Security Engineer IV - Exposure Management
Security architect job in Saint Louis, MO
Innovate here. And see your ideas come to life. It's an exciting time to work in tech at Edward Jones. We are making massive investments in emerging technologies to improve how we work with our clients and with each other. Relationships are the focus of our business model. And working in Technology here means using your skills to build, deliver and maintain the technologies that enable us to deepen and support those relationships. The best part? We develop and create our own industry-leading solutions internally. And you can be a part of it. Working with emerging new technologies. Creating platforms, programs and experiences that change how we work together - and support our client-first focus. Changing the future of our firm, the industry and the advisor-client relationship.
Job Overview
Position Schedule: Full-Time
This job posting is anticipated to remain open for 30 days, from 18-Nov-2025. The posting may close early due to the volume of applicants.
Team Overview:
The Exposure Management team protects Edward Jones by identifying, prioritizing, and reporting vulnerabilities across all assets that handle business information. As part of a team, you will manage scanning platforms and workflows to proactively prevent exploitation and strengthen the firm's security posture.
What You'll Do:
Design, implement, and administer vulnerability scanning platforms and appliances.
Manage internal and external scans, analyze results, and ensure accurate detection of vulnerabilities.
Optimize scanning workflows and tune configurations for efficiency across diverse technology stacks.
Collaborate with cross-functional teams to remediate findings and improve security processes.
Mentor and train associates in your area of expertise.
Provide technical leadership, including guidance on tools, methodologies, frameworks, best practices, and standards.
Research and implement technical improvements to enhance security posture.
Represent the team in cross-functional groups and communicate issues and resolutions to stakeholders.
Conduct feasibility studies and cost-benefit analyses for system requirements.
Ensure prudent use of the firm's financial resources.
Edward Jones' compensation and benefits package includes medical and prescription drug, dental, vision, voluntary benefits (such as accident, hospital indemnity, and critical illness), short- and long-term disability, basic life, and basic AD&D coverage. Short- and long-term disability, basic life, and basic AD&D coverage are provided at no cost to associates. Edward Jones offers a 401k retirement plan, and tax-advantaged accounts: health savings account, and flexible spending account. Edward Jones observes ten paid holidays and provides 15 days of vacation for new associates beginning on January 1 of each year, as well as sick time, personal days, and a paid day for volunteerism. Associates may be eligible for bonuses and profit sharing. All associates are eligible for the firm's Employee Assistance Program. For more information on the Benefits available to Edward Jones associates, please visit our benefits page.
Hiring Minimum: $99200
Hiring Maximum: $168900
Qualified applicants with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act. Edward Jones is prohibited from hiring individuals with certain specified criminal history as set forth in Section 3(a)(39) and 15(b)(4) and Rule 17a-3(a)(12) of the Securities and Exchange Act of 1934, and conducts background reviews consistent with FINRA Rule 3110(e). A copy of a notice regarding the provisions of the Los Angeles County Fair Chance Ordinance is available at: dcba.lacounty.gov/wp-content/uploads/2024/08/FCOE-Official-Notice-Eng-Final-8.30.2024.pdf.
Read More About Job Overview
Skills/Requirements
What Experience You'll Need:
Bachelor's degree in information technology, Telecommunications, Engineering, or equivalent experience.
Minimum of 7 years of experience in a relevant technical discipline.
Subject matter expertise in information systems, with experience across multiple platforms or technologies (networking, computing, operating systems, data, software deployment, patching, software infrastructure, vulnerability management, security).
Ability to design systems and analyze requirements for feasibility and cost-effectiveness.
Proven ability to provide strategic direction and technical leadership aligned with firm objectives.
Strong interpersonal and communication skills (written and verbal); persuasive and credible communicator.
Ability to manage multiple large and complex projects simultaneously.
Knowledge of brokerage or financial industry processes is preferred.
Familiarity with project management concepts and system development methodologies.
Ability to quickly learn and apply emerging technologies and adapt to change.
Demonstrates accuracy, thoroughness, and initiative to improve processes and systems.
Build strong team environments through mentoring and collaboration.
Experienced in globalization considerations for technology design and deployment in multinational environments.
Current home-based associates please note: Even as a hybrid posted role you are eligible to apply and, if selected, may retain your home-based status. However future business or regulatory needs may require on-site work and some roles may carry a preference for hybrid presence.
**External Candidates that live within in a commutable distance from our Tempe, AZ and St. Louis, MO home office locations are expected to work in the office three days per week, with preference for Tuesday through Thursday.**
Read More About Skills/Requirements
Awards & Accolades
At Edward Jones, we are building a place where everyone feels like they belong. We're proud of our associates' contributions to the firm and the recognitions we have received.
Check out our U.S. awards and accolades: Insights & Information Blog Postings about Edward Jones
Check out our Canadian awards and accolades: Insights & Information Blog Postings about Edward Jones
Read More About Awards & Accolades
About Us
Join a financial services firm where your contributions are valued. Edward Jones is a Fortune 500¹ company where people come first. With over 9 million clients and 20,000 financial advisors across the U.S. and Canada, we're proud to be privately-owned, placing the focus on our clients rather than shareholder returns.
Behind everything we do is our purpose: We partner for positive impact to improve the lives of our clients and colleagues, and together, better our communities and society. We are an innovative, flexible, and inclusive organization that attracts, develops, and inspires performance excellence and a sense of belonging.
People are at the center of our partnership. Edward Jones associates are seen, heard, respected, and supported. This is what we believe makes us the best place to start or build your career.
View our Purpose, Inclusion and Citizenship Report.
¹Fortune 500, published June 2024, data as of December 2023. Compensation provided for using, not obtaining, the rating.
Edward Jones does not discriminate on the basis of race, color, gender, religion, national origin, age, disability, sexual orientation, pregnancy, veteran status, genetic information or any other basis prohibited by applicable law.
#LI-HO
Senior Security Engineer - IAM Analyst
Security architect job in Saint Louis, MO
Innovate here. And see your ideas come to life. It's an exciting time to work in tech at Edward Jones. We are making massive investments in emerging technologies to improve how we work with our clients and with each other. Relationships are the focus of our business model. And working in Technology here means using your skills to build, deliver and maintain the technologies that enable us to deepen and support those relationships. The best part? We develop and create our own industry-leading solutions internally. And you can be a part of it. Working with emerging new technologies. Creating platforms, programs and experiences that change how we work together - and support our client-first focus. Changing the future of our firm, the industry and the advisor-client relationship.
Job Overview
Position Schedule: Full-Time
This job posting is anticipated to remain open for 30 days, from 01-Dec-2025. The posting may close early due to the volume of applicants.
Team Overview:
As an IAM Analyst you will work independently to identify and define IAM solution requirements for both existing capabilities and the expansion of new features. You will ensure that all platforms within your span of responsibility meet your customer's requirements; designed, built, documented, and maintained in adherence with the Firm's standards and architectural patterns; and are managed to the highest level for performance, stability, and security. Serving as a Security practicioner, you will bring deep industry knowledge and experience to understand the threat landscape and use that knowledge to shape the platforms that the Firm depends on for critical identity lifecycle functions. In this role you will regularly engage in leading-edge technology initiatives, including research, vetting, and adoption of emerging technologies, tools and methodologies in alignment with the overall security strategy.
What You'll Do:
Identify and implement opportunities to improve solutions that combat advanced and relevant threats while considering integration into the environment, stability, availability, disaster recovery, and cost-effectiveness.
Serve as a subject matter expert for the identity management platform (Saviynt) and be a key contributor to stabilization and expansion efforts.
Lead conversations centered on solving for complex business requirements in solution designs, and ensuring compliance with internal standards, policies, and regulatory requirements.
Identify potential gaps in existing IAM processes or systems and recommending solutions to improve security and efficiency.
Manage SOX compliance, auditing, and access review processes.
Collaborate with internal teams and stakeholders to understand requirements and develop solutions.
Effectively document solutions and configurations for future reference.
Produce, maintain, and facilitate distribution of training resources to effectively empower key stakeholders with the information needed to meet Firm objectives and/or drive adoption of new processes.
Establish and maintain effective communications and relationships across key departments, business areas, and vendors, including supporting engagements with key vendors to ensure the correct level of support to the Firm and drive solution roadmaps to meet Firm expectations.
Creating and maintaining documentation for IAM processes, procedures, solution designs, requirements, etc.
Edward Jones' compensation and benefits package includes medical and prescription drug, dental, vision, voluntary benefits (such as accident, hospital indemnity, and critical illness), short- and long-term disability, basic life, and basic AD&D coverage. Short- and long-term disability, basic life, and basic AD&D coverage are provided at no cost to associates. Edward Jones offers a 401k retirement plan, and tax-advantaged accounts: health savings account, and flexible spending account. Edward Jones observes ten paid holidays and provides 15 days of vacation for new associates beginning on January 1 of each year, as well as sick time, personal days, and a paid day for volunteerism. Associates may be eligible for bonuses and profit sharing. All associates are eligible for the firm's Employee Assistance Program. For more information on the Benefits available to Edward Jones associates, please visit our benefits page.
Hiring Minimum: $99200
Hiring Maximum: $168900
Qualified applicants with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act. Edward Jones is prohibited from hiring individuals with certain specified criminal history as set forth in Section 3(a)(39) and 15(b)(4) and Rule 17a-3(a)(12) of the Securities and Exchange Act of 1934, and conducts background reviews consistent with FINRA Rule 3110(e). A copy of a notice regarding the provisions of the Los Angeles County Fair Chance Ordinance is available at: dcba.lacounty.gov/wp-content/uploads/2024/08/FCOE-Official-Notice-Eng-Final-8.30.2024.pdf.
Read More About Job Overview
Skills/Requirements
What Experience You'll Need:
Minimum 4-5 years experience
In-depth understanding of Saviynt product functionality, including provisioning, access certification, SOD, analytics, RBAC, workflow, email notifications, etc.
Experience designing JML flows for Saviynt automation.
Experience integrating applications with Saviynt using various connectors.
Solid understanding of workflows in ARS and the ability to leverage Saviynt analytics tools.
Experience managing SOX compliance, auditing, and access review processes within Saviynt.
Experience with configuration management of Rules Technical Users, UI Global Configurations, Backend configurations, and GSP files.
Excellent written and verbal communication skills.
Experience with APIs and integrations
Strong analytical and problem-solving skills
Excellent communication and collaboration skills
Experience using ticketing systems (e.g., Jira)
**Candidates that live within in a commutable distance from our Tempe, AZ and St. Louis, MO home office locations are expected to work in the office three days per week, with preference for Tuesday through Thursday.**
Current INTERNAL home-based associates: While this role is posted as hybrid, if selected and accepted, you may retain your home-based status. Edward Jones intends in good faith to continue offering the role as home-based, though future business or regulatory needs may require on-site work.
Read More About Skills/Requirements
Awards & Accolades
At Edward Jones, we are building a place where everyone feels like they belong. We're proud of our associates' contributions to the firm and the recognitions we have received.
Check out our U.S. awards and accolades: Insights & Information Blog Postings about Edward Jones
Check out our Canadian awards and accolades: Insights & Information Blog Postings about Edward Jones
Read More About Awards & Accolades
About Us
Join a financial services firm where your contributions are valued. Edward Jones is a Fortune 500¹ company where people come first. With over 9 million clients and 20,000 financial advisors across the U.S. and Canada, we're proud to be privately-owned, placing the focus on our clients rather than shareholder returns.
