, monitoring for security incidents and vulnerabilities, coordinating end user activities, and participating in the investigation and response of any breaches or attacks. The ideal candidate will be a self-starter who can work both independently and collaboratively with diverse technical and business teams. He or she will report to the Chief Information Security Officer. Additional responsibilities include:
Managing the vulnerability management program, including internal and external scanning, monitoring threat feeds, news sources, and vendor bulletins for risks and tracking remediation
Maintaining and monitoring control baselines, hardening standards, asset/coverage metrics, and configuration compliance
Monitoring and documenting key performance indicators (KPIs) and governance, risk, and compliance (GRC) evidence
Suggesting and evaluating new technologies
Educating employees on security best practices to reduce the risk of human error
Collaborating with the Cloud, Systems, Network, Database, Desktop, and Development engineering teams on risk identification, analysis, and remediation
Assisting with vendor due diligence
Assisting with physical security infrastructure projects, maintenance, and updates
QUALIFICATIONS
The ideal candidate should have the following experience:
3+ years of experience in a Security Engineer role
Proficiency with managing EDR solutions, SIEM, network security, cloud security, mobile security, vulnerability management, identity and access management, encryption, and a solid understanding of operating systems like Windows and Linux
Strong ability to analyze security data, identify threats, and create effective solutions
Ability to document and communicate technical information clearly to both technical and non-technical audiences
Scripting/automation experience a plus
The ideal candidate possesses the following traits:
Creativity: the ability to deploy different approaches and be resourceful.
Intellectual curiosity: passion for learning and investigating a broad range of subject matter; satisfaction derived from the consumption and understanding of information and increasing knowledge base.
Accountability: ownership of individual responsibilities and work product.
Strong people skills: ability to build relationships internally and externally and to be versatile in engaging with different constituents.
Chief Information Security Officer
Security architect job in New York, NY
Chief Information Security Officer (CISO)
📍
💰
Base Salary:
Up to $325,000 + Bonus + Equity
🏢
Our Client:
A Blockchain & Digital Asset Infrastructure Company
About Our Client
Our client is a fast-growing organization building infrastructure, software, and services that support the next generation of blockchain and digital asset ecosystems. They power secure transactions, institutional-grade solutions, and high-performance platforms used across the crypto economy.
As the business scales, they are expanding their leadership team with a Chief Information Security Officer (CISO) who will own the strategic direction, operations, and continuous improvement of all information and cybersecurity initiatives.
Role Overview
The CISO will set the long-term vision for security across the entire organization, covering infrastructure, products, employee environments, and customer-facing systems. This leader will ensure that the company's digital asset capabilities, blockchain networks, APIs, and cloud environments meet the highest standards of protection, resilience, and regulatory readiness.
This role requires an executive who can operate across technical, operational, and strategic levels-partnering with engineering, legal, compliance, product, and leadership teams.
Key Responsibilities
Design and drive a holistic security strategy covering infrastructure security, application security, product security, data governance, and operational risk.
Safeguard digital asset environments, including wallets, key management systems, consensus mechanisms, and blockchain-based services.
Build and lead an advanced threat detection, monitoring, and incident response program, ensuring rapid response and clear communication pathways.
Collaborate with engineering teams to integrate secure development practices into blockchain, smart contract, and cloud-native workflows.
Establish and maintain security controls, audits, and certifications, ensuring alignment with industry frameworks and regulatory expectations.
Oversee vendor security, supply-chain risk management, and third-party assessments.
Develop a culture of security throughout the business, including training, policy development, and ongoing risk awareness.
Provide regular reports and briefings to the executive team on emerging threats, risk posture, and security roadmap progress.
Experience & Qualifications
15+ years of experience in cybersecurity, with at least 5 years leading security organizations or programs at scale.
Strong experience in blockchain security, digital asset custody, exchange or infrastructure security, or related crypto-native environments.
Demonstrated success leading enterprise security programs that span cloud infrastructure, distributed systems, and high-availability environments.
Skilled in working with frameworks such as SOC 2, ISO 27001, NIST, and global data protection standards.
Expertise in cloud security (AWS, GCP, Azure), network security architecture, identity management, and DevSecOps.
Comfortable operating in fast-moving, engineering-driven environments.
Professional certifications (CISSP, CISM, CCISO, etc.) are a strong plus.
Chief Information Security Officer
Security architect job in New York, NY
A financial firm is looking for a Chief Information Security Officer (CISO) to join their team in New York, NY.
Compensation: $150-200K
Responsibilities:
Define and maintain the enterprise information security strategy, roadmap, and governance framework, aligned with business objectives and regulatory requirements
Draft, maintain, and periodically review security-related policies and procedures
Establish and chair/co-chair an Information Security / Cyber Risk Committee and contribute to Board-level reporting on cyber risk
Develop and maintain the firm's information security governance framework
Lead the firm's SOC 1 (Type 1/Type 2) and SOC 2 (Type 1/Type 2) readiness and ongoing attestation efforts
Own the control catalog, control testing coordination, evidence collection, and remediation tracking across technology, operations, and third parties
Act as primary security point of contact for external auditors, assessment firms, and key institutional partners
Ensure security program alignment with SEC Regulation S-P, Reg S-ID, Reg SCI, SEC / Client cybersecurity expectations, and NYDFS 23 NYCRR 500
Partner with Compliance and Legal to interpret new regulations, assess impact, and implement necessary control and policy changes
Maintain and periodically test the Incident Response Plan, Business Continuity and Disaster Recovery (BC/DR) from a security perspective
Provide security oversight for cloud (AWS) and on-prem infrastructure, including network security, endpoint security, identity and access management (IAM), and data protection
Work with Infrastructure/DevOps and application teams to embed secure SDLC practices, including code review, security testing, and secure deployment pipelines
Oversee vulnerability management, including patch management processes, penetration testing, and remediation programs
Define and oversee Security Operations Center (SOC) / XDR usage, log management, SIEM, threat detection, and incident handling
Design and enforce data classification, data loss prevention (DLP), encryption, and key management controls
Partner with business and product teams to ensure client data privacy and secure data flows, including with third-party vendors and partners
Own the vendor security risk management program, including security due diligence, contract security clauses, and ongoing monitoring
Evaluate and manage key security vendors
Build and lead a small but high-impact security team, scaling capabilities over time
Promote a security-first culture through training, awareness programs, and regular communication with staff at all levels
Qualifications:
Required
Bachelor's degree in Computer Science, Information Security, Engineering, or related field; or equivalent experience
7+ years of progressive experience in information security, including at least 3 years in a leadership role (Head of Security, Deputy CISO, CISO, or equivalent)
Hands-on experience leading SOC 1 and/or SOC 2 attestation projects at a financial institution, fintech, or SaaS provider
Strong background in financial services or capital markets (broker-dealer, clearing firm, trading platform, or similar)
Understanding of Information security frameworks (e.g., NIST CSF, NIST 800-53, ISO 27001)
Understanding of Regulatory landscape for U.S. financial firms (e.g., SEC, Client, possibly NYDFS 500)
Experience with Identity & access management, network security, endpoint security, and cloud security (preferably AWS)
Experience building and maintaining incident response, BC/DR, and vulnerability/patch management programs
Strong track record of cross-functional leadership, communicating complex security and risk topics to non-technical executives and boards
Preferred
Experience as CISO, Deputy CISO, or security leader at a broker-dealer, clearing firm, exchange/ATS, or large fintech
Professional certifications such as CISSP, CISM, CISA, CRISC, CCSP or similar
Experience with AWS security services
Familiarity with DevSecOps practices and secure CI/CD pipelines
Experience managing data localization and cross-border data separation initiatives
Senior Security Engineer
Security architect job in New York, NY
You will provide guidance and technical support to clients deploying security integrations. You'll act as the technical partner, providing strategic guidance around complex systems to secure a digital environment. Interacting directly with the client, you'll partner closely with client personnel to guide and suggest integrations to better serve their success. Your thorough understanding of our product integrations contributes to the development of new principles and concepts - providing detailed analysis around what's working, what's not, and what could be better.
