Employment Type: Full-Time Compensation: $158,500.00 - $198,250,00(Range applies to US candidates only) + Benefits/Variable Comp/Equity - Range may vary based on experience. Benefits Offered: Vision, Medical, Life, Dental, 401K
Summary
The AI Security Architect collaborates on the design, implementation, and ongoing maintenance of the security architecture that protects AI/ML systems, data pipelines, and model-driven products. This role defines and promotes security patterns for AI workloads, partners closely with engineering and development teams to embed security controls throughout the AI lifecycle, and leads threat modeling and risk assessments focused on the unique attack surfaces introduced by machine learning technologies.
Reporting directly to the Chief Information Security Officer (CISO), the AI Security Architect drives cross-functional alignment and helps further integrate information security into the organization's culture and platform development practices. The ideal candidate brings a strong passion for information security and AI, is results-driven, and combines deep technical expertise with strong leadership capabilities and a strategic mindset.
Primary Duties and Responsibilities
Define, document, and maintain a secure reference architecture for all AI and machine learning (ML) systems, pipelines, and deployments.
Develop, implement, and enforce secure ML operations practices, including AI-focused CI/CD pipelines, model signing, validation, and continuous monitoring.
Establish and oversee AI guardrails for both internal and external AI systems to ensure safe, complaint, and responsible use.
Ensure alignment with applicable AI governance and security frameworks and regulations, including the EU AI Act and the NIST AI Risk Management Framework.
Partner with security operations teams on AI/ML-specific monitoring, incident response, and investigations related to misuse, data exposure, or model compromise.
Lead AI-specific threat modeling efforts to identify risks across data, model, infrastructure, and application layers.
Define and drive mitigation strategies, ensuring security controls are embedded throughout the AI and ML development lifecycle.
Required Education and Experience
Bachelor's degree in Computer Science, Engineering, or a related field.
7+ years of experience in Information Security, with demonstrated depth across enterprise and cloud environments.
Experience working with AI and machine learning technologies, including an understanding of their unique security considerations.
Deep knowledge of modern threat landscapes, security technologies, and enterprise architecture principles.
Familiarity with industry best practices, standards, and frameworks related to information and application security.
Strong understanding of modern application security, cloud security architectures, and secure software development practices.
Experience across IT security and infrastructure, security risk management, compliance frameworks (e.g., SOC 2, FedRAMP), security policies and procedures, security testing and auditing, and internal audit processes.
Preferred Education and Experience
Industry recognized certifications:
ISC2 - CISSP
ISACA CISM
GIAC - GSTRT
CompTIA Security+
Other relevant security certifications
Knowledge, Skills, and Abilities
Strong communication and interpersonal skills; able to translate between technical and business audiences.
Confident facilitator and coach who can lead meetings with energy, empathy, and focus.
Skilled in problem-solving and navigating ambiguity.
Ability to drive consensus and make recommendations based on both data and team feedback.
Organized and detail-oriented with a continuous improvement mindset.
Who We Are
OneStream is how today's Finance teams can go beyond just reporting on the past and Take Finance Further by steering the business to the future. It's the only enterprise finance platform that unifies financial and operational data, embeds AI for better decisions and productivity, and empowers the CFO to become a critical driver of business strategy and execution. Our vision is to be the operating system for modern finance, digitizing core financial functions and empowering the CFO to become a critical driver of business strategy. To learn more visit ******************
Why Join The OneStream Team
Transparency around corporate structure, salary, and benefits
Core value of customer success
Variety of project work (not industry-specific)
Strong culture and camaraderie
Multiple training opportunities
Benefits at OneStream
OneStream employees are passionate, hardworking individuals who go above and beyond to keep our customers happy and follow through on our mission statement. They consistently deliver the best and in turn, we make every effort to keep them cared for and happy. A sample of the benefits we provide are:
Excellent Medical Plan
Dental & Vision Insurance
Life Insurance
Short & Long Term Disability
Vacation Time
Paid Holidays
Professional Development
Retirement Plan
All candidates must be legally authorized to work for any company in the country where this position is located without sponsorship.
OneStream is an Equal Opportunity Employer.
#LI-CB1
#LI-Remote
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.
$158.5k-198.3k yearly 22h ago
Looking for a job?
Let Zippia find it for you.
Cyber Engineer (Detroit, MI)
Insight Global
Security engineer job in Sterling Heights, MI
This engineering management role supports the Cyber and C5ISR section, focusing on architecture, evaluation, testing, and compliance across U.S. markets. The position contributes to the delivery of cyber-secure products for Ground Combat Platforms, executing guidance from the Chief Engineer, Systems Engineering Manager, and functional leadership.
________________________________________
Key Responsibilities
- Lead cyber integration across vehicle systems
- Develop and enforce system requirements (SWaP-CRaM)
- Conduct trade studies and structured decisions
- Oversee verification plans and testing
- Support root cause analysis and corrective actions
- Evaluate new technologies for GDLS platforms
- Coordinate with cross-functional teams and IPTs
$60/hr to $70/hr
Exact compensation may vary based on several factors, including skills, experience, and education.
Benefit packages for this role will start on the 31st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401K retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to ********************.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: ****************************************************
Skills and Requirements
- Bachelor's degree in Engineering or related science (cyber certifications and management credentials considered)
- 5-10+ years of experience
- Experience with:
- Cameo Systems Modeler and SysML
- Embedded systems engineering in cyber environments
- NIST SP 800-37 and 800-53 compliance
- Threat Analysis and Risk Assessment (TARA)
- System Security Plans (SSPs), POA&Ms, and related documentation
$60 hourly 13d ago
Data Security Engineer
Mindlance 4.6
Security engineer job in Auburn Hills, MI
Mindlance is a national recruiting company which partners with many of the leading employers in the Life Sciences, IT, and Financial Services sectors, feel free to check us out at *************************
Job Title: Data SecurityEngineer
Duration: 12+ months
Location: Auburn Hills, MI
Job Description:
Candidates come ready to protect the enterprise landscape of data and computer systems. An International organization focused on secure, next generation data infrastructure is seeking a Data SecurityEngineer who has a passion for security coupled with large-scale know-how. As part of the Chief Information Security Officer's team, responsibilities of the Data SecurityEngineer will include, but not be limited to:
• Teaming up with the usual suspects (a.k.a., cross-functional IT members) to determine the “best path forward” plan to securing the environment through controls, scanning, remediation, and hardening.
• Actively identifying security vulnerabilities, threats, and exposures within the enterprise (servers, applications, and databases).
• Bringing your “A” game to security testing techniques (scanning, auditing, and penetration testing).
• Identifying concerns of residual risk, vulnerabilities, and other security exposures due to legacy systems or configuration errors.
• Staying sharp by identifying new-to-market solutions that lead to best-in-class security practices.
• Serving as security sense-check for IT project delivery and server lifecycle build process.
• Joining forces with the ranks of Information Security leadership to develop strategies and plans to enforce security requirements and address identified risks.
• Reporting security metrics for dynamic dashboards and executive reviews.
• Doing the right thing by aligning cutting edge data and systems security practices to law of the land (regulations and policies).
• Lending expertise to know when risk may be acceptable.
• Ensuring security is top of mind.
• Other challenging opportunities as assigned.
Required Skills and Education:
• Operational knowledge and skills (4+ years preferred) related to general industry security standards for application security, vulnerability management, and overall data security
• Self-motivated and able to plan and carry out responsibilities with minimal direction and supervision
• Excellent decision-making, analytic, and organizational skills
• Strong written and verbal communication skills
• Superior interpersonal skills (“team player” characteristics) and professional demeanor at all levels of the organization
• Bachelor's Degree in Computer Science, Information Technology, Management Information Systems, or Software Engineering
NOTE: A combination of education and experience equaling at least a Bachelor's degree will also be considered.
• Working knowledge of common network devices as well as Windows and Unix operating systems
• Familiarity with industry standards regarding system and application hardening and associated scanning tools.
