Post job

Security director work from home jobs - 88 jobs

  • Director, Physical Security Governance, NA

    Vantage Data Centers 4.3company rating

    Remote job

    Vantage Data Centers powers, cools, protects and connects the technology of the world's well-known hyperscalers, cloud providers and large enterprises. Developing and operating across North America, EMEA and Asia Pacific, Vantage has evolved data center design in innovative ways to deliver dramatic gains in reliability, efficiency and sustainability in flexible environments that can scale as quickly as the market demands. Role Summary The Director, Physical Security Governance will be responsible for designing, building, and leading Vantage Data Centers' North American physical security governance program from inception through full operational maturity. This role establishes the framework that ensures security is delivered consistently, compliantly, and at scale across all North American sites, while enabling the business to grow with confidence. This leader will own the policies, quality assurance, compliance oversight, performance measurement, and continuous-improvement mechanisms that transform physical security from site-based execution into a governed, measurable, enterprise-grade program. This position serves as the central authority for how physical security is defined, governed, measured, and improved across Vantage Data Centers' North American portfolio. Core Responsibilities Security Governance & Program Leadership Design and implement the North American Physical Security Governance Program, including governance models, operating frameworks, and control structures aligned with enterprise security objectives. Establish clear accountability, ownership, and decision rights across Physical Security Design, Delivery, Operations, Technology, and the Security Management Center (SMC). Serve as the executive-level authority for physical security governance across North America, ensuring all sites operate under a unified framework. Policy, Standards & Procedures Develop, maintain, and govern all North American physical security policies, standards, and procedures, including but not limited to: Access control Video surveillance Guard force operations Incident and threat management Visitor management Construction site security Data center physical security controls Ensure policies align with corporate risk, legal, compliance, privacy, and customer contractual obligations. Translate security standards into operationally executable procedures across all North American sites. Quality Assurance, Audits & Continuous Improvement Build and lead a Quality Assurance and Compliance function for physical security, including audit programs, control testing, site inspections, and validation of operating effectiveness. Define and manage corrective action and remediation programs resulting from audits, incidents, and performance gaps. Own the governance of all physical security after-action reviews, ensuring root-cause analysis, corrective actions, and preventive controls are documented, tracked, and closed. Performance Management, KPIs & Metrics Define and own the physical security performance framework, including key performance indicators (KPIs), key risk indicators (KRIs), and quality metrics. Establish measurable standards for: Policy compliance Control effectiveness Incident response quality Training and certification completion Site security performance Ensure leadership and site teams have clear, data-driven visibility into security performance, risks, and trends. Training, Certification & Enablement Design, develop, and govern the enterprise security training and awareness framework for North America, covering all employees, contractors, and site personnel, including: Physical security awareness and policy training Workplace violence prevention and response Threat awareness, reporting, and escalation Visitor management and access control expectations New-hire and new-site onboarding security training Annual and recurring security awareness and compliance training Own the creation, maintenance, and governance of all security training content, including standards, curricula, learning materials, and certification requirements. Ensure training programs remain aligned with evolving threats, regulatory requirements, customer security expectations, and internal risk priorities. Partner with Human Resources, Legal, Compliance, Operations, the Security Management Center (SMC), and Technology teams to embed security training into onboarding, lifecycle training, and daily business operations. Outreach, Engagement & Program Adoption Build and mature the Outreach and Engagement function to drive adoption of physical security governance across: Data center site leadership Construction and delivery teams Operations and IT Corporate stakeholders External partners, including law enforcement and relevant government agencies Establish and maintain strong working relationships with local, state, and federal law enforcement and government entities to support incident response, investigations, emergency preparedness, and threat mitigation. Lead change management, communications, and stakeholder engagement to ensure security standards, expectations, and governance models are consistently understood and applied across the North American portfolio. Required Qualifications 10+ years of experience in physical security, risk management, compliance, or governance within data centers, critical infrastructure, or high-reliability environments. Proven experience building and scaling enterprise governance, compliance, or quality assurance programs. Deep understanding of physical security controls, guard force operations, access control systems, and surveillance technologies. Experience operating in audited, regulated, or customer-validated environments. Demonstrated ability to define metrics, KPIs, and control frameworks and hold organizations accountable to them. Preferred Experience Experience supporting hyperscale or colocation data centers. Background in audit, compliance, or quality management systems. Experience partnering with legal, risk, compliance, construction, IT, and operations teams. Familiarity with security platforms, incident management tools, and compliance tracking systems. Additional Details Salary Range: $180,000 - $195,000 (this range is based on Colorado market data and may vary in other locations) This position is eligible for company benefits including but not limited to medical, dental, and vision coverage, life and AD&D, short and long-term disability coverage, paid time off, employee assistance, participation in a 401k program that includes company match, and many other additional voluntary benefits. Compensation for the role will depend on a number of factors, including your qualifications, skills, competencies, and experience and may fall outside of the range shown. Physical Demands and Special Requirements The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. While performing the duties of this job, the employee is occasionally required to stand; walk; sit; use hands to handle, or feel objects; reach with hands and arms; climb stairs; balance; stoop or kneel; talk and hear. The employee must occasionally lift and/or move up to 25 pounds. #LI-Remote #LI-AH1 We operate with No Ego and No Arrogance. We work to build each other up and support one another, appreciating each other's strengths and respecting each other's weaknesses. We find joy in our work and each other, actively seeking opportunities to inject fun into what we do. Our hard and efficient work is rewarded with an above market total compensation package. We offer a comprehensive suite of health and welfare, retirement, and paid leave benefits exceeding local expectations. Throughout the year, the advantage of being part of the Vantage team is evident with an array of benefits, recognition, training and development, and the knowledge that your contribution adds value to the company and our community. Don't meet all the requirements? Please still apply if you think you are the right person for the position. We are always keen to speak to people who connect with our mission and values. Vantage Data Centers is an Equal Opportunity Employer Vantage Data Centers does not accept unsolicited resumes from search firm agencies. Fees will not be paid in the event a candidate submitted by a recruiter without an agreement in place is hired; such resumes will be deemed the sole property of Vantage Data Centers. We'll be accepting applications for at least one week from the date this role is posted. If you're interested, we encourage you to apply soon-we're excited to find the right person and will keep the role open until we do!
    $180k-195k yearly Auto-Apply 6d ago
  • Job icon imageJob icon image 2

    Looking for a job?

    Let Zippia find it for you.

  • Director of Security

    Onestudyteam

    Remote job

    At OneStudyTeam (a Reify Health company), we specialize in speeding up clinical trials and increasing the chance of new therapies being approved with the ultimate goal of improving patient outcomes. Our cloud-based platform, StudyTeam, brings research site workflows online and enables sites, sponsors, and other key stakeholders to work together more effectively. StudyTeam is trusted by the largest global biopharmaceutical companies, used in over 6,000 research sites, and is available in over 100 countries. Join us in our mission to advance clinical research and improve patient care. One mission. One team. That's OneStudyTeam. The Director of Security leads enterprise security strategy and execution across governance, risk, compliance, and security engineering. This role manages the GRC and Security Engineering teams, partners with technology and business leaders, and ensures the design and operation of secure systems and processes across the organization. The Director is accountable for program maturity, audit readiness, and continual improvement. The scope includes third party risk, vendor assessment and qualification, security architecture oversight, AI related security assessments and guidance, incident response leadership, and budget ownership for security programs. This is a hands-on, technical leadership role with high autonomy that blends strategic program leadership with practical execution. The Director will develop roadmaps and metrics, allocate resources, and ensure alignment with business priorities and regulatory obligations. What You'll Be Working On: Lead and manage the GRC and Security Engineering teams, including strategy, objectives, staffing, coaching, and performance management. Own governance, risk, and compliance programs. Maintain ISO 27001 and related controls. Drive audit readiness for HIPAA and other frameworks. Coordinate policy lifecycle management and control testing. Run vendor assessment and qualification program. Oversee third party risk management, due diligence, contractual security requirements, and continuous monitoring. Provide AI related security assessments and guidance. Establish acceptable use guardrails for AI, assess model and data risks, and advise on controls for AI enabled solutions. Oversee security architecture for cloud environments and enterprise platforms. Partner with engineering on secure design for AWS, Azure, identity, network, and data protection. Direct security engineering operations. Manage EDR and threat detection with CrowdStrike, SIEM operations, CSPM posture management, vulnerability management, and SOAR automation. Lead incident response readiness and execution. Run tabletop exercises, coordinate investigations, and deliver root cause and lessons learned. Own and manage security budgets, multiyear planning, vendor contracts, and cost optimization while meeting control objectives. Report program status and risk posture to executives and the board. Define and track KPIs and KRIs. Communicate clearly with technical and non technical stakeholders. Establish and enforce secure software development practices and SDLC controls with engineering leadership. Maintain a current security roadmap and maturity plan aligned to business priorities. Oversee metrics, dashboards, and reporting for program performance and risk reduction. Coordinate with Legal, Privacy, and Compliance on regulatory obligations and customer security assessments. Champion security awareness training and culture, sponsor targeted training for engineering and high risk roles. Evaluate, select, and manage strategic security vendors and platforms, drive successful implementations and integrations. Represent security in customer meetings and due diligence, provide credible technical and compliance answers. What You'll Bring to OneStudyTeam: 15+ years of progressive experience in information security or related fields. 10+ years of management experience leading security teams, including people leadership and program ownership. Bachelor's degree in Computer Science, Engineering, Information Security, or related field. Relevant certifications strongly preferred. Examples include CISSP and CISM. [Proven leadership of security programs at enterprise scale. Ability to set strategy, drive execution, and deliver measurable outcomes. Demonstrated expertise in governance, risk, and compliance programs, including driving the implementation of ISO27001, SOC2, or HITRUST certification. Experience with AI security risk management, data protection for AI use cases, and acceptable use guardrails for AI and large language models. Strong background in secure software development, application security, and SDLC controls, including threat modeling and secure coding practices. Hands-on knowledge of cloud security for AWS and Azure, identity and access management, network security, data protection, and key management. We value diversity and believe the unique contributions each of us brings drives our success. We do not discriminate on the basis of race, sex, religion, color, national origin, gender identity, age, marital status, veteran status, or disability status. Note: OneStudyTeam is unable to sponsor work visas at this time. If you are a non-U.S. resident applicant, please note that OneStudyTeam works with a Professional Employer Organization. As a condition of employment, you will abide by all organizational security and privacy policies. This organization participates in E-Verify (E-Verify's Right to Work guidance can be found here).
    $90k-144k yearly est. Auto-Apply 7d ago
  • Client Director - Cyber Security

