Senior Security Analyst
Security engineer job in Cleveland, OH
Our client is looking for a detail-oriented and proactive Senior Security Analyst to support ongoing security initiatives, maintain compliance, and ensure that security policies and standards are followed within a fast-paced, evolving environment. This position is part of the Information Security team and collaborates across business functions to ensure regulatory requirements and organizational compliance standards are met.
Key Responsibilities
Ensure compliance with applicable regulations and standards, including SOX, SOC 2, CCPA, HIPAA, and other industry-specific frameworks.
Assist with third-party risk management (TPRM), assessing, monitoring, and managing vendor risks.
Perform risk assessments, audits, and compliance reviews to identify potential risks and implement mitigation strategies.
Map controls across compliance frameworks, translate them into actionable steps, and provide guidance to stakeholders.
Deliver and enhance security awareness campaigns to maintain understanding of best practices and compliance requirements across the organization.
Update and maintain the risk register, ensuring it reflects the current risk landscape and supports decision-making.
Support ongoing maintenance and improvement of GRC solutions, including control testing.
Collaborate with cross-functional teams to embed risk management practices into operational processes.
Participate in process reviews, identifying opportunities to improve operational efficiency and compliance effectiveness.
Stay informed on regulatory changes, industry trends, and best practices to continuously improve security and compliance programs.
Perform other duties as required to support the Senior Security Analyst role.
Preferred Qualifications
Minimum of 5 years of GRC experience within a public company.
In-depth knowledge of regulatory requirements such as SOX, CCPA, HIPAA, and other relevant frameworks.
Hands-on experience with GRC solutions and third-party risk management programs.
Strong understanding of IT governance, information security, and data privacy principles.
Excellent communication, management, and interpersonal skills, with the ability to influence stakeholders at all levels.
Ability to develop and implement security policies, procedures, and controls.
Relevant certifications (e.g., CISA, CISM, CISSP, CRISC) are a plus.
Additional experience with Identity and Access Management (IAM), Data Classification, and Data Loss Prevention (DLP) is highly desirable.
Minimum Qualifications
College degree or equivalent.
6+ years of related experience.
Expert technical knowledge and understanding of industry regulations.
Ability to lead and coordinate team activities.
Ability to formulate, document, and recommend new policies and procedures.
Proven ability to work effectively in a team and lead initiatives.
Cyber Defense Forensics Analyst
Security engineer job in Cleveland, OH
At EY, you'll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we're counting on your unique voice and perspective to help EY become even better. Join us and build an exceptional experience for yourself, and a better working world for all.
The exceptional EY experience. It's yours to build.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
Today's world is fuelled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team helps protect the EY brand and build client trust.
Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.
**The opportunity**
Cyber Triage and Forensics (CTF) Incident Analyst will work as a senior member of the technical team responsible for security incident response for EY. The candidate will work as an escalation point for suspect or confirmed security incidents. Responsibilities include performing digital forensic analysis, following security incident response standard methodologies, malware analysis, identify indicators of compromise, support remediation or coordinate remediation efforts of a security incident, and develop documentation to support the security incident response process.
**Your key responsibilities**
+ Investigate, coordinate, bring to resolution, and report on security incidents as they are brought up or identified
+ Forensically analyze end user systems and servers found to have possible indicators of compromise
+ Analysis of artifacts collected during a security incident/forensic analysis
+ Identify security incidents through 'Hunting' operations within a SIEM and other relevant tools
+ Interface and connect with server owners, system custodians, and IT contacts to pursue security incident response activities, including: obtaining access to systems, digital artifact collection, and containment and/or remediation actions
+ Provide consultation and assessment on perceived security threats
+ Maintain, manage, improve and update security incident process and protocol documentation
+ Regularly provide reporting and metrics on case work
+ Resolution of security incidents by identifying root cause and solutions
+ Analyze findings in investigative matters, and develop fact based reports
+ Be on-call to deliver global incident response
**Skills and attributes for success**
+ Resolution of security incidents by identifying root cause and solutions
+ Analyze findings in investigative matters, and develop fact-based reports
+ Proven integrity and judgment within a professional environment
+ Ability to appropriately balance work/personal priorities
**To qualify for the role you must have**
+ Bachelors or Masters Degree in Computer Science, Information Systems, Engineering or a related field
+ 5+ years experience in incident response, computer forensics analysis and/or malware reverse engineering;
+ Understanding of security threats, vulnerabilities, and incident response;
+ Understanding of electronic investigation, forensic tools, and methodologies, including: log correlation and analysis, forensically handling electronic data, knowledge of the computer security investigative processes, malware identification and analysis;
+ Be familiar with legalities surrounding electronic discovery and analysis;
+ Experience with SIEM technologies (i.e. Splunk);
+ Deep understanding of both Windows and Unix/Linux based operating systems;
**Ideally, you'll also have**
+ Hold or be willing to pursue related professional certifications such as GCFE, GCFA or GCIH
+ Background in security incident response in Cloud-based environments, such as Azure
+ Programming skills in PowerShell, Python and/or C/C++ Understanding of the best security practices for network architecture and server configuration
**What we look for**
+ Demonstrated integrity in a professional environment
+ Ability to work independently
+ Have a global mind-set for working with different cultures and backgrounds
+ Knowledgeable in business industry standard security incident response process, procedures, and life cycle
+ Excellent teaming skills
+ Excellent social, communication, and writing skills
**What we offer you**
The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary range/s. At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more .
We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $87,700 to $164,000. The salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $105,200 to $186,400. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options. Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year. Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances. You'll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
**Are you ready to shape your future with confidence? Apply today.**
EY accepts applications for this position on an on-going basis.
For those living in California, please click here for additional information.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
**EY | Building a better working world**
EY is building a better working world by creating new value for clients, people, society, and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy, and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY's Talent Shared Services Team (TSS) or email the TSS at ************************** .