Demonstrated Technical Experience:
• Vulnerability scanners
• Application security testing
• Security and technology controls
Desired Certifications:
• Certified Information Systems Security Professional (CISSP) or,
• Certified Information Systems Manager (CISM) or,
• GIAC Security Leadership (GSLC) or,
• GIAC Information Security Professional (GISP) or,
• GIAC Certified Web Application Defender (GWEB)
Travel Requirement:
• Limited International travel may be required
Additional Information
$79k-104k yearly est. 60d+ ago
Corporate Security Analyst
Robert Bosch 4.8
Security engineer job in Farmington Hills, MI
We Are Bosch. At Bosch, we shape the future by inventing high-quality technologies and services that spark enthusiasm and enrich people's lives. Our areas of activity are every bit as diverse as our outstanding Bosch teams around the world. Their creativity is the key to innovation through connected living, mobility, or industry.
Let's grow together, enjoy more, and inspire each other. Work #LikeABosch
* Reinvent yourself: At Bosch, you will evolve.
* Discover new directions: At Bosch, you will find your place.
* Balance your life: At Bosch, your job matches your lifestyle.
* Celebrate success: At Bosch, we celebrate you.
* Be yourself: At Bosch, we value values.
* Shape tomorrow: At Bosch, you change lives.
Job Description
Support the implementation, monitoring, and continuous improvement of the Physical Security Management System (PSMS) across the USA and Canada in alignment with legal requirements and the corporate regulatory framework. Strengthen the internal and external regional security network, enhance PSMS awareness among managers and employees, and contribute to regional and cross-regional investigations, including compliance-related inquiries. A successful candidate will be able to demonstrate analytical, systematic, and strategic thinking. This role reports to the Corporate Security Manager in Farmington Hills, MI.
Key Tasks
* Provide oversight to Bosch locations and business units on security concepts and the implementation of protection measures.
* Conduct site- and business-unit audits to evaluate security governance effectiveness and report findings.
* Develop, publish, and maintain corporate security training and awareness materials.
* Coordinate site-level security teams on regionally relevant security topics.
* Support the adaptation of the regional security strategy based on threat trends, legal changes, and business priorities.
* Conduct or support security investigations and communicate results.
* Assist with security-related due diligence for M&A activities and post-merger integrations.
* Contribute to the development of corporate security best practices, policies, and regulations.
Qualifications
Required Skills
* 4+ years' experience in risk assessment, security investigations and report writing
* Excellent verbal and written communication skills for clearly conveying complex security risks, audit findings, and policy requirements to both technical security specialists and non-technical executive leadership
* Develop close collaboration with international and cross-cultural teams
* Experience in creating, reviewing, and implementing security policies or SOPs that focus on corporate risk mitigation within the overall company strategy
Preferred Skills
* Effective use of emerging digital tools, such as AI technologies
* Experience with internal auditing
* Direct experience supporting Mergers & Acquisitions (M&A) or other large projects by performing security due diligence activities, including assessing current security controls, identifying risk, and integrating new entities into a corporate security framework
* Proven ability to research, interpret, and apply security regulations, federal/state laws (e.g., C-TPAT, local life safety codes), and corporate security policies across the USA and Canadian regions
Education, Training, and Certifications
* Associate's degree in physical security, criminal justice, or business administration with 8 years' experience in corporate security or a related field. Or,
* Bachelor's degree in physical security, criminal justice, or business administration with 4 years of relevant security or law enforcement experience.
* CPO, PSP, CPI certifications are a plus
Additional Information
Indefinite U.S. work authorized individuals only. Future sponsorship for work authorization unavailable.
In addition to your base salary, Bosch offers a comprehensive benefits package that includes health, dental, and vision plans; health savings accounts (HSA); flexible spending accounts; 401(K) retirement plans with an employer match; wellness programs; life insurance; short- and long-term disability insurance; paid time off; parental leave, adoption assistance; and reimbursement of education expenses.
Learn more about our full benefits offerings by visiting: ************************ Pay ranges included in the postings generally reflect base salary; certain positions may include bonus, commission, or additional benefits.
Equal Opportunity Employer, including disability / veterans
* Bosch adheres to Federal, State, and Local laws regarding drug-testing. Employment is contingent upon the successful completion of a drug screen and background check. Candidates who have been offered the position must pass both screenings before their start date.
Your well-being matters at Bosch! We offer a competitive compensation and a benefits package designed to empower you in every area of your life. This includes premium health coverage, a 401(k) with generous matching, resources for financial planning and goal setting, ample paid time off, parental leave, and comprehensive life and disability protection. We're investing in your success!
$81k-109k yearly est. 43d ago
IT SAP Security Engineer
Hitachi Astemo Ohio Manufacturing
Security engineer job in Farmington Hills, MI
The SAP Security Analyst - Role Design & SailPoint will be responsible for the day-to-day management of SAP user access, security role design, and governance processes across the AM region. This includes provisioning SAP accounts, collaborating with functional teams on secure access design, and supporting identity lifecycle management using SailPoint. The analyst will ensure the integrity and compliance of SAP S/4HANA access while providing support for audits, access reviews, and segregation of duties (SoD) monitoring.
Job Summary:
This position plays a vital role in maintaining secure and compliant SAP environments by designing, administering, and reviewing access controls. The ideal candidate will have a deep understanding of SAP security concepts (roles, authorizations, profiles) and hands-on experience with role provisioning, GRC tools, and identity governance platforms such as SailPoint. The analyst will also support global and regional initiatives, participate in SAP rollout projects, and contribute to continuous improvement in SAP security processes.
Job Responsibilities:
Design and maintain SAP security roles (single, composite, derived) for SAP S/4HANA and related systems.
Support new project rollouts, security role mapping, and SoD (Segregation of Duties) compliance.
Collaborate with functional leads to define access requirements and translate them into secure role concepts.
Partner with the Identity & Access Management (IAM) team to support SailPoint provisioning workflows.
Manage day-to-day user provisioning and de-provisioning for all AM Region SAP accounts, ensuring timely and accurate access.
Conduct periodic access reviews, audit support, and remediation of identified risks.
Provide technical guidance for GRC ruleset maintenance and SoD analysis.
Develop documentation for security design, user provisioning processes, and governance procedures.
Perform user and role analysis to identify redundant, obsolete, or excessive access.
Investigate and resolve access issues, violations, or user provisioning errors.
Stay updated on SAP security trends, tools, and regulatory changes impacting access control.
Provide support during go-live cutovers and critical production support windows.
Qualifications:
Knowledge, Skills, and Abilities:
Strong understanding of SAP authorization concepts and role-based access control.
Ability to manage high-volume provisioning and support multiple SAP environments.
Experience supporting manufacturing or regulated industries preferred.
Strong communication skills for collaboration with business users and audit teams.
Familiarity with IT general controls, SOX compliance, and access certification processes.
Ability to prioritize and manage multiple tasks in a fast-paced environment.
Experience working in international or global teams is a plus.
Technical Skills:
Hands-on experience in SAP Security for S/4HANA, Fiori, and ECC systems.
Proficiency in SAP authorization objects, PFCG role maintenance, SUIM, ST01, SU53, and SU24.
Experience with SAP GRC Access Control (ARA, BRM, ARM).
Experience with SailPoint IdentityNow or other Identity Governance tools.
Familiarity with ticketing systems like ServiceNow or SAP Solution Manager.
Understanding of SAP modules such as MM, SD, PP, and FICO from a security perspective.
Education: Bachelor's degree in business, Engineering, Computer Science, Information Systems, or related field.
Experience:
Minimum 5 years of experience in SAP Security administration.
At least 2 years of experience with S/4HANA security and/or Fiori applications.
Experience with SailPoint Identity Governance tools highly preferred.
Experience supporting SAP implementations and working on project teams.
Audit and compliance support experience is a plus.
Working Conditions
Open to travel up to 30%, including extended stays for project implementation.
Ability to work in a professional setting, adhering to company and regulatory safety requirements.
Work in a safe and professional manner while adhering to all regulatory requirements (OSHA, EPA, State, and Federal regulations, etc.).
Comprehend and adhere to management directions and/or safety instructions with no restrictions.
Effectively communicate in Business English language.
Location: Close to at least one of the US plants is highly desirable
Equal Opportunity Employer (EOE) - Qualified applicants will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender, identity, disability, protected veteran status and national origin.
