Information Security Manager
Security architect job in Danbury, CT
This role offers the chance to take real ownership of an organization's security posture and guide how it continues to evolve. The environment is supported by a managed services provider, and this position will serve as the internal point of leadership and direction for all security initiatives-both strategic and hands-on.
Principle Lead IT Security Analyst
Location: Danbury, CT -Hybrid
Salary - $130,000 - $160,000 +Bonus
This role offers meaningful visibility, influence, and a path to future leadership roles such as Security Manager or CISO.
You will work closely with senior leadership, drive priorities, lead the MSP, and represent the security function to internal stakeholders and external customers. The scope includes cloud security, infrastructure security, risk management, audits, tooling, and incident response. This is a strong role for someone who is confident technically and ready to broaden into leadership responsibility with clear visibility and influence.
Key Responsibilities
Lead and direct the MSP on all security-related work, ensuring accountability and alignment to security objectives.
Strengthen and mature Azure cloud and Microsoft infrastructure security measures.
Manage vulnerability assessments, incident response coordination, and threat analysis activities.
Lead audit and compliance efforts, including ISO, SOC2, NIST, and related standards and frameworks.
Evaluate current tools and identify opportunities to implement or enhance security solutions.
Represent the security function in internal meetings and customer discussions; clearly communicate risk posture, decisions, and rationale.
Conduct regular internal security reviews and status meetings with senior leadership.
Identify and recommend improvements to organizational security strategy and controls.
Ideal Background
Experience in a broad security role supporting cloud, infrastructure, monitoring, and risk management.
Ability to guide third-party partners or MSP resources in the execution of security initiatives.
Strong analytical and problem-solving skills; able to identify gaps and design practical solutions.
Comfortable working in a role that is both strategic and hands-on.
Clear, confident communication skills with both technical and non-technical audiences.
Organized, steady under pressure, and able to prioritize effectively.
Preferred Experience
Azure cloud security, Microsoft infrastructure security, and network security fundamentals.
Security monitoring/logging platforms, vulnerability scanning, incident response practices.
Familiarity with NIST or CIS frameworks and security audit requirements.
Experience evaluating and implementing new security tools or platforms.
Exposure to emerging security automation or AI-driven security tooling is a plus.
Information Technology Security Manager
Security architect job in Cheshire, CT
Lane Construction is one of America's leading construction companies, specializing in large, complex civil infrastructure. For 135 years, it has contributed to the development of the country's transportation systems including the Interstate Highway System and a vast network of roads, bridges, airports, metros, and railways. Lane specializes in mobility, tunneling, and water resources to address sustainable development and climate change adaptation challenges.
Responsibilities
Develops and enforces security policies, procedures, and protocols to safeguard digital assets.
Leads incident response efforts and manage investigations of security breaches.
Conducts regular security audits, risk assessments, and vulnerability scans.
Oversees the deployment, integration, and configuration of security solutions (e.g., firewalls, antivirus, SIEM).
Collaborates with IT and business units to ensure secure system architecture and data protection.
Monitors security trends, emerging threats, and regulatory changes to keep the organization protected and compliant.
Trains and educates staff on cybersecurity awareness and best practices.
Manages vendor relationships and evaluates third-party security tools and services.
Prepares and presents security reports to senior management and stakeholders.
Manages the Disaster Recovery plan and conducts necessary testing activities.
Performs other duties as assigned.
Requirements
Education: Bachelor's Degree
Employment Conditions:
5 years of experience in IT security
Professional certification such as CISSP, CISM, CEH, or CompTIA Security+ preferred
Knowledge of IT security frameworks, standards and practices required
Experience with cloud security (AWS, Azure, GCP) and managing modern IT hybrid and multi-cloud environments
Strong hands-on experience deploying and managing security and network solutions such as SIEM (Security Information and Event Management), Email Security, Network Security, Endpoint Detection & Response (EDR), DLP (Data Loss Prevention), IPS/IDS (Intrusion Prevention & Detection Systems).
Experience managing 24x7x365 security operations
Knowledge of scripting or automation tools (e.g., Python, Powershell)
Lane Construction offers a comprehensive benefits package with an excellent opportunity to grow and be part of one of the most respected names in the construction industry. Lane is an Equal Opportunity Employer.
Director, Client Security Engineering Architect
Security architect job in Melville, NY
Known for being a great place to work and build a career, KPMG provides audit, tax and advisory services for organizations in today's most important industries. Our growth is driven by delivering real results for our clients. It's also enabled by our culture, which encourages individual development, embraces an inclusive environment, rewards innovative excellence and supports our communities. With qualities like those, it's no wonder we're consistently ranked among the best companies to work for by Fortune Magazine, Consulting Magazine, Seramount, Fair360 and others. If you're as passionate about your future as we are, join our team.
KPMG is currently seeking a Director, Tech Engineering to join our Tax Ignition Group.
Responsibilities:
* Lead the function of responding to clients' security inquires
* Meet with clients to answer their security questions and negotiate compensating controls when there are gaps between client requirements and our product offerings
* Drive innovation and improvement in the client security inquiry process such incorporating Artificial Intelligence into the process, creating additional collateral such as whitepapers, managing metrics, and improving the tooling and interactions with requestors
* Partner with various groups within Tax's technology function and business teams to incorporate trends into product roadmaps; collaborate with other compliance teams, and raise awareness around client security requirements
* Review and respond to client security questionnaires and assessments
* Build and maintain a knowledge base of common client questions
Qualifications:
* Minimum ten years of recent experience in Information Technology (IT) security compliance, risk management or related IT security within a large IT organization, preferably within a professional services firm, software product, or other highly regulated environment
* Bachelor's degree from an accredited college or university is preferred
* Deep understanding of cloud architecture, modern software development, and technical security controls is required; Azure experience is preferred
* Strong executive presence, negotiation, presentation, and communication skills are required; excellent analytical and problem-solving skills to assess complex security issues and develop effective solutions; capability to work effectively in a global environment, understanding diverse cultural perspectives and international client needs
* Proven experience in client-facing roles, particularly in handling security inquiries, negotiations, and managing client relationships; demonstrated ability to drive innovation and continuous process improvement, particularly in integrating new technologies and methodologies into existing processes
* Demonstrated knowledge of industry authoritative sources such as COBIT, NIST, ISO standards; CISM, CISA, ISO 27001 Auditor, LSS Green Belt, CRISC, CIPP, CGEIT or ITIL preferred
* Must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa
KPMG LLP and its affiliates and subsidiaries ("KPMG") complies with all local/state regulations regarding displaying salary ranges. If required, the ranges displayed below or via the URL below are specifically for those potential hires who will work in the location(s) listed. Any offered salary is determined based on relevant factors such as applicant's skills, job responsibilities, prior relevant experience, certain degrees and certifications and market considerations. In addition, KPMG is proud to offer a comprehensive, competitive benefits package, with options designed to help you make the best decisions for yourself, your family, and your lifestyle. Available benefits are based on eligibility. Our Total Rewards package includes a variety of medical and dental plans, vision coverage, disability and life insurance, 401(k) plans, and a robust suite of personal well-being benefits to support your mental health. Depending on job classification, standard work hours, and years of service, KPMG provides Personal Time Off per fiscal year. Additionally, each year KPMG publishes a calendar of holidays to be observed during the year and provides eligible employees two breaks each year where employees will not be required to use Personal Time Off; one is at year end and the other is around the July 4th holiday. Additional details about our benefits can be found towards the bottom of our KPMG US Careers site at Benefits & How We Work.
Follow this link to obtain salary ranges by city outside of CA:
**********************************************************************
KPMG offers a comprehensive compensation and benefits package. KPMG is an equal opportunity employer. KPMG complies with all applicable federal, state and local laws regarding recruitment and hiring. All qualified applicants are considered for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, citizenship status, disability, protected veteran status, or any other category protected by applicable federal, state or local laws. The attached link contains further information regarding KPMG's compliance with federal, state and local recruitment and hiring laws. No phone calls or agencies please.