    Redapt 3.8company rating

    Remote job

    Redapt Inc. is a pioneering world-class data center infrastructure integrator, technology engineering firm, and cloud services provider. Our teams focus on delivering innovative solutions and services that power our customers most demanding applications and enable them to extract powerful insights from data that drives true business value. We are seeking a dynamic and results-driven Client Director to join our team. In this consultative acquisition sales role, you will be responsible for acquiring, building and maintaining strong client relationships. You will have a solid understanding of client's business needs and providing customized solutions and professional services which are adjacent to cybersecurity, cloud, data center, and networking technologies. This enterprise sales role will require executive peer to peer dialogue and leadership capabilities that will engage the client and internal resources for open and trusted collaboration. You will identify opportunities and engage internal team personnel with clients while simultaneously achieving meaningful wins that advance the clients most strategic projects and/or initiatives. If you are a motivated individual with a passion for building long term relationships in a fast paced and evolving space that has tremendous upside, then we invite you to apply for this exciting opportunity. Responsibilities: You will develop and execute a strategic sales plan to achieve and exceed sales targets within the cybersecurity and IT solutions portfolio. Prospect, acquire, build and nurture relationships with target clients, understanding their unique challenges and objectives. Collaborate with internal teams, including technical experts, to design and present comprehensive solutions that address client needs. Stay updated on industry trends, emerging technologies, and competitor offerings to maintain a competitive edge. Lead and participate in client presentations, negotiations, and contract discussions. Provide accurate sales forecasts and reports to the leadership team so we can communicate the necessary resources to execute initiatives for our clients. Engage with partner OEM, ISV, and Infrastructure technologies to expand relevance and opportunities for our clients to optimize, reduce risk, increase business resiliency, and safeguard digital assets from threats. Skills you bring with you: Proven experience in consultative sales, preferably in the cybersecurity and IT industry. Strong understanding of cybersecurity solutions and IT services. Excellent communication and presentation skills, with the ability to articulate complex technical concepts to a non-technical audience. Demonstrated success in building and maintaining long-term client relationships. Proactive and results-oriented approach to sales. Must be willing and open to learn new concepts, ideas, frameworks, and technologies that advance and impact our client's organization. Demonstrated ability to cultivate new relationships and gain trust from key stakeholders. Qualifications: Bachelor's degree in a related field or equivalent experience. 5+ years of experience in consultative sales, preferably with a focus on cybersecurity and IT solutions. 100% Hunter Worked for a Value-Added Reseller or an Integrator. Travel required: Travel typically 15-25% or more a month Equal Employment Opportunity: Redapt is an equal opportunity employer. Applicants will not be discriminated against because of race, color, creed, sex, sexual orientation, gender identity or expression, age, religion, national origin, citizenship status, disability, ancestry, marital status, veteran status, medical condition, or any protected category prohibited by local, state, or federal laws. All employment is decided based on qualifications, merit, and business need. #LI-LM1
    $93k-134k yearly est. Auto-Apply 60d+ ago
  • Alliance Director - API Security

    Wallarm

    Remote job

    Since 2016, Wallarm has been on a mission to secure the internet's critical infrastructure: APIs. Today, we are the trusted choice for over 200 of the world's most innovative companies, from high-growth startups to Fortune 500 and Nasdaq leaders. Our unified platform provides full-lifecycle API security - helping teams discover their attack surface, protect against modern threats, and respond to incidents in real-time. As a graduate of Y Combinator and fueled by a recent $55M Series C, we are scaling our global, remote-first team of 150+ innovators to solve the next generation of security challenges. About the role: We are seeking an experienced and highly motivated Alliance Director to lead and expand strategic partnerships with technology vendors. This role will play a critical part in scaling our go-to-market efforts by developing joint solutions, enabling co-selling and co-marketing motions that create long-term value through aligned ecosystem strategies. Responsibilities: Alliance Strategy & Execution Define and execute the strategic partnership roadmap aligned with business goals. Identify, evaluate, and onboard new partners that enhance our API security platform offering. Develop joint business plans with key partners, including co-selling, co-marketing, and solution integration opportunities. Partner Management & Enablement Own and grow relationships with strategic alliance partners. Build executive-level and field-level alignment between Wallarm and alliance partner organizations. Lead alliance enablement programs to ensure successful technical and sales collaboration. Go-to-Market (GTM) Collaboration Drive joint GTM initiatives, including campaigns, demand generation, and solution launches. Align with sales leadership to develop partner-influenced pipeline and revenue targets. Monitor and report on performance metrics for each alliance and recommend adjustments as needed. Cross-Functional Leadership Collaborate with product, marketing, sales engineering, and legal to ensure the successful execution of alliances. Influence product roadmap by advocating for partner-integrated features and capabilities. Job requirements We are looking for candidates with: 7-10 years of experience in strategic alliances, business development, or channel sales within cybersecurity or cloud/SaaS environments. Deep understanding of the cybersecurity landscape; API security knowledge is a strong plus. Experience managing alliances with technology partners. Proven ability to build high-impact GTM partnerships that drive measurable results. Strong business acumen and ability to influence C-level stakeholders both internally and externally. Excellent communication, negotiation, and presentation skills. Bachelor's degree required; MBA or technical degree a plus. Nice to have: Familiarity with modern API ecosystems (e.g., REST, GraphQL, OpenAPI, Kubernetes, API gateways). Background in enterprise security products, including API security. Ability to thrive in a fast-paced, high-growth startup environment. Why Join Us: Be part of a category-defining company in the booming API Security space. Work with a passionate, high-performing team at the intersection of security, innovation, and go-to-market strategy. Remote work and flexible working hours. Competitive salary and bonuses. Paid days off and medical insurance. Working equipment. Professional development and career growth opportunities. All done! Your application has been successfully submitted! Other jobs
    $82k-147k yearly est. 60d+ ago
  • Manager, Vulnerability & Data Security

    MQ Referrals Only

    Remote job

    As Marqeta's Information Security Manager you will lead Vulnerability Management and establish a Data Security program. You'll drive risk reduction across cloud, endpoints, and applications, while building controls and monitoring to safeguard critical data end-to-end across all of Marqeta's systems and services-100% cloud-based, with no data center footprint. We work Flexible First. This role can be performed remotely anywhere within the United States. We'd love for you to join us! The Impact You'll Have: Vulnerability Management Lead program strategy and operations: asset coverage, scanning cadence, prioritization, and measurable risk reduction using Tenable (Nessus/SC/IO) and Snyk. Integrate Tenable and Snyk findings into engineering backlogs with clear SLAs; partner with SRE, platform, and application teams to drive remediation. Establish risk-based prioritization (CVSS, KEV, EPSS, exploitability, business criticality) and publish dashboards for transparency to leadership. Mature patching and configuration baselines; build preventative controls and secure-by-default guardrails. Coordinate vulnerability disclosure, pen test intake, and threat-driven campaigns for actively exploited CVEs. Report program health, trends, and exceptions to security leadership and auditors. Data Security (Program Build & Ownership) Establish clear data ownership and stewardship across critical datasets; define roles, responsibilities, and decision rights. Define and enforce data classification, access, and usage policies; drive best practices and guard rails for least privilege and segregation of duties. Operationalize Sentra (DSPM) and Google DLP to monitor data exposure and access risks; drive timely remediation with accountable teams. Build data lifecycle controls (creation, storage, use, sharing, archival, destruction) and technical guardrails embedded in platforms and workflows. Ensure compliance with data protection regulations (e.g., PCI, SOX); partner on control design, testing, and evidence collection. Collaborate with Security, Legal, Privacy, and Data teams to protect data across its lifecycle and enable safe analytics/product use cases. Develop metrics (DLP incidents, misconfigurations, toxic combinations, stale sensitive datasets, policy violations) and report to leadership. Who You Are: 7-10+ years in information security with 3+ years leading programs or teams; regulated/fintech experience preferred. Hands-on depth managing vulnerabilities at scale with Tenable and Snyk across cloud-native, containers, endpoints, and CI/CD. Practical experience building/maturing data security programs with Sentra (DSPM) and Google DLP; strong policy design and enforcement. Partner management across engineering, data, and compliance; able to translate risk into actionable plans and measurable outcomes. Familiarity with PCI and SOX; knowledge of SDLC, DevSecOps, and cloud security architectures (AWS/GCP/Azure). Comfort with IAM/IGA, SIEM, CNAPP, and ticketing/workflow integrations; solid grasp of data governance concepts (stewardship, lineage). Excellent communication and reporting-clear narratives, crisp metrics, executive-ready updates. Certifications such as CISSP or CISM are a plus. How you'll measure success Reduction in high-risk vulnerabilities and time-to-remediation across prioritized asset classes. Complete inventory coverage and adherence to patch/configuration SLAs via Tenable/Snyk dashboards. Implemented and adopted data classification and access policies with defined ownership. Sentra and Google DLP coverage with declining exposure trends and timely remediation. Successful PCI/SOX audits for relevant controls; fewer exceptions and faster closure. Clear metrics and dashboards used by leadership for decision-making. Nice to Have's: Experience automating Tenable/Snyk workflows into CI/CD and GRC/Risk registers. Background in data governance (stewardship councils, RACI) and analytics platform security (e.g., Snowflake, Databricks, BigQuery). Exposure to SaaS Security Posture Management and third-party data controls at scale. Manager: Chetan Jha Recruiter For This Role: Kayla Osuna Compensation and Benefits: Marqeta is a Flex First company which allows you to choose your best working environment, whether that be from home or at a company office. To support Flex First, we calibrate pay to a competitive value according to working location. Compensation is aligned according to three tiers within the United States: National: A baseline tier that applies to most of the geographic territory of the United States. Premium: Slightly elevated from the National tier, and oriented toward a narrower set of higher cost-of-living areas, such as Los Angeles CA and Seattle WA Premium Plus: A tier for the most expensive working areas, like the San Francisco Bay area and New York City. Visit this page or consult with a Recruiter to determine which tier would be applicable to you. When determining salaries, we consider several factors including, but not limited to, skills, prior experience, and work location. The new-hire base salary range for this position is: National: $167,100 - $208,900 Premium: $179,800 - $224,700 Premium Plus: $$195,400 - $244,400 We also believe in recognizing the contributions of our people. That's why we award annual bonuses to eligible employees, rewarding both individual performance and the success of the entire company. Along with monetary compensation, Marqeta offers Multiple health insurance options Flexible time off - take what you need Retirement savings program with company contribution and after tax contributions Equity in a publicly-traded company and an Employee Stock Purchase Program Family-forming benefits, fertility support, and up to 20 weeks of Parental Leave Free therapy sessions, financial and professional coaching, and legal advice Monthly stipend to support our remote work model Annual “development dollars” to support our people growth and development Through Flex First, the freedom to live and work wherever you and your family thrive
    $179.8k-224.7k yearly Auto-Apply 8d ago
  • Information Security - Governance, Risk, and Compliance (GRC) Director (Remote)

    P&G 4.8company rating

    Remote job

    Information Technology at Procter & Gamble is where business, innovation and technology integrate to build a competitive advantage for P&G. Our mission is clear -- we deliver IT to help P&G win with the over 5 billion consumers we serve worldwide. Our IT professionals are diverse business leaders who apply IT expertise to deliver innovative, tech-focused business models and capabilities for our 65 iconic, trusted brands. From Day 1, you'll be trusted to dive right in, take the lead, use your initiative, and build billion-dollar brands that help make everyday activities easier and make the world a better place! Our company offers purposeful work that will take your career places you never envisioned, in creative workspaces where innovation thrives and where your technical expertise is recognized and rewarded. The Opportunity P&G is seeking a Governance, Risk, and Compliance Director passionate about safeguarding data, enabling business through smart risk management, and shaping the future of cybersecurity. The IT Governance, Risk, and Compliance (GRC) Organization at Procter & Gamble is responsible for risk identification, assessment, and remediation across the IT landscape, as well as driving automated governance and compliance breakthroughs. As the GRC expert, you'll play a critical role in maturing and maintaining the security risk and compliance posture of our organization. You will lead initiatives that align our security program with business goals, ensure regulatory and policy compliance, and creatively solve problems to manage risk for the company. Responsibilities: Governance: Maintain and evolve the information security policy framework and controls aligned with industry best practices (e.g., NIST, ISO 27001, CIS). Establish and track metrics to measure policy adherence and program maturity. Drive internal alignment on security roles, responsibilities, and expectations. Risk Management: Manage the enterprise risk management process including risk identification, analysis, treatment planning, and reporting. Conduct security risk assessments for internal systems, projects, vendors, and business processes. Facilitate risk-based decision-making at all levels of the organization. Compliance: Ensure ongoing compliance with applicable regulations and frameworks (e.g., GDPR, HIPAA, CCPA, SOX). Maintain a library of evidence and documentation to support audit and regulatory needs. Monitor the effectiveness of IT controls and identify gaps in compliance. Analyze control measurements for negative trends and reoccurrence frequency. Collaborate with internal/external auditors on compliance audits, audit findings, and issue remediation Awareness & Enablement: Contribute to the continuous improvement of the risk and compliance mindset across P&G. Build IT risk awareness by providing support and training to others. Collaborate cross-functionally with IT, Legal, Privacy, and Business Operations teams. Stay up to date with how current events, security focus areas, and the regulatory environment may impact P&G's compliance processes Estimated Percent of Time Spent on Work 25% - Risk identification, analysis, and assessment 40% - Plan and drive enterprise-wide initiatives to reduce risk and improve compliance across the organization 25% - Assess and improve the effectiveness of IT controls and compliance across the enterprise 10% - Collaboration with internal/external auditors, driving a risk-aware compliance mindset Job Qualifications Required: Bachelor's degree in Computer Science, Computer Systems Engineering, Cybersecurity, Industrial Engineering, Business Management Information Systems, Software Development, or related field Prior hands on experience working in a security-focused role, such as Information Security Analyst, SOC Analyst, Security Engineer, etc. 8+ years of experience in Governance, Risk, and Compliance with a focus on Information Security In-depth knowledge of major security frameworks (e.g., NIST CSF, ISO 27001, SOC 2). Experience conducting risk assessments, audits, and control testing. Strong understanding of regulatory compliance requirements (e.g., GDPR, HIPAA, SOX, PCI DSS). Proven ability to write policies, manage documentation, and communicate clearly to both technical and non-technical stakeholders. Ability to influence and build relationships with business unit stakeholders, external service providers, and architecture teams. The ability to work independently, collaborate, and learn quickly. English fluency (speak, write, and read) Preferred Skills: Certified in CISSP, ISACA CRISC, CGEIT, CISA, or similar Pay Range: $160,000 - $220,000 Compensation for roles at P&G varies depending on a wide array of equal opportunity factors including but not limited to the specific office location, role, degree/credentials, relevant skills, and level of experience. At P&G compensation decisions are dependent on the facts and circumstances of each case. Total rewards at P&G include salary + bonus (if applicable) + benefits. Your recruiter may be able to share more about our total rewards offerings and the specific salary range for the relevant location(s) during the hiring process. Our company is committed to providing equal opportunities in employment. We value diversity and do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. Immigration Sponsorship is not available for this role. For more information regarding who is eligible for hire at P&G along with other work authorization FAQ's, please click HERE. P&G participates in e-verify as required by law. Qualified individuals will not be disadvantaged based on being unemployed. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation. Job Schedule Full time Job Number R000136880 Job Segmentation Experienced Professionals Starting Pay / Salary Range $160,000.00 - $220,000.00 / year
    $160k-220k yearly Auto-Apply 60d+ ago
  • Manager, Security Operations