At Astemo, we're challenging the status quo with the power of diversity, inclusion, and collaboration. Our goal is to build an inclusive work environment that celebrates the differences of our employees. We want to ensure that every employee feels valued, respected and empowered. We don't just accept difference-we celebrate it, we support it, and we thrive on it for the benefit of our employees, our products, and our community. Astemo is proud to be an equal opportunity employer.
If you need a reasonable accommodation to apply for a job at Astemo, please send the nature of the request and contact information to ************************* when applying for the position.
$73k-100k yearly est. Auto-Apply 60d+ ago
Security Architect
Member Driven Technologies 3.9
Security engineer job in Farmington Hills, MI
The role of the Security Architect at MDT is to ensure that security requirements necessary to protect MDT's mission, vision and business processes are adequately addressed. The Security Architect is responsible for designing and implementing comprehensive security solutions and strategies. This role serves as a key security and technical advisor and strategist, partnering with technology, development, and business teams to ensure secure-by-design solutions across the organization's technology landscape.
DUTIES & RESPONSIBILITIES
Design and implement security controls for cloud, on-premises, and hybrid environments (e.g., AWS, Azure, GCP).
Monitor and review cloud service provider security policies to help ensure compliance with organizational requirements.
Partner with Enterprise Architects and Development teams to ensure security best practices and principles are embedded in their workflows.
Conduct security assessments and risk analysis to identify vulnerabilities and propose mitigation strategies within the Zero Trust framework.
Design and implement Zero Trust principles and frameworks to enhance the security posture of our systems and networks.
Design and maintain robust CI/CD pipelines with integrated security checks to "shift security left," ensuring vulnerabilities are identified early in the development process.
Collaborate with cross-functional teams to define access policies, user authentication mechanisms, and secure connectivity across various environments.
Design and collaborate with cross-functional teams to deploy secure SSO solutions with identity providers (IdPs), directory services, and third-party applications for seamless and centralized authentication and authorization across multiple applications and systems.
Collaborate with stakeholders to understand business requirements and translate them into effective security controls and solutions.
Make recommendations to reduce risks.
Supports administration of the enterprise security infrastructure including, but not limited to, the systems supporting: network security monitoring, two-factor authentication, web application firewalls, vulnerability management, endpoint detection and response, data loss prevention, and enterprise logging.
Supports incident response processes.
Compiles metrics for leadership.
Assists in installing, implementing, and maintaining security software.
Maintains the availability, patching, and operational functionality of assigned security systems.
Evaluates new security tools, products, and solutions for applicability to security needs.
Makes recommendations regarding purchase of security products.
Ensures MDT's reputation is maintained internally and externally.
Ensures appropriate levels of security and confidentiality are always maintained.
Acts as a representative of MDT with business and professional organizations and external IT contacts.
Keeps management informed of area activities and any significant concerns.
Attends and participates in meetings as required.
Completes accurate tickets, reports, records, and other documentation as necessary.
Stay up to date with industry trends, emerging technologies, and security best practices to proactively identify potential threats and vulnerabilities.
Responsible for working with the security team and other departments to ensure work is flowing effectively and timely throughout the organization.
Assists in setting department and company standard practices and procedures.
Responsible for working with company vendors to ensure the delivery of products or services is successful.
Acts as a subject matter expert for co-workers and fosters a culture of continuous learning and cross-training.
Assigned to the on-call rotation to support security operations.
Stays informed of trends and changes in the information security field.
Completes special projects and research studies as required.
Keeps work area clean, secure, and well maintained
EDUCATION & EXPERIENCE REQUIREMENTS
Bachelor's degree in Computer Science or a related field, or an equivalent combination of training and experience in Computer Science.
Professional certifications such as CISSP, CISM, CCSK, or CCSP are highly desirable.
Ten years of experience as a Security Architect or similar role, with a focus on cloud security and Zero Trust architecture.
REQUIRED KNOWLEDGE
Strong knowledge of cloud platforms (e.g., AWS, Azure, Google Cloud) and associated security controls.
Experience designing and implementing Zero Trust architectures, including network segmentation, secure access controls, and strong authentication mechanisms.
Experience with designing and implementing Secure Access Service Edge (SASE) and Software-Defined Wide Area Network (SD-WAN).
Experience with the design and integration of security into the SDLC by implementing secure coding standards, automated security testing (SAST, DAST), and vulnerability scanning.
In-depth understanding of SSO protocols and standards (e.g., SAML, OAuth, OpenID Connect) and their implementation.
Technical understanding of threat actor attack techniques.
Familiarity with security frameworks and standards (e.g., NIST Cybersecurity Framework, ISO 27001, CIS Controls).
Excellent analytical and problem-solving skills, with the ability to assess complex security requirements and recommend appropriate solutions.
Effective communication and interpersonal skills to collaborate with cross-functional teams and communicate security concepts to non-technical stakeholders.
Self-motivated and ability to meet deadlines with minimal supervision.
Well organized and attentive to detail.
Strong leadership abilities.
Project management skills.
Ability to maintain confidentiality.
WORKING CONDITIONS
Special
No hazardous or significantly unpleasant conditions (such as in a typical office).
Additional hours, including on-call with Saturday/Sunday support, as required.
Long duration of computer workstation usage.
INTENT AND FUNCTION OF S
s assist organizations in ensuring that the hiring process is fairly administered and that qualified employees are selected. They are also essential to an effective appraisal system and related promotion, transfer, layoff, and termination decisions. Well-constructed job descriptions are an integral part of any effective compensation system.
All descriptions have been reviewed to ensure that only essential functions and basic duties have been included. Peripheral tasks, only incidentally related to each position, have been excluded. Requirements, skills, and abilities included have been determined to be the minimal standards required to successfully perform the positions. In no instance, however, should the duties, responsibilities, and requirements delineated be interpreted as all inclusive. Additional functions and requirements may be assigned by supervisors as deemed appropriate.
In accordance with the Americans with Disabilities Act, it is possible that requirements may be modified to reasonably accommodate disabled individuals. However, no accommodations will be made which may pose serious health or safety risks to the employee or others or which impose undue hardships on the organization.
$99k-146k yearly est. 10d ago
Cyber Security Engineer (5+ years experience)
The Panther Group 3.9
Security engineer job in Sterling Heights, MI
Exercise authority and responsibility for Cyber and tasks to help integrate cross-functional technical scope within schedule and other constraints. Help project team to ensure a balanced, integrated, and compliant Cyber design across the vehicle system.
Manage/support the identification, development and implementation of platform cyber-physical design best practices, tools and education across the entire engineering enterprise. This will be done with a cross functional team of engineering and program disciplines and form the basis for developing a cyber security culture within the engineering organization.
Develop and manage System requirements and interface allocations including Performance and Space, weight and Power-Cooling, Reliability and Maintenance SWaP-CRaM), and enforce across the design team; develop system specification requirements compliance documentation
Manage and coordinate requirements, architectures and system designs and any changes, conditions, inputs and final resolution for requirements, trades, and alternatives
Manage, develop, support and conduct trade studies/structured decisions for system and subsystem design including system-level impacts to include balance of space, weight, power, cost, reliability, and performance across a Cyber vehicle suite
Oversee/support development of verification plans and manage their execution including test and production and field site shakedown and verification
Participate in and lead design and integration troubleshooting/Root Cause Corrective Action (RCCA) and problem report/test incident resolution for production, development, test, or modification projects
Develop and evaluate checkpoint and design milestone artifacts and Contract Data Requirements List (CDRLs) and review to ensure technical accuracy and compliance with contract requirements
Coordinate with platform Design Integrated Product Teams (IPTs) where interface is required, such as in threat analysis, interface development and requirements decomposition and compliance
Evaluate new Cyber and C5ISR technologies for potential use on our products
Manage and participate in peer reviews
Requirements
Candidates will be considered on the aggregate of the position requirements, it is not required that candidates possess experience in
all
categories:
Bachelor of Science in Engineering, related science or equivalent (Relevant cyber technical certificates and management credentials will be considered)
Minimum of 7+ years' experience
Experience leading engineering and/or military projects
Experience with embedded system engineering Cyber space.
Experience with Threat Analysis and Risk Assessment (TARA)
Experience with Cross-Domain Solution sets
Experience with Cyber Tabletop Exercise (CTTX) drills
Ensure compliance with federal regulations and standards, including NIST SP 800-37 and NIST SP 800-53.