KPMG recruits on a rolling basis. Candidates are considered as they apply, until the opportunity is filled. Candidates are encouraged to apply expeditiously to any role(s) for which they are qualified that is also of interest to them.
Los Angeles County applicants: Material job duties for this position are listed above. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness, and safeguard business operations and company reputation. Pursuant to the California Fair Chance Act, Los Angeles County Fair Chance Ordinance for Employers, Fair Chance Initiative for Hiring Ordinance, and San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Cyber security Architect
Security architect job in West Babylon, NY
Job DescriptionBenefits:
401(k)
401(k) matching
Competitive salary
Title: Cyber security Architect Work authorization: US Citizen Key Responsibilities Design and develop enterprise-class architecture across assigned technologies.
Manage project tasks, timelines, deliverables, and technical resources.
Review firewall policies to identify, analyze, and report cybersecurity gaps.
Assess firewall interface configurations and provide detailed findings on security risks.
Review and validate firewall zones for proper segmentation and compliance.
Create comprehensive documentation, diagrams, and technical artifacts to support system architecture.
Collaborate with cross-functional teams to ensure secure, scalable, and reliable system implementations.
Required Qualifications
Minimum Experience: 8+ years of enterprise-level experience in technical architecture or related fields.
Certifications: Multiple industry and/or vendor certifications (e.g., CISSP, CCNP/CCIE, AWS/Azure Architect, Security+).
Education: Bachelors Degree in Computer Science or related field.
Equivalent education or experience may be substituted.
Preferred Skills
Strong knowledge of cybersecurity frameworks and industry best practices.
Expertise in firewall technologies, configurations, and policy management.
Excellent analytical, documentation, and diagramming skills (e.g., Visio, Lucidchart).
Ability to communicate complex technical concepts to both technical and non-technical stakeholders.
Experience leading technical teams or acting as a project technical lead.
SAP Identity Management
Security architect job in Stamford, CT
E*Pro Consulting service offerings include contingent Staff Augmentation of IT professionals, Permanent Recruiting and Temp-to-Hire. In addition, our industry expertise and knowledge within financial services, Insurance, Telecom, Manufacturing, Technology, Media and Entertainment, Pharmaceutical, Health Care and service industries ensures our services are customized to meet specific needs. For more details please visit our website *****************
We have been retained for providing recruiting assistance, for direct hires, by one of the world-leading information technology consulting, services, and business process outsourcing organization that envisioned and pioneered the adoption of the flexible global business practices that today enable companies to operate more efficiently and produce more value.
Job Description
Required Skills:
• knowledge of SAP Identity Management 7.2 version
• knowledge of SAP IDM integration points with SAP and non-SAP products/tools
• LDAP/Active Directory, PD-Org, NWBC, Solution Manager 7.1.
• Experience in SAP security, SAP GRC is a plus.
• Basis experience is a plus
• 6+ years of SAP Identity Management Implementation and support experience.
• Experience as the SAP IDM SME in at least 2 implementations
• Experience with gap analysis and strategic roadmap/blueprint development
• Experience in configuring SAP IDM for user provisioning in a complex SAP landscape comprising of ABAP, JAVA and duel stack systems as well as non-SAP systems
• Involve in Onsite-Offshore coordination activities (handover-takeover, off business hour activity tracking, offshore reporting)
• Provide SAP IDM support to SAP implementation as well as support teams and internal customers/clients
Additional Information
All your information will be kept confidential according to EEO guidelines.
-Principal Product Security Engineer
Security architect job in North Haven, CT
We anticipate the application window for this opening will close on - 20 Dec 2025 At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You'll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.
**A Day in the Life**
The Principal Product Security Engineer plays a critical role in ensuring the security of Medtronic Surgical Operating Unit medical device solutions. Reporting to the Director of Product Security, this role drives the integration of advanced cybersecurity measures, identifies and mitigates potential vulnerabilities, and supports initiatives that improve cyber-resiliency throughout the product lifecycle. You will serve as a technical subject matter expert and mentor, collaborating across teams and contributing to long-term improvements in our security posture.
**Careers that Change Lives**
In this engineering-focused role, you will join a world-class team of systems, mechanical, electrical, software, and quality engineers within Medtronic's Surgical Operating Unit (OU). The Surgical OU brings together the people and portfolios of Surgical Robotics and Surgical Innovations to advance surgical care through robotics, surgical energy technologies, and digital solutions.
This role focuses on cybersecurity for medical devices and embedded systems. It is not an IT security, compliance, or GRC-focused position. The ideal candidate will have deep experience working with engineering teams to integrate cybersecurity into real-time systems, embedded firmware, connected devices, or other product-level security contexts.
With the Medtronic Mission as our North Star, we build on our legacy of proven surgical solutions and continue advancing the promise of robotics and digital technologies to improve outcomes for our customers and patients.
This is an onsite role and can be located at one of these office locations: Boston, MA, Lafayette, CO, Minneapolis, MN, or North Haven, CT with a strong preference of Boston or Lafayette.
_Make your impact by exploring a career with the world's leading Medical Device company, striving "to alleviate pain, restore health, and extend life."_
**A Day in The Life**
The Principal Product Security Engineer plays a critical role in ensuring the security of Medtronic Surgical Operating Unit medical device solutions. Reporting to the Director of Product Security, this role drives the integration of advanced cybersecurity measures, identifies and mitigates potential vulnerabilities, and supports initiatives that improve cyber-resiliency throughout the product lifecycle. You will serve as a technical subject matter expert and mentor, collaborating across teams and contributing to long-term improvements in our security posture.
**Key Responsibilities** :
+ **Product Security Strategy & Continuous Learning** - Stay abreast of emerging cybersecurity threats, technologies, and regulations specific to medical devices and health software. Contribute to OU and enterprise-wide product security strategy and roadmap development.
+ **Secure Product Development Lifecycle** - Drive security integration into all stages of the product lifecycle, from concept and design to postmarket. Work closely with system architects, software leads, and hardware engineers to embed secure design patterns in both embedded and cloud-connected environments.
+ **Threat Modeling & Risk Assessment** - Lead threat modeling sessions, conduct security risk assessments, and identify mitigation strategies in accordance with IEC 81001-5-1, ISO 14971, and FDA premarket cybersecurity guidance.
+ **Security Architecture & Design** - Collaborate on the design and implementation of secure architectures, focusing on secure boot, secure communications, data protection, access control, secure software updates, and hardware-software integration.
+ **Security Testing & Analysis** - Support and interpret results from vulnerability scans, penetration tests, and static/dynamic code analysis. Coordinate with internal teams and third-party vendors to ensure timely and appropriate risk mitigation.
+ **Security Awareness & Mentorship** - Promote a culture of security awareness within R&D and provide mentorship to junior engineers. Lead by example through documentation, review participation, and active knowledge sharing.
+ **Regulatory & Standards Compliance** - Ensure alignment with applicable standards (e.g., NIST, IEC 60601-4-5, IEC 81001-5-1) and support security documentation efforts for global regulatory submissions.
+ **Vendor & Supply Chain Security** - Review and assess the cybersecurity posture of third-party suppliers and open-source software components used within product designs.
+ **Incident Response Support** - Provide technical leadership during postmarket security incidents or field issues. Lead root cause investigations, containment strategies, and risk assessments.
+ **Security Documentation** - Maintain comprehensive security documentation, including threat model diagrams, risk assessments, shared service inventories, design patterns, security guidelines, and product security plans/reports.