    U.S. Renal Care, Inc. 4.7company rating

    Remote job

    USRC's greatest strength in being a leader in the dialysis industry is our ability to recognize and celebrate the differences in our diverse workforce. We strongly believe in recruiting top talent and creating a diverse and inclusive work climate and culture at all levels of our organization. SUMMARY As a key leader within the Information Security organization, the Security Operations Manager is responsible for overseeing day‑to‑day security operations and ensuring the effective detection, investigation, containment, and remediation of cyber threats impacting the enterprise. This role manages a team of analysts, drives operational readiness, and strengthens the organization's security posture through continuous improvement, technical leadership, and cross‑department collaboration. The Security Operations Manager must be capable of operating independently, demonstrating advanced critical‑thinking skills, strong analytical capabilities, sound judgment under pressure, and the ability to comprehend and address complex technical and organizational challenges without relying solely on predefined checklists or prescriptive workflows. Responsibilities listed below represent the minimum expectations for this role. Additional duties may be assigned as necessary to support business, regulatory, or operational objectives. Essential Duties and Responsibilities include the following. Other duties and tasks may be assigned. Security Operations Leadership Oversee day‑to‑day SOC operations across cloud, on‑premises, endpoint, and application environments. Provide technical direction and operational leadership to SOC analysts. Ensure all security events and incidents are managed consistently, accurately, and in alignment with organizational priorities. Team Management & Development Lead, mentor, and coach SOC analysts to support skill development, analytical capability, and operational maturity. Assist in performance evaluations, guide career progression, and foster a culture of accountability and high performance. Establish expectations for independent analysis, strong reasoning, and effective decision‑making by team members. Incident Response Ownership Direct and coordinate incident response activities, including investigation, containment, and remediation. Provide real‑time guidance to analysts during high‑severity incidents and ensure timely, well‑documented resolution. Serve as an escalation point for complex investigations or ambiguous threat scenarios requiring executive decision‑ Threat Detection, Monitoring & Analysis Evaluate and enhance detection coverage, analytic depth, and SOC visibility. Partner with threat intelligence, engineering, and architecture teams to refine detection logic and improve response capability. Ensure SOC maintains awareness of emerging threats and incorporates relevant intelligence into operations. Cross‑Functional Collaboration Coordinate with IT Infrastructure, Networking, Application, Clinical, and Cybersecurity Architecture teams to support remediation activities. Collaborate closely with Compliance and HR during internal investigations requiring log analysis, evidence gathering, or technical validation. Support audit engagements, including SOC2 and regulatory requirements (e.g., HIPAA, NIST CSF), by providing evidence, insights, and technical expertise. Process, Playbooks & Documentation Develop, maintain, and continuously improve SOC playbooks, incident response procedures, and operational documentation. Identify and eliminate operational bottlenecks, introducing process efficiencies based on experience and analytical insight. Technology Ownership & Optimization Oversee SOC technologies including SIEM, EDR/XDR, SOAR, threat intelligence platforms, and related detection or investigation tooling. Ensure platform configurations, alerting logic, and integrations remain optimized for accuracy, visibility, and speed. Analytics, Reporting & Metrics Track SOC KPIs and operational metrics to effectively communicate security posture, incident volume, and response effectiveness. Deliver concise, executive‑ready reporting on incidents, trends, risks, and opportunities for improvement. AI‑Enablement & Automation Integration Identify opportunities to leverage AI and automation to improve SOC efficiency, reduce manual workload, and strengthen response capability. Explicit leadership of AI‑driven security solutions and responsible AI governance (frameworks, adoption, alignment with ERM/compliance). Partner with engineering teams to integrate automation into investigation and response workflows. On‑Call Requirement & After‑Hours Support Participation in the on‑call rotation as needed by operational needs. Incident response and CSIRT activation may require engagement during evenings, nights, weekends, or holidays. Maintain readiness to support critical and high‑severity incidents requiring immediate leadership involvement. Participation and engagement in tabletop exercises and risk assessments Penetration testing participation (internal/external; cloud/mobile/app) with third-party vendors Cloud security strategy definition and execution (posture management, tenant onboarding, compliance alignment). Authoring enablement documentation for assessments and platform integrations. Additional responsibilities may be assigned as necessary based on evolving technologies, threats, business needs, or regulatory requirements. Upholds management goals of corporation by leading staff in team concepts and promoting a team effort. Maintains effective personnel management and employee relations, including evaluating the performance of all personnel; approving and submitting all hours worked and counseling and disciplining employees. Recruits, trains, develops, and supervises personnel. Effectively communicates expectations; accepts accountability and holds others accountable for performance. Regular and reliable attendance is required for the job.
    $44k-85k yearly est. 1d ago
  • Global Security - Vulnerable Adult Investigations Manager

    JPMC

    Remote job

    The mission of the Global Security (GS) team is the protection of the firm's people and assets, ensuring the safety and soundness of JPMorgan Chase's business operations throughout the world. GS works to minimize disruption and threats that undermine our businesses' ability to serve our customers by staying in front of external and internal risks, screening all new employees, protecting our franchises when needed with thorough investigations, ensuring the safety of business travelers, and working to keep our businesses open during extraordinary situations from weather disruptions to local protests. As a Global Security - Vulnerable Adult Investigations Manager within the Global Security team, you will be responsible for supervising and directing the activities of a team of investigators and performing investigations of elder/vulnerable adult financial exploitation. Your focus will be on root cause analysis, quantifying risk, and ensuring compliance with the GS Vulnerable Adult Investigations Procedure. You will communicate your findings to management, prompting them to initiate system, process, and procedural changes to address identified areas of concern. Job responsibilities: Manages the investigation process with a focus on gathering evidence for elder/ vulnerable adult investigations while ensuring compliance with regulatory requirements as well as internal policies and procedures. Maintains team compliance and collaboration with referrals to applicable Adult Protective Service (APS) agencies and/or state regulators. Works closely with Risk and other key Line of Business (LOB) personnel to analyze controls based on investigation findings and recommend enhancements/remediation when deficiencies or opportunities are identified.. Works closely with Americans with Disabilities Act (ADA) Compliance, ADA Works effectively with JPMC's technology support teams to discover how frauds occur through a deep understanding of JPMC systems and the processes that support them. Maintains strong liaison and working relationships with all federal, state and local law enforcement and regulatory agencies, including international enforcement agencies. Manages incorporating feedback from Investigators to identify credible, actionable intelligence. Required qualifications, capabilities, and skills: Bachelor's degree in Criminal Justice, Business, related field or work experience 10+ years of experience in financial fraud investigations or related law enforcement Advanced understanding of fraud and risk, working with internal management, and acting as a liaison with the law enforcement community at the local, state, federal, and international levels Ability to manage staff and/or work remotely as the business model has the team spread across diverse geographies Ability to coordinate, work with and gain the trust of business stakeholders, technical resources, and third-party vendors Able to articulate sophisticated fact patterns to non-technical line of business risk partners and memorialize investigations into regular reporting requirements Excellent written and verbal communication skills are required Preferred qualifications, capabilities, and skills: Industry recognized certifications such as CFE, PCI, etc. are preferred Court room testimony experience JD or MBA preferred
    $83k-140k yearly est. Auto-Apply 60d+ ago
  • Cyber Security Manager