You enjoy implementation work, are proactive about resolving potential concerns, and operate well around strict best practices that enable our clients on their road to a more secure digital world. You're creative, innovative, and you love a challenge - learning how integrations might work better around new products and technologies.
Responsibilities
Communicate with the customer(s), sales teams, peers, engineering and support teams as appropriate
Understand the customer environment, requirements, and security roadmap to implement the appropriate security solution
Configure, implement, and maintain Security Operating Platform
Optimize and migrate policies and objects from the existing environment to our Next-Gen Firewall
Test and validate the migration environment
Coordinate and execute cutover to production
Provide guidance on code upgrades
Facilitate the development of new application and threat signatures
Interact with our Technical Assistance Center (TAC) to understand and diagnose support cases
Some travel may be required, dependent on customer request
You work with the customer's security & network teams to build confidence across the business units impacted by the change
Experience
High level of experience with Panorama and log collectors
NGFW
Global Protect
BS in Computer Science, MIS, business, or equivalent education/training/experience
Minimum of 5 years' experience with network/security solutions and technologies (BGP, SD-WAN concepts, VXLAN and general routing and switching)
Minimum of 3 years' experience leading security solutions in large environments)
Detailed technical experience in the installation, configuration, and operation of high-end firewall appliances, ideally Palo Alto Networks products
You're experienced in internetworking, LAN, and WAN technologies
You have a good understanding of Internet protocols and applications
Any of the following industry certifications or equivalent experience is a plus: CISSP, CCNA, PCNSE, JNCIE-SEC
You effectively handle multiple projects and work calmly in high pressure
You're an excellent writer, with strong verbal communication skills, with demonstrable ability to communicate to senior leaders and technical peers
Sr Technical Security Engineer
Security architect job in New York, NY
Sr. Technical Security Engineer, W2 remote Minimum Requirements
5+ years of experience in application or product security, with a track record of securing desktop and mobile applications.
Strong understanding of secure architecture for thick clients, including local storage protection, inter-process communication, JavaScript engines, OS-level security features, and web security standards (CSP, same-origin policy, TLS/HTTPS).
Experience with mobile (iOS/Android) and desktop (Windows/mac OS/Linux) application security models.
Proficiency in GenAI security, modern cryptography, certificate management, secure authentication (OAuth, WebAuthn, FIDO2), and secure session handling.
Knowledge of OS-level hardening techniques, sandboxing, privilege separation, and secure use of platform APIs.
Hands-on experience with secure coding practices in at least one systems language (C++, Rust, Go) and one application language (Kotlin, Swift, C#).
Familiarity with static/dynamic analysis tools, fuzzing, penetration testing, and reverse engineering for client applications.
Experience embedding security into the software development lifecycle (threat modeling, code reviews, secure design patterns).
Ability to manage incident response and vulnerability remediation for thick client environments.
Strong cross-team communication skills and ability to write clear developer-facing security guidelines.
Senior Cloud Security Engineer (Infrastructure and Security) - New York - Competitive Salary + Competitive Package + Opportunity to work with an Ambitious, Young, Growing Organisation!
Security architect job in New York, NY
This young and agile company, providing identity risk solutions is currently seeking a Senior Cloud Security Engineer with a focus on Infrastructure and Security to join their growing team.
You will assist with the continuous maturation of their Cloud Security services within the Security division.
This is an excellent opportunity for an experienced Cloud Security Engineer with experience in both Infrastructure and Security to take the next step into a challenging position with a company offering significant growth potential.
About the Company:
Founded in the last 10 years, they are one the fastest growing companies in their space.
They are a fast-growing company that have built a platform that allows finance organisations and fintechs to strengthen their security defences.
Their mission is to allow companies to manage their identity and fraud risk.
Everything they do is entrenched in achieving engineering excellence.
Their culture is not corporate, and they like to trust their employees to take on a lot of responsibility and have input into the shape of growth of the organisation.
About the Senior Cloud Security Engineer (Infrastructure and Security) Vacancy:
What you will be doing:
• Serve as a cloud security subject matter expert, advise on and implementing best practices
• Respond to security incidents and provide timely and appropriate solutions
• Conduct cloud security risk assessments and audits
• Conduct investigations into security incidents and potential threats
• Take part in on call rotations for incident response and remediation
• Assist with policy management, security audits, and due diligence for cloud security concerns
• Advise on, configuring, and managing a variety of security tools
• Keep informed about and respond to emerging security threats and vulnerabilities
• Assist with cloud security reviews of potential vendors
Ideal Requirements for the Senior Cloud Security Engineer (Infrastructure and Security) Vacancy:
• Several years of experience working in a similar role with a focus on Cloud Security in AWS
• Experience provisioning infrastructure in AWS using Terraform, CloudFormation, CDK, or similar tools
• Experience configuring VPCs, route tables, NACLs, Security Groups, iptables, Web Application Firewall, Config, GuardDuty, Inspector, KMS, IAM, etc.
• In depth knowledge of AWS security best practices around systems hardening, monitoring, and incident response
• Experience taking part in an on-call rotation
• You are passionate about securing infrastructure, reducing risk, and protecting data!
• You are a subject matter expert on cloud security in AWS
• You have a solid understanding of network architecture and protocols
• You can advise on cloud security policies and procedures
Apply to the Role:
Roles like these are snapped up very quickly, so act now if you do not want to miss out! Reply to this advert or email your CV to **********************
Lead Security Engineer
Security architect job in New York, NY
Lead Security Engineer - Hands-On Role with Leadership Opportunity
We're looking to hire a senior-level Security Engineer who's ready to step up and take the lead. Someone who's still very hands-on technically but also enjoys mentoring others, setting direction, and building scalable solutions that make a real difference.
Title: Lead Security Engineer
Salary: $160,000 to 190,000 +Bonus
Location: Queens, NY (Hybrid)
This role sits at the center of engineering, operations, and security-you'll be working directly with software and infrastructure teams to make sure security is embedded into everything we do. You won't just be managing tools; you'll help shape how security is done across the company.
If you're based in the NYC area and looking for the next serious step in your career-where your ideas are heard and your work actually drives change-this is worth a conversation.
What the Role Looks Like:
You'll lead and mentor a small but growing team of security engineers, helping them grow while staying deep in the tech yourself.
Work with internal teams to design and implement security solutions-cloud security, PAM, app and system hardening, etc.
You'll be the one connecting the dots between development, infrastructure, and security-building relationships across teams and making sure security is part of the process from the start.
Help optimize and improve the tools we already have, and figure out what's missing.
What We're Hoping You Bring:
A few years of experience leading or mentoring other security engineers-you don't need to have managed huge teams, but you've helped others level up.
Solid technical background (5+ years in security engineering) and experience with on-prem and cloud security solutions (AWS or Azure).