Security Engineer, Assurance
Security engineer job in Cleveland, OH
The Security Assurance Engineer will be part of an elite team of Cyber Security specialists whose mission is to proactively test enterprise information security controls for effectiveness and to coordinate manual or automated remediation of weaknesses and gaps in the detection, prevention and response to cyber attacks.
This member of the Security Assurance team is responsible for identifying and cataloging all security controls within the global AmTrust environment, working with key stakeholders to determine what defines "effectiveness" for each control, and then designing and implementing automated testing of those controls.
Responsibilities
* Vet, select and/or design and implement an automated security control testing platform
* Work with key stakeholders to define seurity control requirements
* Design and implement security control tests
* Design and implement a security control defect management system
* Work closely with the Security Operations Center to improve their response and alerting services
* Work closely with the Security Engineering team to improve controls based on emerging threats, control testing results
* Work with other Security Assurance team members to automate security control testing
Qualifications
* Bachelor's Degree in IT, CyberSecurity or Equivalent Experience
* 10+ Years Cyber Security Experience
* 5+ Years Programming or Non-Trivial Scripting Experience
Preferred:
* Data Forensics Experience
* Software Quality Assurance Experience
* CISSP Certification
Technical Skills:
* Extensive experience with one or more IT Automation frameworks (Ansible, Terraform, etc)
* Extensive experience with one or more Security Information and Event Management Systems (Splunk ES, IBM QRadar, etc)
* Deep familiarity with one or more offensive security platforms (Metasploit, for example)
* Software Development and Scripting Experience
* Familiarity with the MITRE ATT&CK and DEFEND Frameworks
* An extensive understanding of modern security controls
The expected salary range for this role is $97,500-$150,000/year.
Please note that the salary information shown above is a general guideline only. Salaries are based upon a wide range of factors considered in making the compensation decision, including, but not limited to, candidate skills, experience, education and training, the scope and responsibilities of the role, as well as market and business considerations.
#LI-HYBRID
#LI-JJ1
What We Offer
AmTrust Financial Services offers a competitive compensation package and excellent career advancement opportunities. Our benefits include: Medical & Dental Plans, Life Insurance, including eligible spouses & children, Health Care Flexible Spending, Dependent Care, 401k Savings Plans, Paid Time Off.
AmTrust strives to create a diverse and inclusive culture where thoughts and ideas of all employees are appreciated and respected. This concept encompasses but is not limited to human differences with regard to race, ethnicity, gender, sexual orientation, culture, religion or disabilities.
AmTrust values excellence and recognizes that by embracing the diverse backgrounds, skills, and perspectives of its workforce, it will sustain a competitive advantage and remain an employer of choice. Diversity is a business imperative, enabling us to attract, retain and develop the best talent available. We see diversity as more than just policies and practices. It is an integral part of who we are as a company, how we operate and how we see our future.
Auto-ApplyCyber Palo Alto Networks Security Operations Senior Consultant
Security engineer job in Cleveland, OH
Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.
Recruiting for this role ends on 12/31/25
The team
Our Cyber Defense & Resilience offering assists clients in defending against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence. Helps manage and protect dynamic attack surfaces and provides rapid crisis and cyber incident response, ensuring clients can be ready for, respond to, and recover from business disruptions.
Work You'll Do
+ Lead the design and deployment of Next-Generation SOC platforms, like Cortex XSIAM, including advanced detection rules and SOAR playbooks, and SIEM ingestion.
+ Integrate diverse log and telemetry sources, ensuring data quality and normalization.
+ Develop and optimize automated response workflows for incident containment and remediation.
+ Advise clients on advanced use cases, threat detection, and automation strategies.
+ Collaborate with cross-functional teams for solution enhancements and threat intelligence integration.
+ Present technical findings and recommendations to stakeholders.
Required Qualifications
+ BA/BS degree in a technical field (e.g., Computer Science, Cyber Security)
+ 4-6 years of progressively responsible experience in cloud, network, or identity security domains, demonstrating increasing levels of responsibility, technical depth, and leadership over time
+ 3-4 years of experience with Security Operations tools and platforms including Cortex XSIAM, Cortex XDR, Splunk, or similar SIEM technologies
+ 3-4 years of Security Operations Center experience demonstrating expertise in detection engineering, automation and playbook development, or SOC maturity methodologies
+ 3-4 years of experience with one or more cloud service providers (AWS, GCP, Azure) and native security tools
+ 3-4 years of experience with management of log sources, data normalization, ingestion and manipulation of data
+ 3-4 years of experience working with detection and response platforms (EDR) like Microsoft Defender, Cortex XDR, CrowdStrike
+ 3-4 years of experience with governance, risk, or compliance initiatives involving common frameworks
+ Certifications including Palo Alto Networks' PCNSE or Certified Cybersecurity Associate or equivalent and/or similar cybersecurity certifications
+ Ability to travel up to 50%, on average, based on the work you perform and the clients and industries/sectors you serve.
+ Limited immigration sponsorship may be available
Preferred Qualifications
+ Experience with Palo Alto Networks' platform of solutions including, but not limited to, next-generation firewalls, Cortex & Prisma Cloud, and Prisma Access, XDR, etc.
+ Strong understanding of vendor competitive analysis within Security Operations (e.g., competitive differences between competing SIEM solutions)
+ Proficiency with advanced scripting, playbook development within a SIEM, SOAR or Security platform
+ Basic proficiency with network routing protocols (e.g., BGP, ECMP) and network architecture concepts (e.g., network segmentation), in support of on-premise and secure cloud infrastructure use cases
+ Ability to communicate and advise on solution design based on client use-cases, requirements, or other success criteria
+ Previous consulting or "Big 4" experience
+ Relevant advanced cybersecurity or related network engineering certifications (e.g., CISSP, CEH, CCSP)
Information for applicants with a need for accommodation: ************************************************************************************************************
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $102,500 - $188,900.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.
Cyber and Information Security Analyst - Cyber Security & TSOC
Security engineer job in Akron, OH
About the Opportunity
We are a forward-thinking electric utility powered by a diverse team of employees committed to making customers' lives brighter, the environment better and our communities stronger.