    Tuesday Health

    Remote job

    Who We Are Tuesday Health is a value-based palliative care provider group dedicated to transforming serious illness and end-of-life care. We deliver goal-centered care focused on alleviating physical symptoms and emotional stress for individuals and their caregivers. Our interdisciplinary care teams reduce avoidable hospitalizations and improve quality of life wherever individuals call home. Through our leading-edge care model, Tuesday Health is shaping the future of community-based palliative care nationwide. The Role The Security Manager safeguards the confidentiality, integrity, and availability of our systems, data, facilities, and medical operations. This role leads security governance, risk management, and compliance efforts; oversees security operations and incident response; and partners with IT, Clinical Operations, Privacy, and Compliance to ensure our organization meets regulatory requirements (e.g., HIPAA Security Rule) and industry frameworks (e.g., SOC 2, HITRUST). The Security Manager is accountable for proactive risk reduction, rapid detection and response to threats, and building a strong security culture across the company. You will work closely with our engineering team and third-party security partners to define secure coding standards, validate security controls, and coordinate penetration testing and remediation for a modern cloud-native stack built on Azure, .NET Minimal APIs, Blazor WASM, MAUI, and PostgreSQL. Key responsibilities of this role may include: · Governance, Risk & Compliance (GRC) o Lead the enterprise security program aligned to HIPAA Security Rule, SOC 2 Type II, HITRUST CSF, and internal policies. o Own risk assessments, risk register, treatment plans, and executive reporting. o Maintain security policies and standards (access control, encryption, vendor risk, vulnerability management, incident response, acceptable use, AI/GenAI usage). o Coordinate audits, evidence collection, corrective actions, and ongoing compliance monitoring. · Security Operations o Oversee daily security operations: SIEM monitoring, EDR, vulnerability scanning, patch management, and email security/anti-phishing. o Implement and tune detection rules, playbooks, and escalation paths; manage MDR/SOC vendors as applicable. o Ensure Azure security posture through Defender for Cloud, Sentinel, and RBAC enforcement. o Validate security configurations for .NET APIs, Blazor WASM, MAUI apps, and PostgreSQL-working with engineering to confirm adherence to secure coding guidelines. o Collaborate with third-party penetration testing vendors: schedule tests, review findings, and track remediation. DevSecOps Guidance o Define and enforce secure coding standards for .NET, Blazor, and MAUI applications. o Ensure CI/CD pipelines include security checks (SAST, DAST, dependency scanning). o Provide oversight for infrastructure-as-code security (ARM/Bicep templates) and zero-trust principles. o Advise engineering on OWASP best practices and secure API design. · Incident Response & Business Continuity o Lead incident response lifecycle (prepare, detect, contain, eradicate, recover, lessons learned) with documented runbooks. o Coordinate with Privacy/Legal on reportable events; align to HIPAA breach requirements and internal incident procedures. o Maintain and test Business Continuity and Disaster Recovery plans; run tabletop exercises at least twice annually. · Identity, Access & Data Protection o Enforce least-privilege, role-based access control (RBAC), and periodic access reviews for PHI/PII and critical systems. o Manage Entra ID, privileged access management (PAM). o Implement data loss prevention (DLP) and encryption standards (in transit and at rest), including key management in Azure Key Vault. · Vendor Management Responsibilities o Oversee third-party risk management for all vendors handling PHI, PII, or critical systems. o Conduct security due diligence, including reviewing SOC 2/ISO certifications, penetration test results, and security questionnaires. o Ensure Business Associate Agreements (BAAs) are in place for vendors processing PHI and verify compliance with HIPAA Security Rule. o Maintain a vendor risk register and track remediation of identified gaps. o Monitor vendor adherence to contractual security obligations, including data residency, retention, and model training restrictions for AI tools. o Collaborate with Procurement and Legal to include security requirements in contracts and enforce breach notification timelines. o Periodically reassess vendor security posture and update risk ratings based on audits or incidents. A strong candidate will demonstrate the following: · Bachelor's degree in Information Security, Computer Science, or related field-or equivalent experience. · 5-8+ years in security roles with 2-3+ years leading security operations or GRC initiatives. · Hands-on experience with cloud security · Working knowledge of HIPAA Security Rule, PHI/PII handling, SOC 2 Type II, and incident response practices. · Hands-on experience with Azure security services (Defender for Cloud, Sentinel, Key Vault, RBAC). · Familiarity with secure development practices for .NET, Blazor WASM, MAUI, and PostgreSQL (oversight, not coding). · Proven ability to run risk assessments, develop policies, and manage audits. · Strong communication skills; ability to influence cross-functional leaders and train non-technical audiences. What We Offer · Competitive compensation, reflecting our commitment to attracting, retaining, and motivating the best talent in the industry · Comprehensive benefits including medical, dental, vision, and life insurance, paid time off and holidays, employer 401(K) match, etc. · Remote work with multiple onsite sessions each year to maximize collaboration and team building · A dynamic and inclusive team environment where you can lean on your teammates, offer candid feedback, bring your true self to work each day, and deliver tremendous impact while having fun along the way · Meaningful work each day; we care deeply about our mission, our patients, and each other If you are passionate about improving the quality of care for seriously ill individuals and their caregivers through innovative solutions, we would love to hear from you. Tuesday Health seeks to recruit and retain staff from diverse backgrounds and encourages qualified candidates to apply. Tuesday Health is an equal opportunity employer and does not discriminate on the basis of age, sex, gender identity/expression, sexual orientation, color, race, creed, national origin, ancestry, religion, marital status, political belief, physical or mental disability, pregnancy, military, or veteran status.
    $89k-137k yearly est. 12d ago
  • Manager, Security Architecture

    Lambda Labs

    Remote job

    Lambda, The Superintelligence Cloud, is a leader in AI cloud infrastructure serving tens of thousands of customers. Our customers range from AI researchers to enterprises and hyperscalers. Lambda's mission is to make compute as ubiquitous as electricity and give everyone the power of superintelligence. One person, one GPU. If you'd like to build the world's best AI cloud, join us. * Note: This position requires presence in our San Francisco, San Jose, or Bellevue office location 4 days per week; Lambda's designated work from home day is currently Tuesday. About the Role Lambda Security protects some of the world's most valuable digital assets: invaluable training data, model weights representing immense computational investments, and the sensitive inputs required to leverage best of breed AI models. We're responsible for securing every byte that powers breakthrough artificial intelligence. Reporting to the Senior Manager of Security, your team serves dual functions: building security for the business and demonstrating that work directly to customers. As security advisors to Product Engineering, Platform Engineering, and IT teams, your team will establish security policies and architecture standards, conduct threat modeling and design reviews for critical systems, and create implementation guidance that engineering teams can adopt. In support of our customers, your team will develop customer-facing security documentation and participate directly in enterprise security discussions. This work ensures the right security decisions get made across Lambda's AI infrastructure while protecting customer data, enabling hypergrowth velocity, and building the trust that closes enterprise deals. As Manager of the Security Architecture team, you'll build and lead a team of 4-5 security engineers with expertise across application security, infrastructure security, and corporate security. You'll hire strong specialists, coach them through complex security problems, set team priorities and architectural direction, and create a culture where security judgment accelerates business velocity rather than creating friction. Your success is measured by the security decisions your team enables across the business: engineering teams building secure-by-default systems, compliance frameworks mapped to technical controls, and customers trusting Lambda's infrastructure with their most valuable AI workloads. Your team will balance proactive architecture work (defining what "good" looks like) with reactive consultation (reviewing designs and answering complex security questions). Your immediate focus will be building your team, establishing processes for design reviews and architecture guidance that scale with Lambda's growth, and developing a 6-12 month roadmap aligned with Lambda's 2026 security strategic plan including compliance initiatives like ISO 27001. We're looking for engineering managers who pair strong people leadership with enough security depth to coach specialists, set architectural direction, and translate security decisions into business value. If you're energized by building high-performing teams, enabling security at scale through excellent judgment rather than brute force, and helping enterprise customers trust their most valuable AI workloads to Lambda's infrastructure, we'd love to talk. We value diverse backgrounds, experiences, and skills, and we are excited to hear from candidates who can bring unique perspectives to our team. If you do not exactly meet this description but believe you may be a good fit, please still apply and help us understand your readiness for this role. Your application is not a waste of our time. What You'll Do Team Leadership & Development * Build, hire, and develop a high-performing team of 4-5 security engineers with deep expertise across application security, infrastructure security, and corporate security. * Foster a culture where security judgment accelerates business velocity, creating an environment where specialists thrive through clear expectations, regular coaching, and opportunities for growth. * Conduct regular one-on-ones and provide constructive feedback that helps your engineers advance their technical depth and expand their cross-functional impact. * Set team priorities and architectural direction, ensuring your team focuses on the highest-impact security decisions across Lambda's AI infrastructure. Strategic Architecture & Program Management * Own your team's 6-12 month roadmap, balancing proactive architecture work (defining security standards and patterns) with reactive consultation (design reviews and complex security questions). * Establish security policies and architecture standards that enable Product Engineering, Platform Engineering, and IT teams to build secure-by-default systems. * Define measurable success criteria for your team's work, translating security architecture decisions into business impact that stakeholders understand. * Proactively guide the evolution of Lambda's security architecture program as the company matures, ensuring architecture decisions align with compliance commitments and evolving customer security requirements. Cross-Functional Collaboration & Customer Enablement * Partner deeply with Product Engineering, Platform Engineering, and IT teams to integrate security architecture guidance at optimal moments in their development cycles. * Conduct and oversee threat modeling and design reviews for critical systems, ensuring your team provides actionable recommendations that balance security rigor with development velocity. * Enable your team to create implementation guidance and architecture patterns that engineering teams voluntarily adopt because they make secure development easier. * Support enterprise sales by developing customer-facing security documentation and coaching your team through direct security discussions with prospective customers evaluating Lambda's infrastructure. * Collaborate with peer security teams (Detection & Response, Platform, Program Coordination) to ensure cohesive security architecture across all security functions. What We Think a Candidate Needs to Demonstrate to Succeed * 5+ years of security engineering or security architecture experience with 3+ years leading technical teams, demonstrating ability to build and develop high-performing security specialists. * Proven track record building team cultures where specialists thrive through clear expectations, effective coaching, and career development that expands both technical depth and cross-functional impact. * Strong technical background in security architecture, threat modeling, and secure design principles with enough depth to guide team decisions, evaluate complex tradeoffs, and coach engineers through difficult security problems. * Experience working across application security, infrastructure security, or corporate security domains, with demonstrated ability to set architectural direction and security standards that engineering teams adopt. * Excellent collaboration skills working with highly technical engineering teams both with and without authority, building relationships that enable security architecture guidance at optimal moments in development cycles. * Skilled communicator who translates security architecture decisions into business value, helping stakeholders understand how technical security work protects customer data and enables business velocity. * Ability to thrive in high-speed, high-ambiguity startup environments where you balance building team capability and security architecture foundations while executing at a fast pace. Nice to Have * Prior experience in AI/ML infrastructure companies or cloud service providers where you've navigated the unique security challenges of multi-tenant systems and customer data isolation at scale. * Hands-on experience driving compliance audits (SOC 2, ISO 27001, PCI-DSS, HIPAA/HITECH, or FedRAMP) including evidence collection, control mapping, and managing auditor relationships. * Deep familiarity with bare metal infrastructure security in addition to cloud platforms, understanding physical security considerations and hardware-level security controls. * Experience creating security architecture patterns that were adopted widely across multiple teams or organizations, demonstrating ability to build reusable solutions that scale beyond a single use case. * Experience managing security engineers through significant career transitions, such as promoting ICs to lead roles or helping specialists successfully pivot between security domains. * Enthusiasm about leveraging Lambda's access to state-of-the-art LLMs to pioneer AI-powered security architecture capabilities-imagine automated threat modeling, intelligent design review assistance, and architecture validation at scale only possible when you host the AI infrastructure yourself. Salary Range Information The annual salary range for this position has been set based on market data and other factors. However, a salary higher or lower than this range may be appropriate for a candidate whose qualifications differ meaningfully from those listed in the job description. About Lambda * Founded in 2012, with 500+ employees, and growing fast * Our investors notably include TWG Global, US Innovative Technology Fund (USIT), Andra Capital, SGW, Andrej Karpathy, ARK Invest, Fincadia Advisors, G Squared, In-Q-Tel (IQT), KHK & Partners, NVIDIA, Pegatron, Supermicro, Wistron, Wiwynn, Gradient Ventures, Mercato Partners, SVB, 1517, and Crescent Cove * We have research papers accepted at top machine learning and graphics conferences, including NeurIPS, ICCV, SIGGRAPH, and TOG * Our values are publicly available: ************************* * We offer generous cash & equity compensation * Health, dental, and vision coverage for you and your dependents * Wellness and commuter stipends for select roles * 401k Plan with 2% company match (USA employees) * Flexible paid time off plan that we all actually use A Final Note: You do not need to match all of the listed expectations to apply for this position. We are committed to building a team with a variety of backgrounds, experiences, and skills. Equal Opportunity Employer Lambda is an Equal Opportunity employer. Applicants are considered without regard to race, color, religion, creed, national origin, age, sex, gender, marital status, sexual orientation and identity, genetic information, veteran status, citizenship, or any other factors prohibited by local, state, or federal law.
    $89k-137k yearly est. 60d+ ago
  • Remote IS Security Manager

    Jobgether

    Remote job

    This position is posted by Jobgether on behalf of a partner company. We are currently looking for a Information System Security Manager - REMOTE. In this role, you will have the opportunity to make a significant impact by ensuring that information system security is upheld within critical governmental operations. You will lead initiatives to implement security programs, conduct audits, and maintain compliance with the established regulations. As part of a collaborative team, you will help elevate the standards of cybersecurity, all while working from anywhere. Your contributions will directly enhance the security posture of the organization and support various missions.Accountabilities Conduct information system security inspections, tests, and reviews to maintain an Authority to Operate (ATO). Implement and enforce a formal information system security program and develop security policies and plans. Demonstrate knowledge of systems engineering, network security concepts, and IT security principles. Ensure software and hardware complies with security configuration guidelines. Report cybersecurity-related events that impact IT authorization. Implement Security Information and Event Management processes. Requirements Bachelor's Degree in Information Systems, Information Assurance Management, Computer Science, or related field (or equivalent experience). 2-7 years of relevant experience in information systems security. IAM Level II DoD approved cybersecurity certification or higher (e.g., CAP, CASP, CISA, CISM, CISSP). Experience with the Risk Management Framework (RMF) and NIST publications (NIST 800-53 and NIST 800-37). Active Secret Security Clearance required. Located within 2 hours of Joint Base Andrews for potential onsite meetings. Benefits Opportunity to work remotely with flexibility. Engagement in meaningful projects that influence national security. Possibility for professional growth and development. A supportive work environment that values diversity and inclusion. Recognition as a military-friendly employer with a commitment to veterans. Why Apply Through Jobgether? We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best!Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.#LI-CL1We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
    $86k-132k yearly est. Auto-Apply 2d ago
  • Director of Loss Forecasting