Hands-on knowledge of privileged access, identity management, system hardening, and network security.
Strong instincts for risk, practical problem-solving, and keeping systems both secure and usable.
Someone who communicates clearly, doesn't get lost in buzzwords, and works well with people across teams.
Nice to Have, But Not Dealbreakers:
Certifications like CISSP, CEH, CISM
Experience with Linux security or scripting
Familiarity with CI/CD pipelines and how security fits into DevOps
Why This Role Might Be Right for You:
You're ready for more responsibility and leadership, but don't want to give up the technical side of the work.
You want to be part of a stable company with real backing and complex challenges to work on.
Sr. Security Researcher - Red Team
Security architect job in Jersey City, NJ
About The Role
The Sr. Security Researcher is responsible for leading and executing offensive security assessments (red teaming) against the organization's systems and networks. This role will leverage advanced penetration testing, social engineering, and other offensive security techniques to identify and exploit vulnerabilities, simulate real-world threats, and enhance the organization's overall security posture.
Responsibilities
Lead and execute red team engagements:
Develop and execute comprehensive red team assessments, including reconnaissance, vulnerability scanning, exploitation, and post-exploitation activities.
Lead and mentor junior red team members, providing guidance, training, and hands-on experience.
Develop and maintain red team methodologies, tools, and infrastructure.
Conduct threat modeling and risk assessments to identify potential attack vectors and prioritize targets.
Develop and execute social engineering campaigns, including phishing, vishing, and physical penetration tests.
Vulnerability research and exploitation:
Stay abreast of the latest threat intelligence, vulnerabilities, and exploits.
Research and develop new exploitation techniques and tools.
Conduct in-depth analysis of vulnerabilities and their potential impact.
Reporting and communication:
Prepare detailed and concise reports documenting red team findings, including technical details, impact assessments, and remediation recommendations.
Effectively communicate findings to technical and non-technical audiences, including senior management.
Present findings and recommendations at security forums and conferences (optional).
Security awareness and training:
Develop and deliver security awareness training programs to employees on topics such as social engineering, phishing, and secure coding practices.
Conduct security awareness campaigns to raise employee awareness of security threats and best practices.
Collaboration:
Collaborate with other security teams (e.g., blue team, incident response) to improve overall security posture.
Work with development teams to identify and remediate security vulnerabilities in applications and systems.
Build and maintain relationships with external security researchers and the cybersecurity community.
Skills and Qualifications
Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent experience).
5+ years of experience in cybersecurity, with 3+ years of hands-on experience in penetration testing, red teaming.
Understanding of blended attacks.
Proven experience leading and mentoring junior security professionals.
Strong understanding of networking, systems administration, and programming concepts.
Expertise in penetration testing methodologies and tools (e.g., Cobalt Strike, Outflank, Sliver, PowerShell Empire, Metasploit, Kali Linux, Nmap).
Proficiency in scripting languages (e.g., Python, Ruby, PowerShell).
Strong understanding of network protocols (e.g., TCP/IP, HTTP, DNS).
Experience with vulnerability scanners, intrusion detection systems, and firewalls.
Experience with cloud security (e.g., AWS, Azure, GCP) is a plus.
Relevant security certifications (e.g., RTO I, RTO II, OSCP, OSCE, GPEN, CRTP) are highly desired.
Excellent analytical and problem-solving skills.
Strong communication and interpersonal skills.
Ability to work independently and as part of a team.
Strong attention to detail and accuracy.
Ability to adapt to new technologies and challenges.
Project Management.
Lead Security Engineer - Trading Technology
Security architect job in Great Neck, NY
The Team:
The Security Engineering Lead will be responsible for designing, building, and maintaining the organization's security infrastructure. This role requires a highly skilled professional who can lead a team of engineers, implement innovative security solutions, and ensure the resilience of the organization's systems and networks. The ideal candidate will have extensive experience in security engineering, a strong technical background, and the ability to manage and deliver complex security projects.
**This Role does NOT provide sponsorship**
Salary: $150k-$190k base w/ 20% bonus
Responsibilities:
Leadership and Management: Lead and mentor a team of security engineers, fostering a culture of continuous learning and innovation. Build and scale a global team to meet organizational needs.
Architecting Security Solutions: Assist teams in designing and implementing advanced security solutions, including cloud security, privilege access management and application/system security.
Collaboration: Partner with software development, infrastructure, and operations teams to embed security into the development lifecycle and operational processes.
Performance Optimization: Regularly evaluate and optimize existing security tools and technologies to ensure maximum efficacy and efficiency.
Training and Knowledge Sharing: Develop and deliver technical security training to engineers and other staff, ensuring a strong organizational security posture.
Documentation and Reporting: Create detailed documentation for security systems and processes, and provide regular project reports senior management.
Required Skills and Experience:
Experience (3+ year) in people leadership roles, nurturing security engineers into high-performing teams.
Experience (5+ years) in a security engineering role, focusing on designing and implementing security solutions and managing security infrastructure, both on-premise and cloud.
Experience working with privilege and identity management solutions.
Experience with operating system security and system hardening.
Knowledge of network security principles, protocols, and technologies.
Strong analytical and problem-solving skills, with the ability to assess risks and develop appropriate security controls.
Excellent communication and interpersonal skills, with the ability to effectively communicate complex security concepts to technical and non-technical stakeholders.
Ability to work independently, prioritize tasks, and manage multiple projects simultaneously.
Strong leadership skills, with the ability to mentor and guide junior team members.
Skills and Experience That Would Help You Stand Out:
A bachelor's degree in Computer Science, Information Security, or a related field. A master's degree is a plus.
Professional certifications such as Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), or Certified Information Security Manager (CISM) are highly desirable.
Linux security experience
Familiarity with DevSecOps and integrating security into CI/CD pipelines.
Scripting experience.
Cyber Command Forensic Analyst
Security architect job in New York, NY
Contact Details:
1.Poonam Khandelwal
Email: poonam.khandelwal@peer-consulting.com
Cell: (732) 797-9766
Job Title: Cyber Command Forensic Analyst
Duration: 48 months
Years of Experience: 8+ years
Required Hours/Week: 35hrs/week
Job Description:
The forensics Analyst will investigate network intrusions and other cyber incidents to determine cause, extent and consequences of the breach.
Research and develop new techniques, and procedures to continually improve the digital forensics process.
Produce high quality written work product presenting complex technical issues clearly and concisely.
Managing and maintaining the analysis labs and forensics tools leveraged for investigations.
Ensuring data is collected and preserved within industry standard best practices and in alignment evidence integrity requirements.
Assisting the Cyber Emergency Response Team during critical incidents.
Investigate network intrusions and other cybersecurity incidents to determine the cause and extent of the breach. Includes ability to perform host-based and network-based forensic analysis.
Mandatory Skills/ Experience:
Candidates who do not have the mandatory skills will not be considered.
Minimum 4 years of experience in Threat Management/Forensics Investigations/Incident Response environment
Proficient in performing digital forensic investigations on a variety of platforms and operating systems with a deep understanding of digital forensics processes and tools.
Desirable Skills/ Experience:
Experience with a wide range of forensic tools (FTK, X-Ways, SIFT, AXIOM, EnCase, etc.)