FirstEnergy (NYSE: FE) is dedicated to integrity, safety, reliability and operational excellence. Headquartered in Akron, Ohio, FirstEnergy includes one of the nation's largest investor-owned electric systems, more than 24,000 miles of transmission lines that connect the Midwest and Mid-Atlantic regions, and a regulated generating fleet with a total capacity of more than 3,500 megawatts.
Location: Position may be filled at Akron, OH or Wadsworth, OH. Position is currently remote but may work at or visit a facility based on business need.
This position is within FirstEnergy Service Company, a subsidiary of FirstEnergy Corp.
This position's base reporting location is in Wadsworth Township, Ohio with significant flexible work location opportunities. This position is part of FirstEnergy's Cyber Security Governance department reporting to the Manager of Cyber Security Policy.
The Cyber and Information Security Analyst works across all FirstEnergy subsidiaries and business units to protect the cyber assets of FirstEnergy. We seek a knowledgeable individual well-versed in current cyber security and information security strategies with skills to effectively apply such strategies to a large, dynamic, heterogeneous landscape.
Location: Position may be filled at Akron, OH or Wadsworth, OH. Position is currently remote but may work at or visit a facility based on business need.
This position is within FirstEnergy Service Company, a subsidiary of FirstEnergy Corp.
This position's base reporting location is in Wadsworth Township, Ohio with significant flexible work location opportunities. This position is part of FirstEnergy's Cyber Security Governance department reporting to the Manager of Cyber Security Policy.
The Cyber and Information Security Analyst works across all FirstEnergy subsidiaries and business units to protect the cyber assets of FirstEnergy. We seek a knowledgeable individual well-versed in current cyber security and information security strategies with skills to effectively apply such strategies to a large, dynamic, heterogeneous landscape.
Responsibilities include
Act as a subject matter expert (SME) between cybersecurity and the business units in the development of appropriate policies, standards, and frameworks
Continuously monitor trends to anticipate and plan for future impact of cyber risk on a specific business unit (BU) or function
Follow all risk remediation protocols to ensure issues are mitigated, risks are accounted for, and exceptions are tracked in accordance with frameworks, policies and standards set by the organization
Educate stakeholders on cybersecurity-related matters to increase awareness and improve culture
Performs focused information risk assessments of existing or new services and technologies, along with business counterparts
Identifies and facilitates implementation of appropriate controls to effectively manage cyber and information risks as needed
Understand software and system vulnerability processes, manage vulnerability patches through a process lifecycle, and perform vulnerability assessments on systems and services
Qualifications
Bachelor's Degree in Computer Science, Information Security, or similar discipline is preferred
A minimum of 10 years professional-level experience and subject matter expert knowledge in at least one major cyber security discipline required
Ability to identify and assess the severity and potential impact of risks. Communicate risk assessment findings to risk owners outside the cybersecurity program in a way that consistently drives objective, fact-based decisions about risk that optimize the trade-off between risk mitigation and business performance
Familiarity with common cyber security related tools such as vulnerability scanners (Tenable preferred), ServiceNow IRM and GRC, Microsoft Power Automate, Microsoft Power BI, and other similar toolchains
Strong decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate one
An ability to work on several tasks simultaneously and pay attention to sources of information from inside and outside one's network within an organization
An ability to effectively influence others by informing their opinions, plans or behaviors
Ability to communicate complex and technical issues to diverse audiences, orally and in writing, in an easily understood, authoritative and actionable manner
Infrequent business travel to Akron, OH may be required
Able to participate in an on-call rotation (cycling daily; on-call once every ~6-8 days) responding to out-of-hours calls and alerts in support of security response
Benefits, Compensation & Workforce Diversity
At FirstEnergy, employees are key to our success. We depend on their talents to meet the challenges of our changing business environment. We are committed to rewarding individual and team efforts through our total rewards philosophy which includes competitive pay plus incentive compensation, a company-sponsored pension plan, 401(k) savings plan with matching employer contribution, a choice of medical, prescription drug, dental, vision, and life insurance programs, as well as skills development training with tuition reimbursement. Please visit our website at *********************** to learn more about all of our employee rewards programs. FirstEnergy proudly supports workforce diversity. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, sex, sexual orientation, gender identity, age, status as a protected veteran, or status as a qualified individual with a disability. No recruiters or agencies without a previously signed contract. Unable to sponsor or transfer H-1B visas at this time.
Safety
Safety is a core value for FirstEnergy and is essential to all of our business activities. We ensure employees have the tools, information, and processes to perform their duties in a manner that assures safety for themselves, their co-workers, our customers and the public. Our goals are to provide a safe work environment, to maintain an accident-free, injury-free workplace, and to promote and maintain public safety. To meet these goals, we dedicate ourselves to achieving world-class safety standards.
Position Classification
Exempt
Auto-ApplySenior Security Engineer
Security engineer job in Strongsville, OH
Job Description
What is great about working for Foundation?
Plenty! We have a fun, casual, yet hard-working culture that invests in our employees, promotes creativity, and delivers on our reputation. Would you like to work for a company that offers manicures and pedicures in the office? We do! How about massages, house cleaning, laundry service, monthly car washes, catered lunches Wednesdays and a monthly happy hour - we offer all this and more!
At Foundation we believe in and promote a work-life balance with a top-notch workout facility, fitness classes and free personal training; and for those competitive types, a game room complete with table tennis, foosball, and video game systems. Also, some comforts of home, there is a full kitchen, free coffee and specialty flavors, soft drinks, and snacks.
Join Foundation Software as a Senior Security Engineer and be at the forefront of safeguarding our innovative IT solutions. Located in Strongsville, Ohio, this onsite offers the opportunity to collaborate directly with a dynamic team that prioritizes a customer-centric approach and high performance. Embrace our culture of problem-solving and innovation, where your expertise can make a real impact on our security landscape.