Prepare and maintain System Security Plans (SSPs), Plan of Action and Milestones (POA&Ms), and other required documentation.
Experience leading teams in technical development projects
Experience in military vehicle development and integration
Experience in interpreting higher level customer requirements and flowing them down to technology areas
Experience in developing and managing system level cyber requirements
Familiarity with various electrical line replaceable units and the development and troubleshooting of electronic hardware
Experience with cyber warfare, offensive and/or defensive
Experience with embedded systems, automotive and military related
Experience with software and computer science principles
Familiarity with cyber physical system security requirements
Familiarity with Microsoft Office software (Word, Excel, PowerPoint, Visio, Project)
Ability to travel (mostly domestic, some international) up to 15%
Must have an active Security Clearance
This position may require the candidate to be able to climb on/off, work in, and work around military vehicles is desired. Must be able to pass ASR test (Anthropometric Size Requirement for confined space)
$82k-113k yearly est. 60d+ ago
Application Security Analyst
FCA Us LLC 4.2
Security engineer job in Auburn Hills, MI
The Application Security product manager is looking for an Application Security Analyst who will be responsible for working with application development team to analyze application code vulnerabilities and involved in running security scans which include but not limited to SAST, DAST, IAST, Mobile, and ad-hoc dynamic testing. Also, Analyst will play role in extending WAF deployment for large number of applications. The candidate will play a key role in a major cybersecurity transformation initiative of “Shift left and Secure Early” as well as implementing additional security controls in SDLC.
The role entails taking responsibility of analyzing security vulnerabilities and capability to provide mitigation solutions to fix issues by writing secure code, providing guidance to application teams, and coordinating with cross functional teams across the platform.
Key responsibilities:
Hands-on experience working with DevSecOps pipeline using CICD automation tools like Jenkins, TeamCity, GitLab, GitHub Action, Checkmarx, GitHub Advance Security, BurpSuite, and open-source tools.
Implement Application Cyber Security Controls/Policies and standards developed by Application Security Program.
Lead deployment of WAF for existing and new applications
Ability to demo security vulnerability to application teams.
Drive application security issues to a resolution.
Provide a clear guidance to application teams during vulnerability mitigation effort
Conduct application security assessment using standard Stellantis application security tools
Collect and report status on application security assessments including milestones, deliverables, timing, tasks, risk areas, and status
Categorize and recommend assessment strategies for existing and new application development
Coach development and supplier teams on application security
Develop user training material and conduct training sessions
About Us: Niterra North America, Inc., established in 1936 and formerly known as NGK Spark Plugs(U.S.A.), Inc., is a global leader in spark plug and oxygen sensor technology and quality. With a legacy of innovation and excellence, Niterra is evolving its business portfolio, leveraging core ceramic technologies to venture beyond traditional domains. The company is committed to developing solutions that address social issues and promote sustainability.
About the Role:
The ideal candidate must possess an enthusiastic and growth minded personality which will enable them to thrive in a dynamic environment. The candidate must be passionate about Cyber Security and possess strong technical knowledge in Security Domain. The Sr. Cyber Security analyst will serve as subject matter expert in various functions within the SecOps team utilizing solutions such as SIEM, EDR, VM, Firewall, Email Security, etc. The team member must be a team player who is eager to contribute to company success and meeting objectives.
Essential Duties:
* Adhere to all company policies and procedures, which include IATF, ISO, ISMS, QMS, TISAX and Safety related policies.
* Investigate security incidents and perform in-depth analysis to identify security threats and perform remediations.
* Deploy/implement security tools to protect company assets.
* Review logs to detect anomalies which may lead to security breaches.
* Serve as point of contact for assigned security vendors responsible for managed services and handle escalations.
* Subject matter expert on vulnerability management to identify vulnerabilities and performin remediation.
* Conduct/assist with performing penetration testing to identify security weaknesses and offer solutions to address identified gaps.
* Participate/lead global incident response activities.
* Subject matter experts on various security functions such as endpoint security, EDR, MDR, Firewall, Email Security, Spam filtering, PAM, etc.
* Leverage automation to streamline workflow to increase efficiency and productivity.
* Review, create or document standard operating procedures.
* Perform periodic user access reviews and governance.
* Assist with internal/external audits and implement security controls based on audit findings.
Experience, Education and Certification:
* 5 plus years of experience in SecOps functions including but not limited to Incident response, EDR, MDR, Email security, Endpoint Security, IAM, Firewall, etc.
* Bachelor's degree in computer science or related field
* Industry standard information security certifications (CompTIA Security +, Network +, CASP+, CISSP, GCIA, Digital Forensic, Ethical hacking, etc.) are a plus.
* In-depth knowledge of TCP/IP networking, Routing, etc.
* Experienced in Security functions including Firewall, IDS/IPS, Email Security, Endpoint Security, SIEM, EDR, Vulnerability Scanning, etc.
* Experience with proactive threat hunting exercise.
* Experience in leading security investigation and incident response and capable of documenting/conducting RCA in support of investigations.
* Familiar with NIST CSF and other security controls/guidelines for incident response
* Knowledge of Malware, ransomware behaviors and techniques
* Ability to coordinate, gain trust of business stakeholders and maintain third party vendor relationships.
* Able to work under pressure in critical circumstances.
Why Work for Niterra?
* Comprehensive Health Benefits: Medical, dental, vision, and life insurance
* Financial Security: Short-term and long-term disability coverage
* Retirement Savings: 401(k) plan with a generous company match of up to 6%
* Time Off: Generous paid time off, including vacation, sick leave, and holidays
* Work-Life Balance: Paid maternity and paternity leave
$72k-97k yearly est. 50d ago
Senior Cyber Security Analyst
Niterra North America
Security engineer job in Wixom, MI
About Us:
Niterra North America, Inc., established in 1936 and formerly known as NGK Spark Plugs(U.S.A.), Inc., is a global leader in spark plug and oxygen sensor technology and quality. With a legacy of innovation and excellence, Niterra is evolving its business portfolio, leveraging core ceramic technologies to venture beyond traditional domains. The company is committed to developing solutions that address social issues and promote sustainability.
About the Role:
The ideal candidate must possess an enthusiastic and growth minded personality which will enable them to thrive in a dynamic environment. The candidate must be passionate about Cyber Security and possess strong technical knowledge in Security Domain. The Sr. Cyber Security analyst will serve as subject matter expert in various functions within the SecOps team utilizing solutions such as SIEM, EDR, VM, Firewall, Email Security, etc. The team member must be a team player who is eager to contribute to company success and meeting objectives.
Essential Duties:
Adhere to all company policies and procedures, which include IATF, ISO, ISMS, QMS, TISAX and Safety related policies.
Investigate security incidents and perform in-depth analysis to identify security threats and perform remediations.
Deploy/implement security tools to protect company assets.
Review logs to detect anomalies which may lead to security breaches.
Serve as point of contact for assigned security vendors responsible for managed services and handle escalations.
Subject matter expert on vulnerability management to identify vulnerabilities and performin remediation.
Conduct/assist with performing penetration testing to identify security weaknesses and offer solutions to address identified gaps.
Participate/lead global incident response activities.
Subject matter experts on various security functions such as endpoint security, EDR, MDR, Firewall, Email Security, Spam filtering, PAM, etc.
Leverage automation to streamline workflow to increase efficiency and productivity.
Review, create or document standard operating procedures.
Perform periodic user access reviews and governance.
Assist with internal/external audits and implement security controls based on audit findings.
Experience, Education and Certification:
5 plus years of experience in SecOps functions including but not limited to Incident response, EDR, MDR, Email security, Endpoint Security, IAM, Firewall, etc.
Bachelor's degree in computer science or related field
Industry standard information security certifications (CompTIA Security +, Network +, CASP+, CISSP, GCIA, Digital Forensic, Ethical hacking, etc.) are a plus.
In-depth knowledge of TCP/IP networking, Routing, etc.
Experienced in Security functions including Firewall, IDS/IPS, Email Security, Endpoint Security, SIEM, EDR, Vulnerability Scanning, etc.
Experience with proactive threat hunting exercise.
Experience in leading security investigation and incident response and capable of documenting/conducting RCA in support of investigations.