Behind everything we do is our purpose: We partner for positive impact to improve the lives of our clients and colleagues, and together, better our communities and society. We are an innovative, flexible, and inclusive organization that attracts, develops, and inspires performance excellence and a sense of belonging.
People are at the center of our partnership. Edward Jones associates are seen, heard, respected, and supported. This is what we believe makes us the best place to start or build your career.
View our Purpose, Inclusion and Citizenship Report.
¹Fortune 500, published June 2024, data as of December 2023. Compensation provided for using, not obtaining, the rating.
Edward Jones does not discriminate on the basis of race, color, gender, religion, national origin, age, disability, sexual orientation, pregnancy, veteran status, genetic information or any other basis prohibited by applicable law.
#LI-HO
Cyber Security Architect
Security architect job in Bridgeton, MO
We are seeking a Cyber Security Architect to join their team. As a Cyber Security Architect, you will be part of the Cybersecurity Department supporting the IT teams. The ideal candidate will demonstrate strategic thinking, technical expertise, and collaborative skills which will align successfully in the organization.
**Job Title:** Cyber Security Architect
**Location:** St. Louis, Missouri
**Pay Range: 135K - 145K**
We're seeking a skilled **Cybersecurity Architect/Engineer** to design and implement robust security solutions across both IT and OT environments. This role is ideal for someone who thrives in complex, hybrid infrastructures and is passionate about protecting critical systems from evolving threats.
**What You'll Do**
+ Architect and deploy enterprise-grade cybersecurity solutions across IT and OT landscapes
+ Develop and maintain security architecture standards and documentation
+ Evaluate and implement technologies including SIEM, EDR, firewalls, IAM, DLP, DSPM, and Zero Trust frameworks
+ Ensure compliance with key regulatory frameworks such as NIST, ISO 27001, CMMC, and SOC 2
+ Lead incident response efforts, conduct forensic investigations, and perform proactive threat hunting and risk assessment
**What You Bring**
+ Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field
+ 4-7 years of progressive experience in cybersecurity, including at least 2 years in OT environments (e.g., manufacturing, energy, utilities)
+ Deep understanding of ICS/SCADA systems, PLC networks, and industrial protocols (Modbus, OPC UA, DNP3)
+ Hands-on experience with vulnerability assessments, network segmentation, IDS/IPS, and Zero Trust in OT settings
+ Advanced certifications such as **CISSP** , **CISM** , or **OSCP** are highly preferred
**What's in it for me?**
+ Opportunity to work in a dynamic and innovative manufacturing environment
+ Engage in impactful projects that enhance organizational security posture
+ Collaborate with a diverse and talented team of professionals
+ Continuous learning and professional development opportunities
+ Be part of a company recognized for its commitment to diversity and ethical standards
**Upon completion of waiting period consultants are eligible for:**
+ Medical and Prescription Drug Plans
+ Dental Plan
+ Vision Plan
+ Health Savings Account
+ Health Flexible Spending Account
+ Dependent Care Flexible Spending Account
+ Supplemental Life Insurance
+ Short Term and Long Term Disability Insurance
+ Business Travel Insurance
+ 401(k), Plus Match
+ Weekly Pay
If this is a role that interests you and you'd like to learn more, click apply now and a recruiter will be in touch with you to discuss this great opportunity. We look forward to speaking with you!
**About ManpowerGroup, Parent Company of: Manpower, Experis, Talent Solutions, and Jefferson Wells.**
_ManpowerGroup (NYSE: MAN), the leading global workforce solutions company, helps organizations transform in a fast-changing world of work by sourcing, assessing, developing, and managing the talent that enables them to win. We develop innovative solutions for hundreds of thousands of organizations every year, providing them with skilled talent while finding meaningful, sustainable employment for millions of people across a wide range of industries and skills. Our expert family of brands -_ **_Manpower, Experis, Talent Solutions, and Jefferson Wells_** _- creates substantial value for candidates and clients across more than 75 countries and territories and has done so for over 70 years. We are recognized consistently for our diversity - as a best place to work for Women, Inclusion, Equality and Disability and in 2023 ManpowerGroup was named one of the World's Most Ethical Companies for the 14th year - all confirming our position as the brand of choice for in-demand talent._
ManpowerGroup is committed to providing equal employment opportunities in a professional, high quality work environment. It is the policy of ManpowerGroup and all of its subsidiaries to recruit, train, promote, transfer, pay and take all employment actions without regard to an employee's race, color, national origin, ancestry, sex, sexual orientation, gender identity, genetic information, religion, age, disability, protected veteran status, or any other basis protected by applicable law.
Application Security Architect
Security architect job in Saint Louis, MO
The Application Security Architect is responsible for designing, implementing, and maintaining the security of the company's applications, systems, and networks. The position requires expertise in security principles, methods, and technologies related to application development, deployment, and maintenance. The Application Security Architect is also responsible for conducting security assessments and audits, identifying vulnerabilities, and recommending solutions to mitigate risks.
Essential Duties and Responsibilities
Design and implement application security strategies, policies, and procedures that meet business and regulatory requirements.
Work with software development teams to integrate security into the development process and ensure that applications are built securely from the ground up.
Evaluate application code and conduct threat modeling to identify potential security risks and recommend solutions.
Conduct vulnerability assessments and penetration testing to identify security vulnerabilities and weaknesses in applications, systems, and networks.
Develop and maintain security metrics and key performance indicators (KPIs) to measure the security program's effectiveness.
Collaborate with internal and external stakeholders to communicate security risks, guide best practices, and facilitate compliance with relevant security standards and regulations.
Develop and maintain knowledge of emerging security threats, vulnerabilities, and technologies to proactively identify and mitigate security risks.
Conduct security awareness training and education for employees to promote a security culture across the organization.
Senior IT Security Analyst
Security architect job in Edwardsville, IL
The Senior IT Security Analyst is responsible for managing activities relating to monitoring and responding to security events. The analyst is responsible for monitoring application, host, and network threats, including external threat actors and rogue insiders. As a trusted member of the Information Security team and industry community, the analyst works closely with internal technical teams, business units, and external entities aligned with the business, including private intelligence-sharing groups, law enforcement, and government agencies.
The analyst is responsible for conducting in-depth research, documenting threats, understanding the risk to the business, and sharing information with those who need to know. Analysts are expected to continually adapt to stay a step ahead of cyber attackers and stay up to date on the latest methods attackers use to infiltrate computer systems. Analysts in this role are expected to consistently learn and grow. This is not a passive career opportunity, but rather one that requires a passion for security and rigor to protect the business.
Duties & Responsibilities
* Responsible for developing, managing, and maintaining threat intelligence and threat hunting program and processes
* Regularly research and identify emerging threats, TTPs in public and closed forums, and work with colleagues to access risk and implement/validate controls as necessary.
* Assist with Security Operations activities, including but not limited to, triage of alarms/alerts, and performing technical security assessments.
* Participate in a call tree for outsourced Security Operations Center to assist with triage and remediation of critical and high rated alerts that are escalated both during and after business hours.
* Research and recommend solutions to fulfill regulatory compliance with all standards set forth by FFIEC guidelines, Sarbanes Oxley, Gramm-Leach-Bliley and other regulations applicable to the financial services industry and publicly traded companies.
* Perform periodic review of IT procedures and security of all systems in order to maintain integrity of company and customer data.
* Document and perform verification of IT related changes in accordance with Company security policies and procedures.
* Research and recommend hardware and software solutions to augment or enhance existing security measures.
* Stay current in events and trends in IT security.
* Investigate and report any security violations and incidents and ensure proper protection and corrective measures have been taken when an incident or vulnerability has been discovered.
* Conduct scheduled reviews of key application security settings.
* Develop metrics and scorecards to measure risk to the organization, as well as effectiveness and efficiency of SOC associates.
* Assist in process development and improvements to maximize the efficiency and effectiveness of the department and related programs
* Supports audit and incident processes, as required
* Monitor and support internal SEIM systems, reports, and searches
* Monitor and support internal phishing email report systems and reports
* Partner and establish relationships to work closely with cross-functional teams consisting of representatives in the business
* Develops strong liaison relationships with key internal business and technology teams
* Coach level I & IIs on security domains and program processes
* Depending on need, VP Security may determine a Team Lead designation for Level III role
* Participate in security work streams for a variety of enterprise projects and initiatives
* Determine and communicate security risk postures to partners and leaders as appropriate
Education & Experience
Knowledge of:
* Strong experience with threat information sharing and threat hunting processes to proactively identify potential or existing threats in medium to large environments.
* Proficient with SIEM tools, threat intelligence platforms, and security orchestration, automation, and response (SOAR) solutions to centralize and manage the incident and remediation workflow.
* Knowledge and understanding of networking concepts and securing traffic across LAN, WAN, and Internet infrastructure.
* Proficiency in operating systems such as Windows, Linux, and MacOS to effectively research and analyze threats in a sandbox environment, and respond to incidents.
* Experience in incident handling and investigation including using formal chain-of-custody methods, forensic tools, and best practices.
* Applicable knowledge of adversary tactics, techniques, and procedures (TTPs), MITRE ATT&CK framework, and CVSS.
* Capable of scripting in Python, Bash, Perl, RegEx, or PowerShell.
* Knowledge and understanding of networking concepts and securing traffic across LAN, WAN, and Internet infrastructure.
* Familiarity with cloud architectures, security standards, and best practices
* Strong oral and written communication skills
* Strong organizational skills and attention to detail
* Excellent interpersonal skills
Ability to:
* Ability to analyze incident logs, attack vectors, and understand vulnerabilities and exploits.
* Take independent action within established options and develops new procedures and approaches to problems when necessary
* Analyze assignments based on a wide knowledge of many factors where application of advanced or technical concepts are required
* Self-starter requiring minimal supervision
* Highly organized and efficient.
* Demonstrated strategic and tactical thinking.
* Stays current with the evolving threat landscape.
* Perform duties and make decisions under frequent time pressures
Education and Training:
* (Preferred) Bachelor's degree in Computer Science, Management Information Systems (MIS) or related field or equivalent work experience.
* On-the-job training in relevant roles relating to security operations, threat intel and hunting, system administration, incident response, or equivalent
* Security+, CySA+, GCIH, CSA, CCSP or similar certification; or willingness and ability to pursue certification/re-certification within the first six months of hire.
* At least 5 years' experience in security operations center environments, threat intelligence/hunting, or security systems administration
* Requires knowledge of Microsoft Office and other productivity tools
Benefits and Compensation
Salary offered is based on factors, including but not limited to, the job duties, required qualifications and relevant experience, and local market trends. The role may be eligible for bonus or incentives based on company and individual performance.
(Base Pay Range: $86,000 - $123,000/year)
Busey provides a competitive Total Rewards package in return for your time, talents, efforts and ultimately, results. Your personal and professional well-being-now and in the years to come-are important to us. Busey's Total Rewards include a competitive benefits package offering 401(k) match, profit sharing, employee stock purchase plan, paid time off, medical, dental, vision, company-paid life insurance and long-term disability, supplemental voluntary life insurance, short-term and long-term disability, wellness incentives and an employee assistance program. In addition, eligible associates may take advantage of pre-tax health savings accounts and flexible spending accounts. Visit Busey Total Rewards for more information.