    Splash Financial

    Remote job

    ABOUT OUR COMPANY: The crushing weight of debt is something that we believe holds people back from reaching their dreams and making a splash in the world. So in 2013, after seeing our friends and family struggle with student loans, we created Splash Financial. Over the years, our mission has expanded to include helping people with other forms of debt - such as refinancing credit cards, which are at all time highs in the US. And we've been able to refinance $6+ Billion in loans through our network of Splash, powered credit union and bank partners who leverage our marketplace and automated loan processing technology. And we've raised over $135 million from investors like partners of DST Global, Citi Ventures, TruStage Ventures, Northwestern Mutual Future Ventures, Detroit Venture Partners, and more. But at our core, we're still that little company from Cleveland with a big dream: to make people more powerful than their debt and we're just getting started.. ABOUT OUR WORKPLACE: Splash is remote-first, and proud of it. We spend our days simplifying financial products and getting them into the hands of people who need them most. Right now, we're focused on building financial technologies that fundamentally transform how the industry lends. Although Splash has been around since 2013, we still operate like a startup - fast-paced, nimble, and full of heart. We're good people who care deeply about doing meaningful work and we approach challenges with creativity, passion, and urgency. And to hire the best, we provide the best: great health insurance, competitive salaries, and unique benefits like quarterly meet-ups and access to engagement tools that keep us connected - even from afar. At Splash, everything we do is guided by our values: Own It - We take full accountability and follow through on commitments. Raise the Bar - We move fast, innovate faster, and push through barriers. Say the Hard Thing - We speak up with honesty, respect, and a desire to solve problems and make things better. Elevate Each Other - We win as a team by lifting each other up. These values show up in how we work and how we connect - whether we're collaborating on big projects or bonding over everyday moments. Yes, we even have Slack channels for #kids-and-pets and #food because we believe being human makes us better teammates. ABOUT THE ROLE: The Director of Loss Forecasting plays a critical role in shaping Splash Financial's credit strategy and long-term performance. This leader owns the development and evolution of loss forecasting methodologies that directly inform executive decision-making, lender confidence, and portfolio growth. In this highly visible role, you will partner closely with senior leadership, lending partners, and cross-functional teams to deliver accurate, transparent, and actionable forecasts. As Splash continues to expand its product offerings, this role will evolve in scope and complexity, offering the opportunity to drive innovation and influence strategy at scale. If you're energized by using data to guide high-stakes decisions and enjoy operating at the intersection of analytics, risk, and business strategy, this role offers meaningful impact and growth. WHAT YOU'LL DO AT SPLASH: Own and evolve loss forecasting methodologies across Splash's lending products, incorporating both macroeconomic and portfolio-level drivers. Identify and analyze key risk drivers using advanced statistical and quantitative techniques to improve forecast accuracy and reliability. Translate complex modeling outputs into clear, actionable insights for executive leadership and lender partners. Partner cross-functionally with Data Science, Credit, Finance, Servicing, and Product teams to align forecasting outputs with credit and collection strategies. Monitor model performance and recalibrate forecasts based on portfolio behavior, economic conditions, and business changes. Build and enhance dashboards and reporting that improve forecast transparency, interpretability, and stakeholder trust. Lead innovation in forecasting approaches, tools, and technologies to stay ahead of industry best practices. Drive strategic initiatives related to risk mitigation, portfolio optimization, and business growth. Serve as a trusted advisor to senior leaders and external partners on loss outlooks and risk trade-offs. Support new product launches by ensuring scalable, well-designed loss forecasting frameworks are in place. WHAT YOU'LL BRING TO SPLASH: Advanced degree (Master's or PhD) in Statistics, Data Science, Economics, Mathematics, or a related quantitative field. 8+ years of experience in loss forecasting, credit risk modeling, or a closely related role within financial services or lending. Strong understanding of statistical modeling techniques, including regression, time series, and machine learning methods, with the ability to guide model selection and application. Proficiency in Python is a strong plus, including experience using Python-based analytics or modeling workflows to explore data, validate assumptions, or partner effectively with data science teams. Deep knowledge of credit risk fundamentals and macroeconomic drivers impacting consumer lending portfolios. Experience working with large, complex datasets and collaborating closely with data science teams. Strong business judgment and the ability to connect analytical insights to strategic and financial outcomes. Excellent communication skills, with experience presenting complex analyses to executive audiences and external partners. Proven ability to work cross-functionally and influence stakeholders across disciplines. Demonstrated leadership in driving analytical initiatives, managing projects, or mentoring team members. Curiosity and innovation mindset, with a desire to continuously improve forecasting approaches and tools. Comfort operating in a fast-growing, evolving environment with increasing product and portfolio complexity. COMPENSATION: The base salary range for this role is $180,000 - $220,000 annually, based on market data and internal compensation practices. This role may also be eligible for a bonus component tied to individual and company performance. Final compensation will be determined by factors such as location, experience, and skill level. SPLASHERS ENJOY: Fully remote work freedom Competitive salary packages Flexible PTO + 9 company holidays Equity: Share in our start-up success Comprehensive and affordable insurance benefits Paid parental leave for both caregivers Essential equipment to get the job done 401(k) for your future savings Quarterly meet-ups: In person & virtual fun Awesome Splash swag to flaunt your team spirit Employment at Splash is based on individual merit. Opportunities are open to all, without regard to race, color, religion, sex, creed, age, handicap, national origin, ancestry, military status, veteran status, medical condition, marital status, sexual orientation, affectional preference, or other irrelevant factors. Splash is an equal opportunity employer.
    $180k-220k yearly Auto-Apply 29d ago
  • Technical Security Operations Center (SOC) Manager (R-00102)

    True Zero Technologies

    Remote job

    True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that said outcomes begin and end with our people, and that is what we have built, a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top tier services to our customers. In 2023, True Zero was recognized as a “Best Places to Work” in two categories ("Prosperous and Thriving" ($5MM - $50MM in gross revenue) and "Mid-Atlantic Region" (DC, DE, MD, NC, VA, WV)) and in 2022, was recognized as one of Inc. Magazine's Top 5000 Fastest Growing Companies. Job Summary: TZT is seeking a highly skilled and experienced Security Operations Center (SOC) Program Manager to join our team. As a SOC Program Manager, you will be responsible for overseeing the successful implementation and management of Security Operations Centers (SOCs) and Information Technologies (IT) projects. This is a critical role that requires a strong understanding of SOC operations, information security principles, and Splunk architectures (or alternate Splunk experience). As a TZT consultant, the candidate will receive access to the full knowledge base which is driven by the True Zero community as well as the technical backing of the entire PS team. True Zero encourages collaboration and growth through information sharing and knowledge workshops. The candidate will also have access to our internal Slack channel to stay connected with the team as well as the necessary tools to train, demo, test and grow their professional skills.SOC Manager Responsibilities Manage end-to-end program delivery for Security Operations Centers and Information Technologies projects. Define, manage, and monitor project scope, goals, deliverables, and projct status in collaboration with stakeholders Develop and maintain project plans, schedules, and budgets. Coordinate and collaborate with cross-functional teams to ensure project objectives and deliverables are met. Provide guidance and mentorship to project teams to drive successful project execution. Monitor project progress, identify risks and issues, and implement mitigation strategies. Facilitate effective communication between project stakeholders, including technical and non-technical audiences. Ensure adherence to project management best practices and industry standards. Conduct regular project status meetings and provideaccurate reporting to senior management. Manage SOC resources, establish SOC staffing/shift plans, identify/manage analyst tasks, provide status reporting and escalation to senior leadership SOC PM Requirements Bachelor's degree in Computer Science, Information Systems, or a related field (or equivalent experience). Proven experience (5+ years) in program management for Security Operations Centers and Information Technologies projects. Strong knowledge and understanding of SOC operations, information security principles, and best practices. Proficiency in Splunk architecture or alternate Splunk experience. Excellent project management skills, including the ability to prioritize tasks, manage resources, and meet deadlines. Solid understanding of project management methodologies and frameworks. Exceptional communication and interpersonal skills, with the ability to effectively engage with stakeholders at all levels. Strong analytical and problem-solving abilities. Project/program management and/or technical certifications, such as PMP, CISSP, or CISM are highly desirable. Proven experience in leading and managing complex cybersecurity projects. Familiarity with other security technologies and tools, such as SIEM, IDS/IPS, and vulnerability management. Experience in managing and mentoring project teams, ensuring high performance and accountability. Knowledge of regulatory compliance frameworks, such as GDPR, HIPAA, or PCI DSS. Ability to adapt to changing priorities and thrive in a fast-paced, dynamic environment. Strong leadership skills and the ability to influence and motivate team members. Attention to detail and a commitment to delivering high-quality results. U.S. Citizenship is required as this is in support of a Federal Customer. We're actively searching for talented security and technology practitioners who are ready to experience the True Zero difference. As a True Zero team member, you'll enjoy: - Competitive salary, paid twice per month- Best in class medical coverage- 100% of medical premiums covered by True Zero- Company wide new business incentive programs- Contribution Incentives (i.e. white papers, blog posts, internal webinars, etc.)- 3 weeks of PTO starting + 11 Paid Holidays Annually- 401k Program with 100% company match on the first 4%- Monthly reimbursement of Cell Phone and Home Internet costs- Paternity/Maternity Leave- Investment in training and certifications to broaden and deepen your technical skills
    $43k-81k yearly est. Auto-Apply 60d+ ago
  • Manager, Security Operations Center (SOC)