Familiar with NIST CSF and other security controls/guidelines for incident response
Knowledge of Malware, ransomware behaviors and techniques
Ability to coordinate, gain trust of business stakeholders and maintain third party vendor relationships.
Able to work under pressure in critical circumstances.
Why Work for Niterra?
Comprehensive Health Benefits: Medical, dental, vision, and life insurance
Financial Security: Short-term and long-term disability coverage
Retirement Savings: 401(k) plan with a generous company match of up to 6%
Time Off: Generous paid time off, including vacation, sick leave, and holidays
Work-Life Balance: Paid maternity and paternity leave
$72k-97k yearly est. Auto-Apply 60d+ ago
ICT Application Security Analyst
Stellantis Nv
Security engineer job in Auburn Hills, MI
The Application Security product manager is looking for an Application Security Analyst who will be responsible for working with application development team to analyze application code vulnerabilities and involved in running security scans which include but not limited to SAST, DAST, IAST, Mobile, and ad-hoc dynamic testing. Also, Analyst will play role in extending WAF deployment for large number of applications. The candidate will play a key role in a major cybersecurity transformation initiative of "Shift left and Secure Early" as well as implementing additional security controls in SDLC.
The role entails taking responsibility of analyzing security vulnerabilities and capability to provide mitigation solutions to fix issues by writing secure code, providing guidance to application teams, and coordinating with cross functional teams across the platform.
Key responsibilities:
* Hands-on experience working with DevSecOps pipeline using CICD automation tools like Jenkins, TeamCity, GitLab, GitHub Action, Checkmarx, GitHub Advance Security, BurpSuite, and open-source tools.
* Implement Application Cyber Security Controls/Policies and standards developed by Application Security Program.
* Lead deployment of WAF for existing and new applications
* Ability to demo security vulnerability to application teams.
* Drive application security issues to a resolution.
* Provide a clear guidance to application teams during vulnerability mitigation effort
* Conduct application security assessment using standard Stellantis application security tools
* Collect and report status on application security assessments including milestones, deliverables, timing, tasks, risk areas, and status
* Categorize and recommend assessment strategies for existing and new application development
* Coach development and supplier teams on application security
* Develop user training material and conduct training sessions
Qualifications:
* Bachelor's degree in computer science, Technology or other related field.
* Strong understanding of application architectures, development methodologies, and programming languages.
* Problem-solving skills and the ability to work both independently and as part of a team.
* Technical writing and communication skills to articulate security risks and findings to both technical and non-technical audiences
* Hands on experience reviewing application securitysecure code preferred in Java, C#, Python etc. popular programming languages.
* Background experience with application development - compiled code, mobile applications, website design, web services
* Hands on experience running SAST, DAST, IAST, SCA and Mobile scans
* Knowledge of security and compliance frameworks like NIST and ISO
* Understanding and experience in NIST SSDF or other secure software development frameworks
* Experienced and knowledgeable in deployment of WAF tools such as Akamai, Cloudflare, Azure Front Door, and AWS WAF etc.
* Knowledge of the OWASP Top 10 and mitigation strategies for each
* Knowledge on techniques of web attacks, DDoS attacks and BOT attacks and management/mitigation controls for them
* Experienced with cloud platforms (AWS, Azure, GCP) and container frameworks
* Knowledge of programming, scripting, and query languages such as Java, SQL, HTML, JavaScript
* At least 5 years of application security analysis, testing and DevSecOps experience.
* Prefer that candidates will have experience in scripting languages.
* Preferable is candidate has GIAC GWEB, ISC2 CSSLP, EC-Council CASE or other comparable professional certificates
$66k-93k yearly est. 41d ago
Information Security Specialist
The Shyft Group, Inc.
Security engineer job in Novi, MI
Information Security Specialist | The Shyft Group, Inc. | Novi, MI Regular Employee | Salary Non-Exempt What you'll do: The IT Security Specialist is responsible for designing, implementing, and maintaining the organization's cybersecurity infrastructure across information technology, operational technology, and cloud environments. This position plays a vital role in safeguarding corporate systems, networks, and information by monitoring emerging threats and vulnerabilities.
The individual in this role will work collaboratively with all departments across Aebi Schmidt Group to assess risk, coordinate vulnerability remediation, and develop defensible architectures to protect our assets. The IT Security Specialist will apply technical expertise to implement and manage security tools, automate key processes, and support incident response activities to minimize business impact and maintain continuity of operations.
This position requires strong analytical and problem-solving skills, a comprehensive understanding of cybersecurity principles and technologies, and the ability to communicate effectively with both technical and non-technical stakeholders.
Key responsibilities
* Design, implement, and manage cybersecurity solutions across endpoints, networks, cloud, and identity management systems
* Conduct vulnerability assessments and coordinate remediation efforts across IT and DevOps teams
* Monitor, triage, and manage alerts from cybersecurity related tools and services
* Leverage cybersecurity related tools and benchmarks to harden and build defensible IT systems and resources
* Participate in incident response efforts including triage, containment, eradication, and post-incident efforts
* Perform risk assessments on new technologies, vendors, and IT system changes
* Automate repetitive tasks using Python, Bash, PowerShell, Terraform, or equivalent scripting languages
What you need to be successful:
* Bachelor's degree in computer science, information systems, cybersecurity, or related field
* Relevant cybersecurity certifications such as CompTIA's Security+
* 5+ years of hands-on experience in cybersecurity or infrastructure security role
* 3 - 5 years of experience in cloud technologies such as AWS and Azure
* Strong understanding of networking and security protocols, firewalls, VPN's, SIEM, EDR/XDR, and vulnerability management
* Knowledge of IAM concepts; idP, MFA, SSO, SAML/OAuth2, and the access policies that control them
* Working knowledge of scripting or automation languages such as Python, PowerShell, or equivalent
* Industry leading certifications such as CISSP, CEH, GICSP, or GSEC
* Exposure to compliance standards such as ISO 27001, NIST, and PCI DSS
* Experience with CI/CD pipelines or DevSecOps methodologies
* Familiarity with the MITRE ATT&CK framework and threat hunting
* Implement and manage OT cybersecurity controls across plant floor networks, control systems, and IT infrastructure
* Data management and discovery tools such as Purview or other data loss prevention technologies
Why The Shyft Group?
Our people are our greatest asset, and your success is our success! That's why we provide comprehensive benefits that support your health, financial security, and work-life balance-so you can thrive both personally and professionally.
* Health & Wellness: Medical, Dental, Vision, HSA/FSA, Wellness Plan
* Financial Security: 401(k) with match, Disability, Life Insurance
* Work/Life & Growth: Educational Reimbursement, EAP, Dependent Care
At The Shyft Group, we don't just offer benefits-we invest in your well-being. Join us and experience the difference!
Who we are:
The Shyft Group is the North American leader in specialty vehicles, including last-mile delivery vans, work trucks, and motorhome chassis. Our 10 brands- Utilimaster, Blue Arc, Royal Truck Body, DuraMag, Magnum, Strobes-R-Us, Spartan RV Chassis, Red Diamond, Builtmore, and Independent Truck Upfitters- are powered by 3,000+ team members across the U.S. and Canada.
Backed by 50 years of innovation and a supportive, entrepreneurial culture, we're leading the way in electrification and proudly ranked among Fortune's 100 Fastest Growing Companies.
Equal Employment Opportunity (EEO)
The Shyft Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, sex, sexual orientation, gender identity, age, genetic information, status as a protected veteran or status as a qualified individual with a disability, or any other characteristic protected by applicable federal, state, or local law. If you have a disability and would like to request an accommodation in order to apply, please email us at *************************.
The Shyft Group is an E-Verify Employer
Shyft uses E-Verify, which is an online system operated by the U.S. Department of Homeland Security in partnership with the Social Security Administration to verify employment eligibility and validate social security numbers. Through participation in the E-Verify program, information entered on Form I-9 will be provided and compared to information available at both of these agencies. See posters for more details. E-Verify Notice U.S. Right to Work Notice.