Collaborate in a flexible, energetic environment that values not just excellence, but also empathy and integrity in every project. If you're looking for a position that challenges your skills while fostering professional growth, this is the right place for you. You will have benefits such as Medical, Dental, Vision, 401(k), Life Insurance, Health Savings Account, Competitive Salary, Paid Time Off, and Employee Discounts. Take the next step in your career and contribute to a team that's dedicated to creating a safer future in technology.
Your role as a Senior Security Engineer
As a Senior Security Engineer at Foundation Software, your day-to-day responsibilities will include assessing and mitigating security risks across our IT infrastructure. You'll conduct regular security audits and vulnerability assessments to identify potential threats and implement effective countermeasures. Collaborate with cross-functional teams to design and enforce security policies and procedures that align with industry's best practices. Troubleshoot security incidents and respond promptly to breaches, document findings and resolutions. Stay updated on emerging security technologies and trends, continuously seeking ways to enhance our security posture.
Additionally, you will mentor junior team members, sharing your knowledge and fostering a culture of security awareness throughout the organization. Your role will be pivotal in ensuring a secure environment for our customers and maintaining the integrity of our systems.
Senior Cybersecurity Engineer - Summary
Key Responsibilities:
Security Implementation & Monitoring: Design, implement, and oversee security measures to protect systems, networks, and information assets.
Architecture & Design: Define system security requirements and develop security architecture and detailed designs.
Operations & Incident Response: Configure, troubleshoot, and monitor security infrastructure; respond rapidly to security incidents and vulnerabilities.
Process & Documentation: Create and maintain standard operating procedures, incident reports, and technical documentation.
Innovation & Automation: Develop tools and automation to reduce security risks and improve efficiency.
Continuous Learning & Mentorship: Stay updated on threat landscapes and mentor junior staff on best practices.
Risk Management - provide technical leadership for GRC activities.
Requirements:
Technical Skills:
Solid foundation in security systems (firewalls, IDS/IPS, antivirus, authentication, etc.)
In-depth understanding of OS, database, network, and web application security.
Familiarity with modern monitoring and logging solutions.
Experience with cloud platforms (Azure, AWS, GCP).
Hands-on with Windows Server environments.
Technical documentation and reporting proficiency.
Experience implementing contemporary risk/compliance frameworks (NIST, CSF, ISO 27001, COBIT, or CIS)
Professional Attributes:
Collaborative, supportive, and innovative-driven mindset.
Strong ownership, accountability, and multi-tasking skills.
Business-aware decision-making.
Ability to communicate technical content clearly to non-technical stakeholders.
Self-motivated, proactive, and organized.
Willingness to continuously learn and adapt.
Educational & Experience:
Degree in Computer Science or related field (or equivalent experience).
Proven hands-on experience in building, deploying, and managing security systems.
Broad exposure to cybersecurity principles, protocols, and tools.
Demonstrated history of continuous learning preferred (conference presentations, industry certifications)
Why Foundation Software?
Foundation Software, a rapidly growing national provider of construction software and services. Foundation is constantly recognized as one of Northeast Ohio's top workplaces. We are a 20-time winner of the NorthCoast 99 award, a multi-year winner of The Plain Dealer's Top Workplaces award, and have been recognized multiple years on the Inc. 5000 list of fastest-growing private companies in the U.S.
Let's start your future at Foundation! Foundation Software is an Equal Opportunity Employer.
Join Our Growing Team at Secure Lending Inc. as an AI Automation & Systems Integration Engineer!
Security engineer job in Cleveland, OH
Job DescriptionSalary: 52
At Secure Lending Inc., were on a mission to transform the mortgage lending and loan industry with cutting-edge technology that makes financial services smarter, faster, and more efficient. Were looking for a creative, passionate, and tech-savvy engineer to join our team and lead the charge in automating our workflows, connecting our systems, and unleashing the power of AI to improve the experience for both our customers and our team.
If youre someone whos always looking for ways to solve complex problems with innovative tech solutions this is your chance to make a real impact. Youll be at the forefront of reshaping the future of finance through automation, AI, and seamless system integrations.
What Youll Be Doing
Revolutionize workflows: Analyze, design, and implement AI-powered automation that reduces manual effort and speeds up loan processing.
Build smarter systems: Integrate and connect our key platforms (CRM, LOS, underwriting tools, e-signature services, and more) to ensure our teams work seamlessly and efficiently.
Automate with AI: Leverage the latest AI tools (from OpenAI to custom-built automation scripts) to eliminate bottlenecks, enhance productivity, and give us a competitive edge.
Create the future of finance: Work closely with business and tech teams to understand challenges and design AI-driven solutions that meet the unique needs of the mortgage lending space.
Own the process: From design to deployment, youll take full ownership of your solutions while ensuring theyre scalable, compliant, and secure in line with industry standards.
What Were Looking For
Experience & Passion: Youve worked in automation, API integrations, or AI-driven solutions for 35 years (or more!). Youre eager to learn and innovate, especially in the mortgage and lending space.
Tech-Savvy Problem Solver: Youve got solid coding skills (Python, JavaScript, etc.), and youve worked with tools like Zapier, Make, Power Automate, or custom automation frameworks.
Systems Integration Guru: Youve helped connect systems (CRM, LOS, compliance software, and financial tools) and you know how to make these platforms work together without missing a beat.
Financial Acumen: You have a basic understanding of mortgage lending, personal loans, and the financial services industry or youre excited to dive into this space and make an impact.
Collaboration Champion: Youre a natural communicator who enjoys working cross-functionally, and you know how to translate complex tech into simple solutions for the business.
Why Youll Love Working at Secure Lending Inc.
Tech-Forward Culture: Join a team where innovation is in our DNA. Youll have the opportunity to shape the future of finance using the latest AI tools and cutting-edge automation.
Make an Impact: The work you do wont just be another project it will drive real-world efficiency and growth for our clients and internal teams alike.