Equal Opportunity
Busey values a diverse and inclusive workplace and strives to recruit, develop and retain individuals with exceptional talent. A team with diverse talent, working together, is essential to Busey's commitment of delivering service excellence. Busey is an Equal Opportunity Employer including Disability/Vets. Visit Busey.com/Careers to learn more about Busey's Equal Opportunity Employment.
Unsolicited Resumes
Busey Bank, and its subsidiaries, does not accept any liability for fees for resumes from recruiters or employment agencies ("Agency"), without a binding, written recruitment agreement between Busey and Agency describing the services and specific job openings ("Agreement"). Busey may consider any candidate for whom an Agency has submitted an unsolicited resume and explicitly reserves the right to hire those candidate(s) without any financial obligation to the Agency, unless an Agreement is in place. Any email or verbal contact with any Busey associate is inadequate to create a binding agreement. Agencies without an Agreement are requested not to contact any associates of Busey with recruiting inquiries or resumes. Busey respectfully requests no phone calls or emails.
Application Deadline 11/15/25
Auto-ApplyInformation System Security Manager (ISSM), Public Sector
Security architect job in Saint Louis, MO
Our Security team works on operational issues at the leading edge of machine learning technology. You will join a creative and solutions-oriented team collaborating with internal teams at Scale and externally with our customers. Scale is looking for an experienced security and compliance professional to support Assessment and Authorization and agency audit activities for Scale's products that are offered in the US Government and global Public Sector space. We are looking for relentlessly curious, deliberately open-minded, and action-oriented generalists who can design effective legal advice, internal policies, and operational processes while employing an empathetic interpersonal style. If you enjoy solving novel and challenging problems and building strong teams and relationships while doing it, we'd love to hear from you!
You will:
Lead public sector security compliance projects and audits (FedRAMP HIGH, DoD Cloud Computing SRG IL4/IL5/IL6 , NIST 800-53 rev 5, NIST 800-171/CMMC, Risk Management Framework)
Collaborate with product, engineering, security, operations, people operations, and legal to implement new technical, administrative, and operational controls
Work with 3PAOs and federal government AOs to achieve compliance certifications and reports
Ensure the implementation, oversight, monitoring, and maintenance of security configurations, practices, and procedures
Serve as a liaison between system owners and other security personnel, ensuring that selected security controls are effectively implemented and maintained throughout the lifecycle of projects
Act as a liaison between system owners and other security personnel to facilitate effective communication and collaboration
Develop, maintain, review, and update system security documentation on a continuous basis
Conduct required vulnerability scans and develop Plan of Action and Milestones (POAMs) in response to reported security vulnerabilities. Manage risks by coordinating correction or mitigation actions and tracking the completion of POAMs
Coordinate system owner concurrence for correction or mitigation actions and monitor security controls to maintain security Authorized To Operate (ATO)
Upload security control evidence to the Governance, Risk, and Compliance (GRC) application (eMASS or Xacta) to support security control implementation during the monitoring phase
Lead Risk Management Assessment and Authorization (A&A) processes for deployments
Perform Cloud system risk assessments, enhance process workflows, and develop new processes
Implement all applicable manual Security Technical Implementation Guides (STIGs), vendor hardening guides and ensuring timely installation of all available patches
Create and maintain ATO packages
Lead security compliance reviews for new products, changes, and features
Proactively evaluate and advise the business on new and evolving certification programs, requirements, and technologies
Develop and provide training to improve the security awareness and knowledge for all employees and contractors
Required:
Active US Top Secret security clearance with minimum IAT Level 2 certification (Security +, CASP, or similar)
Ideally you'd have:
Experience implementing and maintaining some of the following frameworks and standards: FedRAMP, DoD Cloud Computing SRG, NIST 800-171, NIST 800-53, CMMC, NIST 800-53.
STIG/RMF policy knowledge & implementation, including validating compliance via ACAS and other relevant tests.
Experience in project management and taking projects from conception to launch
An ability to translate between business and technical risk and communicate clearly to leadership
Excellent organizational and communications skills
Understanding of cybersecurity controls for cloud service providers
Knowledge of AWS and other government authorized cloud services
5+ years of security compliance or technology audit related experience
Nice-to-haves:
Bachelor's degree in accounting, information systems, computer science, or a related field
Compensation packages at Scale for eligible roles include base salary, equity, and benefits. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position, determined by work location and additional factors, including job-related skills, experience, interview performance, and relevant education or training. Scale employees in eligible roles are also granted equity based compensation, subject to Board of Director approval. Your recruiter can share more about the specific salary range for your preferred location during the hiring process, and confirm whether the hired role will be eligible for equity grant. You'll also receive benefits including, but not limited to: Comprehensive health, dental and vision coverage, retirement benefits, a learning and development stipend, and generous PTO. Additionally, this role may be eligible for additional benefits such as a commuter stipend.
The base salary range for this full-time position in the location of Washington DC is:$195,800-$245,300 USD
Compensation packages at Scale for eligible roles include base salary, equity, and benefits. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position, determined by work location and additional factors, including job-related skills, experience, interview performance, and relevant education or training. Scale employees in eligible roles are also granted equity based compensation, subject to Board of Director approval. Your recruiter can share more about the specific salary range for your preferred location during the hiring process, and confirm whether the hired role will be eligible for equity grant. You'll also receive benefits including, but not limited to: Comprehensive health, dental and vision coverage, retirement benefits, a learning and development stipend, and generous PTO. Additionally, this role may be eligible for additional benefits such as a commuter stipend.
The base salary range for this full-time position in the location of St. Louis is:$195,800-$245,300 USD
PLEASE NOTE:
Our policy requires a 90-day waiting period before reconsidering candidates for the same role. This allows us to ensure a fair and thorough evaluation of all applicants.
About Us:
At Scale, our mission is to develop reliable AI systems for the world's most important decisions. Our products provide the high-quality data and full-stack technologies that power the world's leading models, and help enterprises and governments build, deploy, and oversee AI applications that deliver real impact. We work closely with industry leaders like Meta, Cisco, DLA Piper, Mayo Clinic, Time Inc., the Government of Qatar, and U.S. government agencies including the Army and Air Force. We are expanding our team to accelerate the development of AI applications.
We believe that everyone should be able to bring their whole selves to work, which is why we are proud to be an inclusive and equal opportunity workplace. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability status, gender identity or Veteran status.
We are committed to working with and providing reasonable accommodations to applicants with physical and mental disabilities. If you need assistance and/or a reasonable accommodation in the application or recruiting process due to a disability, please contact us at accommodations@scale.com. Please see the United States Department of Labor's
Know Your Rights poster
for additional information.
We comply with the United States Department of Labor's
Pay Transparency provision
.
PLEASE NOTE: We collect, retain and use personal data for our professional business purposes, including notifying you of job opportunities that may be of interest and sharing with our affiliates. We limit the personal data we collect to that which we believe is appropriate and necessary to manage applicants' needs, provide our services, and comply with applicable laws. Any information we collect in connection with your application will be treated in accordance with our internal policies and programs designed to protect personal data. Please see our privacy policy for additional information.
Auto-ApplySecurity Engineer
Security architect job in Saint Louis, MO
Job DescriptionSecurity Engineer Position: Direct HireLocation: Bridgeton, MO. If not, local you must be willing to relocate.Salary: $95K - $140K (Depending on experience).Pay Frequency: Semi Monthly.Hours: M - F (8 to 5) Fully On-Site.Status: Must be a US citizen.Travel: N/A.Benefits: PTO, Holiday Pay, Healthcare coverage, Profit-Sharing, Tuition Reimbursement, Parental Leave and free onsite fitness & rec center. Experience Level: Mid to Senior.Summary: Our client is seeking a Security Engineer to join their team.Duties:
Design, implement, manage, maintain, improve, and troubleshoot company's various security systems, including but not limited to Data Loss Prevention (DLP), SIEM and UEBA, endpoint protection, and data security/auditing platforms.
Analyze and audit systems, software, processes, implementations, and environments for compliance with policies, regulations, and security best practices; and recommend and implement refinements and enhancements, in collaboration with individuals and teams.
Conduct threat, vulnerability, and risk assessments, at times in collaboration with external auditors, to understand and eliminate potential system and network vulnerabilities.
Develop and improve monitoring and visibility capabilities of information systems, and act as a technical leader for security incident detection, response, handling, and forensics.
Provide reporting on incidents, investigations, vulnerabilities, trends, conditions, and events.
Remain current on information security topics, trends, events, and developments.
May occasionally provide end-user security training.
Provide end-user support as necessary.
Provide exceptional customer service while acting ethically and maintaining business confidentiality.
Provide after-hours support as required and be able to identify critical issues that require urgent response.
Additional duties as assigned.
Skills Needed:
7+ years of experience in Information Technology required; inclusive of up to 4 years of relevant education, including 3+ years of experience in security.
Must have demonstrable experience with:
Microsoft/Office 365 Security landscape.
Azure and on-premises Active Directory.
PowerShell and Regular Expressions.
Software Development and/or Development Security Operations.
Performing and managing proactive risk identification and mitigation, including penetration testing, network vulnerability assessments, and system risk profiling.
Security incident detection, response, handling, and forensics.
Must understand networking concepts, protocols, and services.
Must have excellent verbal and written communication skills.
Must possess a very strong troubleshooting methodology to tackle issues efficiently.
Must be self-starting and self-sufficient to complete tasks in a timely and effective manner.
Product Security Engineering 2
Security architect job in Saint Charles, MO
JOB TITLE: Product Security Engineering 2 PAY RATE: $53-67/hour
We are a national aerospace and defense staffing agency seeking highly qualified candidates for a position with a top-tier client.
Job Details:
Job Type: Contract (12 months with potential for extension)
Clearance: Active Top Secret U.S. Security Clearance required (must be active within the last 24 months)
Industry: Aerospace / Defense / Aviation
Benefits: Medical, dental, and vision (Cigna)
Perks: Bonus potential + Priority access via Tier 1 supplier
Openings Nationwide: Thousands of opportunities across the U.S.
Qualifying Questions:
Are you a U.S. person as defined under ITAR regulations?
Do you meet the educational and experience requirements for this role?
Can you commute to the job location or relocate if necessary?
Summary:
Assess organization-wide security and privacy risks, updating assessment results on an ongoing basis.
Perform system analysis and develop system tests for cyber threats, cybersecurity evaluations, and large-scale event assessments.
Ensure adherence to the product security engineering development lifecycle, emphasizing clear requirements development and verification (using CAMEO).
Conduct criticality analyses, collaborate with suppliers, identify critical components, and integrate them into overall system designs.
Perform cyber risk assessments and develop mitigation plans (e.g., POA&Ms, SCRM) using tools including but not limited to CAMEO.
Support and facilitate ATO/IATT packages, including processing IAVMs and CTOs.
Perform software assurance tasks, including developing software assurance risk reports.
Support proposal development efforts (e.g., BOE generation, GR&A development, trade studies).
Assist with the engineering installation and analysis of patches, updates, and upgrades to assess system impact.
Attend and facilitate program boards, collect data, and manage project documentation and collaboration.
Apply Security Technical Implementation Guides (STIGs) and manage Cyber Tasking Orders (CTOs).
Document and verify all installation and configuration steps for labs and operational deliveries.