Experience with memory analysis tools (i.e. Volatility, MemProcFS)
Experience with Linux and open source tools
Experience investigating intrusions on Windows and Linux/Unix operating systems
Experience with performing forensics collections in cloud environments (AWS, Azure, GCP)
Knowledge of gathering, accessing, and assessing evidence from computer systems and electronic devices
Knowledge of virtual environments
Knowledge of forensic imaging techniques
Knowledge of Microsoft Windows operating system and Windows artifacts
Knowledge of Linux/UNIX operating systems and artifacts
Knowledge of mac OS operating system and forensics artifacts
Knowledge of file systems
Strong analytical skills
Cyber Security Analyst
Security architect job in New York, NY
Job Title: Sr. Cybersecurity Risk Analyst
Duration: 24+Months
Responsibilities:
Build new risk processes and implement risk frameworks to enable better monitoring and evaluation of risks across the City;
Manage complex, cross-functional projects, pushing through ambiguity and challenges which may arise;
Work with stakeholders across various divisions, soliciting input and working through feedback;
Evaluate risk of third parties used by New York City agencies;
Document and track remediation of risks in the Risk Register;
Review and analyze various cybersecurity risk cases, justification, and exceptions documents submitted by agencies;
Assist in the development of cybersecurity risk assessment procedures and testing methodologies based on established frameworks and guidelines;
Initiating corrective actions to remediate vulnerabilities or weaknesses where necessary;
Engage in communications with NYC Agencies;
Handle special projects and initiatives as assigned.
Required Sklls:
A minimum of 4 years of experience in risk management or cybersecurity risk assessment or 4 years of experience evaluating and managing third parties in a cybersecurity team.
DESIRABLE SKILLS/EXPERIENCE:
BS/BA degree in Cybersecurity, Risk Management, Information Systems, Computer Science, or a related field.
One or more of the following certifications are a plus:
Certified Information Systems Auditor (CISA)
Certified Information Systems Security Professional (CISSP)
Certified in Risk and Information Systems Control (CRISC)
Certified Information Security Manager (CISM)
CompTIA Security+
CompTIA Network+
CompTIA A+
CompTIA CySA+
Cisco Certified Network Associate - CCNA
CEH: Certified Ethical Hacker
GIAC Information Security Fundamentals (GISF)
GIAC Security Essentials (GSEC)
(ISC)2 Systems Security Certified Practitioner (SSCP)
Ability to work effectively in a team environment.
Being highly organized, motivated and a self-directed professional.
Knowledge of hardware, software, data, and network principles and systems related to Private and/or Public Sectors services.
Understanding of commonly used computer operating systems, databases, network structures.
Familiarity with cybersecurity framework(s) (NIST, SANS, PCI, ISO 27001/27002, or CIS)
Investigative and analytical skills.
Excellent oral and written communication skills;
Knowledge of the current and evolving cyber threat landscape;
Knowledge of laws, regulations, policies, and ethics related to cybersecurity and information privacy;
Cyber Security Specialist
Security architect job in New York, NY
Akkodis is seeking a Cybersecurity Operations Specialist role is a Direct hire with a client located in NYC 10022 (Hybrid). Ideally looking for applicants to have a solid background in Security operations, SOC, Financial services, FINRA, SEC would come as a big plus.
Salary Range: $130k-$140k/Annum + Benefits, The salary may be negotiable based on experience, education, geographic location, and other factors.
We are seeking a Cybersecurity Operations Specialist to join our security operations team and play a hands-on role in monitoring, protecting, and improving the firm's cybersecurity posture.
This position focuses on day-to-day security operations, vulnerability management, and incident response across our on-premise and cloud environments (AWS and Microsoft 365). The ideal candidate has strong technical knowledge of endpoint protection, identity management, and network security, combined with an analytical mindset and attention to detail suitable for a regulated financial environment.
Key Responsibilities:
Security Operations & Monitoring
Monitor and investigate alerts from CrowdStrike Falcon XDR, Microsoft Defender, and Intune.
Conduct triage and escalation of suspicious activities in coordination with infrastructure and IT teams.
Maintain visibility and reporting through Tenable Security Center and Nessus vulnerability scans.
Support log analysis, correlation, and event tracking through integrated dashboards or SIEM platforms.
Vulnerability & Patch Management
Perform routine vulnerability assessments and track remediation status.
Collaborate with system administrators to ensure timely patching of Windows, Linux, and network devices.
Validate risk reduction and patch compliance before closing findings.
Endpoint & Identity Security
Administer and monitor Symantec Endpoint Protection Manager (EPM) and Microsoft Intune policies.
Enforce endpoint encryption (Corporate Laptop), application control, and posture management.
Manage Microsoft Entra (Azure AD) identity policies, MFA enforcement, and conditional access rules.
Review privileged account usage and assist in quarterly access recertification.
Network & Cloud Protection
Support network segmentation, VPN access, and firewall change reviews on Juniper platforms.
Monitor ZScaler logs for anomalous web traffic or policy violations.
Assist with AWS and Microsoft 365 security baselines, configuration hardening, and identity governance.
Security Awareness & Compliance
Administer and report on employee phishing and training campaigns via KnowBe4.
Support audit requests (FINRA, SEC, SOC1/2) by preparing evidence and log samples.
Maintain documentation of incidents, vulnerabilities, and security control tests.
Incident Response & Reporting
Participate in incident containment, investigation, and remediation.
Collect forensic artifacts (logs, screenshots, binaries) as directed by the CISO.
Prepare post-incident summaries and lessons-learned documentation.
Qualifications:
Required
Bachelor's degree in Information Security, Computer Science, or related field (or equivalent experience).
3-5 years of experience in security operations, SOC, or IT security support.
Working knowledge of EDR/XDR platforms (CrowdStrike, Defender), vulnerability scanners (Nessus), and firewall/IDS systems.
Understanding of Windows/Linux administration, TCP/IP networking, and cloud identity management.
Strong analytical, documentation, and communication skills.
Preferred
Experience with regulated financial institutions (FINRA, SEC, NFA, CFTC).
Certifications such as CompTIA Security+, CySA+, Microsoft Certified: Security Operations Analyst, or GIAC GSEC.
Familiarity with scripting or automation (PowerShell, Python) for security tasks.
If you are interested in this role, then please click APPLY NOW. For other opportunities available at Akkodis, or any questions, feel free to contact me at *********************************.
Equal Opportunity Employer/Veterans/Disabled
Benefits offerings include but are not limited to:
• 401(k) with match
• Medical insurance
• Dental Insurance
• Vision assistance
• Paid Holidays Off
To read our Candidate Privacy Information Statement, which explains how we will use your information, please visit ******************************************
The Company will consider qualified applicants with arrest and conviction records in accordance with federal, state, and local laws and/or security clearance requirements, including, as applicable:
· The California Fair Chance Act
· Los Angeles City Fair Chance Ordinance
· Los Angeles County Fair Chance Ordinance for Employers
· San Francisco Fair Chance Ordinance
Senior Cyber Security Engineer (IAM, PAM, SOAR)
Security architect job in New York, NY
Senior Cyber Security Engineer, NYC Hybrid (3 Days a week Onsite)
Our client is a financial services provider and they're looking for a senior engineer with real depth in Python OO and CyberArk or Swimlane to step into a high impact role. This is a hands-on position in a stable environment where you will own serious engineering problems and build the next generation of identity and PAM controls.