**Must Have Requirements**
+ Bachelor's degree with 7 years of experience
+ Or advanced degree with 5 years of technical experience
**Nice to Have**
+ Bachelor's degree in a relevant engineering field of study (e.g., Computer Engineering, Software Engineering, or related discipline), completed and verified prior to start
+ Minimum 3 years of experience integrating security into embedded systems or connected medical devices in a regulated product development environment
+ Strong understanding of secure development lifecycle (SDLC), secure boot, cryptography, secure firmware update, secure communication, and hardware/software interface security
+ Master's degree in a relevant engineering or cybersecurity field
+ Industry-recognized certifications (e.g., CISSP, CSSLP, CISM, CEH)
+ Experience mentoring or technically guiding junior security engineers
+ Demonstrated ability to implement secure architecture in embedded and connected device ecosystems
+ Familiarity with FDA and MDR cybersecurity submission requirements
+ Knowledge of secure coding practices and common vulnerabilities (e.g., OWASP, CWE, CVSS)
+ Experience supporting cross-functional design reviews or formal design assurance processes
+ Working knowledge of secure boot chains, cryptographic controls, and device authentication protocols
**Physical Job Requirements**
The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position.
The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. For Office Roles: While performing the duties of this job, the employee is regularly required to be independently mobile. The employee is also required to interact with a computer, and communicate with peers and co-workers. Contact your manager or local HR to understand the Work Conditions and Physical requirements that may be specific to each role.
**Benefits & Compensation**
**Medtronic offers a competitive Salary and flexible Benefits Package**
A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage.
Salary ranges for U.S (excl. PR) locations (USD):$152,800.00 - $229,200.00
This position is eligible for a short-term incentive called the Medtronic Incentive Plan (MIP).
The base salary range is applicable across the United States, excluding Puerto Rico and specific locations in California. The offered rate complies with federal and local regulations and may vary based on factors such as experience, certification/education, market conditions, and location. Compensation and benefits information pertains solely to candidates hired within the United States (local market compensation and benefits will apply for others).
The following benefits and additional compensation are available to those regular employees who work 20+ hours per week: Health, Dental and vision insurance, Health Savings Account, Healthcare Flexible Spending Account, Life insurance, Long-term disability leave, Dependent daycare spending account, Tuition assistance/reimbursement, and Simple Steps (global well-being program).
The following benefits and additional compensation are available to all regular employees: Incentive plans, 401(k) plan plus employer contribution and match, Short-term disability, Paid time off, Paid holidays, Employee Stock Purchase Plan, Employee Assistance Program, Non-qualified Retirement Plan Supplement (subject to IRS earning minimums), and Capital Accumulation Plan (available to Vice Presidents and above, or subject to IRS earning minimums).
Regular employees are those who are not temporary, such as interns. Temporary employees are eligible for paid sick time, as required under applicable state law, and the Employee Stock Purchase Plan. Please note some of the above benefits may not apply to workers in Puerto Rico.
Further details are available at the link below:
Medtronic benefits and compensation plans (**************************************************************************************************************
**About Medtronic**
We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions.
Our Mission - to alleviate pain, restore health, and extend life - unites a global team of 95,000+ passionate people.
We are engineers at heart- putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary.
Learn more about our business, mission, and our commitment to diversity here (************************* .
It is the policy of Medtronic to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Medtronic will provide reasonable accommodations for qualified individuals with disabilities.
If you are applying to perform work for Medtronic, Inc. ("Medtronic") in any position which will involve performing at least two (2) hours of work on average each week within the unincorporated areas of Los Angeles County, you can find here (*************************************************************************************************************************************** a list of all material job duties of the specific job position which Medtronic reasonably believes that criminal history may have a direct, adverse and negative relationship potentially resulting in the withdrawal of a conditional offer of employment. Medtronic will consider for employment qualified job applicants with arrest or conviction records in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.
We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions.
Our Mission - to alleviate pain, restore health, and extend life - unites a global team of 95,000+ passionate people.
We are engineers at heart- putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary.
**We change lives** . Each team member, each day, helps to improve and redefine how the world treats the most pressing health conditions, from heart disease to diabetes. Our industry leadership comes from the passion and ingenuity of our people. That's who we are. Working alongside one another, we use science, medicine, and a profound understanding of the human body to build extraordinary technologies that can transform lives.
**We build extraordinary solutions as one team** . With one Medtronic Mindset defining how we work. Speed and decisiveness run through our DNA. Diverse perspectives inspire our bold answers to any challenge that comes our way. And we deliver results the right way, breakthrough after patient breakthrough.
**This life-changing career is yours to engineer** . By bringing your ambitious ideas, unique perspective and contributions, you will...
+ **Build** a better future, amplifying your impact on the causes that matter to you and the world
+ **Grow** a career reflective of your passion and abilities
+ **Connect** to a dynamic and inclusive culture that welcomes the challenge of life-long learning
These commitments set our team apart from the rest:
**Experiences that put people first** . Respect for people is the hallmark of our humanity. It fuels our team to positively impact even a single life. And it means we put our people first at Medtronic as well, creating a culture of belonging and always pushing to get you the career-building resources you need.
**Life-transforming technologies** . No matter your role, you contribute to technologies that transform lives. What we build empowers patients to live life on their terms.
**Better outcomes for our world** . Here, it's about more than the bottom line. Our Mission to improve human welfare drives us. We advance healthcare, society, and equity with every design, inside and outside our walls.
**Insight-driven care** . Fresh viewpoints. Cutting-edge AI, data, and automation. You're shaping the future of healthcare technology and defining the next generation of breakthroughs in care
It is the policy of Medtronic to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Medtronic will provide reasonable accommodations for qualified individuals with disabilities.
For sales reps and other patient facing field employees, going into a healthcare setting is considered an essential function of the job and we expect our employees to comply with all credentialing requirements at the hospitals or clinics they support.
This employer participates in the federal E-Verify program to confirm the identity and employment authorization of all newly hired employees. For further information about the E-Verify program, please click here (*********************************** .
For updates on job applications, please go to the candidate login page and sign in to check your application status.
If you need assistance completing your application please email *******************
To request removal of your personal information from our systems please email *****************************
Easy ApplyCloud Security Engineer
Security architect job in Melville, NY
This role is Hybrid, 3 days a week to any local, US based UL Solutions Office. We are seeking a highly skilled Cloud Security Engineer with strong Application Security expertise to join our security architecture team. This role will be responsible for designing, implementing, and maintaining secure cloud environments and applications across multi-cloud platforms, with a focus on Azure. The ideal candidate will have hands-on experience with cloud-native security tools, DevSecOps practices, and compliance frameworks such as NIST 800-53, SOC 2, and CIS Controls.
Cloud Security Engineering
+ Design and implement security controls for cloud infrastructure (Azure, AWS, GCP).
+ Develop and maintain security architecture patterns (e.g., hub-and-spoke, Zero Trust).
+ Integrate security tools such as Wiz, Microsoft Defender for Cloud, Silverfort, and Terraform.
+ Conduct threat modeling and risk assessments for cloud-native services.
+ Collaborate with IAM, SOC, and GRC teams to align cloud security with enterprise policies.
Application Security
+ Perform secure code reviews, static/dynamic analysis, and vulnerability assessments.
+ Integrate security into CI/CD pipelines using tools like Snyk, Checkmarx, or Veracode.
+ Guide development teams on secure coding practices and OWASP Top 10.
+ Design and implement API security strategies including OAuth2, OpenID Connect, and mTLS.
+ Support remediation of application vulnerabilities and provide technical guidance.
Compliance & Governance
+ Map cloud and application security controls to compliance frameworks (NIST 800-53, SOC 2, CIS).
+ Assist in audits and evidence collection for regulatory compliance.
+ Maintain documentation of security architecture, policies, and procedures.
+ Bachelor's degree in Computer Science, Cybersecurity, or related field.
+ 3-4 years of experience in cloud security engineering and application security.
+ Strong understanding of Azure security services and architecture.
+ Experience with infrastructure-as-code (Terraform, Bicep).