$73k-103k yearly est. 33d ago
Network Security Engineer
Epitec 4.4
Security engineer job in Southfield, MI
Network Engineer with 3 to 5 years of experience that has strong firewall, IP Networking and VPN skills. Candidates will be part of the Engineering team completing customer implementations and providing ongoing customer support. They will need experience with Fortinet firewalls (required) and other major firewalls including Checkpoint, Juniper, Cisco (preferred), and good customer relationship skills.
Qualifications
3-5 years experience in Information Technology with specific knowledge in IT firewall, IP Networking and VPN.
Hands-on experience with Fotinet firewalls.
Knowledge and experience with network protocols and concepts including: SSH, FTP, ICMP, TCPIP (IPv4 & IPv6), Network Address Translation (NAT), SNMP, IPSec, GRE, QoS, and VLANs.
Ability to interpret output from network traffic analysis tools such as Ethereal (Wireshark)
Effective interpersonal and consulting skills to be used to align customer needs to tactical and strategic solutions
Ability to effectively collaborate in a dynamic team environment
Strong written and verbal communication skills necessary for clear client communication, definition of scope, project deliverables, appropriate system documentation and client communication
Documentation (Excel & Visio)
Must have professional demeanor and ability to prioritize and work in a fast paced environment
Additional InformationAll your information will be kept confidential according to EEO guidelines.
$80k-108k yearly est. 60d+ ago
Legal Counsel, Data Privacy Manager and Information Security Officer
Rheinmetall Aktiengesellschaft
Security engineer job in Auburn Hills, MI
WHAT WE ARE LOOKING FOR The Legal Counsel, Data Privacy Manager and Information Security Officer will be an integral part of the North American Legal, Compliance and Information Security team. The Legal Counsel, Data Privacy Manager and Information Security Officer responsibility on the one hand is to preview, negotiate and draft commercial contracts. On the other hand, data privacy and information security is a relevant part of the responsibility. The Legal Counsel, Data Privacy Manager and Information Security Officer will also provide day-to-day advice and guidance to help each business unit meets its objectives by developing a deep understanding of the laws and regulations applicable to data privacy. In addition, the Legal Counsel, Data Privacy Manager and Information Security Officer, will also be responsible for implementation and support of data protection activities (Data Privacy Management System) as part of the business, as well as Information Security activities (Information Security Management System). RESPONSIBILITIES include the following. Other duties may be assigned. •Draft, review and negotiate broad range of commercial agreements with our customers and suppliers, including but not limited to, Non-Disclosure Agreements, OEM terms and conditions, Master Services Agreements, subcontractor agreements, Full and Final Releases, licensing agreements etc. •Provide support in defending the organization in lawsuits/legal claims as well as in the prosecution of lawsuits on behalf of the organization against others. •Conduct, research and provide interpretations, opinions and recommendations on business operations issues and on legislation and regulations that may affect the organization. •Enforce adherence to legal guidelines and in-house policies to maintain the company's legality and business ethics. •Support legal entities in the United States and Mexico complying with applicable laws and following Rheinmetall's international requirements related to compliance, especially anti-corruption. •Assess local data protection requirements and activities, e.g. advice all levels of management and employees on data privacy matters and evaluate and advise as to data privacy risk. Maintain and further develop the Data Privacy Management System in close alignment with the Divisional responsible and business. •Data breach management. Attends to general inquiries from supervisory data protection authorities as a first responder. •Provide data protection-related advice and support of business departments. This includes the introduction of new or change of existing processes and/or assets (especially IT solutions). •Develop and enforce the organization's information security policies, standards, and procedures. •Conduct risk assessments to identify and mitigate information security vulnerabilities. •Oversee the implementation of security technologies, including firewalls, intrusion detection systems, and encryption tools. •Lead the response to information security incidents, including investigations and post-incident reviews. •Primary contact with the corresponding legal entity for Rheinmetall's data privacy organization. Primary data protection counterpart for the management and employees within the legal entity. •Nominated as the Data Privacy Regional Manager and Information Security Officer. •Perform other duties that may be assigned.
WHAT QUALIFICATIONS YOU SHOULD HAVE
EDUCATION and/or EXPERIENCE The candidate must be a graduate of an accredited law school with three (3) to six (6) years of related experience and be admitted to the state bar. The candidate should also possess the following: •In-depth knowledge of global data protection regulations and frameworks (e.g. GDPR, CCPA). •Strong understanding of information security principles, practices, and technologies. •Excellent analytical and problem-solving skills. •Certifications such as CIPP/E, CIPM, CISSP, CISM, or equivalent are highly desirable. •Strong communication and interpersonal skills to interact with all levels of the organization. •Ability to manage multiple projects and priorities simultaneously. •High level of integrity and strong commitment to maintaining confidentiality.
$91k-138k yearly est. 14d ago
Principal Security Engineer - IAM
Lennar 4.5
Security engineer job in Waterford, MI
We are Lennar
Lennar is one of the nation's leading homebuilders, dedicated to making an impact and creating an extraordinary experience for their Homeowners, Communities, and Associates by building quality homes and providing exceptional customer service, giving back to the communities in which we work and live in, and fostering a culture of opportunity and growth for our Associates throughout their career. Lennar has been recognized as a Fortune 500 company and consistently ranked among the top homebuilders in the United States.
Join a Company that Empowers you to Build your Future
The Principal SecurityEngineer is the highest technical position within the securityengineering team, responsible for driving the overall security strategy of the organization. This role is focused on designing cutting-edge security solutions, with a strong emphasis on cloud security, and leading the organization's response to the most complex security challenges.
A career with purpose.
A career built on making dreams come true.
A career built on building zero defect homes, cost management, and adherence to schedules.
Your Responsibilities on the Team
Define and lead the implementation of the organization's security strategy, with a focus on Cloud Security, Identity Access Management, and all other aspects of Cybersecurity
Architect and oversee the deployment of IAM solutions across both on-premise and cloud environments, ensuring they meet the highest standards of security.
Lead the most complex security assessments, including threat modeling, red teaming, and cloud security reviews.
Collaborate with executive leadership to ensure that security initiatives align with the organization's strategic goals and risk appetite.
Act as the technical lead for large-scale security projects, coordinating cross-functional teams to ensure successful delivery.
Architect and implement solutions across workforce IAM, PAM, and customer IAM ecosystems.
Provide thought leadership in adopting passwordless authentication, passkeys, adaptive MFA, and AI-driven access orchestration strategies
Engineer integrations with Agentic AI tools for intelligent decisioning, policy enforcement, and autonomous identity lifecycle operations.
Develop and implement automated provisioning/deprovisioning workflows
Ensure integration of IAM with cloud platforms (Azure, AWS, GCP) and SaaS applications.
Mentor and develop the skills of senior securityengineers, fostering a culture of continuous improvement and innovation.
Requirements
Education: Bachelor's degree in Computer Science, Cybersecurity, or a related discipline; Master's degree is highly preferred.
Professional Experience: Minimum of 10 years in securityengineering, with significant expertise in Identity and Access Management (IAM).
Project Leadership: Demonstrated success in leading large-scale IAM initiatives and formulating security strategies for complex organizations.
IAM Solutions: Design and hands-on engineering across IAM:
Identity Providers (such as Microsoft Entra ID, Okta, Ping, ForgeRock),
Identity Governance & Administration (SailPoint, Saviynt),
Privileged Access Management (CyberArk, Delinea, HashiCorp Vault), and
Customer IAM (Auth0, PingOne-preferred).
Protocols & APIs: Deep understanding of federation protocols (SAML, OAuth2.0, OIDC), SCIM, and RESTful APIs.
Directory Services & Cloud IAM: Hands-on experience with Active Directory, LDAP, and cloud IAM solutions (Azure, AWS, GCP).
Security Frameworks: Solid foundation in Zero Trust architecture and contemporary security standards.
Automation: Proficient in scripting and automation using PowerShell, Python, Java, or RESTful APIs.
Recognized industry certifications such as CISSP, CCSP, AWS Certified Security - Specialty, or equivalent credentials.
Exceptional leadership and communication abilities, capable of influencing executive decision-makers and directing cross-functional teams.
Physical & Office/Site Presence Requirements
This is primarily a sedentary office position which requires the incumbent to have the ability to operate computer equipment, speak, hear, bend, stoop, reach, lift, and move and carry up to 25 lbs. Finger dexterity is necessary.