    Ultraviolet Cyber

    Remote job

    Make a difference here. UltraViolet Cyber is a leading platform-enabled unified security operations company providing a comprehensive suite of security operations solutions. Founded and operated by security practitioners with decades of experience, the UltraViolet Cyber security-as-code platform combines technology innovation and human expertise to make advanced real-time cybersecurity accessible for all organizations by eliminating risks of separate red and blue teams. By creating continuously optimized identification, detection, and resilience from today's dynamic threat landscape, UltraViolet Cyber provides both managed and custom-tailored unified security operations solutions to the Fortune 500, Federal Government, and Commercial clients. UltraViolet Cyber is headquartered in McLean, Virginia, with global offices across the U.S. and in India. UltraViolet Cyber is a leading platform-enabled unified security operations company providing a comprehensive suite of security operations solutions. Founded and operated by security practitioners with decades of experience, the UltraViolet Cyber security-as-code platform combines technology innovation and human expertise to make advanced real-time cybersecurity accessible for all organizations by eliminating risks of separate red and blue teams. UltraViolet Cyber is seeking a technically proficient, process-driven Manager to lead our Shared Services team. This role oversees a group of Security Analysts responsible for maintaining the quality, integrity, and availability of client environments during incident handling and investigations. The Manager will develop operational strategies, implement innovative security technologies, and coordinate timely, effective responses to emerging threats and incidents. This role blends leadership and hands-on technical expertise to ensure we have a world class analyst and operations. What You'll Do: Lead day-to-day SOC operations including monitoring, detection, analysis, and incident response. Develop and maintain SOC policies, procedures, and playbooks aligned with frameworks MITRE Oversee deployment, tuning, and optimization of SIEM, SOAR, IDS/IPS, EDR, and threat intel platforms. Coordinate cross-functional incident response and lead post-incident reviews. Work with IT, legal, compliance, and business units to align with risk management goals. Monitor emerging threats and adjust defenses and strategies proactively. Recruit, mentor, and develop SOC staff, fostering continuous improvement. Prepare and present SOC performance, threat landscape, and risk posture to internal and external stakeholders Define and track KPIs and metrics to measure the effectiveness of the team Use automation and scripting (e.g., Python, KQL, PowerShell) to enhance detection efficiency What You've Done: US Citizenship is Required 7+ years in cybersecurity with at least 2+ years in leading and mentoring teams Ability to communicate complex cybersecurity issues to both technical and non-technical stakeholders 3+ years of experience with dark web, OSINT tools Proficiency with SIEM, EDR, and cloud-native security tools (e.g., Sentinel, Splunk, Defender, Elastic, CrowdStrike). Hands-on experience scripting in Python, Bash, KQL, PowerShell, or similar languages. Ability to work with Linux, including command line for analysis of large datasets. Ability to communicate complex cybersecurity issues to both technical and non-technical stakeholders Excellent written and verbal communication skills, including the ability to brief executives on complex technical issues. Ability to work under pressure and manage multiple priorities in a fast-paced environment Preferred Education and Certifications: Bachelor's degree in Cybersecurity, Computer Science, or related field (or equivalent experience). Industry certifications such as GCTI, GCFA, GCIA, GREM, or OSCP. What We Offer: 401(k), including an employer match of 100% of the first 3% contributed and 50% of the next 2% contributed Medical, Dental, and Vision Insurance (available on the 1st day of the month following your first day of employment) Group Term Life, Short-Term Disability, Long-Term Disability Voluntary Life, Hospital Indemnity, Accident, and/or Critical Illness Participation in the Discretionary Time Off (DTO) Program 11 Paid Holidays Annually UltraViolet Cyber maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect our company's differing products, services, industries and lines of business. Candidates are typically placed into the range based on the preceding factors. We sincerely thank all applicants in advance for submitting their interest in this position. We know your time is valuable. UltraViolet Cyber welcomes and encourages diversity in the workplace regardless of race, gender, religion, age, sexual orientation, gender identity, disability, or veteran status. If you want to make an impact, UltraViolet Cyber is the place for you!
    $43k-81k yearly est. Auto-Apply 60d+ ago
  • Manager, Security Architecture

    Lambda 4.2company rating

    Remote job

    Lambda, The Superintelligence Cloud, is a leader in AI cloud infrastructure serving tens of thousands of customers. Our customers range from AI researchers to enterprises and hyperscalers. Lambda's mission is to make compute as ubiquitous as electricity and give everyone the power of superintelligence. One person, one GPU. If you'd like to build the world's best AI cloud, join us. *Note: This position requires presence in our San Francisco, San Jose, or Bellevue office location 4 days per week; Lambda's designated work from home day is currently Tuesday. About the Role Lambda Security protects some of the world's most valuable digital assets: invaluable training data, model weights representing immense computational investments, and the sensitive inputs required to leverage best of breed AI models. We're responsible for securing every byte that powers breakthrough artificial intelligence. Reporting to the Senior Manager of Security, your team serves dual functions: building security for the business and demonstrating that work directly to customers. As security advisors to Product Engineering, Platform Engineering, and IT teams, your team will establish security policies and architecture standards, conduct threat modeling and design reviews for critical systems, and create implementation guidance that engineering teams can adopt. In support of our customers, your team will develop customer-facing security documentation and participate directly in enterprise security discussions. This work ensures the right security decisions get made across Lambda's AI infrastructure while protecting customer data, enabling hypergrowth velocity, and building the trust that closes enterprise deals. As Manager of the Security Architecture team, you'll build and lead a team of 4-5 security engineers with expertise across application security, infrastructure security, and corporate security. You'll hire strong specialists, coach them through complex security problems, set team priorities and architectural direction, and create a culture where security judgment accelerates business velocity rather than creating friction. Your success is measured by the security decisions your team enables across the business: engineering teams building secure-by-default systems, compliance frameworks mapped to technical controls, and customers trusting Lambda's infrastructure with their most valuable AI workloads. Your team will balance proactive architecture work (defining what "good" looks like) with reactive consultation (reviewing designs and answering complex security questions). Your immediate focus will be building your team, establishing processes for design reviews and architecture guidance that scale with Lambda's growth, and developing a 6-12 month roadmap aligned with Lambda's 2026 security strategic plan including compliance initiatives like ISO 27001. We're looking for engineering managers who pair strong people leadership with enough security depth to coach specialists, set architectural direction, and translate security decisions into business value. If you're energized by building high-performing teams, enabling security at scale through excellent judgment rather than brute force, and helping enterprise customers trust their most valuable AI workloads to Lambda's infrastructure, we'd love to talk. We value diverse backgrounds, experiences, and skills, and we are excited to hear from candidates who can bring unique perspectives to our team. If you do not exactly meet this description but believe you may be a good fit, please still apply and help us understand your readiness for this role. Your application is not a waste of our time. What You'll Do Team Leadership & Development Build, hire, and develop a high-performing team of 4-5 security engineers with deep expertise across application security, infrastructure security, and corporate security. Foster a culture where security judgment accelerates business velocity, creating an environment where specialists thrive through clear expectations, regular coaching, and opportunities for growth. Conduct regular one-on-ones and provide constructive feedback that helps your engineers advance their technical depth and expand their cross-functional impact. Set team priorities and architectural direction, ensuring your team focuses on the highest-impact security decisions across Lambda's AI infrastructure. Strategic Architecture & Program Management Own your team's 6-12 month roadmap, balancing proactive architecture work (defining security standards and patterns) with reactive consultation (design reviews and complex security questions). Establish security policies and architecture standards that enable Product Engineering, Platform Engineering, and IT teams to build secure-by-default systems. Define measurable success criteria for your team's work, translating security architecture decisions into business impact that stakeholders understand. Proactively guide the evolution of Lambda's security architecture program as the company matures, ensuring architecture decisions align with compliance commitments and evolving customer security requirements. Cross-Functional Collaboration & Customer Enablement Partner deeply with Product Engineering, Platform Engineering, and IT teams to integrate security architecture guidance at optimal moments in their development cycles. Conduct and oversee threat modeling and design reviews for critical systems, ensuring your team provides actionable recommendations that balance security rigor with development velocity. Enable your team to create implementation guidance and architecture patterns that engineering teams voluntarily adopt because they make secure development easier. Support enterprise sales by developing customer-facing security documentation and coaching your team through direct security discussions with prospective customers evaluating Lambda's infrastructure. Collaborate with peer security teams (Detection & Response, Platform, Program Coordination) to ensure cohesive security architecture across all security functions. What We Think a Candidate Needs to Demonstrate to Succeed 5+ years of security engineering or security architecture experience with 3+ years leading technical teams, demonstrating ability to build and develop high-performing security specialists. Proven track record building team cultures where specialists thrive through clear expectations, effective coaching, and career development that expands both technical depth and cross-functional impact. Strong technical background in security architecture, threat modeling, and secure design principles with enough depth to guide team decisions, evaluate complex tradeoffs, and coach engineers through difficult security problems. Experience working across application security, infrastructure security, or corporate security domains, with demonstrated ability to set architectural direction and security standards that engineering teams adopt. Excellent collaboration skills working with highly technical engineering teams both with and without authority, building relationships that enable security architecture guidance at optimal moments in development cycles. Skilled communicator who translates security architecture decisions into business value, helping stakeholders understand how technical security work protects customer data and enables business velocity. Ability to thrive in high-speed, high-ambiguity startup environments where you balance building team capability and security architecture foundations while executing at a fast pace. Nice to Have Prior experience in AI/ML infrastructure companies or cloud service providers where you've navigated the unique security challenges of multi-tenant systems and customer data isolation at scale. Hands-on experience driving compliance audits (SOC 2, ISO 27001, PCI-DSS, HIPAA/HITECH, or FedRAMP) including evidence collection, control mapping, and managing auditor relationships. Deep familiarity with bare metal infrastructure security in addition to cloud platforms, understanding physical security considerations and hardware-level security controls. Experience creating security architecture patterns that were adopted widely across multiple teams or organizations, demonstrating ability to build reusable solutions that scale beyond a single use case. Experience managing security engineers through significant career transitions, such as promoting ICs to lead roles or helping specialists successfully pivot between security domains. Enthusiasm about leveraging Lambda's access to state-of-the-art LLMs to pioneer AI-powered security architecture capabilities-imagine automated threat modeling, intelligent design review assistance, and architecture validation at scale only possible when you host the AI infrastructure yourself. Salary Range Information The annual salary range for this position has been set based on market data and other factors. However, a salary higher or lower than this range may be appropriate for a candidate whose qualifications differ meaningfully from those listed in the job description. About Lambda Founded in 2012, with 500+ employees, and growing fast Our investors notably include TWG Global, US Innovative Technology Fund (USIT), Andra Capital, SGW, Andrej Karpathy, ARK Invest, Fincadia Advisors, G Squared, In-Q-Tel (IQT), KHK & Partners, NVIDIA, Pegatron, Supermicro, Wistron, Wiwynn, Gradient Ventures, Mercato Partners, SVB, 1517, and Crescent Cove We have research papers accepted at top machine learning and graphics conferences, including NeurIPS, ICCV, SIGGRAPH, and TOG Our values are publicly available: ************************* We offer generous cash & equity compensation Health, dental, and vision coverage for you and your dependents Wellness and commuter stipends for select roles 401k Plan with 2% company match (USA employees) Flexible paid time off plan that we all actually use A Final Note: You do not need to match all of the listed expectations to apply for this position. We are committed to building a team with a variety of backgrounds, experiences, and skills. Equal Opportunity Employer Lambda is an Equal Opportunity employer. Applicants are considered without regard to race, color, religion, creed, national origin, age, sex, gender, marital status, sexual orientation and identity, genetic information, veteran status, citizenship, or any other factors prohibited by local, state, or federal law.
    $82k-136k yearly est. Auto-Apply 60d+ ago
  • IS Security Manager