+ Familiarity with Snowflake security features and data protection strategies.
+ Knowledge of identity and access management (Azure AD, Conditional Access, MFA).
+ Hands-on experience with DevSecOps tools and practices.
Preferred Qualifications
+ Certifications: Azure Security Engineer Associate, CISSP, CCSP, OSCP, or GIAC.
+ Experience with multi-subscription Azure environments.
+ Familiarity with Zero Trust architecture and implementation.
+ Experience with security automation and orchestration.
Soft Skills
+ Strong analytical and problem-solving skills.
+ Excellent communication and collaboration abilities.
+ Ability to work independently and in cross-functional teams.
+ Passion for continuous learning and staying current with security trends.
What you'll experience working for ULS
UL Solutions has been pioneering change since 1894 and we're still leading the way. From day one, we've blazed a trail protecting the planet and everyone on it. Our teams have influenced billions of products, plus services, software offerings and more. We break things, burn things and blow things up. All in the name of safety science.
That's where you come in - because none of it could happen without you. It takes passion to protect people, problem-solving to safeguard personal data and conviction to make the world a more sustainable place. It takes bold ideas and brilliant minds to build a better world for future generations across the globe.
This is more than a job. It's a calling. A passion to use our expertise and play our part in creating a more secure, sustainable world today - and tomorrow. As a member of our safety science community, you'll use your ideas, your energy and your ambition to innovate, challenge and ultimately, help create a safer world.
Everyone here is unique. But we're also a global community, working together to help create a safer world. Join UL Solutions and you can connect with the brightest minds in the business, all bringing their distinct perspectives and diverse backgrounds together to deliver real change.
Empowering our customers to keep the world safe means thinking ahead. It means investing in training and empowering our people to learn and innovate. At UL Solutions, we help build a better future - one where everyone benefits.
Join UL Solutions to be at the center of safety. To learn more about us and the work we do, visit UL.com
Total Rewards: We understand compensation is an important factor as you consider the next step in your career. The estimated salary range for this position is $95,000 to $120,000 and is based on multiple factors, including job-related knowledge/skills, experience, geographical location, as well as other factors. This position is eligible for annual bonus compensation with a target payout of 10% of the base salary. This position also provides health benefits such as medical, dental and vision; wellness benefits such as mental and financial health; and retirement savings (401K) commensurate with the standard rewards offered in each individual location or country. We also provide full-time employees with paid time off including vacation (15 days), holiday including floating holidays (12 days) and sick time off (72 hours).
#LI-SG2
#LI-Hybrid
UL LLC has been and will continue to be an equal opportunity employer. To assure full implementation of this equal employment policy, we will take steps to assure that:
Persons are recruited, hired, assigned and promoted without regard to race, color, age, sex or gender, sexual orientation, gender identity, gender expression, transgender status, religion, creed, national origin, ethnicity, citizenship, ancestry, disability, genetic information, military or veteran status, pregnancy, marital or familial status, or any other protected category under applicable law.
Email Security Engineer
Security architect job in Armonk, NY
**Introduction** The CISO Cybersecurity Operations Platform (CSOP) team is looking to add an engineer to the Analytics and Data Exploitation team. The Platform provides the technology, services and expertise required by IBM's Cyber Threat Detection and Response teams. We support the
Advanced Threat Detection (threat hunting, intelligence, incident response), Vulnerability
Detection and Response, Innovation and Remediation, Security Operations Centers and
Command Centers teams to deliver enterprise-wide security to one of the world's most
established technology companies. We process tens of billions of events per day, meaning
effective analysis and data exploitation practices are critical to our success. This is a technical
position within the Analytics and Data Exploitation team who employ commercial, open source
and in-house developed tools to deliver critical cybersecurity services such as event processing,
automation, complex analytics and support to digital investigations. This role operates across our
development, test, pre-production and production networks to create, maintain and improve our
services -an important component of which is fault-finding and the ability to work within
complex, dynamic environments.
The right candidate thrives in high-pressure situations and has practical experience working with
Big Data technologies -such as Spark, Hadoop and Elasticsearch. The role requires a proven,
practical knowledge of container orchestration technologies -specifically Kubernetes and RedHat
OpenShift. The work will include the design and optimization of container-deployed systems, as
well as the day-to-day engineering and administration of the orchestration environment. This
includes cluster management, Pod assignment / configuration, application virtual routing,
security, container image registry management and optimization of the runtime engines. Wider
knowledge of data ingestion, extraction, transformation and loading technologies is important -
including Streamsets and Flink. The role is rounded-out by some software development tasks -
all related to cyber security. These will involve Java, SQL, Python and automation scripting so experience with DevSecOps methods is highly advantageous. The Platform team employs hybrid cloud hosting and this includes provisioning, administration and management of services within environments spanning IBM Cloud, Amazon Web Services and Microsoft Azure.
About the Team
The CISO Cybersecurity Operations Platform (CSOP) team is looking to add an Email Security Engineer to the team. The CSOP provides the technology, services and expertise required by IBM's Cyber Threat Detection and Response teams. We support the Advanced Threat Detection (threat hunting, intelligence, incident response), Vulnerability Detection and Response, Remediation, Security Operations Center and Command Center teams to deliver enterprise-wide security to one of the world's most established technology companies.
**Your role and responsibilities**
Job Duties:
· Contribute to the day-to-day work that supports our critical cybersecurity analysis and
data processing workflows
· Protect organization against phishing, spoofing, malware, and advanced threats while maintaining user experience and compliance
· Familiarity with Exchange, ProofPoint Email Solutions, Powershell, Azure, and M365 suite
· Design, implement and maintain secure email solutions within the Microsoft 365 tenant and related servces
· Moniotr and respond to email-related security incidents, phishing attempts, and compromise events
· Support the team leadership to improve overall exploitation of technologies that best
serve our requirements
· Partner with CIO and CISO teams to develop email security policies, rules, and playbooks
- Work as part of a deeply technical, passionate team of engineers to tackle significant IT
challenges
**Required technical and professional expertise**
· 3 or more years' experience in an email security engineer or similar role
· Experience with Microsoft 365 Exchange or Proofpoint email solutions
· Hands on experience with SPF, DKIM, and DMARC configuration and rollout at an enterprise level
· Experience with (or a proven aptitude for) working within a fast-paced environment
where the success criteria are defined by external factors. This includes having to
change course quickly, based on the evolving needs of a complex and dynamic
environment
· Strong experience with incident response processes for phishing and email-based threats
· Experience with IBM Cloud, AWS, Azure or similar cloud environments
· Strong understanding of email protocols ISMPT, IMAP, POP3) and security controls
· Familiarity with SIEM tools for monitoring and automation on email threats
· Excellent problem-solving, communication, and documentation skills
**Preferred technical and professional experience**
· Experience with secure email gateways (Proofpoint, M365, etc)
· Microsoft certification
· Knowledge of zero trust frameworks and modern authentication methods (MFA, conditional access)
· Familiarity with cloud-native security tools (Sentinel, Defender, XDR)
· Understanding of email encryption solutions (TLS, S/MIME, PGP)
· Experience in large enterprise environments with hybrid Microsoft Exchange deployments
· Ansible experience is a strong advantage
IBM is committed to creating a diverse environment and is proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, caste, genetics, pregnancy, disability, neurodivergence, age, veteran status, or other characteristics. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.