Career Growth: Whether youre looking to expand your technical skills, dive deeper into the mortgage/finance space, or grow into a leadership role we have a clear path to help you reach your career goals.
Collaborative Environment: We value teamwork, creativity, and a growth mindset. We know that the best solutions come from diverse perspectives working together.
Competitive Compensation: We offer a competitive salary, bonus potential, and a full suite of benefits including, PTO, and a tech stipend to help you grow professionally.
Compensation & Perks
Base Salary: $90,000 $110,000 (based on experience)
Paid Time Off (PTO): Generous PTO, paid holidays, and sick leave
Professional Development: Annual budget for courses, certifications, and conferences
At Secure Lending Inc., were building the future of finance and we need your expertise to make that happen! If youre excited to dive into the world of AI-driven automation and transform the way mortgage lending works, we want to hear from you.
Take the next step in your career and help us build a smarter, faster, and more efficient future in financial services.
Sr. Security Engineer
Security engineer job in Strongsville, OH
Senior Security Engineer
The Senior Security Engineer is responsible for assessing and mitigating security risks across IT infrastructure. This role conducts regular security audits, vulnerability assessments, and implements effective countermeasures to protect systems, networks, and data. The engineer collaborates with cross-functional teams to design and enforce security policies, responds to incidents, and stays ahead of emerging threats while mentoring junior team members and fostering a culture of security awareness.
Key Responsibilities
Security Implementation & Monitoring: Design, implement, and oversee security measures to protect systems, networks, and information assets.
Architecture & Design: Define system security requirements and develop security architecture and detailed designs.
Operations & Incident Response: Configure, troubleshoot, and monitor security infrastructure; respond rapidly to security incidents and vulnerabilities.
Process & Documentation: Create and maintain standard operating procedures, incident reports, and technical documentation.
Innovation & Automation: Develop tools and automation to reduce security risks and improve efficiency.
Continuous Learning & Mentorship: Stay updated on threat landscapes and mentor junior staff on best practices.
Risk Management: Provide technical leadership for governance, risk, and compliance activities.
Requirements
Technical Skills
Strong foundation in security systems (firewalls, IDS/IPS, antivirus, authentication, etc.).
In-depth knowledge of OS, database, network, and web application security.
Familiarity with modern monitoring and logging solutions.
Experience with cloud platforms (Azure, AWS, GCP).
Hands-on experience with Windows Server environments.
Proficiency in technical documentation and reporting.
Experience implementing contemporary risk/compliance frameworks (e.g., NIST CSF, ISO 27001, COBIT, CIS).
Professional Attributes
Collaborative, supportive, and innovation-driven mindset.
Strong ownership, accountability, and multitasking skills.
Business-aware decision-making.
Ability to clearly communicate technical content to non-technical stakeholders.
Self-motivated, proactive, and organized.
Commitment to continuous learning and adapting to evolving threats.
Education & Experience
Degree in Computer Science or related field, or equivalent experience.
Proven hands-on experience building, deploying, and managing security systems.
Broad exposure to cybersecurity principles, protocols, and tools.
Demonstrated history of continuous learning (e.g., certifications, industry engagement) preferred.
Working Place: Strongsville, Ohio, United States Company : 2025 Nov. 6th Virtual Fair - Foundation Software
Senior Security Engineer - SSO / Web Security
Security engineer job in Strongsville, OH
Pittsburgh Pennsylvania
Strongsville, OH
Exp 5-7 yrs
Deg Bachelors
Occasional Travel
Job Description
As an Infrastructure Engineer Senior and a member of our Information Technology, you will be part of a diversified financial services firm that reflects the needs, values and goals of our customers, employees, communities and shareholders. You will be institutional in helping to maintain our reputation for technology excellence in both business applications and new innovations.
As an Infrastructure Engineer you will provide accurate and cost efficient security maintenance and support services to internal & external clients. Responsibilities include ongoing management and support of security infrastructure in a large environment. Must be able to analyze situations, assess risk and determine appropriate actions necessary to remediate risk. This individual must be able to work with internal technology groups to coordinate deployment of solutions. Must exercise good judgment in the handling of security related matters, must be sensitive to both legal and personnel related ramifications of their actions. Provide consulting support in area of responsibility to other internal teams. Participate in providing 24/7 support of security systems as necessary to proactively protect the integrity, confidentiality, and availability of information of the company. Perform administrative tasks including updating and maintaining trouble logs, metrics, time reporting, Change Control records, production documentation, etc. Maintains expertise on the security products and functions supported through continued education and training.
Work hours 8-5 with 24x7 on call rotation duties.
Summary:
This position will be responsible for supporting systems and solutions within Cyber Security specifically authentication and authorization. Support will not be limited to break-fix situations, but also includes implementation activities and day-to-day administration of devices & solutions. Opportunities to cross train on other security platforms.
Requirements:
• 4-7 years experience in Information Technology
• Possess an expert level and thorough understanding of IT concepts including network structures, operating system capabilities, and application architecture requirements
• Strong understanding of web based applications
• Unix / Linux, TCP/IP networking proficiency
• Strong verbal and written communication skills
• Programming / scripting experience preferred
Additional InformationAll your information will be kept confidential according to EEO guidelines.
Direct Staffing Inc
Senior Offensive Security Engineer (Red Team)
Security engineer job in Brooklyn, OH
Serves as the senior process owner for vulnerability management and incident response activities for the entire organization. All associated efforts are to promote and advance an information security processes, culture and must reflect compliance with best practices, applicable federal and industry regulations, as well as company information security policies and standards.
Position Summary
Our Cyber Adversary and Exposure Mgmt. team rolls up into Key's broader Cyber Defense function within Corporate Information Security. Cyber Defense's mission is simple: We aim to Deter, Detect, Deny, and Disrupt adversaries through proactive threat centric defense.