    Careoregon 4.5company rating

    Remote job

    --------------------------------------------------------------- The IS Information Security Manager leads the development, implementation, and ongoing improvement of CareOregon's information security program. This role partners with leaders across the organization to strengthen security governance, reduce risk, and ensure compliance with regulatory and industry standards. The position oversees security operations, incident response, vulnerability management, and third-party risk, while providing strategic guidance on secure architecture and emerging threats. This position manages a high performing security team and fosters strong collaboration with internal stakeholders and external partners to maintain a resilient enterprise security posture. Estimated Hiring Range: $151,965.00 - $185,735.00 Bonus Target: Bonus - SIP Target, 5% Annual Current CareOregon Employees: Please use the internal Workday site to submit an application for this job. --------------------------------------------------------------- Essential Responsibilities Program Leadership Implement and oversee a comprehensive Information Security Program aligned with organizational goals and industry best practices. Partner with IS and executive leadership to define security objectives, maintain the Information Security Roadmap, and report on program performance. Advise senior leadership on security risks, emerging threats, and strategic cybersecurity needs. Establish and maintain a security metrics framework and key performance indicators aligned with organizational priorities and standards. Prepare and deliver clear, actionable reports for senior leadership, including key risk indicators, program status, and operational metrics. Governance, Risk, and Compliance Recommend updates to security policies and standards to align with HIPAA, HITRUST, NIST, and other frameworks. Coordinate implementation of security programs, policies, and configuration standards across IS. Lead risk assessments, vulnerability analyses, remediation planning, and the administration of a GRC platform. Manage third‑party risk processes, including vendor assessments and ongoing monitoring. Oversee penetration tests, program maturity assessments, and risk assessments. Ensure ongoing compliance with regulatory, contractual, and audit requirements. Lead the response to audit requests and efforts to remediate adverse results. Security Operations & Incident Management Build and lead operational security capabilities to monitor, detect, analyze, and respond to threats. Utilize threat intelligence, monitoring, incident management, behavioral analysis, and advanced detection technologies. Maintain SOPs, runbooks, and playbooks supporting incident investigation, containment, recovery, and post‑incident review. Lead the Information Security Incident Response Plan, including training, exercises, and cross‑team readiness initiatives. Aggregate and analyze security data using SIEM technologies to identify patterns, evaluate alerts, and prioritize responses. Conduct proactive threat hunting and enhance monitoring to detect emerging threats. Technical Security Oversight Provide guidance on secure architecture and operations for on‑premises and Azure cloud environments. Manage core security domains such as Vulnerability Management, Identity and Access Management, and Privileged Access Management. Collaborate with other IS teams to ensure robust security configuration management for systems, hardware, and firmware. Perform security reviews and risk assessments for software acquisitions and technology initiatives. Lead periodic testing and improvement of the IS Disaster Recovery Plan. Leadership & Collaboration Lead, mentor, and develop a high‑performing cybersecurity team, fostering innovation, learning, and operational excellence. Act as a subject matter expert for IS and business teams, providing guidance on secure architecture, risk mitigation, and best practices. Maintain strong partnerships with key vendors, partners, and external stakeholders. Facilitate security governance meetings and deliver clear, actionable updates to executive leadership. Awareness & Training Develop, maintain, and continuously improve the organization‑wide information security awareness program. Ensure training content is current, engaging, and effective in reducing human‑related risk and supporting compliance. Employee Supervision Manage team and recommend team direction and goals in alignment with the organizational mission, vision, and values. Identify work and staffing needs to meet work expectations; recruit and hire, using an equity, diversity, and inclusion lens. Plan, organize, schedule, and monitor work; ensure employees have information and resources to meet job expectations. Lead the development, communication, and oversight of team and individual goals; ensure goals, expectations, and standards are clearly understood by staff. Train, supervise, motivate, and coach employees; provide support toward employee development. Incorporate guidance from CareOregon equity tools into people leadership, planning, operations, evaluation, and decision making. Ensure team adheres to department and organizational standards, policies, and procedures. Evaluate employee performance and provide regular feedback to support success; recognize strong performance and address performance gaps and accountability (corrective action). Perform supervisory tasks in collaboration with Human Resources as needed. Experience and/or Education Required Minimum 6 years' experience in information security systems, solutions or related services Experience must include most of the following: Leading teams, including developing and mentoring staff and supporting change management Leading complex systems projects Managing vendors and contracts Influencing others Developing policy and strategy roadmaps with business partners and aligning work efforts and solutions accordingly Developing and implementing information or cyber security programs Preferred Minimum 2 years' experience in a supervisory position or minimum 1 year experience in a supervisory position with completion of CareOregon's Aspiring Leaders Program Knowledge, Skills and Abilities Required Knowledge Strong understanding of information security best practices and secure design principles Knowledge of ITIL frameworks and their application within IS environments Knowledge of cross‑team alignment practices and organizational calibration processes Understanding of governance standards and adherence to established processes Skills and Abilities Ability to apply core managerial disciplines, including project and change management, cross‑functional collaboration, innovation, and organizational effectiveness Experience across multiple information security domains, including governance risk and compliance, attack surface management, identity and access management, network security, data protection, disaster recovery, security operations, incident response, and threat modeling Experience managing Intrusion Detection and Prevention systems such as Rapid7, InsightIDR and Defender ATP Experience with Data Loss Prevention and data classification Ability to promote continuous learning, empowerment, engagement, and development opportunities for employees Strong oral and written communication skills, including meeting facilitation and presentations Ability to clearly convey complex or controversial topics to diverse audiences Ability to form an independent perspective, collaborate in decision‑making, and motivate others-especially during challenging situations Ability to propose solutions and articulate business value Ability to elevate strategic concerns to senior leadership clearly, accurately, and promptly Ability to build strong working relationships with internal leaders and external partners Ability to collaborate effectively with coworkers, staff, leaders, and executives across all departments Ability to maintain a high degree of professionalism and a positive attitude Ability to develop and monitor policies, risks, and solutions Sound judgment with the ability to develop, implement, and reinforce policy and strategy Ability to see the broader context behind requests and apply holistic, systems‑thinking approaches Advanced project management skills Advanced vendor management skills Advanced budget management skills Strong analytical and research skills Ability to identify patterns in data and draw accurate conclusions Ability to work effectively with diverse individuals and groups Ability to learn, focus, interpret information, and determine appropriate actions Ability to accept direction and feedback, and manage stress effectively Ability to see, read, and perform repetitive finger and wrist movement for at least 6 hours/day Ability to hear and speak clearly for at least 3-6 hours/day Working Conditions Work Environment(s): ☒ Indoor/Office ☐ Community ☐ Facilities/Security ☐ Outdoor Exposure Member/Patient Facing: ☒ No ☐ Telephonic ☐ In Person Hazards: May include, but not limited to, physical and ergonomic hazards. Equipment: General office equipment and mobile technology Travel: May include occasional required or optional travel outside of the workplace; the employee's personal vehicle, local transit or other means of transportation may be used. Work Location: Work from home We offer a strong Total Rewards Program. This includes competitive pay, bonus opportunity, and a comprehensive benefits package. Eligibility for bonuses and benefits is dependent on factors such as the position type and the number of scheduled weekly hours. Benefits-eligible employees qualify for benefits beginning on the first of the month on or after their start date. CareOregon offers medical, dental, vision, life, AD&D, and disability insurance, as well as health savings account, flexible spending account(s), lifestyle spending account, employee assistance program, wellness program, discounts, and multiple supplemental benefits (e.g., voluntary life, critical illness, accident, hospital indemnity, identity theft protection, pre-tax parking, pet insurance, 529 College Savings, etc.). We also offer a strong retirement plan with employer contributions. Benefits-eligible employees accrue PTO and Paid State Sick Time based on hours worked/scheduled hours and the primary work state. Employees may also receive paid holidays, volunteer time, jury duty, bereavement leave, and more, depending on eligibility. Non-benefits eligible employees can enjoy 401(k) contributions, Paid State Sick Time, wellness and employee assistance program benefits, and other perks. Please contact your recruiter for more information. We are an equal opportunity employer CareOregon is an equal opportunity employer. The organization selects the best individual for the job based upon job related qualifications, regardless of race, color, religion, sexual orientation, national origin, gender, gender identity, gender expression, genetic information, age, veteran status, ancestry, marital status or disability. The organization will make a reasonable accommodation to known physical or mental limitations of a qualified applicant or employee with a disability unless the accommodation will impose an undue hardship on the operation of our organization.
    $152k-185.7k yearly Auto-Apply 9d ago
  • Manager, Cloud Security and Compliance

    Altium 4.4company rating

    Remote job

    ⚡️ Why Altium? Altium is transforming the way electronics are designed and built. From startups to world's technology giants, our digital platforms give more power to PCB designers, supply chain, and manufacturing, letting them collaborate as never before. Constant innovation has created a transformative technology, unique in its space More than 30,000 companies and 100,000 electronics engineers worldwide use Altium We are growing, debt-free, and financially strong, with the resources to become #1 in the EDA industry About the role: We are looking for a Manager, Cloud Security and Compliance who will oversee the adherence of Cloud Business unit policies and monitor the processes, and regulatory systems that govern Altium's activities to ensure smooth operations and minimize risks. A day in the life of our Manager, Cloud Security and Compliance: You'll establish compliance standards and improve the design of our internal control structures in Cloud Business Unit Work with other senior managers to develop corporate governance guidelines Minimize legal risks by complying with legal requirements, enforcing regulations, and understanding legislation Develop compliance organizational strategies with information, analysis, and recommendations on strategic direction; ensure functional and organizational objectives align Align financial resources, develop action plans, analyze results and initiate corrections, and minimize the impact of variances Create training, coaching, counseling, disciplinary, and communication programs to support compliance across the organization Develop state-of-the-art compliance programs that attract new clients Enhance our compliance and organizational reputation by bringing recognition to the company and leadership to the industry Stay current on compliance matters through educational opportunities, publications, and professional organizations Who We're Looking For BA or BS in business management, or a similar field 8+ years of compliance experience, preferably in a financial environment Strong understanding of regulatory frameworks with experience developing legal compliance standards Managerial and leadership experience International Compliance Association (ICA) certification required; Certified Securities Compliance Professional (CSCP) is a strong plus Familiar with process improvement methods Able to both embrace complexity and attend to details Skilled in critical thinking, problem-solving, project management, and strategic planning Excellent in verbal communication and creating documentation The salary range for this role is $240,000 - $260,000. Actual compensation packages within this range are based on a wide array of factors unique to each candidate and role requirements, including but not limited to skill set, years and depth of experience, certifications, and specific location. Our Benefits 🏥 Medical, Dental, Vision Plans and HSA and FSA accounts ❤️ Basic Life and AD&D insurance; disability coverage where applicable 🌅 Retirement 401(k) Plan Option with Altium match 🧘 Employee Assistance Program 🏖 Paid holidays plus a “Choice Day” off per quarter ✈️ Paid time-off on arising schedule upon key milestones 🤒 Sick time for Dr. appointments or family health needs 👶 Family medical, maternity, paternity, and military leave 🥳 Employee referral program 🌍 Remote working abroad program 📚 Professional development support and resources 🥪 Free lunch, snacks, and drinks in the office 🚗 Free parking 🌍 Also, we would like you to know We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender, gender identity or expression, or veteran status. We are proud to be an equal opportunity workplace. 💡 Learn more about why a career at Altium is an opportunity like no other: ******************************************* ✈️ Altium Benefits: ************************************** 👏 Are you already an Altium employee? Please apply directly through our internal Greenhouse job board. If you have questions, please contact HR.
    $240k-260k yearly Auto-Apply 6d ago
  • Director, Information Security