Provide feedback to Cyber Leadership and engineers to improve tools and processes.
Collaborate with Information System Security Officers (ISSOs) to ensure compliance with cybersecurity standards and regulations.
Support cyber threat intelligence, scanning, patching, remediation, and tool/application development.
Assist in compliance activities including TEMPEST, DFARS, COMSEC, and CNSSI.
Develop tools for cyber forensics and identify opportunities for efficiency and productivity improvements.
Perform system analysis trade studies to define technical concepts and solutions.
Requirements:
Active Top Secret U.S. Security Clearance required (must be active within the last 24 months)
Bachelor's degree (or equivalent technical education) in engineering, engineering technology, computer science, data science, mathematics, physics, or chemistry.
2 or more years of related experience, or an equivalent combination of education and experience.
Current DoD 8570 certification at IAT Level II / IAM Level I or higher (e.g., Security+, GSEC, SCNP, SSCP, CISSP, CISA, GSE, SCNA).
1+ years of experience in product security or cybersecurity engineering.
1+ years of experience with cybersecurity frameworks (NIST, OWASP, DFARS).
Strong analytical, collaboration, communication, and organizational skills.
ABET accreditation preferred but not required.
Must be a U.S. Citizen (as defined by ITAR).
Preferred Qualifications:
Proficiency with CAMEO.
2+ years of Windows/RHEL system administration experience, including tuning and troubleshooting cyber tools (ESS/HBSS, ConfigOS, Splunk, etc.).
2+ years of experience configuring and scripting audit tools.
Experience with Software Assurance (SwA) static and/or dynamic code analysis tools (e.g., Fortify).
Familiarity with FISMA/RMF and NIST 800-53 requirements.
Experience leading cyber test and evaluation at system or component level.
Strong written and verbal communication skills with the ability to simplify complex technical issues.
Understanding of DoD defense systems architectures, communications systems, and test/data analysis methods.
About Us:
The Structures Company is a premier national aerospace and defense staffing agency specializing in contract, contract-to-hire, and direct hire placements. We deliver expert workforce solutions across engineering, IT, production, maintenance, and support roles.
As trusted partners to major aerospace OEMs and Tier 1 suppliers, we connect professionals with opportunities to grow and excel in the aviation and aerospace industries.
Eligibility Requirements:
Must be a U.S. Citizen, lawful permanent resident, or protected individual under 8 U.S.C. 1324b(a)(3) to comply with ITAR regulations.
Keywords: aerospace, aviation, engineering, maintenance, aircraft design, defense
Take your career to new heights-apply today!
Engineers - #Hotjobs
Mid-Level Product Security Engineer
Security architect job in Hazelwood, MO
Company:
The Boeing Company
Boeing is seeking an innovative and experienced Mid-Level Product Security Engineer - Avionics Development to join our growing team as part of an integrated Product Security Organization, located in Berkeley, MO, Hazelwood, MO, Saint Louis, MO, Saint Charles, MO. The successful candidate will be responsible for the development, implementation, and sustainment of product cyber security and resiliency engineering for avionics through requirements, design, analysis, build, test, production, operations, support and sustainment.
You will be a part of Boeing's Product Security Engineering Organization, which is a growing multi-disciplinary cybersecurity engineering organization that is responsible for the cyber security and resiliency of our products, platforms, and services. You will have the opportunity to shape and influence Product Security Engineering within Boeing and engage with Boeing's Product Security community. Furthermore, your effort will directly inform our Enterprise Product Security Engineering team with lessons learned and technologies, that directly enhances our commercial and defense offerings.
Primary responsibilities:
Develop and enhance the enterprise OT Vulnerability Management Program to deploy OT aware scanning and patching tooling across targeted OT environments such as production equipment, facilities, and labs
Lead the development, implementation, and sustainment of product security for Boeing avionics systems, throughout the requirements, design, analysis, build, test, production, operations, support and sustainment lifecycle
Coordinate with platforms and system-of-systems product security counterparts for requirements, activities, artifacts, and solutions
Coordinate with other engineering stakeholders - systems, software, and hardware - advising on the results of security analysis - to develop secure architectures and designs
Lead, establish, and integrate standards and processes for product security engineering for avionics development, and to meet applicable program and certification requirements
Utilize the Risk Engineering digital thread to inform product requirements surrounding cyber survivability against specified cyber threats - by performing criticality, adversity, threat analysis for avionics systems
Assessing internal customer requirements to derive strategies and detailed security requirements system and technical requirements
Executing PSE activities - security requirements, architectures, risk assessments
Documenting PSE activities and delivering PSE artifacts
Lead risk reduction and technology maturation activities - where appropriate - resulting in innovative solutions in product and services offering
Identifying and elevating product security risks to the integrated product team(s) and management
Basic Qualifications (Required Skills and Experience):
Bachelor of Science degree in Engineering, Engineering Technology (including Manufacturing Technology), Computer Science, Data Science, Mathematics, Physics, Chemistry or non-US equivalent qualifications directly related to the work statement
5+ years of related work experience or an equivalent combination of education and experience
Understanding of cybersecurity controls, frameworks, and the vulnerability management lifecycle
Experience in architecture, design, management, administration and troubleshooting of networks with a focus on security controls and firewall administration
Experience in cyber security and/or product security engineering
Experience in analysis of customer security requirements and deriving detailed security requirements, architecture & design
Demonstrated ability to identify new opportunities and engage with stakeholders to define, plan, resource and deliver solutions
Experience with the development of cybersecurity philosophies, patterns, requirements, secure architectures and designs
Experience coordinating and presenting technical content to a diverse audience, as well as preparing technical documentation
Experience performing adversity (threat) analysis, security risk assessments, and maturing the analysis throughout the development lifecycle - to inform requirements, and design
Experience generating product cyber security artifacts for customer/certifiers
Experience with defense security standards (DoDI 8510.01, ICD-503, CNSSI-1253, NIST 800-53) to perform risk analysis and provide strategic direction for system architectures, operations and delivered products
Preferred Qualifications (Desired Skills and Experience):
Security certification is desired: DoD 8570.01M / DoDD 8140.01 certification at IASAE Level II or higher (such as Security+ CE, GSEC, SSCP, CISSP, CISA, CCNA-Security)
Experience with military avionics and military platform operations
Drug Free Workplace:
Boeing is a Drug Free Workplace where post offer applicants and employees are subject to testing for marijuana, cocaine, opioids, amphetamines, PCP, and alcohol when criteria is met as outlined in our policies.
Pay & Benefits:
At Boeing, we strive to deliver a Total Rewards package that will attract, engage and retain the top talent. Elements of the Total Rewards package include competitive base pay and variable compensation opportunities.
The Boeing Company also provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and a number of programs that provide for both paid and unpaid time away from work.
The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, and the applicability of collective bargaining agreements.
Pay is based upon candidate experience and qualifications, as well as market and business considerations.
Summary Pay Range: $123,250 - $166,750
Language Requirements:
Not Applicable
Education:
Bachelor's Degree or Equivalent
Relocation:
This position offers relocation based on candidate eligibility.
Export Control Requirement:
This is not an Export Control position.
Safety Sensitive:
This is not a Safety Sensitive Position.
Security Clearance:
This position requires the ability to obtain a U.S. Security Clearance for which the U.S. Government requires U.S. Citizenship. An interim and/or final U.S. Secret Clearance Post-Start is required.
Visa Sponsorship:
Employer will not sponsor applicants for employment visa status.
Contingent Upon Award Program
This position is not contingent upon program award
Shift:
Shift 1 (United States of America)
Stay safe from recruitment fraud! The only way to apply for a position at Boeing is via our Careers website. Learn how to protect yourself from recruitment fraud - Recruitment Fraud Warning
Boeing is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national origin, gender, sexual orientation, gender identity, age, physical or mental disability, genetic factors, military/veteran status or other characteristics protected by law.
EEO is the law
Boeing EEO Policy
Request an Accommodation
Applicant Privacy
Boeing Participates in E - Verify
E-Verify (English)
E-Verify (Spanish)
Right to Work Statement
Right to Work (English)
Right to Work (Spanish)
Auto-ApplySr Security Engineer
Security architect job in Saint Louis, MO
The Cyber Security Audit Engineer will manage a variety of technical security auditing capabilities, including a holistic auditing approach of applications, databases, servers, networking devices, and software. Responsible for demonstrating skills in assessing IT process and technology risks, identifying and evaluating the design of IT controls, designing, executing and documenting IT audit tests, and making initial determination of reportable issues. Assist with HIPAA / HITECH assessments, and data breach preparedness. Will work in close coordination with team members and other business owner's partners to carry our customer requirements. Job Description: ROLES and RESPONSIBILITIES:
Design, build, implement and monitor a holistic audit program across the enterprise.
Develop understanding of appropriate business aspects, IT risks, IT control requirements, processes and systems under review.
Perform process and technology risk analysis with a cybersecurity mindset and focus, prepare process maps and flowcharts, prepare effective and efficient compliance and substantive technical approach; and execute in depth IT audit review.
Perform assessment of IT process and security controls within information systems environment.
Evaluate test results: accurately identify symptoms, root cause, problems, identify alternative controls and develop recommendations.
Perform audit reviews of technology such as applications, databases, servers, networking devices (i.e., firewalls and routers), and security tools such as IDS/IPS, anti-malware, and authentication systems (e.g., Active Directory).
Performing technology assessments in a wide variety of business environments, including:
Information Technology Operational and Cyber Security Assessments in accordance with industry frameworks, such as COBIT 5, ISO 27001, ISO 27005, and NIST SP 800-30 and Cybersecurity Framework
HIPAA Security Rule and HITECH Act Compliance
Cloud Security Compliance
Assisting clients with the performance of Business Impact Analyses (BIAs) along with the development of business continuity and disaster recovery plans (BCPs and DRPs);
Assisting organizations with all aspects of data breach and information security Incident Response preparation and management
Performing Service Organization Control Examinations in accordance with AICPA requirements (SOC 1 SSAE 16, SOC 2 AT 101, SOC 3 AT 101)
Providing data classification services
Developing information technology and security policies and procedures
Providing trusted advisory services and guidance to clients that will reduce organizational risk and improve their overall cyber security posture
Preparing reports and other deliverables that contain strategy, technical analysis, and findings in connection with our advisory and assessment engagements and communicating those results to client management
Excellent technical and interpersonal skills required.
Experience with Qualys / Nessus Vulnerability scanning tools.
Cloud Experience a plus
EXPERIENCE, QUALIFICATION AND EDUCATION
Minimum of 5 of experience with Enterprise Network, DMZ, and Security infrastructure, including design, implementation, and ongoing management and troubleshooting required.
Minimum of 5 years' experience in designing, developing, implementing, and managing solutions across cybersecurity domains (Cyber Defense, Threat and Vulnerability Management. Advanced Security Analytics, Data Security, Identity Management, Security Operations and Managed Security Services etc.)
Three years or more of professional experience or job-related experience in Information Security, or Information Technology
Extensive knowledge and skill of IT analysis which includes expertise in analyzing confidentiality, integrity, availability of complex IT systems.
Familiarity with Secure Software Development practices
Hands On experience with various programming languages or scripting languages and tools.
Effective oral and written communication skills.
Strong interpersonal skills and demonstrable leadership ability.