Cyber Security Analyst
Security architect job in Bethpage, NY
The Network and Cyber Security Analyst will be responsible for designing, implementing, and maintaining the network and security infrastructure of the IT organization. This role requires a combination of hands-on experience with firewalls and other security tools, strong network knowledge, and expertise in Microsoft Azure networking and security. The ideal candidate will also have experience in setting and documenting security policies as well as working with 3rd party security vendors. Key Responsibilities: - Design, deploy, and maintain secure and high-performance network solutions, including switches, routers, and wireless systems. - Act as 2nd in line patch and troubleshooting support - Monitor and troubleshoot network performance and connectivity issues to ensure minimal downtime. - Optimize network configurations to enhance scalability, efficiency, and security. - Implement and manage firewalls, intrusion prevention systems (IPS), and other security appliances. - Perform regular vulnerability assessments and lead the remediation of identified risks. - Develop and enforce security policies, procedures, and incident response protocols. - Design, deploy, and manage secure cloud networking solutions, with a primary focus on Microsoft Azure. - Configure virtual networks, firewalls, and security groups in Azure to ensure compliance with organizational standards. - Manage identity and access solutions in Azure, including multi-factor authentication (MFA) and conditional access policies. - Collaborate with cross-functional teams to align IT infrastructure with business goals. - Manage 3rd party security partners - Maintain up-to-date documentation of network architecture, configurations, and security policies. - Generate regular reports on network performance, security incidents, and compliance metrics. - Provide guidance and training to staff on security best practices and awareness. - Stay up-to-date with the latest security trends, threats, and technology solutions. Qualifications: - Bachelor's degree in Information Technology, Computer Science, or a related field (or equivalent experience). - Minimum of 8+ years of experience in network administration and cybersecurity roles. - Expertise in configuring and managing network devices such as Cisco, Juniper, or similar switches and routers. - Hands-on experience with firewall platforms such as Cisco, Palo Alto, Fortinet, or similar solutions. - Proficiency in Azure cloud networking, including virtual networks, VPNs, and security configurations. - Strong knowledge of network protocols (TCP/IP, DNS, DHCP, VLANs, etc.) and troubleshooting tools. - Experience in setting and documenting security policies and procedures. - Excellent problem-solving, communication, and leadership skills. Preferred Skills. - Experience with endpoint protection, SIEM solutions, and log management tools. - Knowledge of compliance standards like ISO 27001, NIST, or GDPR. - Certifications such as CCNA, CCNP, Azure Network Engineer Associate, or equivalent are highly desirable.
Skills
Cyber security, Information security, Firewall, Arcitc Wolf, siem, azure, cisco, Vulnerability assessment, Vulnerability management, palo alto, juniper, CCNA, CCNP, azure network engineer associate, log management tools
Top Skills Details
Cyber security,Information security,Firewall,Arcitc Wolf,siem,azure,cisco
Additional Skills & Qualifications
- Experience with endpoint protection, SIEM solutions, and log management tools. - Knowledge of compliance standards like ISO 27001, NIST, or GDPR. - Certifications such as CCNA, CCNP, Azure Network Engineer Associate, or equivalent are highly desirable. Contract to Hire role (approximate time contracting is 6 months)
Experience Level
Expert Level
Job Type & Location
This is a Contract to Hire position based out of Bethpage, NY.
Pay and Benefits
The pay range for this position is $65.00 - $72.00/hr.
Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following: - Medical, dental & vision - Critical Illness, Accident, and Hospital - 401(k) Retirement Plan - Pre-tax and Roth post-tax contributions available - Life Insurance (Voluntary Life & AD&D for the employee and dependents) - Short and long-term disability - Health Spending Account (HSA) - Transportation benefits - Employee Assistance Program - Time Off/Leave (PTO, Vacation or Sick Leave)
Workplace Type
This is a hybrid position in Bethpage,NY.
Application Deadline
This position is anticipated to close on Dec 19, 2025.
h4>About TEKsystems:
We're partners in transformation. We help clients activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 clients, including 80% of the Fortune 500, across North America, Europe and Asia. As an industry leader in Full-Stack Technology Services, Talent Services, and real-world application, we work with progressive leaders to drive change. That's the power of true partnership. TEKsystems is an Allegis Group company.
The company is an equal opportunity employer and will consider all applications without regards to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.
About TEKsystems and TEKsystems Global Services
We're a leading provider of business and technology services. We accelerate business transformation for our customers. Our expertise in strategy, design, execution and operations unlocks business value through a range of solutions. We're a team of 80,000 strong, working with over 6,000 customers, including 80% of the Fortune 500 across North America, Europe and Asia, who partner with us for our scale, full-stack capabilities and speed. We're strategic thinkers, hands-on collaborators, helping customers capitalize on change and master the momentum of technology. We're building tomorrow by delivering business outcomes and making positive impacts in our global communities. TEKsystems and TEKsystems Global Services are Allegis Group companies. Learn more at TEKsystems.com.
The company is an equal opportunity employer and will consider all applications without regard to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.
Security Engineer
Security architect job in Middlebury, CT
L3 Resource with good experience in handling end to end infrastructure security operations which includes o Perimeter security (Checkpoint & CISCO ASA Firewalls etc.) o Endpoint security (Sophos , Symantec etc.) o Web Gateways ( Sophos, Blucote) o Email Gateways ( Sophos, Symantec etc.)
o Vulnerability Management (Qualys, DDI etc.)
o Information security & Compliance ( IS Auditing, Policies & Procedure reviews)
o Global Access Management
o SIME (ArcSight etc.)
· Should have hands on experience in troubleshooting issues
· Should have good experience in ITIL Processes(Change management, Problem management, Incident Management etc. )
· Technically sound on the above listed technologies / tools
· Good experience in performing Security incident analysis
· Preferably the candidate should have certifications like CISSP, CISA, CISM
· Should have good communication & presentation skills
Additional Information
All your information will be kept confidential according to EEO guidelines.
Firewall Security Engineer
Security architect job in Stamford, CT
Duration: 6+ Months Experienced Firewall administrator for operational implementation, maintenance and configuration of firewalls. Key Responsibilities: Performs maintenance and changes in firewalls as required. Implementation of new firewalls as required
Assists with troubleshooting network connectivity as it relates to firewalls
Utilizes change management, request, and ticketing systems, documents status updates and problem resolutions
Complete All assignments in a timely manner with an acceptable level of quality
Maintains documentation related to work area
Completes network change requests
Follows documented processes, procedures and policies
Performs customer service duties and responds to customer and project requests as defined by management
Other related duties assigned as needed.
Qualifications/Requirements:
Bachelor's degree and with 3 to 4 years of operational experience administering Firewalls
4 or more years networking/firewall background
Must have networking TCP/IP routing protocol experience
Desired Characteristics:
In-depth experience in security aspects of multiple platforms, operating systems, software, communications and network protocols is desired
Competency in verbal, written, and presentation communications and interpersonal understanding
Ability to understand customer's business needs.
Leadership of work teams/groups
Ability to work with all levels of employees
Highly motivated and able to work effectively under minimal supervision in a fast-paced environment
Team-oriented, placing priority on quality and the successful completion of team goals
Organization and planning skills that include: time management, project coordination and management, and the ability to handle multiple deadlines and associated pressures.
Competency in developing effective solutions to business problems
Ability to analyze problems and to make decisions
REQUIRED SKILLS
YEARS OF EXPERIENCE
WHEN THE SKILL WAS LAST USED
Expert knowledge of Cisco Security products, ASA and Firepower
Expert knowledge of NSX
Expert knowledge of Palo Alto systems
Security Certifications a Plus
Must have networking TCP/IP routing protocol experience
Networking/firewall background
Operational experience administering Firewalls
Additional Information
All your information will be kept confidential according to EEO guidelines.