This description outlines the basic responsibilities and requirements for the position noted. This is not a comprehensive listing of all job duties of the Associates. Duties, responsibilities and activities may change at any time with or without notice.
Life at Lennar
At Lennar, we are committed to fostering a supportive and enriching environment for our Associates, offering a comprehensive array of benefits designed to enhance their well-being and professional growth. Our Associates have access to robust health insurance plans, including Medical, Dental, and Vision coverage, ensuring their health needs are well taken care of. Our 401(k) Retirement Plan, complete with a $1 for $1 Company Match up to 5%, helps secure their financial future, while Paid Parental Leave and an Associate Assistance Plan provide essential support during life's critical moments. To further support our Associates, we provide an Education Assistance Program and up to $30,000 in Adoption Assistance, underscoring our commitment to their diverse needs and aspirations. From the moment of hire, they can enjoy up to three weeks of vacation annually, alongside generous Holiday, Sick Leave, and Personal Day policies. Additionally, we offer a New Hire Referral Bonus Program, significant Home Purchase Discounts, and unique opportunities such as the Everyone's Included Day. At Lennar, we believe in investing in our Associates, empowering them to thrive both personally and professionally. Lennar Associates will have access to these benefits as outlined by Lennar's policies and applicable plan terms. Visit Lennartotalrewards.com to view our suite of benefits.
Join the fun and follow us on social media to see what's happening at our company, and don't forget to connect with us on Lennar: Overview | LinkedIn for the latest job opportunities.
Lennar is an equal opportunity employer and complies with all applicable federal, state, and local fair employment practices laws.
$94k-122k yearly est. Auto-Apply 60d+ ago
IT Info/Security Manager
Genisys Credit Union 4.1
Security engineer job in Auburn Hills, MI
Responsible for the total information security needs and the development and delivery of a comprehensive information and cybersecurity strategy to ensure the Credit Union's assets are adequately protected. The IT Information Security Manager will oversee modifications to the intrusion detection and prevention system, firewall, SIEM, anti-virus applications and other pertinent hardware in response to technological advances in order to maintain top-level security and protect the Credit Union's information from theft or disruption. This position will also be responsible for identifying, evaluating and reporting on information security risks in a manner that meets compliance and regulatory requirements and aligns with and supports the risk posture of the Credit Union.
This position reports directly to the CIO with a dotted line reporting to the CEO.
This position is located at our Corporate Office in Auburn Hills Michigan and has a requirement of 3 days per week on site.
ESSENTIAL FUNCTIONS AND BASIC DUTIES
Supervise and direct activities of the information security staff.
Research and recommend the purchase of software and hardware used for managing security systems.
Investigate, test and install new security software applications as warranted.
Negotiate contracts and coordinate activities with Credit Union vendors with respect to hardware upgrades, system maintenance, system monitoring and replacement.
Remain abreast of information/cyber security technology and trends for improvements in the Credit Union's security infrastructure.
Develop, document and implement credit union policies related to network security.
Maintain procedures to analyze, triage, contain, and eradicate malicious activity.
Monitor user adherence of Credit Union security policies
Lead the development of processes and procedures to improve incident response times, accurate analysis of incidents.
Maintain regular contact with all departments to obtain information about possible security risks.
Proactively communicates all incidents and possible security violations to the CIO and IT Security Committee.
Maintaining a comprehensive risk management program using generally accepted security management standards.
Oversee programs for risk assessment, threat modeling, vulnerability management, and incident prevention.
Perform routine risk assessments and execute tests of data processing systems to ensure functioning of data processing security measures.
Be the IT lead on external audits/exams working with 3rd party partners and the NCUA and State of Michigan ensuring these partners get the documentation they need to complete their audits.
Maintain effective professional relations with vendors and service providers.
Ensure strict compliance with relevant standards and regulations. These include NCUA (National Credit Union Administration) regulations, GLBA (Gramm Gramm-Leach-Bliley Act), and other state/federal mandates
Maintain a detailed incident response plan and conduct yearly table top testing.
Serve as the IT lead for the Incident Response Team (IRT). Manage the lifecycle of a breach or security event, from detection to post-mortem analysis.
Lead enterprise IT risk assessments.
Ensure compliance with frameworks and requirements such as NIST.
Evaluate the security posture of third-party vendors (FinTech partners, core processors) to ensure they meet the credit union's security standards.
Perform installation, configuration, maintenance, and troubleshooting of all aspects of security on the network
Plans and implements any security upgrades or workstation and servers on the network. Schedule critical systems downtime during non-business hours and weekends for least impacting to users and members.
Setup, configure and support internal and external network security devices.
Investigate, test and install new security software applications as warranted.
Lead in the development and implementation of security best practices and users appropriate use.
Lead detailed risk analysis and risk assessment to identify, mitigate, and control risks to infrastructure, information systems, and data; advocate security and risk management to key stakeholders in order to balance security and business needs.
Setup, configure, and support the patch management software and maintain documentation.
Setup, configure, and support the vulnerability management software and maintain documentation.
Setup, configure, and support the SIEM log management and maintain documentation.
Works closely with the CIO to develop, document and implement policies related to support, security, and maintenance of all facets of the security infrastructure.
Assist with ongoing security awareness programs educating users with proper security practices.
Perform other duties, as assigned by management
QUALIFICATIONS
EDUCATION/CERTIFICATION:
Bachelor's Degree in Information Security, related degree, or equivalent relevant work experience.
Certifications preferred - CISSP or other security-focused certification.
Ability to become and remain 100% bonded.
REQUIRED KNOWLEDGE / EXPERIENCE:
Minimum of 5-7 years in information security, with at least 2 years in a leadership or management capacity. Financial services experience is strongly preferred.
Extensive experience with SIEM, IPS/IDS, Firewall, Log management and vulnerability scanning technologies.
Investigative and analytical problem-solving skills required - very familiar with Windows, Linux, networking principles, cloud-based solutions, endpoint protection, Microsoft/Google security products and services.
Experience performing network and application security penetration testing and/or vulnerability management, interpreting results, and remediating findings.
Knowledge of best practice of information security, pertaining to Windows workstations and Windows Servers.
Able to effectively manage workload in a fast-paced environment.
Experience performing incident triage and response activities.
Experience working as a team lead and training and mentoring teammates
Knowledge of VPN and functioning remotely to perform all aspects for networks and systems.
Scripting knowledge and report writing.
Experience supporting end users
Will quickly acquire thorough knowledge of Genisys Credit Union IT policies and procedures; including policies related to the Bank Secrecy Act (BSA), including Anti-Money Laundering.
Experience working with BSA Manager to complete suspicious activity reports when required for items like website disruption or malicious activity that disrupts the network.
EOE M/V/Disability/Veteran.
$99k-117k yearly est. Auto-Apply 5d ago
Information System Security Officer
General Dynamics Land Systems Inc.
Security engineer job in Sterling Heights, MI
Do you want to learn and grow in a great company? Do you want to join a team that protects the most critical networks of the best defense contractor in the country? GDLS is looking to hire a mid career-level Information Systems Security Officer, the perfect place to challenge your Information Technology skills.
Company Information:
General Dynamics is a successful Fortune 100, global aerospace and defense company, with over 90,000 employees world-wide. General Dynamics Land Systems, a business unit of General Dynamics, has a strong foundation of delivering core engineering and manufacturing capabilities to our clients for military vehicles. Our team is focused on continuous process and productivity improvements that reduce product costs, while increasing troop safety and effectiveness. Land Systems continues to work with the US Armed Forces and its Allies to ensure these vehicles remain survivable, relevant, flexible, affordable and capable of addressing a dynamic threat environment.
What We Offer:
Starting your career or you are an experience professional, we offer a Total Rewards package that is Impactful and built for you.
* Healthcare including medical, dental, vision, HSA and Flex Spending
* Competitive base pay and incentive pay that rewards individual and team performance, and comprehensive benefits.
* 401k Match (6%)
* Educational Assistance
* 9-80 Work Schedule (This position's standard work schedule is a 9/80. The 9/80 schedule allows employees who work a nine-hour day Monday through Thursday to take every other Friday off)
* Onsite cafeteria, fitness center, and outdoor fitness track
Responsibilities to Anticipate/Expect:
* Interprets and applies NISPOM and DAAG requirements on classified systems and networks.