The Senior Offensive Security Engineer is a key member of the Cyber Defense Cyber Adversary and Exposure Mgmt. team, responsible for simulating advanced persistent threats (APTs) and emulating real-world adversaries to assess and improve KeyBank's detection, response, and resilience capabilities. This role goes beyond traditional red teaming and penetration testing by incorporating threat intelligence, custom tooling, and stealthy tradecraft to test the effectiveness of security controls and incident response processes.
The ideal candidate will have deep experience in adversary simulation, red teaming, and offensive security operations across hybrid environments (on-prem, cloud, and physical). This role requires strong technical acumen, creativity, and the ability to communicate complex findings to both technical and executive audiences.
Key Responsibilities
Lead and execute adversary emulation engagements using intelligence-driven threat scenarios aligned with frameworks such as MITRE ATT&CK.
Design and conduct full-scope red team operations, including initial access, lateral movement, privilege escalation, and data exfiltration simulation.
Conduct physical, external/internal, and wireless network assessments, as well as web and mobile application testing.
Perform security assessments across cloud platforms (Google Cloud, Microsoft Azure, AWS) and embedded systems.
Develop and test threat actor emulation tools, tactics, and procedures for the Red Team to employ on-demand in assessments of application, system, and network security controls.
Employ these tools and techniques in the KeyBank environment with minimal supervision.
Partner with the Cyber Threat Intelligence team to ensure Red Team capabilities and tactics accurately reflect the current threat landscape.
Consult with cross-functional teams during project testing phases and architectural design reviews to ensure appropriate security controls are in place to mitigate threats.
Coordinate and monitor third-party penetration testing engagements, ensuring alignment with requirements, effective communication, and timely, accurate reporting.
Generate and publish Red Team metrics and reporting to track program effectiveness and stakeholder visibility.
Lead efforts to track remediation of findings to completion through coordination with application and technology system owners.
Expand the team's capabilities through:
- Creation of custom tools and automation frameworks.
- Research and development of novel offensive techniques and tradecraft.
- Incorporation of threat actor intelligence into emulation scenarios.
- Delivery of internal presentations and knowledge-sharing sessions.
Collaborate with the Cyber Threat Intelligence team to translate real-world TTPs into emulation plans.
Evaluate the effectiveness of detection and response capabilities across SOC, EDR, SIEM, and other security layers.
Provide detailed post-mortem reports and executive briefings with prioritized recommendations.
Mentor junior team members and contribute to the development of adversarial tradecraft within the team.
Partner with blue teams to conduct purple team exercises and improve detection engineering.
Contribute to the continuous improvement of adversarial emulation methodologies, tooling, and documentation.
Required Qualifications
Bachelor's degree or equivalent work experience.
8+ years of experience in Red Team or Penetration Testing roles.
Proficiency with Red Team tools and Command & Control (C2) frameworks.
Strong scripting and programming skills in PowerShell, Python, JavaScript, Bash, Golang or similar languages.
Deep understanding of Windows, Linux, Kali Linux, and mac OS operating systems.
Hands-on experience with one or more of the following:
Google Cloud, Microsoft Azure, and AWS platforms.
Advanced networking knowledge and experience with attack simulation.
Familiarity with the MITRE ATT&CK framework and adversary TTPs.
Deep understanding of one or more Penetration Testing Methodologies such as PTES, ISECOM, ISSAF, and OSSTMM
Strong research and reporting skills.
Willingness to travel for on-site assessments.
Preferred Certifications
Offensive Security Certified Professional (OSCP)
Offensive Security Certified Expert (OSCE)
Offensive Security Experienced Penetration Tester (OSEP)
Certified Red Team Professional (CRTP)
GIAC Penetration Tester (GPEN)
GIAC Web Application Penetration Tester (GWAPT)
CREST Registered Penetration Tester / CBEST Qualifications
COMPENSATION AND BENEFITS
This position is eligible to earn a base salary in the range of $94,000.00 - $175,000.00 annually. Placement within the pay range may differ based upon various factors, including but not limited to skills, experience and geographic location. Compensation for this role also includes eligibility for incentive compensation subject to individual and company performance.
Please click here for a list of benefits for which this position is eligible.
Key has implemented an approach to employee workspaces which prioritizes in-office presence, while providing flexible options in circumstances where roles can be performed effectively in a mobile environment.
Job Posting Expiration Date: 12/18/2025 KeyCorp is an Equal Opportunity Employer committed to sustaining an inclusive culture. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, genetic information, pregnancy, disability, veteran status or any other characteristic protected by law.
Qualified individuals with disabilities or disabled veterans who are unable or limited in their ability to apply on this site may request reasonable accommodations by emailing HR_**********************.
#LI-Remote
Auto-ApplyIT Security Manager
Security engineer job in Solon, OH
Swagelok is a global organization and one of the largest employers of manufacturing talent in Northeast Ohio. We are driven by our core values of Quality, Integrity, Respect for the Individual, Customer Focus, Innovation, and Continuous Improvement, which are demonstrated through our daily actions. For over 75 years, our dedication to our core values has been the foundation for our success. Our products have been up into space, down to the bottom of the ocean, and everywhere in between. That same dedication spans to our customers.
Throughout our organization we demonstrate a commitment to these values and those we bring onboard. Whether you want to grow in your role or explore broad opportunities and develop new skills-you'll thrive in a culture that promotes learning and development.
We strive to be a company where we all can do our best work with a true sense of purpose and belonging.
**Be** Connected. **Be** Valued. **Be** You.
We hope you'll consider joining our team.
The IT Security Manager is responsible for directly assessing and holistically executing all aspects of risk brought to bear on the enterprise including legislative/regulatory compliance issues in the areas of cyber security, technology, IT operations, and data.
Additionally, the IT Security Manager plans and delivers actions supporting the enterprise IT security strategy. The IT Security Manager is expected to execute the needed security programs and activities. This includes interfacing with peers in the Information Technology departments as well as with the leaders of the business including shop floor, innovation, manufacturing operations, new product development, data and Swagelok Sales and Service locations. The incumbent will share and implement the corporate security vision with key stakeholders and work to achieve higher levels of enterprise and data security. Secondary tasks will include the selection of appropriate IT security partners and solutions in collaboration with the enterprise architects.