Data Security Engineer
Security architect job in Stamford, CT
What you'll do • Design and implement comprehensive data security architectures, with particular focus on database platforms (primarily SQL Server) • Develop and maintain enterprise-wide encryption strategies for securing structured and unstructured data both in transit and at rest, both and both on-premise and in the cloud
• Enhance logging, monitoring and SecOps capabilities of enterprise databases and other data stores
• Configure and optimize Identity and Access Management (IAM) solutions across data platforms and repositories to align to least privilege principles
• Implement Data Loss Prevention (DLP) strategies and controls
• Implement and maintain Information Rights Management (IRM) and Digital Rights Management (DRM) solutions
• Design and implement data tokenization strategies where appropriate
• Secure data processing pipelines and ensure appropriate controls for data workflows
• Create and maintain data security documentation, including policies, procedures, and standards
• Collaborate with development teams to ensure security best practices in data handling
• Conduct vulnerability assessments of the firm's database architecture and associated data storage and processing systems
• Assist in monitoring and managing security patching and upgrade processes for database platforms
What's required
• Bachelor's degree in computer science, cybersecurity, or related technical field
• 6+ years of experience in data/database security engineering and governance
• Deep expertise in database security, particularly SQL Server
• Comprehensive understanding of data warehouse/data lake architectures and tools, particularly Databricks (required)
• Subject matter expertise in Object Storage (eg: S3, Azure Blob, etc) and related security
• Understanding of Active Directory Delegation (constrained vs. unconstrained) and associated best practices
• Experience with 3rd-party SQL Server security governance and monitoring products (eg: Idera, Solarwinds)
• Extensive knowledge of encryption technologies for both structured and unstructured data
• Broad knowledge of secure data/file sharing solutions and ETL workflows
• Experience designing and implementing data tokenization solutions
• Experience with data classification and DLP technologies
• Scripting/automation capabilities (eg: SQL, PowerShell, Python)
• Commitment to the highest ethical standards
Qualifications
Ivy league
colleges education preferred or huge plus.
Additional Information
All your information will be kept confidential according to EEO guidelines.
Senior Information Security Analyst (NOT Remote)
Security architect job in New Haven, CT
Current Saint Francis Employees - Please click HERE to login and apply. Full Time Days PLEASE NOTE: Due to the nature of this role, candidates must be either local to the area or willing to relocate, as this position requires full-time onsite presence. Job Summary: As a member of the Information Security team, responsibilities include manages and mitigates information security risk by identifying, evaluating, assessing, designing, monitoring, administering, reporting and implementing systems, policies and processes. Provides information security risk insight and guides management on information security risk issues and serves as advisor to peers, team members and management.
Minimum Education: Bachelor's degree in Computer Science, MIS, Computer Engineering, Cyber Security or related discipline.
Licensure, Registration and/or Certification: None. One or more of the following certifications are preferred: Certified Information Systems Security Professional (CISSP), or Certified in Risk and Information Systems Control (CRISC) or Certified Information Systems Auditor (CISA).
Work Experience: 3 - 4 years related experience inclusive of two years working directly in an Information Services department and previous experience with HIPAA/PHI compliance programs, policies, procedures, risk assessments and audits.
Knowledge, Skills and Abilities: In-depth knowledge of cyber security methodology and security practices. Knowledge of HIPAA, PCI, SOX, ISO and NIST cybersecurity frameworks. Knowledge of intrusion detection and intrusion prevention systems, penetration and vulnerability testing. Knowledge of data loss prevention, anti-virus and anti-malware software tools. Knowledge of computer networking, TCP/IP, routing and switching, network protocols and packet analysis tools. Knowledge of Windows, UNIX and Linux operating systems. Excellent problem solving and analytical skills. Excellent written and oral communication skills. Excellent organizational and interpersonal skills. Ability to work independently as well as in a team setting.
Essential Functions and Responsibilities: Define, implement, and enforce information security policies, strategies, and procedures that align with healthcare laws and regulations, such as HIPAA. Conduct and/or support targeted risk assessment. Determine significant risk points and exercise process for risk assessment and risk acceptance. Review assessment results for vulnerabilities, gaps, control deficiencies, and work with key stakeholders to establish plans for sustainable resolution. Maintain an effective information security awareness program and educate internal teams on best practices. Ensures that business and clinical software applications include adequate information and security controls. Establish and maintain metrics based on the information security framework used at SFHS.
Decision Making: Independent judgment in making decisions from many diversified alternatives that are subject to general review in final stages only.
Working Relationships: Works directly with patients and/or customers. Works with internal customers via telephone or face to face interaction. Works with external customers via telephone or face to face interaction. Works with other healthcare professionals and staff. Works frequently with individuals at Director level or above.
Special Job Dimensions: None.
Supplemental Information: This document generally describes the essential functions of the job and the physical demands required to perform the job. This compilation of essential functions and physical demands is not all inclusive nor does it prohibit the assignment of additional duties.
Information Technology - Information Security - Yale Campus
Location:
Tulsa, Oklahoma 74136
EOE Protected Veterans/Disability
Auto-ApplySenior Cyber Security Engineer
Security architect job in Shelton, CT
For over 75 years, BIC has been creating ingeniously simple and joyful products that are a part of every heart and home. As a member of our team, you'll be a part of reigniting a beloved brand as we continue to reimagine everyday essentials in new, sustainable and responsible ways.
Our "roll up your sleeves and get the job done" approach to work creates an environment where self-starters, problem solvers and innovative thinkers thrive. BIC team members are empowered to take ownership of their careers and bring their unique perspectives to the table to make a meaningful impact on our mission.
It's a colorful world - make your mark by joining the BIC team today.
As **Senior Cybersecurity Engineer,** you will collaborate and partner with a global, cross-functional team to build cybersecurity capabilities and improve maturity. This role involves designing, implementing, and managing security technology to protect the company from cyber threats. Besides, you will support incident response, investigations, playbook development and efforts to identify and mitigate risk.
**In this role you will:**
+ Analyze, triage, and investigate alerts from various sources to determine the appropriate response or escalation
+ Document analysis, findings, and actions for case management and metrics
+ Support security incident response planning, procedure/playbook development and investigations
+ Participate in on-call rotation for off-hours escalations
+ Administer, optimize, and maintain the health of security tools, such as endpoint protection and response (EDR), network detection and response (NDR), and logging pipelines (Syslog/Cribl).
+ Assist with remediation of identified security risks
+ Minimum 6 years' experience in Information Technology or Cybersecurity
+ IT or cybersecurity certifications from industry recognized sources preferred
**What you bring to BIC:**
+ Minimum 6 years' experience in Information Technology or Cybersecurity
+ IT or cybersecurity certifications from industry recognized sources preferred
+ Prior experience interpreting or analyzing log data and working with log pipelines
+ Triaging alerts from various sources, following playbooks, and escalating legitimate issues
+ Knowledge of security tools such as endpoint protection, firewalls, intrusion prevention, SIEM and EDR (CrowdStrike)
+ Strong understanding of Windows server and desktop operating systems, networking fundamentals, security concepts, Active Directory, Microsoft Azure, Office 365.
+ In-depth analytical and problem-solving skills to resolve complex issues
BIC is an Equal Opportunity Employer. We strongly commit to hiring people with different backgrounds and experiences to help us build better products, make better decisions, and better serve our customers. We do not discriminate based upon race, religion, color, national origin, gender, sexual orientation, veteran status, disability status, or similar characteristics. All employment is decided based on qualifications, merit, and business need.
BIC is not seeking assistance or accepting unsolicited resumes from search firms for this employment opportunity. Regardless of past practice, all resumes submitted by search firms to any team member at BIC via email, or directly to a BIC team member in any form without a valid written search agreement in place for that position will be deemed the sole property of BIC, and no fee will be paid in the event the candidate is hired by BIC as a result of the referral or through other means.
Chief Information Security Officer
Security architect job in Shelton, CT
Title - Chief Information Security Officer Region: Shelton, CT Ready for a fresh, new career? Look no further because one of the world's most iconic brands can help you get there. Why Join Us? At Subway, "better" is baked into our DNA. We are a brand that believes in continued improvement … in our lives, our businesses, and our planet. From the handshake that started our very first sandwich shop to earning our position as one of the world's leading restaurant brands, we've always embraced change and the path ahead. And today, we're making better living way easier.