Certifications in one or more of the following: CISSP, CWSP, CCNP, ACE, CCNP Security, Security+, or related.
Familiarity with various operating system platforms (Linux, Windows) and databases security best practices for each.
Strong analytical and problem-solving ability.
Ability to work independently.
Senior AI Security Engineer
Security architect job in OFallon, MO
Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Senior AI Security EngineerJob Description Summary
As an Information Security Engineer specializing in AI Security, you will be at the forefront of protecting our AI systems and data. Your role will involve deep technical expertise in designing, implementing, and maintaining advanced security measures to safeguard our AI infrastructure from sophisticated threats and vulnerabilities. You will be instrumental in ensuring the robustness, confidentiality, and availability of our AI-driven solutions.
Key Responsibilities:
- Security Architecture Design: Architect and implement robust security frameworks for AI systems, including authoring of secure coding practices and secure design principles.
- Vulnerability Assessment: Identify, implement and manage tooling and methodologies for penetration testing on AI models and systems to identify and remediate security weaknesses.
- Secure AI Development: Collaborate with data scientists and software engineers to integrate security best practices into the AI development lifecycle, including secure model training, validation, and deployment. Support security engineers in the evaluation of AI systems being developed and implemented.
- Compliance and Standards: Keep track of emerging industry standards, regulations, and best practices for AI security, such as NIST, ISO, and GDPR.
- Research and Innovation: Stay abreast of the latest advancements in AI security, conduct research, and contribute to the development of innovative security solutions.
- Documentation and Reporting: Prepare and document standard operating procedures, protocols, and security reports, including assessment-based findings and recommendations for further system security enhancement.
- Advisory and Support: Provide guidance and support on security matters, including answering queries, providing feedback, and advising on best practices
- Technical Training and Mentorship: Provide technical training and mentorship to team members and stakeholders on AI security principles and practices.
- Experimentation and POCs: Design and execute experiments and proof of concepts (POCs) to validate emerging threats and security solutions. Conduct R&D to explore new methodologies and technologies for enhancing AI security.
Qualifications:
- Bachelor's or Master's degree in Computer Science, Information Security, or a related field.
- Extensive experience in information security, with a strong focus on AI security.
- In-depth knowledge of AI technologies, machine learning algorithms, and data protection techniques.
- Proven expertise in designing and implementing security measures for AI systems, including secure coding, encryption, and access controls.
- Strong analytical and problem-solving skills, with the ability to conduct vulnerability assessments and penetration testing.
- Excellent technical communication and collaboration skills to work effectively with diverse teams.
- Relevant certifications such as CISSP, CEH, OSCP, or equivalent are highly desirable.Mastercard is a merit-based, inclusive, equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law. We hire the most qualified candidate for the role. In the US or Canada, if you require accommodations or assistance to complete the online application process or during the recruitment process, please contact reasonable_accommodation@mastercard.com and identify the type of accommodation or assistance you are requesting. Do not include any medical or health information in this email. The Reasonable Accommodations team will respond to your email promptly.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
Abide by Mastercard's security policies and practices;
Ensure the confidentiality and integrity of the information being accessed;
Report any suspected information security violation or breach, and
Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
In line with Mastercard's total compensation philosophy and assuming that the job will be performed in the US, the successful candidate will be offered a competitive base salary and may be eligible for an annual bonus or commissions depending on the role. The base salary offered may vary depending on multiple factors, including but not limited to location, job-related knowledge, skills, and experience. Mastercard benefits for full time (and certain part time) employees generally include: insurance (including medical, prescription drug, dental, vision, disability, life insurance); flexible spending account and health savings account; paid leaves (including 16 weeks of new parent leave and up to 20 days of bereavement leave); 80 hours of Paid Sick and Safe Time, 25 days of vacation time and 5 personal days, pro-rated based on date of hire; 10 annual paid U.S. observed holidays; 401k with a best-in-class company match; deferred compensation for eligible roles; fitness reimbursement or on-site fitness facilities; eligibility for tuition reimbursement; and many more.
Pay Ranges
O'Fallon, Missouri: $115,000 - $184,000 USD
Auto-ApplyCloud Security Engineer
Security architect job in Saint Louis, MO
Compunnel Software Group is a New Jersey based premier information technology consulting & services company into this market for nearly two decades now; with close to two decades of experience in IT Industry which includes consulting, development, e-learning etc.
Our company is going through a tremendous growth spurt and we are now interested in personnel like you to augment the work force in the company. We have several projects starting that we are staffing for. If you think you would like to become a consultant for
Compunnel Software Group Inc
., please send me an updated copy of your resume along with a detailed summary of your work experience. I need a phone number to contact you. I look forward to possibly working with you on these positions.
We offer specialized services to our clients to meet their business objectives. Successful solutions that are valued by our clients are in industry areas such as pharmaceuticals, telecommunications, banking, finance, manufacturing, publishing and consumer products.
Job Description
Position: Cloud Security Engineer
Duration: 6+ months
Location: St. Louis, MO, 63167
Must Have:
Cloud Security
Security Patches
Cloud Security Automation Engineer
Client is seeking a Cloud Security Automation Engineer with deep technical experience in securing cloud technologies.
The successful candidate possesses out of the box thinking, the ability to collaboration with development team members, and experience with automation and solving end to end application/infrastructure security problems.
Our mission is to design and build a highly secure cloud environment without sacrificing our developers' ability to quickly innovate and deliver world class software solutions.
Responsibilities:
•
Define security best practices for our cloud platform and provide guidance to development teams.
• Build tools to monitor for compliance of security policy and automate the resolution process.
• Evangelize security throughout the enterprise and collaborate to help architect secure applications.
• Research emerging technologies and build proof of concepts to investigate better ways of meeting our control objectives.
• Collaborate with incident response, risk and compliance, product security and development teams to solve critical security problems.
• Develop an AppSec pipeline and integrate it into the agile software development process.
Required Qualifications:
•
BA/BS degree in Computer Science, Information Systems, Cyber Security or a related technical field or equivalent experience.
• At least 3 years of experience in Information Security and/or infrastructure
engineering.
• An accomplished security practitioner with a strong understanding of industry trends in all areas of security.
• Experience with building IaaS cloud based solutions including AWS, Azure, etc.. and knowledge of their network security and IAM models.
• Experience working with security vendors including evaluating and implementing new products.
Desired Qualifications:
•
Expertise in common AWS services (CloudFormation, Route53, VPC, EC2, Lambda, etc...) and their security best practices.
• Programming experience in JavaScript, Java, Scala, Python, Perl, Ruby, etc.. and their use in automating security and compliance.
• Strong understanding of security technologies including host and network based protection and detection technologies.
• Experience with vulnerability management (including: running vulnerability scans, creating reports, communicating with asset owners and giving remediation guidance).
• Experience with continuous integration and automation tools (e.g. Jenkins, Chef, Puppet, Ansible).
• Experience writing security white papers and/or presenting security products and technologies to diverse audiences.
• CISSP or CSSLP (Certified Secure Software Lifecycle Professional) certification.
Qualifications
Must Have:
Cloud Security
Security Patches
Additional Information
All your information will be kept confidential according to EEO guidelines.
Product Security Engineering 2
Security architect job in Saint Charles, MO
This job is with Encode, Inc a fully owned subsidiary of Lancesoft Active Top Secret Clearance Primary Responsibilities: Team members will work with other industry partners in the development and execution of a comprehensive assessment program supporting the specialized Advanced Weapons Proprietary Programs in the Space, Intelligence & Weapons Systems (SIWS) organization. These individuals will act as the primary product security engineers on the program for assessing, updating, and maintaining the security posture of the programs. This team will be supporting the program's systems by interacting continuously with the cyber team compliance team to remediate any vulnerabilities found during automated or manual cyber scans. A detailed oriented individual with a strong leadership skillset is a must for this position.
•Assess organization-wide security and privacy risk and update assessment results on an ongoing basis
•Perform system analysis and develop system test for cyber threats, cyber test activities, and the cybersecurity of large-scale events
•Ensure product security engineering development lifecycle is followed, with an emphasis on clear requirements development/verification (using CAMEO)
•Perform criticality analysis to include the ability to work with suppliers, identify critical components, and integrating them into the overall system
•Perform cyber risk assessments and develop risk mitigation plans (i.E., POA&Ms, SCRM, etc.) using a variety of tools including but not limited to CAMEO
•Support and facilitate various ATO/IATT packages including processing IAVMs and CTOs for the same
•Perform software assurance tasks, including but not limited to software assurance risk reports
•Support proposal development efforts, including but not limited to: BOE generation, GR&A development, trade study analysis
•Support the engineering installation & analysis of patches and various system updates and upgrades to determine system consequence of these changes
•Attend, collect data from, out brief, and facilitate collaboration and project management from various program boards
•Applying Security Technical Implementation Guides (STIGs)
•Managing and addressing any Cyber Tasking Orders (CTOs) related to the Cyber Tools
•Documentation and verification of all installation and configuration steps for the labs and operations deliveries
•Providing feedback to Cyber Leadership and engineers to improve the cybersecurity tools and processes
•Collaborating with local Information System Security Officers (ISSOs) to ensure compliance with relevant cybersecurity standards and regulations
•Support cyber threat intelligence activities
•Support the development and maintenance of cyber scanning, patching, remediation, tools and applications
•Support, as required, TEMPEST, DFARS, COMSEC, CNSSI, and other compliance drivers as needed
•Perform and/or support the development of tools for cyber forensics
•Develop, define efficiencies and improvements to tools to improve team productivity
•Perform system analysis trade studies to define technical concepts and solutions
This position requires an active Top Secret U.S. Security Clearance. (A U.S. Security Clearance that has been active in the past 24 months is considered active.)
Basic Qualifications (Required Skills/Experience):
•Bachelor of Science degree from an accredited course of study in engineering, engineering technology (includes manufacturing engineering technology), chemistry, physics, mathematics, data science, or computer science.
•Current DoD 8570 certification at IAT Level II / IAM Level I or higher (e.G., Security+, GSEC, SCNP, SSCP, CISSP, CISA, GSE, SCNA)
•1+ years of experience in product security / cybersecurity engineering
•1+ years of experience with industry standard cybersecurity frameworks (NIST, OWASP, DFARS)
•Experience using analytical, collaboration, communication and organizational skills
Preferred Qualifications (Desired Skills/Experience):
•Experience using CAMEO (proficiency preferred)
•2+ years of experience in Windows/RHEL System admin experience, installing, tuning & troubleshooting Cyber Tools to include ESS/HBSS, ConfigOS, Splunk, etc.
•2+ years of experience in configuring, running, and scripting audit tools
•2+ years of experience using knowledge of Software Assurance (SwA) static and/or dynamic code analysis (e.G. Fortify)
•Experience with Federal Information Security Management Act (FISMA)/RMF and National institute of Standards and Technology (NIST) 800-53 requirements
•Experience leading system and component level cyber test and evaluation, including threat and security assessments, and tabletop exercises
•Experienced self-starter with strong written and oral communication skills, and a focus on translating technically complex issues into simple, easy to understand concept
•Growing understanding of DoD defense systems architectures and communications system concepts, mission, and common system test and data analysis techniques
Typical Education/Experience:
Associate (2): Education/experience typically acquired through advanced technical education from an accredited course of study in engineering, engineering technology (includes manufacturing engineering technology), computer science, engineering data science, mathematics, physics or chemistry (e.G. Bachelor) and typically 2 or more years'related work experience or an equivalent combination of technical education and experience or non-US equivalent qualifications. In the USA, ABET accreditation is the preferred, although not required, accreditation standard.