**Essential Duties and Responsibilities:**
+ Work with the executive and business managers to align the Information Technology organization with business unit security and compliance needs.
+ Acts as a technical consultant for the enterprise, ensuring security design for systems align with business needs, architecture and technical standards.
+ Develop, institute and maintain an Information Security Strategy Roadmap for all Security Technology domains with input on the strategic direction from the architecture team.
+ Create and maintain the enterprise's security documents (policies, standards, baselines, guidelines and procedures).
+ Ensure current cyber and data security services encompass the enterprise including new product development, data governance and digital programs.
+ Lead and coordinate incident response to problematic security and data activity, ensuring timely resolution and provide on-going communication with senior management.
+ Run the design and execution of vulnerability assessments, penetration tests and security audits.
+ Ensure regular security awareness and data handling training for all employees to ensure consistently high levels of compliance with enterprise security documents.
+ Conduct/participate in data privacy risk assessments and implement mitigation measures.
+ Oversee and ensure security and data privacy requirements for third-party vendors.
+ Classify and evaluate enterprise data assets in conjunction with the Data Governance team.
+ Ensure the confidentiality, integrity and availability of the data residing on or transmitted to/from/through enterprise workstations, servers and other systems and in databases and other data repositories.
+ Prepares system security reports and KPI by collecting, analyzing, and summarizing data and trends to track and measure the enterprise's risk posture.
+ Responsible for establishing and leading a high-performance team of security professionals that oversees the proper deployment, configuration, and administration of the security and identify management systems. Approximate # of direct reports - 4
+ Plan and manage IT Security budget to improve security posture and ensure effective budget utilization.
**Education and/or Work Experience Requirements:**
**Education**
+ _College diploma or university degree in the field of computer science and/or 5 years equivalent work experience._
+ _One or more certifications in CISSP, CISA, CISM, CIPM or CIPT is preferred._
**_Skills_**
+ _Strong problem solver with excellent oral and written communication skills._
+ _Possess the ability to interact with a variety of diverse people in a complex environment._
+ _Specific knowledge of risk management principles and models._
+ _Experience in audit of legislative and/or regulatory compliance._
+ _Strong knowledge of corporate level security systems and implementation procedures, corporate and government security regulations, security software products, domain structures, user authentication, user profiles, and digital signatures._
+ _Excellent understanding of cloud security and experience with design and/or implementation of applications in the cloud._
+ _Extensive knowledge of technical security controls and technologies (e.g. IDS, IPS and Web Application Firewalls; Data Loss Prevention (DLP); Antivirus, Anti-malware and Zero Day protections; Security Information and Event Management (SIEM); Identify and Access Management and Privileged User Management; Public Key Infrastructure and Certificate management)._
**_Working Conditions and/or Physical Requrements:_**
+ Working conditions associated with normal office environment.
+ Ability to operate standard office equipment (e.g., computer, telephone, copier, printer, etc.).
+ Ability to effectively communicate in both small and large groups and settings.
+ Ability to traverse between multiple locations in Ohio and Pennsylvania as needed.
+ Ability to safely and successfully perform the essential job functions consistent with the ADA, FMLA and other federal, state, and local standards, including meeting qualitative and quantitative productivity standards.
+ Ability to maintain regular, punctual attendance consistent with the ADA, FMLA and other federal, state, and local standards.
Swagelok provides a comprehensive package of valuable benefits called Total Rewards focused on health and wellness, compensation, retirement planning, and supplemental rewards.
To apply:
1. Click 'Apply Now' to the role of interest, upload your resume and complete the application.
2. Those that match our qualifications will be contacted to schedule a phone interview.
Congratulations on taking the first step to **B** e Connected. **B** e Valued. **B** e You.
_Swagelok is proud to be an Equal Opportunity Employer. Applicants are selected without regard to race, ethnicity, creed, color, religion, sex, pregnancy, pregnancy-related medical conditions, age, national origin or ancestry, disability, genetic information, veteran/military status, sexual orientation, gender identity, or other protected characteristic under federal, state or local law._
_Swagelok will make reasonable accommodations in compliance with the Americans with Disabilities Act of 1990, the Americans with Disabilities Act Amendments Act of 2008, and Ohio state law. _
_This job summary is intended to be brief and does not list all the duties for this position. Nothing in this job description should be construed as an express or implied contract of employment. Swagelok is an at-will employer, which means that either party is free to terminate the employment relationship at any time, without any advanced notice, for any reason or no reason. _
\#LI-LK1
\#LI-Hybrid
Senior Security Engineer
Security engineer job in Akron, OH
Full Time 40 Hours/Week Monday - Friday, 8:00am - 4:30pm Remote On-Call Rotation The Sr Security Engineer is an integral part of the Cybersecurity program. This position will be responsible for maturing the Risk Management, and Incident response areas. This will be accomplished by conducting risk assessment of third parties, systems & equipment being placed on the network and cloud systems. Incident Response duties include organizing table top exercise and working with other staff on remediation of gaps identified. Day to day this position will interface with staff at all levels of the organization.
Responsibilities:
* Assists with the implementation, execution and continuous improvement of the Information Security Program including but not limited to: Policy and Document Maintenance, Risk Assessment, Security Controls and Technical Oversight.
* Maintains information security policies, procedures, and standards.
* Conducts periodic risk analysis and risk management assessments.
* Develops and coordinates application security reviews and is responsible for vulnerability and incident management.
* Responsible for evaluation, selection, and implementation of information security tools.
* Ability to problem solve/remediate in a highly complex and matrixed environment.
* Ability to successfully work in a fast-paced environment with a variety of personalities and work styles.
* Ability to successfully work well under pressure with tight deadlines and with a sense of urgency.
* Possess excellent written, oral, and active listening skills.
* Other duties as required.
Other information:
Technical Expertise
* Experience in HIPAA, HITECH, PCI, NIST, and other frameworks is required.