Our purpose is more than the food we serve in our restaurants. It's centered on fueling healthy businesses and healthier lives. It is one of the most exciting times to join the Subway team and contribute to our transformational journey.
About the Role:
The Chief Information Security Officer is responsible for leading the organization's cybersecurity strategy and operations. This role is focused on protecting company data, systems, and networks from cyber threats, ensuring the confidentiality, integrity, and availability of critical information assets. The CISO develops and implements cybersecurity policies, technologies, and incident response plans to defend against evolving threats and vulnerabilities and drives continuous improvement in the organization's cyber defense posture.
Responsibilities:
Develop and implement a comprehensive cybersecurity strategy aligned with the organization's business goals, focusing on the protection of data, systems, and networks.
Establish and enforce information security policies, standards, and procedures to ensure compliance with relevant laws, regulations, and industry best practices.
Develop and oversee incident response plans for operational risks.
Oversee incident response plans to effectively address and mitigate the impact of security incidents.
Oversee the monitoring of networks and systems for security breaches, vulnerabilities, and suspicious activity; coordinate rapid response to cyber incidents.
Continuously assess and prioritize cybersecurity risks, considering emerging threats, vulnerabilities, and technology trends.
Select and implement appropriate security controls and technologies to defend against cyber threats.
Regularly report on the organization's information security risk posture to executive leadership and relevant stakeholders. Collaborate with IT and business leaders to integrate cybersecurity considerations into technology projects and business processes
Manage third-party risk as it relates to cybersecurity, ensuring vendors and partners adhere to company security standards.
Foster an information security aware culture by promoting best practices and proactive security/risk management behaviors.
Develop and deliver training programs to enhance operational information security awareness across the organization. Implement programs to raise awareness of information security risks among employees and stakeholders.
Ability to align cybersecurity with business objectives.
Deep expertise in cybersecurity technologies, threat intelligence, and incident response.
Strong understanding of network, system, and application security
Experience with security operations centers (SOC), vulnerability management, and penetration testing.
Leadership and team management skills.
In-depth knowledge of cybersecurity technologies and trends.
Leadership and team management capabilities.
Knowledge of relevant regulatory requirements and industry best practices. (e.g., NIST, ISO 27001, GDPR).
Strong knowledge of industry regulations, standards, and best practices.
Qualifications:
Bachelor's Degree Business, Finance, Risk Management, Information Security, Computer Science, or a related field.
15 or more Extensive experience in cybersecurity, information security, or related technical fields, with a proven track record in leadership roles.
Demonstrated experience in designing and managing enterprise cybersecurity programs, incident response, and security operations
What do we Offer?
Insurance Plans (Medical/Life)
Pension/401K/RSP (country specific)
Competitive Bonus
Mobility Allowance
Tuition Reimbursement
Company Holidays
Volunteering time
And Many More…..
Actual pay is determined based on several job-related factors including skills, education, training, credentials, qualifications, scope and complexity of role responsibilities, geographic location, performance, and working conditions.
Information Security Specialist
Security architect job in Wallingford, CT
Community Health Network of Connecticut, Inc. (CHNCT) is currently seeking an Information Security Specialist. This is a full-time, hybrid position requiring 2 days per week onsite in our Wallingford, CT office.
Primary Responsibilities:
Under the direction of the Director of Information Security, the Information Security Specialist is responsible for operations, auditing, and technical monitoring of CHNCT's Information Security and related activities.
These activities include but are not limited to implementing and maintaining Information Security related systems, policies and processes in compliance with applicable security regulations (i.e., HIPAA and State of CT Security laws), and establishing and developing security-related operating procedures and standards.
Works directly with contracted vendors for the implementation and maintenance of security hardware, software and services.
Assists with the selection and evaluation of security related state-of-the-art systems.
Tasks Performed:
Monitors and maintains all aspects of the information security program.
As a COMPUTER SECURITY INCIDENT RESPONSE TEAMS (CSIRT) member, logs and responds to incidents including communication of potential violations of the company's information security policies to CHNCT's Chief Information Security Officer.
Independently acts to prevent or deter security breaches or intrusions that threaten the integrity of mission critical data or applications.
Monitors email and Data Loss Prevention logs and responds to potential policy or regulatory violations.
Monitors Phishing alerts and end user notifications.
Audits network and file permissions structure and password and account maintenance.
Assists in the development and testing of the Disaster Recovery and Business Continuity Plans.
Processes exception requests and performs risk analysis on these and other customer requests.
Actively reviews threat alerts and determines relevance and criticality to the organization.
Contributes to project activities as a project team member or ad-hoc as requested.
Other duties as assigned.
Essential Functions:
Implementation and maintenance of Information security related software, hardware and systems.
Systems include but are not limited to phishing identification and prevention, Internet content filtering, Data Loss Prevention (DLP), Intrusion Detection/Prevention (IDS/IPS), Endpoint Detection and Response (EDR), Log Management, and Advanced Threat Mitigation.
Duties include information security policy administration and configuration, security related server management, Disaster Recovery Planning, proactively identifying or rapidly responding to customer security issues and security events.
Desired Education: 2 years post-secondary schooling
Desired Degree: Associate's degree
Desired Major: Computer Assurance or Computer Science
Desired Job Experience: 3+ years' direct information security experience, preferably in healthcare
Other Qualifications: Security+ or other security-related certification. Hands on exposure to providing information security operational support in a medium to large scale healthcare organization preferred. Knowledgeable in the management and setup of security related software and hardware Working knowledge of security administration, DLP, or other information security systems. Knowledge of EDR, EPP, IDS/IPS, AD and network infrastructure. Detail oriented, with meticulous attention to system and procedure documentation.
CHNCT Offers Great Benefits:
Medical, dental and vision coverage options
Flexible spending and health savings accounts
Group term life insurance
A 401(k) plan with company-match and immediate vesting
Voluntary accidental injury coverage
Tuition reimbursement and continuing education opportunities
A generous paid-leave bank and company holidays
Wellness program
We are dedicated to having a workplace where everyone feels valued, respected, and empowered to succeed. We embrace a wide range of perspectives and backgrounds, ensuring fair treatment and opportunities for all employees. We value our team's rich array of experiences and viewpoints, which contribute to our innovative and collaborative environment.
Auto-ApplyOT Security Engineer
Security architect job in Stamford, CT
The OT Security Engineer, Global Information Security (GIS) will have primary responsibility for Crane's Operational Technology security solutions that protect Crane's manufacturing environments. You will implement OT and IoT security solutions throughout the enterprise and ensure that OT/IoT security solutions identify threats, uncover vulnerabilities, and measure risks of operational equipment.
Coordinating with both IT and OT teams at all manufacturing sites, you will define and develop security standards and technical solutions. As a subject matter expert in the hardening and defense of OT, you will work with business units to implement security standards, securely modify systems, and implement secure network architectures during implementations of OT related projects to ensure secure system deployments.
You will work closely with other GIS functional areas, supporting security engineering, administration, operations, and incident response. You will integrate the OT/IoT security solutions with other GIS and business unit tools such as SIEM, SOAR, AD, and other tools to gain a unified view of security events and respond more effectively to security incidents both for OT and IT.
Responsibilities and Duties:
* Support and maintain OT/IoT security tool set and associated integrations with other systems
* Collaborate with the manufacturing function across lines of business to develop and define security requirements
* Design OT security controls for architectures, systems and networks ensuring that alerting to threats is efficient and effective.
* Identify and implement supporting security technologies for the identification of threats and defense of OT systems and provide secure methods for remote access.
* Work directly with plant leaders, process engineers, and support/system vendors to ensure OT security controls are implemented
* Develop and implement standard work supporting the Global OT security function and supporting solutions
* Develop and maintain security models, templates, standards and procedures that can be used to leverage security capabilities in projects and operations
* Assist in the identification, response, investigation, and remediation of OT security events and incidents as needed
* Ensure security best practices are identified and integrated into all approaches and methodologies.