Education/experience typically acquired through advanced technical education from an accredited course of study in engineering, engineering technology (includes manufacturing engineering technology), computer science, engineering data science, mathematics, physics or chemistry (e.G. Bachelor) and typically 2 or more years'related work experience or an equivalent combination of technical education and experience or non-US equivalent qualifications. In the USA, ABET accreditation is the preferred, although not required, accreditation standard.
Security Engineer IV
Security architect job in Maryland Heights, MO
This role requires the ability to work lawfully in the U.S. without employment-based immigration sponsorship, now or in the future. is not eligible for immigration sponsorship. Spectrum's Product and Technology team creates, develops, and operates the nation's fastest mobile service, most reliable internet service, most viewed live TV app, and the most advanced WiFi, serving nearly 100 million users and 500 million devices. We are transforming the next era of connectivity and entertainment experiences. The diversity of experience available within Spectrum's Product and Technology team is unmatched and there are opportunities to grow your career as a designer, architect, engineer, developer, operator, or data scientist. We are creative, disciplined, hard-working, complex-problem solvers that believe in collaborating to deliver the highest quality customer experience.
BE A PART OF THE CONNECTION
As a Security Engineer IV on the Information Security Engineering team, you'll drive security engineering activities that monitor, detect and alert on potential security threats and vulnerabilities concerning company database and application software systems. You'll work closely with database admins and technical operations staff to coordinate and communicate incident and remediation efforts and incident status to management.
MAJOR DUTIES AND RESPONSIBILITIES
* Designs and implements queries and use cases to correlate security relevant system and application log data to alert and report on potential security events.
* Leads the security incident response lifecycle for any cyber security related events affecting Charter's databases and services.
* Responsible for providing timely updates to security management according to Charter's Incident Response Plan.
* Leads efforts to integrate and maintain scanning services with SEIM, ASPM and vulnerability management systems.
* Implements, maintains and monitors threat intelligence data from various resources that is relevant to Charter's networks and systems.
* Proactively hunts for security related threats and vulnerabilities that potentially affect Charter's databases and services.
* Develops and coordinates the implementation of security counter-measures with the appropriate organizations.
* Develops and recommends security policies, standards, and configurations to the security governance committee.
* Leads and performs the advanced forensics analysis and data evidence gathering for critical security events.
* Recommends, designs and implements security systems and tools used for Database Security
* Manages security scanning infrastructure and integrations, mentoring others on management and providing ongoing system support.
* Develops security requirements for new projects and performs the security testing prior to going into production.
* Ensures compliance with security standards, policies and procedures.
* Adheres to industry specific local, state, and federal regulations, as applicable
Required Qualifications
Education:
* Bachelor's Degree or Master's in Computer Science or Information Systems or related field or equivalent experience
* Minimum five (5) years of Information security experience
* Minimum four (4) years of Information security operations experience
PREFERRED JOB QUALIFICATIONS:
* Current security certifications, such as CISSP, CEH, or SANS GIAC.
* Oracle Certified Professional - Oracle Database Security Expert
* Computer forensics
* Cyber Security Risk Management and assessment methodologies
* Understanding of AWS and cloud infrastructure
Abilities:
* Ability to read, write, speak and understand the English language to communicate with employees, customers, suppliers, in person, on the phone, and by written communications in a clear, straight-forward, and professional manner
Skills:
* Demonstrated knowledge of database management or database security
* Experience with security scan assessment tools of Oracle, MSSQL, PostgreSQL or other relational or NoSQL databases.
* Must understand what is required to prevent security exploits, how to detect security attacks and anomalies and how to respond to security incidents and intrusions
* Expert knowledge of forensic methodologies and best practices to investigate intrusions, preserve evidence and coordinate a unified security response
* Advanced knowledge of database management and administration.
* Advanced knowledge of industry security standards and cyber security frameworks.
* Demonstrated experience in managing information security events and incidents for large and sophisticated networks
* Demonstrated leadership capabilities with the ability to work across functional boundaries, build consensus and drive results
* Strong written and verbal communication skills and should have good presentation skills
* Demonstrated understanding of file storage systems; block filesystems, NFS, S3
* Must be a problem solver, able to balance competing priorities, have a strong process orientation and be able to manage through complexity and rapid change
Working Conditions:
* Office Environment
* Occasional off-hours incident response for critical security events.
* May require some weekend and evening shift work for infrastructure administration
* Minimal Travel Required
SPECTRUM CONNECTS YOU TO MORE
* Innovative Tools & Tech: Work with high-performing software and applications on the forefront of the digital telecommunications industry.
* Dynamic Growth: The growth of our industry and evolving technology will power your career as you move up or around the company.
* Supportive Teams: Who you are matters here. We aim to foster an inclusive workplace where every person is empowered to bring their best ideas.
* Total Rewards: See all the ways we invest in you-at work and in life.
#LI-SS5
ISE313 2025-62913 2025
Here, our employees don't just have jobs, they're building careers. That's why we offer a comprehensive pay and benefits package that rewards employees for their contributions to our success, supporting all aspects of their well-being at every stage of life.
A qualified applicant's criminal history, if any, will be considered in a manner consistent with applicable laws, including local ordinances.
Get to Know Us Charter Communications provides superior communication and entertainment products for residential and business customers through the Spectrum brand. Our offerings include Spectrum Internet, TV, Mobile and Voice. Beyond our connectivity solutions, we also provide local news, programming and regional sports via Spectrum Networks and multiscreen advertising solutions via Spectrum Reach. When you join our team, you'll be keeping our customers connected to what matters most in 41 states across the U.S. Watch this video to learn more.
Grow Your Career Here We're committed to growing a workforce that reflects the customers and communities we serve - providing opportunities for employment and advancement to all team members. Spectrum is an Equal Opportunity Employer, including job seekers with disabilities and veterans. Learn about Life at Spectrum.
INTL GCP Cloud Security Engineer
Security architect job in Edmundson, MO
Implement fine-grained access controls for PHI/PII Automate data classification, configure security monitoring Ensure compliance, test/validate security controls We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to ********************.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: ****************************************************
Skills and Requirements
Start by December 1
Onsite in Hyderabad 4 days/week
5+ years cloud security (2+ years data security)
Strong GCP security, BigQuery, DLP, KMS, SIEM, healthcare/HIPAA experience Security certifications (CISSP, CHC, GCP Security Engineer)
Zero Trust, DevSecOps, container security
Sr. Security Analyst - Perimeter Security Team
Security architect job in Saint Louis, MO
Innovate here. And see your ideas come to life. It's an exciting time to work in tech at Edward Jones. We are making massive investments in emerging technologies to improve how we work with our clients and with each other. Relationships are the focus of our business model. And working in Technology here means using your skills to build, deliver and maintain the technologies that enable us to deepen and support those relationships. The best part? We develop and create our own industry-leading solutions internally. And you can be a part of it. Working with emerging new technologies. Creating platforms, programs and experiences that change how we work together - and support our client-first focus. Changing the future of our firm, the industry and the advisor-client relationship.
Job Overview
Position Schedule: Full-Time
This job posting is anticipated to remain open for 30 days, from 01-Dec-2025. The posting may close early due to the volume of applicants.
Team Overview:
As a Security Analyst you will work independently to manage 1 - 2 platforms within a product team and collaborate with colleagues to solve routine to difficult engineering challenges. You will ensure that all platforms within your span of responsibility meet your customer's requirements; are designed, built, documented, and maintained in adherence with the Firm's standards and architectural patterns; and are managed to the highest level for performance, stability, and security. As a Security Engineer you deeply understand network architecture and data flows, proxy solutions, remote access platforms and have the ability and drive to solve complex issues and manage competing priorities.
What You'll Do:
Identify and implement opportunities to improve solutions and ensure system availability while maintaining acceptable risk levels for the firm to remain in compliance with industry regulations and security framework.
Serve as a subject matter expert for proxy and intrusion prevention platforms, remote access connectivity, zero-trust, and network security monitoring.
Lead and oversee the solution design lifecycle for Zscaler and IPS, including stakeholder requirement gathering and prioritization, alignment with architectural standards and best practices, implementation planning, implementation execution, documentation completeness, and ongoing health monitoring and maintenance.
Provide design thinking and oversight for Zscaler and IPS to ensure cohesiveness, completeness, and effectiveness of the platform; and provide feedback to the Team Lead on the overall direction of the technology stack.
Continue to implement new features and performance improvements for Zscaler and IPS in partnership with key stakeholders.
Adhere to frameworks and processes for cohesive change management, health monitoring, performance monitoring, stability, and backups across the product space.
Support technology incidents including: triaging technology services performance segregation or outages, performing root cause analysis across a complex environment, and identifying short and long-term solutions while operating in stressful and time sensitive situations.
Effectively communicate with peers and leaders to ensure the awareness of progress, the awareness of challenges, the identification and escalation of risks, and the impact of ongoing security work. Including the ability to clearly discuss complex technical or security topics with a non-technical audience.
Establish and maintain effective communications and relationships across key departments, business areas, and vendors. Including supporting engagements with key vendors to ensure the correct level of support to the Firm and drive solution roadmaps to meet Firm needs.
Mentor and coach less senior team members and represent the Firm across the financial service's information security community through industry forums, working groups, and conference presentations.
Edward Jones' compensation and benefits package includes medical and prescription drug, dental, vision, voluntary benefits (such as accident, hospital indemnity, and critical illness), short- and long-term disability, basic life, and basic AD&D coverage. Short- and long-term disability, basic life, and basic AD&D coverage are provided at no cost to associates. Edward Jones offers a 401k retirement plan, and tax-advantaged accounts: health savings account, and flexible spending account. Edward Jones observes ten paid holidays and provides 15 days of vacation for new associates beginning on January 1 of each year, as well as sick time, personal days, and a paid day for volunteerism. Associates may be eligible for bonuses and profit sharing. All associates are eligible for the firm's Employee Assistance Program. For more information on the Benefits available to Edward Jones associates, please visit our benefits page.
Hiring Minimum: $84100
Hiring Maximum: $143100
Qualified applicants with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act. Edward Jones is prohibited from hiring individuals with certain specified criminal history as set forth in Section 3(a)(39) and 15(b)(4) and Rule 17a-3(a)(12) of the Securities and Exchange Act of 1934, and conducts background reviews consistent with FINRA Rule 3110(e). A copy of a notice regarding the provisions of the Los Angeles County Fair Chance Ordinance is available at: dcba.lacounty.gov/wp-content/uploads/2024/08/FCOE-Official-Notice-Eng-Final-8.30.2024.pdf.
Read More About Job Overview
Skills/Requirements
What Experience You'll Need:
Degree in Cyber Security, Computer Science, Computer Engineering, or Information Systems or related field preferred; or equivalent training and certifications (A+, Net+, Sec+, SANS, Cloud, etc), or related work experience
3-5 years of managing enterprise class proxy solutions, remote access solutions, network security platforms, on-prem and cloud data centers.
Experience in a variety of technical fields including software, infrastructure, and security engineering at an enterprise level. This experience gives you deep understanding of the full stack required to deliver and operate software and platforms at an enterprise level.