What you will work on:
• Engineering CyberArk (IAM/PAM) integrations and custom PAM solutions
• Building Python based tooling, APIs, and automation that matter
• Strengthening enterprise identity platforms across a complex environment
• Collaborating with senior architects while still owning the code
What we are looking for:
• Python object-oriented engineering, not scripting
• CyberArk (IAM/PAM) or Swimlane (SOAR) engineering experience
• Infrastructure security background
• 15+ years' experience in Engineering and/or Cyber Security
• Experience in financial services or large enterprise is a plus
Who usually fits this role:
• Identity and PAM platform engineers
• SOAR engineers who build with Python
• Infra security engineers tired of purely operational work
Application Security Architect
Security architect job in New York, NY
ABOUT THE JOB
The ACLU seeks applicants for the full-time position of Application Security Architect in the Information Security Department of the ACLU's National office in New York, NY
.
This is a hybrid role that has in-office requirements of two (2) days per week or eight (8) days per month.
This role will define how secure applications are designed, integrated, and maintained across the ACLU's cloud, SaaS, and hybrid environments. You'll lead efforts to embed security throughout our software development lifecycle (SDLC), own our internal Security Architecture Review (SAR) process, and guide secure integration practices for highly customized platforms and other third-party applications critical to our civil liberties mission.
The AppSec Architect will partner closely with product and platform teams, Tech Engineering, Devops, IT, and affiliates to assess and mitigate risks associated with application design, data flows, integrations, and third-party software usage. You'll help set and enforce security standards, perform hands-on threat modeling, define secure development and deployment patterns, and directly support high-impact systems involving donor data, legal case workflows, and internal operational apps.
This hands-on technical leadership role will own and drive the ACLU's application security efforts across both internally developed and externally adopted applications.
This position is part of a collective bargaining unit. It is represented by ACLU Staff United (ASU).
WHAT YOU'LL DO
Reporting to the Director, Security Architecture & Engineering, the Application Security Architect will define and drive the ACLU's application security roadmap-from code to cloud, and everything in between.
YOUR DAY TO DAY
Lead the ACLU's Application Security Program, owning the InfoSec SDLC strategy and continuous improvement of application-layer security across cross-functional teams.
Own the Security Architecture Review (SAR) process, including intake, risk evaluation, documentation, and partner engagement.
Perform and guide threat modeling for new applications, integrations, and high-risk workflows-including financial systems, legal platforms, and supporter/donor tools.
Define secure design patterns for authentication (OAuth/OIDC), secrets management, API authorization, session handling, and data flow protections across internal and third-party systems.
Evaluate, deploy, and maintain AppSec tooling such as SAST, DAST, SCA, API security tools, and secrets detection platforms, based on risk and developer stack alignment.
Partner with stakeholders to assess internal cloud apps, low-code tools, and internal workflow automations for security risks.
Oversee application-layer vulnerability triage, analysis, and escalation-including issues from internal testing, coordinated disclosure, and external penetration testing.
Collaborate with platform owners of high-risk SaaS platforms to validate that application-level security controls-authZ, audit logging, IP allowlists, token lifetimes, etc.-are in place and enforced.
Ensure application-layer security extends across data ecosystems, including ETL and reverse ETL pipelines, data warehouse platforms (e.g., Redshift, Snowflake), and high-risk integrations that move or transform sensitive donor, legal, or supporter data between internal systems and external SaaS tools.
Identify and reduce emerging application-layer risks related to AI adoption, including prompt injection, model abuse, insecure integrations with LLM APIs, and exposure of sensitive data through AI-powered features or automations.
FUTURE ACLU'ERS WILL
Be committed to advancing the mission of the ACLU
Center and embed the principles of equity, inclusion and belonging in their work by demonstrating commitment to diversity with an approach that respects and values multiple perspectives
Be committed to work collaboratively and respectfully toward resolving obstacles and conflicts
WHAT YOU'LL BRING
Extensive experience in application or product security, secure software development, or DevSecOps architecture.
Practical experience designing and implementing secure SDLC, AppSec testing workflows, or automated CI/CD security gates.
Deep understanding of common software vulnerabilities (e.g., OWASP Top 10), secure coding practices, and threat modeling methodologies.
Familiarity with GitHub Actions, modern SaaS stacks, and secure API design principles.
Familiarity with CMS tooling (e.g., Drupal, WordPress), cloud computing platforms (e.g., GCP, Azure, AWS), and containerization environments (e.g., Kubernetes, Docker, ECS).
Experience securing data pipelines and warehouse environments, with a focus on protecting structured data.
Experience partnering directly with developers and product teams to influence secure outcomes.
Excellent communication skills, especially when translating technical issues into business risk language.
COMPENSATION The ACLU is committed to equity, transparency, and clarity in pay. Consistent with our compensation philosophy, there is a set salary for each role based on geographic work location. The annual salary for this position is $161,123 (Level - E), reflecting the salary of a position based in New York, NY. Salaries are subject to a regional pay adjustment if authorization is granted to work outside of the location listed in this posting. For details on our pay structure, please visit: ************************************************************************ WHY THE ACLU
For over 100 years, the ACLU has worked to defend and preserve the individual rights and liberties guaranteed by the Constitution and laws of the United States. Whether it's ending mass incarceration, achieving full equality for the LGBTQ+ community, establishing new privacy protections for our digital age, or preserving the right to vote or the right to have an abortion, the ACLU takes up the toughest civil liberties cases and issues to defend all people.
We know that great people make a great organization. We value our people and know that what we offer is essential not just their work, but to their overall well-being.
At the ACLU, we offer a broad range of benefits, which include:
Time away to focus on the things that matter with a generous paid time-off policy
Focus on your well-being with comprehensive healthcare benefits (including medical, dental and vision coverage, parental leave, gender affirming care & fertility treatment)
Plan for your retirement with 401k plan and employer match
We support employee growth and development through annual professional development funds, internal professional development programs and workshops
OUR COMMITMENT TO ACCESSIBILITY, EQUITY, DIVERSITY & INCLUSION
Accessibility, equity, diversity and inclusion are core values of the ACLU and central to our work to advance liberty, equality, and justice for all. For us diversity, equity, accessibility, and inclusion are not just check-the-box activities, but a chance for us to make long-term meaningful change. We are a community committed to learning and growth, humility and grace, transparency and accountability. We believe in a collective responsibility to create a culture of belonging for all people within our organization - one that respects and embraces difference; treats everyone equitably; and empowers our colleagues to do the best work possible. We are as committed to anti-oppression, anti-ableism, and anti-racism internally as we are externally. Because whether we're in the courts or in the office, we believe ‘We the People' means all of us.
With this commitment in mind, we strongly encourage applications from all qualified individuals without regard to race, color, religion, gender, sexual orientation, gender identity or expression, age, national origin, marital status, citizenship, disability, veteran status and record of arrest or conviction, or any other characteristic protected by applicable law.
The ACLU is committed to providing reasonable accommodation to individuals with disabilities. If you are a qualified individual with a disability and need assistance applying online, please email
************************
. If you are selected for an interview, you will receive additional information regarding how to request an accommodation for the interview process.
Auto-ApplyManager, Information Security Compliance
Security architect job in New York, NY
Department Description At Disney, we're storytellers. We make the impossible, possible. The Walt Disney Company (TWDC) is a world-class entertainment and technological leader. Walt's passion was to continuously envision new ways to move audiences around the world-a passion that remains our touchstone in an enterprise that stretches from theme parks, resorts and a cruise line to sports, news, movies and a variety of other businesses. Uniting each endeavor is a commitment to creating and delivering unforgettable experiences - and we're constantly looking for new ways to enhance these exciting experiences.