    Moov

    Remote job

    As Director of Information Security at Moov you will be responsible for the comprehensive enterprise-wide information security policy, strategy, architecture, operations, and capability enhancements of Moov and our platform. This position collaborates with the senior leadership team on security strategy, capability enhancements, and the development of enterprise security awareness and accountability. You will: Key Responsibilities: Develop, implement, and maintain information security policies, practices, and operations. Oversee incident evaluation and response, ensuring swift and effective handling. Manage corporate information security risk and regulatory architecture and status reporting efforts. Create and roll out audit and compliance programs. Implement technical compliance solutions and support for security awareness and training programs to ensure compliance. Collaborate with cross-functional teams to maintain a high standard of cybersecurity posture and response. Build and operate a security and compliance program for money movement regulations, aligning with information security policies and standards. Foster a security-conscious culture and ensure the platform's security. Leadership and Strategy: Execute a plan to achieve and maintain industry compliance for SOC 1, SOC 2, PCI, NACHA, FedRAMP, and other compliance programs. Research, educate, and recommend technical solutions to support compliance efforts. Develop, implement, and manage a comprehensive organization-wide information security and risk management program. Deliver education on compliance with security policies. Conduct security risk assessments and manage risk management processes. Ensure compliance with relevant laws, regulations, and policies in Moov's information security practices. Lead the information security team that is protecting Moov. Recruit, motivate, mentor, and lead the best security talent. You have: Bachelor's degree in Computer Science, Engineering, Information Systems, Cyber Security, Business, or a related academic discipline. 7-10+ years of relevant experience or an equivalent combination of education and experience. Strong knowledge of regulatory requirements and information security management frameworks, including SOC 1, SOC 2, ISO/IEC 27001, ITIL, SOX, PCI, FedRamp, and NIST. Ability to work in a fast-paced environment. Knowledge of payment systems, fintech, or online banking. Certification in CISSP, CISM, CRISC, CISA, CFE, or similar is highly recommended. Experience with banking regulations. Knowledge of OSS tools and active participation in OSS community. Experience working with remote-only teams. Experience with mid-size organizations and startups. Our company: Moov is a 100% remote company with people from more than 26 states. We're backed by a16z and other respected investors. We won Visa's global Everywhere Initiative and our community of builders grows larger every day. We're committed to building a team that represents a variety of backgrounds, perspectives, and skills and we embrace diversity, creativity, and equal opportunity. Our people: Our customers come from all walks of life and so do we. We hire great people from a variety of backgrounds, not just because it's the right thing to do, but because it makes our company stronger. We have mountain bikers, skiers/boarders, runners, video gamers, musicians, movie buffs, weight lifters, and about every other type of person in between. We enjoy solving problems and tackling challenges with creativity. If we don't know the answer, we revel in the hunt to find it. We like helping people and choose to give first. We're patient, open, and honest. If you share our values and enthusiasm for making the complex simple and delightful, you'll find a home at Moov. Benefits include: Competitive base salary + employee stock options w/early exercise opportunity 100% remote. We make remote-work work. We match what you contribute to your 401(k) up to 5% of your salary Generous parental leave Medical Ins: Health Savings Account (HSA) option w/employer contribution EAP and other wellness resources Unlimited PTO+ generous paid holiday schedule Professional Development Budget, we have a culture that encourages and promotes professional growth and development Home office stipend Culture of people helping people who give first, celebrate wins together and embrace autonomy, transparency, and trust The opportunity to join an experienced and ambitious team passionate about solving customers' needs and who love what they do Partner with a community of 3000+ developers around the world, helping them focus on possibilities vs payments Employee referral incentive Salary range: $220k - $232k based on experience, geography, and other key factors Advice: If you're nervous about not meeting every qualification above, apply anyway. Moov is all about pushing boundaries-ours, yours, and the industry's-so we look for curious people willing to experiment and grow. While we can't teach curiosity and compassion, we can teach some technical skills. Of course, we can't guarantee anything, but as Michael Scott says,“You miss 100% of the shots you don't take!” (Or was that Wayne Gretzsky?) One more thing: Don't go iron your clothes for your interview (do people still own irons?). We're all pretty casual here, so you can wear whatever you are most comfortable in. Okay-last thing: When you meet with us, have some concrete, tangible examples of when you've added value, improved something, created something, or done some fantastic, customer-centric work. We also want to learn about you as a person. If you want to know what it's like working at Moov, check out stories from our employees. PS: Share our job roles with others! Wouldn't it be nice to make new friends and bring over old friends? We think so. Moov Financial is a participant of E-Verify. All potential employees and employees are bound by the guidelines in the MOU and the rules and responsibilities. For more or up to date information on E-verify, go to ********************** and click on E-verify.
    $220k-232k yearly 50d ago
  • Director, Auto Total Loss

    Snapsheet 4.4company rating

    Remote job

    Job Title: Director, Auto Total Loss Company: Snapsheet Job Type: Full-time Job Department: Estimating About Snapsheet: Snapsheet is claims technology the way it should be: purposeful, precise, and designed to deliver outcomes. Where others bolt things on, we engineer them in to our core systems and processes across cloud-based claims management, virtual vehicle appraisals, and elite loss and recovery services. Trusted by over 170+ P&C Carriers, MGAs, MGUs, TPAs, and logistics companies, our open architecture is built to fit how our companies work, not the other way around. What you'll get: Remote working environment - your new commute is however long it takes to walk to your desk! Flexibility - empathy is ingrained in who we are and we are happy to offer a flexible PTO policy, casual dress code, and more! Development - Mentorship programs, 1-on-1 management, promote when ready culture, quarterly internal promotion opportunities, and goal setting sessions. Fun - Celebrations just because, yearly in-person and remote events, Snapsheet Swag, Employee Resource Groups, and more! Job Overview: As a Director in Auto Total Loss, you will oversee the day-to-day operations and success of our “Total Loss” team. Understanding our business objectives and department goals, you make recommendations to set us up for success in the short and long term. You use your experience in collaboration to manage vendor partnerships and work with our Account Management team to build out strategy and products needed to grow business. Working with our Learning and Development team, you determine the content and training needs for new workflows, products, and vehicle type cross training. You are a performance and coaching fanatic, managing efficiency and quality of your team while driving improved performance for the organization. Being well versed in metrics, you leverage data to analyze the success of your decision making and report back outcomes. Responsibilities: Manage the success of the Total Loss team, ultimately driving individual and organizational success Recommend new workforce models and strategies that allow us to reduce costs associated with handling of virtual total loss claims Build, implement, and manage both manual and automated workflows to increase operational efficiency Use data to articulate current and future planning and report on successes and opportunities Apply knowledge of industry best practices to build out programming that will improve quality in the claims handling for the total loss team as well as services such as repair management and field appraisals Coach and mentor estimating managers, encouraging collaboration and elevating overall department performance Qualifications: Minimum of 8 years of Total Loss or repair experience with at least 4 years of management experience Proven track record of leading high-performing teams Extensive knowledge of insurance principles and how they apply to appraisal decisions Thorough understanding of vehicle repair, parts costs, total loss classification, and fraud detection practices A strong knowledge of total loss settlement and salvage processes Working experience in one or more estimating platforms: Mitchell, CCC, Adjustwrite, or Duncan Ability to work in a fast-paced, production-based, and results-driven environment Desire to thrive in a remote environment ripe with opportunity to advance Data driven - ability to use data to identify problems and potential solutions and consistently report back We're Built to Grow With You - And That Starts With How We Support You At Snapsheet, we know that growth doesn't happen in a vacuum-it's fueled by the right support at the right time. That's why we've built a benefits experience designed to grow with you, wherever life takes you. Choose from 2 robust medical plans through Blue Cross Blue Shield-plus, we contribute to your HSA when you enroll in our high-deductible health plan. Offer two dental plans and one vision plan to keep you and your family healthy. Peace of mind with company-paid Short Term Disability, Long Term Disability, and Life Insurance. Additional protection through voluntary benefits like Accident Insurance, Hospital Indemnity, Critical Illness, and Legal Assistance. 401(k) with a 4% company match-because your future is worth investing in. Employee Assistance Program (EAP) with 6 sessions per life incident to support your mental well-being. Perks That Make Growing Here Even Better: Flexible PTO and 7.5 company-observed holidays to recharge on your terms. In-person connection points throughout the year including our annual Summit and Roadshows. Snapsheet SWAG and surprise mailers to keep the spirit alive. Endless opportunity to shape your path-career growth, learning, and real impact are all within reach. Health and wellness campaigns that evolve with you year over year. We are currently accepting applications for candidates who reside in the following states: AL, AK, AZ, AR, AS, CO, CT, DE, DC, FL, GA, GU, HI, ID, IL, IN, IA, KS, KY, LA, ME, MD, MA, MI, MN, MS, MO, MT, MP, NE, NV, NH, NJ, NM, NC, ND, OH, OK, OR, PA, PR, RI, SC, SD, TN, TX, UT, VT, VA, VI, WA, WV, WI, WY *Please note that we are unable to sponsor applicants for work visas for this position at this time. Don't meet every single requirement? Studies have shown that women and people of color are less likely to apply for jobs unless they meet every single qualification. At Snapsheet, we are dedicated to building a diverse, inclusive, and authentic workplace, so if you're excited about this role but your experience doesn't align perfectly with every qualification in the job description, we encourage you to apply anyways. Snapsheet is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need assistance or accommodations, please let us know by emailing [email protected]. Snapsheet is proud to be an Equal Opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. #BI-Remote #LI-Remote Snapsheet is an equal opportunity employer.
    $56k-83k yearly est. Auto-Apply 13d ago
  • Security Manager - Awareness & Training

    Neko Health AB

    Remote job

    Neko Health is a Swedish healthcare technology company co-founded in 2018 by Hjalmar Nilsonne and Daniel Ek. Neko's vision is to shift healthcare from reactive treatment toward preventative health and early detection. This requires completely reimagining the patient's experience and incorporating the latest advances in sensors and AI. Neko Health has developed a new medical scanning technology concept to make it possible to do broad and non-invasive health data collection that is convenient and affordable for the public. The company is based in Stockholm, offering the Neko Body Scan experience at locations in Stockholm, London and Manchester, with over 500 employees. We are looking for a Security Manager - Awareness & Training to lead our global security education program and strengthen Neko's security culture. This role focuses on reducing human‑driven risk, designing engaging training, driving behavioural change, and ensuring all employees meet security and compliance obligations. You will own Neko's security awareness roadmap, phishing program, onboarding experience, role-based training, and internal communication strategy. You will also support security requirements for ISO 27001, HIPAA, SOC 2, IEC 81001‑5‑1, and security‑related audits. This is a high‑impact role where you will collaborate closely with Engineering, IT, People/HR, Compliance, Platform, and Leadership teams to embed security into daily operations. Responsibilities * Awareness & Behavioural Security * Own and lead the company‑wide Security Awareness & Training Program. * Design and deliver engaging learning formats: micro‑training, videos, workshops, newsletters, simulated exercises. * Run and continuously improve phishing simulation campaigns, including reporting metrics and follow‑up training. * Maintain a quarterly awareness and communication campaign calendar. Training & Competence Ensure employees meet all required annual and role‑based security training, including: onboarding training secure coding and developer education incident response roles clinical and operational security basics Maintain training records and prepare audit‑ready evidence. Define and track security culture KPIs: competence scores, reporting rates, behavioural improvement indicators. Cross‑Functional Enablement Collaborate with Engineering & Platform teams to deliver secure coding and best‑practice training. Partner with People/HR to embed security into onboarding, offboarding, and role changes. Support internal communication of security requirements, policy changes, and emerging threats. Prepare and maintain awareness-related artifacts for audits and compliance reviews. Requirements * 5+ years in security awareness, information security, training, behavioural security, or a related role. * Strong understanding of human risk, phishing, social engineering, and behavioural change principles. * Experience designing or managing security awareness programs. * Familiarity with secure coding or technical security topics (AppSec, cloud security fundamentals). * Excellent communication skills; ability to translate complex topics into simple, engaging content. * Experience with LMS platforms or enterprise learning tools. * Experience in regulated industries (health‑tech, medical device, healthcare, fintech). * Background in psychology, behavioural science, or learning & development is a plus. About the Engineering Team Distributed and Remote First We are nearly 100 full time engineers at the company, working from Berlin, Chamonix, Hamburg, Lisbon, Marseille, Vilnius, and Stockholm, spanning diverse disciplines such as Hardware Engineering, Firmware Development, Electrical Design, Algorithm Development, Machine Learning Development, Optronics Research, Frontend Development and more. We don't expect people to join us with a specific tech knowledge, but we do expect you to work with our tools. We use a mix of React, Typescript, C++, and Python. Our APIs are written in C# with ASP.NET Core, uses Azure Cosmos DB, and Azure Active Directory for authentication. Our headquarters and our hardware development team are in Stockholm, Sweden. We are a Remote First company; however, it is of course much easier to work remotely as a software engineer than a hardware or firmware engineer (since they require access to hardware or devices occasionally). Software engineers based in Stockholm work maybe one day a week or one day every two weeks from the office. We meet a couple of times per year to get to know each other and have fun. Organization and Way of Working The engineering team is divided into smaller cross functional project teams that each focus on a specific goal or target, where some groups are long-lived, and some are short-lived, depending on how big the goal or deliverable is. We strive to create groups which are cross-functional and able to complete their goals without dependence on other teams, even though this is of course not always possible. Groups track goals on a yearly and quarterly basis with goal follow-up across the entire engineering organization on a bi-weekly basis. Most groups do internal planning on a bi-weekly basis, but in the end it's up to the group to decide how they want to work. We have, however, mandated that all groups must present their progress or failures or hacks at our bi-weekly engineering demo, a fun meeting/presentation where we talk about everything from short-circuiting power-modules, how hard it is to calibrate cameras or align polygons in space, to neat new command line tools for operations, a new auth mechanism in the backend, a cool new way to visualize health data or a new feature which helps our doctors be more productive. We have a flexible workplace that focuses on work/life balance, and we strongly believe in our mission but do not think that achieving it requires sacrificing everything else. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
    $65k-96k yearly est. 6d ago

Learn more about security director jobs