* Define requirements and design standards to protect Crane's OT solutions from security threats and for mitigating the impacts of these threats.
* Define reference network architectures based on industry best practices and work with business units to implement for OT solutions
* Consult on business unit OT projects and provide cybersecurity expertise
Qualifications and Competencies:
* 2yrs experience with securing Operational Technology and related systems environments
* Strong understanding and prior experience with the application of securing OT and related systems
* Current deep technical understanding of common OT systems such as PCS, SCADA, PLCs, RTUs, HMIs, CNC
* Deep technical understanding of TCP/IP Networking and Firewalls
* Deep technical understanding of system integration methods including API's and authentication methods
* Knowledgeable in NIST CSF, NIST 800-82, Purdue Model, IEC 62443 standards
* Solid foundation cybersecurity domains such as network security, EDR, anomaly detection
* Understanding of common OT communications protocols such as MQTT, MODBUS, DNP3, S7, G-code
* Comfortable with designing and overseeing the implementation of secure OT architectures
* Prior experience in the direct remediation of vulnerabilities or compensating controls within OT environments
* Commitment to security training and earning corresponding certifications
* Highly motivated with passion for solving complex problems
* Excellent verbal and written communication skills, comfortable with presenting to Operational Teams
* Flexibility to work outside regularly scheduled/normal business hours as required
* Ability and desire to travel both domestically and internationally
* Required: Degree in a related field or at least 4 years relevant professional experience
* Required: Mobility and ability to be on your feet for long periods in a manufacturing setting
* Required: Technical professional security certification such as GICSP, GRID, OSCP, CEH or similar
* US Person as defined under EAR PART 772 AND ITAR 120.15
This description has been designed to indicate the general nature and level of work being performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of employees assigned to this job.
Crane Company. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment and will not be discriminated against on the basis of race, color, religion, gender, sexual orientation, general identity, national origin, disability or veteran status.
Auto-ApplyInformation Security Risk Analyst
Security architect job in Setauket-East Setauket, NY
I have a client located in the East Setauket, NY area that has an opportunity for a Information Security Risk Analyst. If you or any of your colleagues are interested in discussing this opportunity please click Apply Now.
In this role you will be an Information Security Risk Analyst for a client that works in the medical industry. This role is responsible for monitoring, determining, and reviewing potential and current information security risks.
This is a 3 month and possibly longer contract. This role must be performed on-site.
The pay on this role is $30.00 to $40.00 an hour based on experience.
Job Requirements:
3+ years of experience with O365 and Purview platforms
Experience reviewing daily Risky Users
Ability to communicate with internal users to evaluate high risk access
Ability to monitor the company's networks and identify security breaches
Perform 3rd party security reviews using UpGuard TPRM tool
Monitor DoJ DSP attestations and manage vendor communication and certs
Help assist in creating IS runbook
Document security processes
Analyze Business Associate Agreements and provide recommendations on security & Liability
Support Audit responses and investigations
#VIS
Director, Client Security Engineering Architect
Security architect job in Stamford, CT
Known for being a great place to work and build a career, KPMG provides audit, tax and advisory services for organizations in today's most important industries. Our growth is driven by delivering real results for our clients. It's also enabled by our culture, which encourages individual development, embraces an inclusive environment, rewards innovative excellence and supports our communities. With qualities like those, it's no wonder we're consistently ranked among the best companies to work for by Fortune Magazine, Consulting Magazine, Seramount, Fair360 and others. If you're as passionate about your future as we are, join our team.
KPMG is currently seeking a Director, Tech Engineering to join our Tax Ignition Group.
Responsibilities:
* Lead the function of responding to clients' security inquires
* Meet with clients to answer their security questions and negotiate compensating controls when there are gaps between client requirements and our product offerings
* Drive innovation and improvement in the client security inquiry process such incorporating Artificial Intelligence into the process, creating additional collateral such as whitepapers, managing metrics, and improving the tooling and interactions with requestors
* Partner with various groups within Tax's technology function and business teams to incorporate trends into product roadmaps; collaborate with other compliance teams, and raise awareness around client security requirements
* Review and respond to client security questionnaires and assessments
* Build and maintain a knowledge base of common client questions
Qualifications:
* Minimum ten years of recent experience in Information Technology (IT) security compliance, risk management or related IT security within a large IT organization, preferably within a professional services firm, software product, or other highly regulated environment
* Bachelor's degree from an accredited college or university is preferred
* Deep understanding of cloud architecture, modern software development, and technical security controls is required; Azure experience is preferred
* Strong executive presence, negotiation, presentation, and communication skills are required; excellent analytical and problem-solving skills to assess complex security issues and develop effective solutions; capability to work effectively in a global environment, understanding diverse cultural perspectives and international client needs
* Proven experience in client-facing roles, particularly in handling security inquiries, negotiations, and managing client relationships; demonstrated ability to drive innovation and continuous process improvement, particularly in integrating new technologies and methodologies into existing processes
* Demonstrated knowledge of industry authoritative sources such as COBIT, NIST, ISO standards; CISM, CISA, ISO 27001 Auditor, LSS Green Belt, CRISC, CIPP, CGEIT or ITIL preferred
* Must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa
KPMG LLP and its affiliates and subsidiaries ("KPMG") complies with all local/state regulations regarding displaying salary ranges. If required, the ranges displayed below or via the URL below are specifically for those potential hires who will work in the location(s) listed. Any offered salary is determined based on relevant factors such as applicant's skills, job responsibilities, prior relevant experience, certain degrees and certifications and market considerations. In addition, KPMG is proud to offer a comprehensive, competitive benefits package, with options designed to help you make the best decisions for yourself, your family, and your lifestyle. Available benefits are based on eligibility. Our Total Rewards package includes a variety of medical and dental plans, vision coverage, disability and life insurance, 401(k) plans, and a robust suite of personal well-being benefits to support your mental health. Depending on job classification, standard work hours, and years of service, KPMG provides Personal Time Off per fiscal year. Additionally, each year KPMG publishes a calendar of holidays to be observed during the year and provides eligible employees two breaks each year where employees will not be required to use Personal Time Off; one is at year end and the other is around the July 4th holiday. Additional details about our benefits can be found towards the bottom of our KPMG US Careers site at Benefits & How We Work.
Follow this link to obtain salary ranges by city outside of CA:
**********************************************************************
KPMG offers a comprehensive compensation and benefits package. KPMG is an equal opportunity employer. KPMG complies with all applicable federal, state and local laws regarding recruitment and hiring. All qualified applicants are considered for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, citizenship status, disability, protected veteran status, or any other category protected by applicable federal, state or local laws. The attached link contains further information regarding KPMG's compliance with federal, state and local recruitment and hiring laws. No phone calls or agencies please.
KPMG recruits on a rolling basis. Candidates are considered as they apply, until the opportunity is filled. Candidates are encouraged to apply expeditiously to any role(s) for which they are qualified that is also of interest to them.
Los Angeles County applicants: Material job duties for this position are listed above. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness, and safeguard business operations and company reputation. Pursuant to the California Fair Chance Act, Los Angeles County Fair Chance Ordinance for Employers, Fair Chance Initiative for Hiring Ordinance, and San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Lead SAP Security & GRC admin- Full time perm job
Security architect job in Stamford, CT
E*Pro Consulting service offerings include contingent Staff Augmentation of IT professionals, Permanent Recruiting and Temp-to-Hire. In addition, our industry expertise and knowledge within financial services, Insurance, Telecom, Manufacturing, Technology, Media and Entertainment, Pharmaceutical, Health Care and service industries ensures our services are customized to meet specific needs. For more details please visit our website ******************
Job Description
SAP Security & GRC
Additional Information
All your information will be kept confidential according to EEO guidelines.