The Enterprise Technology mission is to deliver technological solutions that align to business strategies while enabling enterprise efficiency and promoting cross-company collaborative innovation. Our group drives competitive advantage by enhancing our consumer experiences, enabling business growth, and advancing operational excellence.
The Global Information Security (GIS) organization strives to secure the magic by employing best-in-class services to assess, prevent, detect, and respond to cyber threats that present risk to The Walt Disney Company. We enable the business by integrating enterprise and business segment-specific supported services to create a robust, efficient, and adaptable cybersecurity program. Our key objectives are to:
* Secure the Magic by protecting information systems and platforms.
* Reduce Risk by proactively assessing, preventing, and detecting to prevent harm to the Company and our Guests.
* Strengthen the business through optimizing execution, application, and technology used to protect the Company.
* Innovate by investing in core capabilities to enhance operational efficiency.
Team Description:
Global Information Security (GIS) supports all of Disney's business segments, including Disney Entertainment & ESPN (DE&E). DE&E encompasses the operations of Disney's streaming services-Disney+, Hulu, ESPN+, Disney+ Hotstar, Star, and the upcoming Venu Sports streaming service-as well as Disney's broadcast and cable networks, including ABC, ESPN, FX, Disney Channels, and National Geographic. DE&E sits at the intersection of entertainment, sports, and technology, striving to connect viewers with beloved stories while advancing the streaming industry with consumer-first innovations. Security professionals supporting DE&E work with industry-leading technologies to deliver world-class, highly secure services to customers.
What You'll Do:
* Independent audit support for:
* SOX 404 ITGCs
* PII
* PCI
* ISPS
* Collaborate with Enterprise Controls and Compliance (ECC) to scope systems and respective ITGCs.
* Perform control health checks and remediation testing procedures to address issues identified via audit assessments, access control reviews, internal or external audits and/or other assessments.
* Develop and lead the Control Assurance Programs (ISPS and SOX).
* Lead Audit Readiness efforts to ensure proper system scoping and respective ITGCs, control validations and timely program onboarding.
* Participate in audit walkthrough meetings to help establish internal testing procedures to gain operational comfort in the design of the Company's automated controls.
* This includes control self-evaluations of new controls or processes that impact the effectiveness of an existing control.
* Perform impact analysis and risk assessment on deficiency findings and documentation associated with the assessment.
* Work with management and internal audit on maintaining the master Risk and Control Matrix over the systems material to Disney Entertainment and ESPN (Broadcast TV and Streaming - Hulu, Disney+, ESPN+, STAR+ products)
* Ensure for timely management response of audit findings into our corporate SOCD/SAD.
* Oversee ISPS Management Audit coordination and open action plans.
* Provide consultancy to Development leads to identify and implement automation and efficiency opportunities to meet governance and compliance demands.
* Management of GRC workflows around coordination of certifications and attestations.
* Partner with leadership to support the PCI-DSS compliance program.
* Develop training materials, coordinate training sessions, and monitor compliance with training requirements.
* Oversee and manage a team of compliance analysts, ensuring day-to-day operations run smoothly and efficiently.
* Assign tasks and projects to team members based on priorities, deadlines, and individual strengths.
* Provide executive level updates on Compliance programs
Must Haves (Years of Experience, languages, programs, tools, etc.):
* Minimum of 8 years of related work experience, with 3 in management roles
* IT SOX experience and proven experience in supporting IT audit/compliance functions
* Experience in managing people
* Thorough understanding of SOX ITGC and ICFR 404 standards and audit objectives
* Interpersonal skills with the ability to work with teams cross-functionally
* Strong verbal and written communication skills and ability to effectively communicate to technical and non-technical audiences, including developers and tech operators
* Detail-oriented but able to understand the big picture. Highly organized and efficient
* Ability to navigate through ambiguity, manage and coordinate multiple project assignments simultaneously in a fast-paced, deadline-driven environment, accepting ownership and accountability of the process and deliver on commitments
* Experience with cloud-based services, specifically AWS
Nice To Haves (see above):
* Experience and knowledge of NIST framework, ISO 27001, K-ISMS, GDPR
* Experience working with companies that have a heavy microservice architecture
Education:
Bachelor's degree in Computer Science, CPA license, Information Systems, Software, Electrical or Electronics Engineering, or comparable field of study, and/or equivalent work experience
The hiring range for this position in Glendale, CA and Santa Monica, CA is $141,900 to $190,300 per year and in New York, NY is $148,700 to $199,400 per year. The base pay actually offered will take into account internal equity and also may vary depending on the candidate's geographic region, job-related knowledge, skills, and experience among other factors. A bonus and/or long-term incentive units may be provided as part of the compensation package, in addition to the full range of medical, financial, and/or other benefits, dependent on the level and position offered.
About The Walt Disney Company (Corporate):
At Disney Corporate you can see how the businesses behind the Company's powerful brands come together to create the most innovative, far-reaching and admired entertainment company in the world. As a member of a corporate team, you'll work with world-class leaders driving the strategies that keep The Walt Disney Company at the leading edge of entertainment. See and be seen by other innovative thinkers as you enable the greatest storytellers in the world to create memories for millions of families around the globe.
About The Walt Disney Company:
The Walt Disney Company, together with its subsidiaries and affiliates, is a leading diversified international family entertainment and media enterprise that includes three core business segments: Disney Entertainment, ESPN, and Disney Experiences. From humble beginnings as a cartoon studio in the 1920s to its preeminent name in the entertainment industry today, Disney proudly continues its legacy of creating world-class stories and experiences for every member of the family. Disney's stories, characters and experiences reach consumers and guests from every corner of the globe. With operations in more than 40 countries, our employees and cast members work together to create entertainment experiences that are both universally and locally cherished.
This position is with Disney Worldwide Services, Inc., which is part of a business we call The Walt Disney Company (Corporate).
Disney Worldwide Services, Inc. is an equal opportunity employer. Applicants will receive consideration for employment without regard to race, religion, color, sex, sexual orientation, gender, gender identity, gender expression, national origin, ancestry, age, marital status, military or veteran status, medical condition, genetic information or disability, or any other basis prohibited by federal, state or local law. Disney champions a business environment where ideas and decisions from all people help us grow, innovate, create the best stories and be relevant in a constantly evolving world.
Apply Now Apply Later
Current Employees Apply via My Disney Career
Explore Location
Information Security Officer
Security architect job in New York, NY
This role is located in New York City and will require a hybrid work schedule of at least 2 days in office per week.
This role is for Vice President level candidates.
About the Bank:
Sumitomo Mitsui Trust Bank, Limited was established through the merger of The Sumitomo Trust and Banking Co., Ltd with Chuo Mitsui Trust and Banking, Ltd. on April 1, 2012. We are one of the largest asset managers in Asia and number one among Japanese financial institutions by AUM, with approximately $850 Billion USD in AUM. The Bank provides an assortment of financial solutions and manages a broad spectrum of financial products across its global branches. Department Overview:
The Americas Division (“AD”) was established in the Sumitomo Mitsui Trust Bank, Limited, New York Branch) (“SMTBNY”) to perform corporate functions and supervise U.S. entities. Established under the AD are the “Global Banking Unit (“GBU”), Americas Division” and “Global Markets Unit (“GMU”), Americas Division” which performs business functions. Information Risk Governance (“IRG”) provides oversight to information and cyber security risk by maintaining and improving branch wide framework that is in-line with the Head Office and regulatory requirements and addresses Confidentiality, Integrity, and Availability for information assets. IRG establishes appropriate policies, procedures, measurement, and monitoring processes to proactively assess and evaluate cyber security and information security risks inherent in the Branch Operations. IRG is directly involved in all information and cyber security related projects, matters, and issues.