Understanding of core enterprise technology platforms including: infrastructure, software, data, cloud and cloud native platforms, microservices, API management, event streaming, CI/CD pipelines.
Experience with core enterprise level information security components, principles, practices, and procedures. Including common technology stack components, deep knowledge of threats and adversary tactics, and experience managing regulatory requirements and common frameworks used by security teams within the Financial Industry.
Understanding of core enterprise best practices, including: security risk management, architecture diagrams and documentation, digital transformation, change management, crisis management, business continuity, disaster recovery, and observability.
Experienced in designing and building highly scalable, distributed & secure solutions that run in a cloud environment such as Azure, AWS, or GCP. Including demonstrated proficiency in deploying infrastructure as code through Terraform, Ansible, or similar technologies.
Experience with managing and delivering on stakeholder requirements in a way that balances design functionality, cost optimization, and production support considerations.
Advanced experience with writing code/scripts in at least one language (Python, PowerShell, Bash, Go, etc)
Demonstrated competency with reading and generating architectural diagrams and maintaining full and accurate documentation of software, systems, and platforms.
Strong understanding of observability, performance monitoring, and root cause analysis principles to perform continuous platform improvements or quickly troubleshoot and restore services in a case of disruption.
Experience working with Product Teams and Agile methodology and practices
Demonstrated proficiency with proxy solutions and zero trust methodologies
Demonstrated proficiency with network security best practices
Candidates that live within in a commutable distance from our Tempe, AZ and St. Louis, MO home office locations are expected to work in the office three days per week, with preference for Tuesday through Thursday.
Current INTERNAL home-based associates: While this role is posted as hybrid, if selected and accepted, you may retain your home-based status. Edward Jones intends in good faith to continue offering the role as home-based, though future business or regulatory needs may require on-site work.
Read More About Skills/Requirements
Awards & Accolades
At Edward Jones, we are building a place where everyone feels like they belong. We're proud of our associates' contributions to the firm and the recognitions we have received.
Check out our U.S. awards and accolades: Insights & Information Blog Postings about Edward Jones
Check out our Canadian awards and accolades: Insights & Information Blog Postings about Edward Jones
Read More About Awards & Accolades
About Us
Join a financial services firm where your contributions are valued. Edward Jones is a Fortune 500¹ company where people come first. With over 9 million clients and 20,000 financial advisors across the U.S. and Canada, we're proud to be privately-owned, placing the focus on our clients rather than shareholder returns.
Behind everything we do is our purpose: We partner for positive impact to improve the lives of our clients and colleagues, and together, better our communities and society. We are an innovative, flexible, and inclusive organization that attracts, develops, and inspires performance excellence and a sense of belonging.
People are at the center of our partnership. Edward Jones associates are seen, heard, respected, and supported. This is what we believe makes us the best place to start or build your career.
View our Purpose, Inclusion and Citizenship Report.
¹Fortune 500, published June 2024, data as of December 2023. Compensation provided for using, not obtaining, the rating.
Edward Jones does not discriminate on the basis of race, color, gender, religion, national origin, age, disability, sexual orientation, pregnancy, veteran status, genetic information or any other basis prohibited by applicable law.
#LI-HO
Cloud Security Engineer
Security architect job in Saint Louis, MO
Compunnel Software Group is a New Jersey based premier information technology consulting & services company into this market for nearly two decades now; with close to two decades of experience in IT Industry which includes consulting, development, e-learning etc.
Our company is going through a tremendous growth spurt and we are now interested in personnel like you to augment the work force in the company. We have several projects starting that we are staffing for. If you think you would like to become a consultant for Compunnel Software Group Inc., please send me an updated copy of your resume along with a detailed summary of your work experience. I need a phone number to contact you. I look forward to possibly working with you on these positions.
We offer specialized services to our clients to meet their business objectives. Successful solutions that are valued by our clients are in industry areas such as pharmaceuticals, telecommunications, banking, finance, manufacturing, publishing and consumer products.
Job Description
Position: Cloud Security Engineer
Duration: 6+ months
Location: St. Louis, MO, 63167
Must Have:
Cloud Security
Security Patches
Cloud Security Automation Engineer
Client is seeking a Cloud Security Automation Engineer with deep technical experience in securing cloud technologies.
The successful candidate possesses out of the box thinking, the ability to collaboration with development team members, and experience with automation and solving end to end application/infrastructure security problems.
Our mission is to design and build a highly secure cloud environment without sacrificing our developers' ability to quickly innovate and deliver world class software solutions.
Responsibilities:
• Define security best practices for our cloud platform and provide guidance to development teams.
• Build tools to monitor for compliance of security policy and automate the resolution process.
• Evangelize security throughout the enterprise and collaborate to help architect secure applications.
• Research emerging technologies and build proof of concepts to investigate better ways of meeting our control objectives.
• Collaborate with incident response, risk and compliance, product security and development teams to solve critical security problems.
• Develop an AppSec pipeline and integrate it into the agile software development process.
Required Qualifications:
• BA/BS degree in Computer Science, Information Systems, Cyber Security or a related technical field or equivalent experience.
• At least 3 years of experience in Information Security and/or infrastructure
engineering.
• An accomplished security practitioner with a strong understanding of industry trends in all areas of security.
• Experience with building IaaS cloud based solutions including AWS, Azure, etc.. and knowledge of their network security and IAM models.
• Experience working with security vendors including evaluating and implementing new products.
Desired Qualifications:
• Expertise in common AWS services (CloudFormation, Route53, VPC, EC2, Lambda, etc...) and their security best practices.
• Programming experience in JavaScript, Java, Scala, Python, Perl, Ruby, etc.. and their use in automating security and compliance.
• Strong understanding of security technologies including host and network based protection and detection technologies.
• Experience with vulnerability management (including: running vulnerability scans, creating reports, communicating with asset owners and giving remediation guidance).
• Experience with continuous integration and automation tools (e.g. Jenkins, Chef, Puppet, Ansible).
• Experience writing security white papers and/or presenting security products and technologies to diverse audiences.
• CISSP or CSSLP (Certified Secure Software Lifecycle Professional) certification.
Qualifications
Must Have:
Cloud Security
Security Patches
Additional Information
All your information will be kept confidential according to EEO guidelines.
Product Security Engineers
Security architect job in Berkeley, MO
Company:
The Boeing Company
We are seeking experienced Product Security Engineers located in Berkeley, MO.
We are looking for you to contribute to the design and development efforts for key computing assets embedded in the most advanced Boeing defense platforms. As a member of our team, you will have the opportunity to be part of the Boeing Anti-Tamper Engineering Capability Center, which is tasked with the protection of all critical computers across all defense products developed within Boeing.
Unlike most aerospace jobs where a team is focused on building a singular product for a specific customer, a career in Boeing's Anti-Tamper Engineering Capability Center offers the opportunity to contribute to products across Boeing's entire elite defense portfolio.
Based on the skills you bring you'll be placed in either an integration or software engineering capacity.
Integration focused engineers: will work directly with customers to define system requirements and architectures, develop and provide oversight of these new designs, and work within all aspects of the system life cycle through final testing, verification, and fielding.
Software focused engineers: support requirements definition, create software architecture, implement software designs, and test our security solutions and the computing devices into which they are included.
We are growing our team to ensure that new and unique protection solutions can be fielded across all of our Boeing and supplier-generated products. Expected solutions will span both hardware and software domains.
Be part of a team that designs and protects our nation's most advanced capabilities.
Position Responsibilities:
Support development programs, research efforts, and strategic initiatives in the areas of Product Security
For software focused engineers: Develop, document and maintain Anti-Tamper (AT) software architectures, requirements, algorithms, interfaces and designs for real- time embedded software systems
For integration focused engineers: Develop AT architectures, requirements, documentation, test plans, test procedures and participate in verification activities in support of Anti-tamper development efforts
Work closely with engineering and non-engineering stakeholders (including DOD customers & suppliers) and industry subject matter experts
This position is expected to be 100% onsite. The selected candidate will be required to work onsite at one of the listed location options.
This position requires the ability to obtain a US Security Clearance for which the US Government requires US Citizenship as a condition of employment.
An interim and/or final U.S. Secret Clearance Post-Start is required
Potential signing bonus for eligible/qualified external candidates
Basic Qualifications (Required Skills/Experience):
Bachelor of Science degree in Engineering, Engineering Technology (including Manufacturing Technology), Computer Science, Data Science, Mathematics, Physics, Chemistry or non-US equivalent qualifications directly related to the work statement
Engineering experience which aligns with the appropriate engineering level
Ability to obtain Secret US Security clearance (post start)
Preferred Qualifications (Desired Skills/Experience):
Security focused coding experience especially AT functions and cryptography implementations
Experience developing solutions for real- time embedded systems
Experience in requirements analysis
Experience or interest in cryptography, secure communications protocols and reverse engineering techniques at a system and component level
Experience in design and/or integration of systems or subsystems in the Defense industry - understanding tactical systems capabilities and operations is crucial to being able to protect them
Experience or interest in commercial off the shelf (COTS) FPGA's and COTS security features
Current US Secret Clearance preferred
Typical Education/Experience:
Level 2: Education/experience typically acquired through advanced technical education from an accredited course of study in engineering, engineering technology (includes manufacturing engineering technology), computer science, engineering data science, mathematics, physics or chemistry (e.g. Bachelor) and typically 2 or more years' related work experience or an equivalent combination of technical education and experience or non-US equivalent qualifications. In the USA, ABET accreditation is the preferred, although not required, accreditation standard
Level 3: Education/experience typically acquired through advanced technical education from an accredited course of study in engineering, engineering technology (includes manufacturing engineering technology), computer science, engineering data science, mathematics, physics or chemistry (e.g. Bachelor) and typically 5 or more years' related work experience or an equivalent combination of technical education and experience or non-US equivalent qualifications. In the USA, ABET accreditation is the preferred, although not required, accreditation standard.
Relocation:
This position offers relocation based on candidate eligibility.
Drug Free Workplace:
Boeing is a Drug Free Workplace where post offer applicants and employees are subject to testing for marijuana, cocaine, opioids, amphetamines, PCP, and alcohol when criteria is met as outlined in our policies
.
Shift:
This position is for 1st shift.
At Boeing, we strive to deliver a Total Rewards package that will attract, engage and retain the top talent. Elements of the Total Rewards package include competitive base pay and variable compensation opportunities.
The Boeing Company also provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and a number of programs that provide for both paid and unpaid time away from work.
The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, and the applicability of collective bargaining agreements.
Please note that the salary information shown below is a general guideline only. Pay is based upon candidate experience and qualifications, as well as market and business considerations.
Summary pay range:
Level 2: $91,800 - $124,200
Level 3: $112,200 - $151,800
The Boeing 401(k) helps you save for your future, with contributions from Boeing that can help you grow your retirement savings. Our best-in-class retirement benefit features:
Best in class 401(k) plan: we'll match your contributions dollar for dollar, up to 10% of eligible pay with Immediate 100% vesting
Student Loan Match: The Boeing 401(k) Student Loan Match allows eligible enrolled U.S. employees to have their qualified student loan debt payments counted, along with any match-eligible contributions they make, for purposes of determining the Company Match to employees' Boeing 401(k) accounts.