* Writes and maintains System Security Plans (SSPs), Plan of Action and Milestones (POAMs) and other security and accreditation related documentation.
* Administrates eMASS Systems of Record to establish, maintain, modify, and decommission IAW Risk Management Framework lifecycles.
* Conducts periodic self-inspections and continuous monitoring of classified systems and networks.
* Assesses and processes system account requests in accordance with company and regulatory requirements.
* Ensures configuration management (CM) for security-relevant software, hardware and firmware is maintained and documented.
* Ensures systems are operated, maintained and disposed of in accordance with DoD/NISPOM requirements as outlined in the relevant SSP.
* Utilizes tools such as Splunk, ACAS, Teramind, and others to validate system performance and user activity.
* Collaborates with the ISSM to develop and recommend system-based solutions for program needs.
* Assists in Incident Response to detect, analyze, and respond to security events and incidents, to include containment, eradication, and recovery IAW company and USG requirements.
* Researches, identifies, and recommends IT equipment meeting NISPOM and/or SCIF requirements to ISSM and IT Management for lab procurement.
* Documents, tracks, and enforces user training and form requirements for access to classified system accounts.
* Participates in security inspections and assessments such as SVA, A&A, and CORA.
Minimum Requirements:
* MUST POSSESS and be able to maintain a U.S. Government SECRET or higher clearance.
* MUST be a United States citizen
* 7 year minimum of experience in a government/industrial security career field, including:
* 3 year minimum of experience in Risk Management, INFOSEC, or IA role.
* 1-3 year minimum of experience in a IT or system administration role.
* Bachelor of Science degree majoring in Computer Science, Information Science and Technology, Information Assurance, Risk Management, or Cybersecurity required. Equivalent alternates considered.
* Must have one of the following certifications (RMF or more advanced certificates considered):
* Security+ CE
* CISA
* CAP
* CASP+
* Must have very good written and verbal communication skills.
* Must be detail-oriented, independent and organized.
* Must have experience with Microsoft Office products: Word, Excel, and PowerPoint.
* Must have experience with ACAS, SIEM, SCAP Compliance Checker, and STIG Viewer.
* Preferred experience with certification/authorization requirements as outlined in the NISPOM, RMF for DoD IT/DIACAP, ICD 503/DCID, DJSIG/JDCSISSS, JSIG/JAFAN & NIST RMF
GDLS considers factors such as, scope/responsibilities of the position, candidate experience and education/training background, in addition to local market comparable and business considerations when extending an offer.
Headquartered in Reston, Virginia, General Dynamics is a global aerospace and defense company offering a broad portfolio of products and services in business aviation; ship construction and repair; land combat vehicles, weapons systems and munitions; and technology products and services. General Dynamics employs more than 100,000 people across 65 countries worldwide and in all 50 U.S. states, more information is available at *********** General Dynamics Land Systems, is a business unit of General Dynamics, and is an innovative leader of ground combat systems' equipment and software for our clients. Our performance-driven team partners with the U.S. Army, U.S. Marine Corp and other militaries across the Globe to ensure that next generation ground combat vehicles are ready to protect our fighting men and women in uniform. General Dynamics Lands Systems provides a competitive compensation package, site specific flexible work schedules, 401(k) with Company Match; Bonus Eligibility, Employee Development Opportunities, Tuition Reimbursement, On-site Amenities, and comprehensive Medical/Dental/Vision Insurance.
As an Equal Opportunity Employer, General Dynamics Land Systems ("GDLS") provides all persons with equal opportunity and access to all aspects of employment process, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, marital status, age, disability, status as a protected veteran, or membership in any group protected by federal, state, or local anti-discrimination laws. GDLS also is committed to providing reasonable accommodations to individuals with disabilities and disabled veterans.. If, due to a disability, you need an accommodation to search or apply for an opportunity with GDLS, please call ************ or send an e-mail to ***************** for assistance and let us know the nature of your request and your contact information.
Share: mail Tweetshare to twitter Share on Facebookshare to facebook Share on LinkedInshare to linkedin
Apply Now
Similar Jobs
Interested in working for Land Systems? Join our Talent Network Today!
Join our Talent Network
* Search Jobs
* Saved Jobs
* Careers Home
facebook twitter linkedin youtube instagram
2026 General Dynamics US. All rights reserved.
$62k-84k yearly est. 13d ago
Data Privacy Manager & Information Security Officer
Rheinmetall Aktiengesellschaft
Security engineer job in Auburn Hills, MI
WHAT WE ARE LOOKING FOR We are seeking an experienced and dedicated Data Privacy Manager and Information Security Officer to join our organization. This dual-role position ensures the confidentiality, integrity, and availability of data, while ensuring compliance with relevant privacy laws, regulations, and best practices.
The ideal candidate will lead efforts to safeguard sensitive data and implement robust information security measures.
Including, but not limited to:
* Assessing local data protection requirements and activities.
Implementing and maintaining the Group-wide data protection management system in his area of responsibility (if applicable, by means of local implementation guidelines).
* Taking on country-wide data protection issues/tasks, supported by the responsible Data Privacy Officer.
* Coordination of data privacy projects.
* Interface to the responsible Data Privacy Officer.
* Data breach management.
* Processing of and/or support with data protection related inquiries.
* If necessary, support during inspections by the relevant authorities.
* Coordination of the Data Privacy Manager in his region
* Identifies the need of further contact partners as potential Data Privacy Manager in the region.
* Attends to general inquiries from supervisory data protection authorities as first responder. At a minimum, the Regional Data Privacy Manager shall act as second responder when, for example, inquiries come directly to management.
* Primary Contact within the legal entity for Rheinmetall's data privacy organization.
* Primary data protection counterpart for the management and employees within the legal entity.
* Regular exchange with the relevant Data Privacy Officer.
* Responsible for data protection related advice and support of business departments.
* Data protection related support of business departments with the introduction of new or change of existing processes and/or assets (especially IT-solutions).
* Develop and enforce the organization's information security policies, standards, and procedures.
* Conduct risk assessments to identify and mitigate information security vulnerabilities.
* Oversee the implementation of security technologies, including firewalls, intrusion detection systems, and encryption tools.
* Lead the response to information security incidents, including investigations and post-incident reviews.
WHAT QUALIFICATIONS YOU SHOULD HAVE
* Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Law, or a related field.
* At least 5 years of experience in data privacy, information security, or a related field.
* In-depth knowledge of global data protection regulations and frameworks (e.g., GDPR, CCPA).
* Strong understanding of information security principles, practices, and technologies.
* Certifications such as CIPP/E, CIPM, CISSP, CISM, or equivalent are highly desirable.
* Excellent analytical and problem-solving skills.
* Strong communication and interpersonal skills to interact with all levels of the organization.
* Ability to manage multiple projects and priorities simultaneously.
* High level of integrity and a strong commitment to maintaining confidentiality.
$91k-138k yearly est. 12d ago
Information Systems Security Officer (ISSO)
Insight Global
Security engineer job in Sterling Heights, MI
Insight Global is seeking a highly skilled Information Systems Security Officer (ISSO) to support a Department of Defense (DoD) customer in Warren, MI. This role is ideal for a cybersecurity professional with a strong background in risk management and system security who thrives in a collaborative, mission-driven environment.
As an ISSO, you will report directly to the Information Systems Security Manager (ISSM) and the Information System Owner (ISO), operating with minimal supervision. You'll play a critical role in maintaining and enhancing the security posture of DoD information systems, ensuring compliance with federal standards and frameworks.
$30/hr to $60/hr : Exact compensation may vary based on several factors, including skills, experience, and education.
Benefit packages while on contract for this role will start on the 31st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to ********************.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: ****************************************************
Skills and Requirements
- 3+ years of experience as a ISSO
- Strong understanding of RMF, NIST standards, and DoD security protocols
- Bachelors Degree in Cybersecurity, Engineering, or related field
- Ability to obtain a DoD Secret Clearance - Active interim or secret clearance
How much does a security engineer earn in Beecher, MI?
The average security engineer in Beecher, MI earns between $65,000 and $119,000 annually. This compares to the national average security engineer range of $77,000 to $141,000.