Your Role Overview:
To assist the Head of the Department with the day-to-day management and operation of the department. To assume the role of Information Security Officer and take the lead on overseeing the timely completion of the department's critical risk management projects. To provide direct assistance to the Head of the Department with regards to accomplishing the department's goals and objectives. To manage, guide and mentor other staff members with the preparation and completion of their assigned tasks. To contribute significantly to the overall success of the department in all key risk management and cyber security areas.
Directly oversee completion of all critical projects, assist the HOD with implementing desired operational strategies and procedures. Recommend ways to improve efficiency, effectiveness, and productivity. Focus on proactive day-to-day operations. As ISO, assist with overseeing all information and cyber security matters.
Your Duties and Responsibilities:
Maintain and improve the information risk framework with guidance from HOD, address regulatory requirements, residual information risks specific to NY Branch Operations.
Provide Information Security subject-matter-expertise to senior management.
Work with IRT and coordinate incident responses to cyber security events.
Keep abreast of industry wide information risk issues that could potentially have an impact on Branch Operations.
Establish processes for communicating data classification guidelines and its governance.
Oversee employee information security awareness training.
Assesses and evaluates critical risk management projects:
Annual Risk Assessment.
Semi-annual Vulnerability Assessments.
Special Risk Assessments done for a Particular Purpose
Trend analysis of key risk management concepts and principles
Attend the ISSRM and Branch Risk Management related meetings.
Performs key information risk governance related tasks as described below:
Provides User Access Control Governance.
Monitors, analyzes and follows-up on Information Risk events/issues.
Reviews information risk and proactively advises as necessary on: IT Projects/Issues Management process, Change Management Process, significant changes to IT procedures, IT Asset Management Report, key IT Vendor Contracts, IT Disaster Recovery Plan/Process, Record Retention Process, any related audit findings, etc.
Establish and maintain Information Risk Key Risk Indicators (KRI).
Periodically updates IT resources on Information risk related practices.
Manages all information and cyber security policy and procedures manuals.
Assist with the management of all matters related to Information Security and Information Risk Management, including directing appropriate Information/Applications Risk Assessments.
Your Qualifications:
Certification in Information Security (CISSP) required.
8+ years of Information Security related experience, IT Audit experience, preferred.
Knowledge of Information Security principles, terminologies, and technologies required.
Knowledge of Information Risk Management framework and principles required.
Ability to analyze and design information security monitoring procedures and activities preferred.
Detailed Knowledge and expertise in Technology Risk Assessments and Risk Analysis required.
Excellent written and verbal communication skills, required.
Good computer skills in Microsoft Office Excel and Word required.
Strong project management and people management skills. preferred
Why you should join SuMi Trust: SuMi Trust embraces flexible ways of working when the business and role permits. We provide employees with a hybrid working model, allowing for in-office work and work from home. Our diverse and inclusive environment along with our global presence enables us to collaborate and communicate to meet our business needs. We believe that efficient teams need truth, loyalty, and a strong sense of purpose to balance risk and their targets. We make sustainable business decisions to improve our society and the world. We believe that each person brings a unique value that drives the business though their creativity and passion.
The Employee Benefits package includes: Paid Time Off, medical, HSA, vision, dental, FSA, 401(k), profit sharing, legal plan, cancer indemnity plan, disability insurance, life insurance, employee assistance program, commuter benefits, business travel accident, paid volunteer day, paid memberships, paid seminars, and tuition assistance.
We offer many socialization opportunities for wellness, financial wellbeing, runs/walks, team building, happy hours, and activities to support the Sustainable Developmental Goals.
Check out our LinkedIn for our employee experience: ***************************************
We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, national origin, disability status, protected veteran status or any other characteristic protected by law. SuMi Trust provides reasonable accommodations for employees and applicants with disabilities consistent with applicable law. If you need a reasonable accommodation during the application
Auto-ApplyInformation Security Manager
Security architect job in New York, NY
Public Health Solutions (PHS) is a 501(c)3 non-profit community-based organization (CBO) that has existed for 70 years to improve health equity and address health-related social needs (HRSN) for historically underserved marginalized communities. As the largest public health nonprofit serving New York City, we improve health outcomes and help communities thrive by providing services directly to vulnerable families, supporting community-based organizations through our long-standing public-private partnerships, and bridging the gap between healthcare and community services. We focus on a wide range of public health issues including food and nutrition, health insurance, maternal and child health, sexual and reproductive health, tobacco control, and HIV/AIDS. Learn more about our work at healthsolutions.org.
PHS administers WholeYouNYC (WYNYC), a coordinated community resource network that builds trustworthy and reliable pathways between healthcare providers, health plans and CBOs providing critical resources in the community that address the social drivers of health. WYNYC brings together over 100 organizations offering various programs - such as food, housing, employment, health insurance, and sexual health services - across all five boroughs. These services and programs make it possible for New Yorkers to live their healthiest lives and ultimately reduce health disparities and advance health equity. To date, our network has already impacted thousands of lives through community partnerships and referrals, generating millions in estimated healthcare savings.
New York State (NYS) recently announced the availability of $500M statewide to support Social Care Network (SCN) lead entities responsible for coordinating social care delivery in various regions across the state. Public Health Solutions (PHS) and our WYNYC network were awarded the role of regional SCN for Brooklyn, Manhattan, and Queens.
This is a grant-funded position ending March 31, 2027.
Position Summary:
The Information Security Manager serves as both a strategic leader and a hands-on practitioner responsible for advancing the organization's cybersecurity, risk management, and compliance programs in accordance with NYS OHIP , and HIPAA standards.
This position provides day-to-day oversight of the organization's security operations, including monitoring, incident response, and vulnerability management, while also directly performing technical work within Microsoft 365, Azure, and other enterprise systems. The Manager functions as a key liaison with the Security Operations Center (SOC), auditors, and internal stakeholders to ensure the confidentiality, integrity, and availability of organizational
Essential Duties and Responsibilities
Governance, Risk, and Compliance
Maintain compliance with NYS OHIP , HIPAA Security practices , and related NYS cybersecurity requirements.
Lead internal and external security assessments, audits, and certification readiness activities.
Develop, update, and enforce security policies, standards, and procedures in collaboration with IT leadership.
Track and document risk remediation, exceptions, and corrective action plans; ensure closure within established timeframes.
Provide evidence and reporting for regulatory, contractual, and audit purposes.
Security Operations (Hands-On)
Actively monitor and investigate alerts from SIEM and threat detection platforms (e.g., Microsoft Sentinel, Stellar Cyber).
Perform hands-on triage, forensic analysis, and root cause determination for incidents in coordination with the SOC.
Manage and fine-tune security configurations within Microsoft 365 Security & Compliance Center , including DLP, retention, threat protection, and auditing.
Oversee Azure identity protection, conditional access, and cloud resource security configurations.
Conduct periodic reviews of user privileges, MFA enforcement, and system baselines.
Support vulnerability scanning, patch verification, and endpoint protection efforts.