Language Requirements:
Not Applicable
Education:
Bachelor's Degree or Equivalent
Relocation:
This position offers relocation based on candidate eligibility.
Export Control Requirement:
Safety Sensitive:
Security Clearance:
This position requires the ability to obtain a U.S. Security Clearance for which the U.S. Government requires U.S. Citizenship. An interim and/or final U.S. Secret Clearance Post-Start is required.
Visa Sponsorship:
Employer will not sponsor applicants for employment visa status.
Contingent Upon Award Program
This position is not contingent upon program award
Shift:
Shift 1 (United States of America)
Stay safe from recruitment fraud! The only way to apply for a position at Boeing is via our Careers website. Learn how to protect yourself from recruitment fraud - Recruitment Fraud Warning
Boeing is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national origin, gender, sexual orientation, gender identity, age, physical or mental disability, genetic factors, military/veteran status or other characteristics protected by law.
EEO is the law
Boeing EEO Policy
Request an Accommodation
Applicant Privacy
Boeing Participates in E - Verify
E-Verify (English)
E-Verify (Spanish)
Right to Work Statement
Right to Work (English)
Right to Work (Spanish)
Auto-ApplyPrincipal Information Security Engineer (Security Product Owner)
Security architect job in OFallon, MO
Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Principal Information Security Engineer (Security Product Owner) Who is Mastercard?
Mastercard is a global technology company in the payments industry. Our mission is to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart, and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments, and businesses realize their greatest potential.
Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. With connections across more than 210 countries and territories, we are building a sustainable world that unlocks priceless possibilities for all.
Overview:
The Security Threat & Response Management (STRM) program within Mastercard's Corporate Security organization is looking for a Security Product Owner to lead execution of our preventative security control strategy. The ideal candidate is driven, proactive about security, analytical, and brings strong technical cyber security expertise. This role is central to shaping and executing the roadmap and strategy for our program's primary security tools and defenses. We are looking for a technically proficient and forward-thinking professional who proactively monitors evolving security trends, modern modern defenses, and leverages advanced knowledge of security tools to foster innovation and strengthen resilience throughout our environments.
Role
• Define and drive the roadmap for the ‘Defend' product, which covers preventative and detective security controls and configurations across dozens of security tools and platforms including SIEM, SOAR, DLP, Application Control, XDR, NGFW, UEBA, NDR, and more.
• As the Defend product owner, you will be the team lead ensuring the Defend product feature team's work is prioritized, aligned to strategy, and properly road mapped.
• Partner with stakeholders from engineering, endpoint, identity, and cloud teams to deploy and optimize security technologies and controls.
• Translate security requirements, risk policies, and threat models into actionable work items and initiatives.
• Lead capability assessments and recommend technologies aligned with business needs and program strategies.
• Configure, integrate, and optimize security tools (e.g., EDR/XDR, NGFW, IDS, DLP, Application Control) in accordance with strategic objectives and initiatives.
• Monitor control effectiveness and continuously tune policies to reduce friction and increase coverage.
• Ensure alignment with internal standards, regulatory frameworks, and industry best practices.
All About You
The ideal candidate for this position should:
• Be an advanced technical expert with hands-on experience across multiple SecOps teams and functions such as Security Operations Center, Security Engineering, Incident Response, Detection Engineering, Threat Hunting, and Insider Threat for a large, global enterprise.
• Understand modern agile methodologies and how to define, assign, and track work for product feature teams and partner engineering teams.
• Be skilled at translating complex security requirements into clear, actionable technical plans in accordance with relevant security strategies and objectives.
• Be confident in how to approach complex security tooling and dependencies such as configuring access controls, tuning detection policies, and integrating tools into detection models and lifecycles.
• Be a strong communicator, able to articulate vision and strategy to technical and non-technical stakeholders at all levels.
Additional capabilities that will set you apart:
• Experience with proactive security strategies and security technology products, platforms, and key technology.
• Expertise in successfully integrating and leveraging threat intelligence data into security controls and tools for proactive, targeted security prevention.
• Deep understanding of modern SecOps concepts and strategies such as ‘SOC 3.0', posture management domains, attack surface reduction, adaptive protections, automated triage and response, zero trust, cloud-native security, etc.
• Familiarity with regulatory compliance standards and frameworks (e.g., NIST, ISO, ATT&CK, D3FEND, PCI).
• Ability to collaborate effectively with SOC, IR, Engineering, and other key stakeholders.
• Passion for innovation and continuous improvement in security technology optimization.
Corporate Security Responsibility:
Every person working for, or on behalf of, Mastercard is responsible for information security. All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and therefore, it is expected that the successful candidate for this position must:
• Abide by Mastercard's security policies and practices;
• Ensure the confidentiality and integrity of the information being accessed;
• Report any suspected information security violation or breach;
• Complete all periodic mandatory security training in accordance with Mastercard's guidelines.Mastercard is a merit-based, inclusive, equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law. We hire the most qualified candidate for the role. In the US or Canada, if you require accommodations or assistance to complete the online application process or during the recruitment process, please contact reasonable_accommodation@mastercard.com and identify the type of accommodation or assistance you are requesting. Do not include any medical or health information in this email. The Reasonable Accommodations team will respond to your email promptly.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
Abide by Mastercard's security policies and practices;
Ensure the confidentiality and integrity of the information being accessed;
Report any suspected information security violation or breach, and
Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
In line with Mastercard's total compensation philosophy and assuming that the job will be performed in the US, the successful candidate will be offered a competitive base salary and may be eligible for an annual bonus or commissions depending on the role. The base salary offered may vary depending on multiple factors, including but not limited to location, job-related knowledge, skills, and experience. Mastercard benefits for full time (and certain part time) employees generally include: insurance (including medical, prescription drug, dental, vision, disability, life insurance); flexible spending account and health savings account; paid leaves (including 16 weeks of new parent leave and up to 20 days of bereavement leave); 80 hours of Paid Sick and Safe Time, 25 days of vacation time and 5 personal days, pro-rated based on date of hire; 10 annual paid U.S. observed holidays; 401k with a best-in-class company match; deferred compensation for eligible roles; fitness reimbursement or on-site fitness facilities; eligibility for tuition reimbursement; and many more.
Pay Ranges
O'Fallon, Missouri: $165,000 - $264,000 USD
Auto-ApplyPrincipal Information Security Engineer (Security Product Owner)
Security architect job in OFallon, MO
Our Purpose Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Principal Information Security Engineer (Security Product Owner)
Who is Mastercard?
Mastercard is a global technology company in the payments industry. Our mission is to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart, and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments, and businesses realize their greatest potential.
Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. With connections across more than 210 countries and territories, we are building a sustainable world that unlocks priceless possibilities for all.
Overview:
The Security Threat & Response Management (STRM) program within Mastercard's Corporate Security organization is looking for a Security Product Owner to lead execution of our preventative security control strategy. The ideal candidate is driven, proactive about security, analytical, and brings strong technical cyber security expertise. This role is central to shaping and executing the roadmap and strategy for our program's primary security tools and defenses. We are looking for a technically proficient and forward-thinking professional who proactively monitors evolving security trends, modern modern defenses, and leverages advanced knowledge of security tools to foster innovation and strengthen resilience throughout our environments.
Role
* Define and drive the roadmap for the 'Defend' product, which covers preventative and detective security controls and configurations across dozens of security tools and platforms including SIEM, SOAR, DLP, Application Control, XDR, NGFW, UEBA, NDR, and more.
* As the Defend product owner, you will be the team lead ensuring the Defend product feature team's work is prioritized, aligned to strategy, and properly road mapped.
* Partner with stakeholders from engineering, endpoint, identity, and cloud teams to deploy and optimize security technologies and controls.
* Translate security requirements, risk policies, and threat models into actionable work items and initiatives.
* Lead capability assessments and recommend technologies aligned with business needs and program strategies.
* Configure, integrate, and optimize security tools (e.g., EDR/XDR, NGFW, IDS, DLP, Application Control) in accordance with strategic objectives and initiatives.
* Monitor control effectiveness and continuously tune policies to reduce friction and increase coverage.
* Ensure alignment with internal standards, regulatory frameworks, and industry best practices.
All About You
The ideal candidate for this position should:
* Be an advanced technical expert with hands-on experience across multiple SecOps teams and functions such as Security Operations Center, Security Engineering, Incident Response, Detection Engineering, Threat Hunting, and Insider Threat for a large, global enterprise.
* Understand modern agile methodologies and how to define, assign, and track work for product feature teams and partner engineering teams.
* Be skilled at translating complex security requirements into clear, actionable technical plans in accordance with relevant security strategies and objectives.
* Be confident in how to approach complex security tooling and dependencies such as configuring access controls, tuning detection policies, and integrating tools into detection models and lifecycles.
* Be a strong communicator, able to articulate vision and strategy to technical and non-technical stakeholders at all levels.
Additional capabilities that will set you apart:
* Experience with proactive security strategies and security technology products, platforms, and key technology.
* Expertise in successfully integrating and leveraging threat intelligence data into security controls and tools for proactive, targeted security prevention.
* Deep understanding of modern SecOps concepts and strategies such as 'SOC 3.0', posture management domains, attack surface reduction, adaptive protections, automated triage and response, zero trust, cloud-native security, etc.
* Familiarity with regulatory compliance standards and frameworks (e.g., NIST, ISO, ATT&CK, D3FEND, PCI).
* Ability to collaborate effectively with SOC, IR, Engineering, and other key stakeholders.
* Passion for innovation and continuous improvement in security technology optimization.
Corporate Security Responsibility:
Every person working for, or on behalf of, Mastercard is responsible for information security. All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and therefore, it is expected that the successful candidate for this position must:
* Abide by Mastercard's security policies and practices;
* Ensure the confidentiality and integrity of the information being accessed;
* Report any suspected information security violation or breach;
* Complete all periodic mandatory security training in accordance with Mastercard's guidelines.
Mastercard is a merit-based, inclusive, equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law. We hire the most qualified candidate for the role. In the US or Canada, if you require accommodations or assistance to complete the online application process or during the recruitment process, please contact reasonable_accommodation@mastercard.com and identify the type of accommodation or assistance you are requesting. Do not include any medical or health information in this email. The Reasonable Accommodations team will respond to your email promptly.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
* Abide by Mastercard's security policies and practices;
* Ensure the confidentiality and integrity of the information being accessed;
* Report any suspected information security violation or breach, and
* Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
In line with Mastercard's total compensation philosophy and assuming that the job will be performed in the US, the successful candidate will be offered a competitive base salary and may be eligible for an annual bonus or commissions depending on the role. The base salary offered may vary depending on multiple factors, including but not limited to location, job-related knowledge, skills, and experience. Mastercard benefits for full time (and certain part time) employees generally include: insurance (including medical, prescription drug, dental, vision, disability, life insurance); flexible spending account and health savings account; paid leaves (including 16 weeks of new parent leave and up to 20 days of bereavement leave); 80 hours of Paid Sick and Safe Time, 25 days of vacation time and 5 personal days, pro-rated based on date of hire; 10 annual paid U.S. observed holidays; 401k with a best-in-class company match; deferred compensation for eligible roles; fitness reimbursement or on-site fitness facilities; eligibility for tuition reimbursement; and many more.
Pay Ranges
O'Fallon, Missouri: $165,000 - $264,000 USD
Auto-Apply