Leadership and Collaboration
Supervise Information Security Analysts and provide technical guidance, mentorship, and workload prioritization.
Serve as an escalation point for incident response and compliance inquiries.
Partner with infrastructure, applications, and compliance teams to align controls with organizational needs.
Coordinate with third-party vendors, the SOC, and auditors to support investigations, testing, and reporting.
Prepare and present reports and risk metrics to the Director of IT and senior management
Perform other duties as assigned.
Qualifications and Experience:
Bachelor's degree in information security, Computer Science, or a related field; or equivalent combination of education and experience.
Minimum of five (5) years of progressively responsible experience in information security or IT risk management, including at least two (2) years in a supervisory or lead capacity.
Demonstrated hands-on experience with:
Microsoft 365 Security & Compliance Center
Azure Security Center / Defender for Cloud
SIEM tools (e.g., Sentinel, Stellar Cyber)
Incident response and forensic analysis
Working knowledge of HITRUST , OHIP NYS , and HIPAA compliance frameworks.
Strong ability to produce audit-ready documentation, reports, and technical summaries.
Excellent analytical, communication, and organizational skills
Preferred Qualifications:
Certifications such as CISSP , CISM , Security+ , Microsoft Certified: Security Operations Analyst Associate , or HITRUST CCSFP .
Experience in public health , nonprofit , or other regulated environments .
Familiarity with NIST CSF , NIST SP 800-53 , and CIS Benchmarks
Reports To:
Deputy Director of Information Systems
Direct Reports:
The position has no direct reports.
Benefits:
• Hybrid Work Schedule.
• Generous Paid Time Off and Holidays.
• An attractive and comprehensive benefits package including Medical, Dental and Vision.
• Flexible Spending Accounts and Commuter Benefits.
• Company Paid Life Insurance and Disability Coverage.
• 403(b) + employer matching and discretionary company contributions.
• College Savings Plan.
• Ongoing trainings and continuous opportunities for professional growth and development.
At PHS, we place immense value on diversity within our teams, understanding that varied backgrounds and experiences significantly enhance our community and propel us toward our goals. If you find you don't have experience in all the areas listed above, we still encourage you to apply and share your background and experiences in your application. We are eager to discover how your unique perspective can bring positive transformations to our team and help advance our mission of creating healthier, more equitable communities.
We look forward to learning more about you!
PHS is proud to be an equal opportunity employer and encourages applications from women, people of color, persons with disabilities, LGBTQIA+ individuals, and veterans.
Auto-ApplyManager, Information Security (Monitoring and Investigation)
Security architect job in New York, NY
Hours: 37.5 Line of Business: Technology Solutions Pay Details: 91,200 - 136,800 CAD TD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience at TD. Our compensation policies and practices have been designed to allow colleagues to progress through the salary range over time as they progress in their role. The base pay actually offered may vary based upon the candidate's skills and experience, job-related knowledge, geographic location, and other specific business and organizational needs.
As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.
Job Description:
TD Bank is seeking a strategic and technically skilled Manager to join our Information Security team, focused on strengthening our fraud detection, authentication, and CIAM (Customer Identity and Access Management) capabilities. This role will lead the expansion of our monitoring and alerting footprint across enterprise platforms, ensuring control effectiveness, regulatory alignment, and rapid incident response in a complex financial environment.
Key Responsibilities
* Lead the design and deployment of monitoring and alerting strategies using Splunk, Datadog, Dynatrace, and Databricks across TD's digital ecosystem
* Define alert thresholds and tuning logic to minimize false positives while maintaining high sensitivity to fraud and access anomalies
* Oversee triage workflows for triggered alerts, coordinating with global teams to ensure timely investigation and resolution
* Develop governance frameworks for alert lifecycle management, including setup, ownership, escalation, and audit readiness
* Monitor control effectiveness across CIAM, authentication, and fraud domains, driving continuous improvement
* Collaborate with fraud and cybersecurity teams to support incident investigations and mitigation strategies
* Analyze alert trends and performance metrics to inform strategic improvements and risk prioritization
* Champion automation and workflow optimization for alert handling, reporting, and compliance documentation
* Ensure alignment with TD's enterprise risk management and regulatory obligations (e.g., OSFI, OCC)
* Provide mentorship and leadership within the security monitoring team, fostering a culture of accountability and innovation
Required Qualifications & Expertise
* 5+ years of experience in information security, CIAM/fraud detection, or observability engineering within financial services
* Hands-on expertise with Splunk, Datadog, Dynatrace, and Databricks for alert creation, analytics, and dashboarding
* Strong understanding of CIAM, authentication protocols, and fraud risk indicators in regulated environments
* Experience designing governance frameworks and control monitoring programs aligned with financial compliance standards
* Proven ability to lead cross-functional teams and drive incident response processes across geographies
* Excellent communication and documentation skills, with a strategic mindset and attention to regulatory detail
Who We Are:
TD is one of the world's leading global financial institutions and is the fifth largest bank in North America by branches/stores. Every day, we deliver legendary customer experiences to over 27 million households and businesses in Canada, the United States and around the world. More than 95,000 TD colleagues bring their skills, talent, and creativity to the Bank, those we serve, and the economies we support. We are guided by our vision to Be the Better Bank and our purpose to enrich the lives of our customers, communities and colleagues.
TD is deeply committed to being a leader in customer experience, that is why we believe that all colleagues, no matter where they work, are customer facing. As we build our business and deliver on our strategy, we are innovating to enhance the customer experience and build capabilities to shape the future of banking. Whether you've got years of banking experience or are just starting your career in financial services, we can help you realize your potential. Through regular leadership and development conversations to mentorship and training programs, we're here to support you towards your goals. As an organization, we keep growing - and so will you.
Our Total Rewards Package
Our Total Rewards package reflects the investments we make in our colleagues to help them and their families achieve their financial, physical, and mental well-being goals. Total Rewards at TD includes a base salary, variable compensation, and several other key plans such as health and well-being benefits, savings and retirement programs, paid time off, banking benefits and discounts, career development, and reward and recognition programs. Learn more
Additional Information:
We're delighted that you're considering building a career with TD. Through regular development conversations, training programs, and a competitive benefits plan, we're committed to providing the support our colleagues need to thrive both at work and at home.
Please be advised that this job opportunity is subject to provincial regulation for employment purposes. It is imperative to acknowledge that each province or territory within the jurisdiction of Canada may have its own set of regulations, requirements.
Colleague Development
If you're interested in a specific career path or are looking to build certain skills, we want to help you succeed. You'll have regular career, development, and performance conversations with your manager, as well as access to an online learning platform and a variety of mentoring programs to help you unlock future opportunities. Whether you have a passion for helping customers and want to expand your experience, or you want to coach and inspire your colleagues, there are many different career paths within our organization at TD - and we're committed to helping you identify opportunities that support your goals.
Training & Onboarding
We will provide training and onboarding sessions to ensure that you've got everything you need to succeed in your new role.
Interview Process
We'll reach out to candidates of interest to schedule an interview. We do our best to communicate outcomes to all applicants by email or phone call.
Accommodation
Your accessibility is important to us. Please let us know if you'd like accommodations (including accessible meeting rooms, captioning for virtual interviews, etc.) to help us remove barriers so that you can participate throughout the interview process.
We look forward to hearing from you!
Language Requirement (Quebec only):
Sans Objet
Auto-Apply