* Experience in securing information system technologies is required.
* Experience with both Technical Security Engineer and Governance, Risk and Compliance (GRC) is strongly preferred.
* Experience working with all levels within an organization is required.
* Experience in healthcare is preferred.
* Proficiency in MS Office [Outlook, Excel, Word] or similar software is required.
* In-depth knowledge of security concepts such as cyber-attacks and techniques, threat vectors, risk management, incident management etc.
* Experience with an organization's privacy and security due diligence efforts when entering into third party relationships or M&A activities a plus.
* Knowledge of various operating system flavors including but not limited to Windows, Linux, Unix
* Knowledge of applications, databases, middleware to address security threats against the same.
* Proficient in preparation of reports, dashboards and documentation
* Excellent communication and leadership skills
* Ability to handle high pressure situations with key stakeholders
* Good Analytical skills, Problem solving and Interpersonal skills
* Ability to adapt and thrive in a dynamic work environment. Exceptional organization skills, ability to work independently as well as part of a team, and demonstrated experience in taking initiative and following up on tasks.
* Proficiency in MS Office [Outlook, Excel, Word, Visio, and SharePoint] or similar software is required.
Education and Experience
* Education: Bachelor degree in related field is required.
* Security Certification Required: CEH, CISSP, GCIH, GSEC, or similar level security certification
* 2-3 years leadership/ supervisory experience preferred
Full Time
FTE: 1.000000
Senior Security Analyst
Security engineer job in Aurora, OH
LOCATED IN AURORA, OHIO***
About Us:
LayerZero Power Systems Inc. is a globally recognized leader in providing state-of-the-art power distribution solutions for critical industries. With a strong focus on reliability, innovation, and customer satisfaction, we deliver advanced power systems products that ensure uninterrupted and dependable power supply in mission-critical environments. Our customer base is comprised of companies in the transaction processing, financial, computer service provision and semiconductor manufacturing sectors. LayerZero Power Systems is on a trajectory of sustained growth, with a loyal customer base of existing Fortune 100 customers and an expanding portfolio of new customers.
Position Description: Senior Security Analyst
Responsible for monitoring, analyzing, and responding to security events across LayerZero's IT environment. This role requires a proactive professional with strong technical skills who can identify risks, investigate incidents, and support the implementation of security controls and best practices.
Primary Duties:
• Monitoring & Incident Response
• Monitor security alerts, logs, and dashboards for potential threats.
• Investigate and respond to security incidents, escalating as needed.
• Perform root cause analysis and recommend corrective actions.
• Risk Management & Compliance
• Assist with vulnerability assessments, penetration testing, and remediation efforts.
• Support compliance initiatives and audits (e.g., ISO, NIST, SOC).
• Maintain documentation of policies, procedures, and incident reports.
• Security Operations
• Manage endpoint protection, firewalls, intrusion detection/prevention systems, and SIEM tools.
• Ensure timely patching and updates across systems.
• Collaborate with IT teams to enforce access controls and data protection practices.
• Continuous Improvement
• Stay current on emerging threats, tools, and best practices.
• Recommend improvements to security architecture and processes.
• Provide training and awareness to employees on cybersecurity practices.
Requirements
Skills & Experience
• Familiarity with SIEM platforms, firewalls, IDS/IPS, and endpoint protection tools.
• Knowledge of security frameworks (NIST, ISO, CIS).
• Strong analytical and problem-solving skills.
• Excellent communication and documentation abilities.
Education:
• Bachelor's degree in Information Security, Computer Science, or related field (preferred).
• 2-4 years of experience in IT security or systems administration.
What We Offer:
Competitive pay with performance incentives
100% company-paid medical, dental, and vision
401(k) with company match
3 weeks PTO, 8 paid holidays, and 2 floating holidays
Why You Will Love Working with Us:
Impact: Develop your skills and expertise in a rapidly growing industry, with your work directly influencing the success of mission-critical projects.
Innovation: Immerse yourself in an environment that celebrates forward-thinking and continuous improvement.
Collaborative spirit: Work closely with engineers, marketers, and other professionals to bring ideas to life.
Grow with us: We are committed to your personal and professional development, offering endless opportunities to improve your skills and advance your career.
At LayerZero, we are proud to be an Equal Opportunity Employer. We welcome and celebrate diversity, and we are committed to creating an inclusive environment for all employees.
Salary Description $85k-115k Annually based on Skills & Experience
Senior Security Analyst
Security engineer job in Cleveland, OH
Quant Analytics Sr. Associate- Model Risk Must Have Technical/Functional Skills As a Senior Quantitative Analytics Associate, you will be responsible for leading independent validations and reviews of the bank's various risk models. This role ensures that models are functioning as intended, comply with regulatory requirements, and that their risks are accurately identified, measured, and reported to senior management. Specifically, you will be performing in-depth validations and reviews of new and existing models used across the bank, including those for fraud risk, compliance risk (such as AML, OFAC), and/or other areas.
Essential Job Functions
* Perform hands-on quantitative model validation/review. This includes testing the model's conceptual soundness, data accuracy, methodology, and ongoing performance through techniques like back testing, benchmarking, and stress testing, etc.
* Provide an effective challenge throughout the model validation/review to ensure that models are robust, and all assumptions and limitations are justified.
* Present findings, weakness and/or observations identified from the validation/review to model developers/owners and provide them with executable finding remediations.
* Prepare detailed validation reports and memos that document the validation approach, findings, and conclusions.
* Participate in internal audits and regulatory exams by presenting validation results and methodologies and assisting in the remediation of any audit or exam findings.
* Act as a subject matter expert on modeling techniques, risk management practices, and regulatory trends. This involves performing research and developing advanced analytical tools or benchmarking models to aid the validation process.
Required Qualifications
* Hands-on experience in statistical and AI/ML model development or validation, with a strong understanding of quantitative modeling methods (including AI/ML algorithms) used for various risk predictive models, such as fraud risk, AML risk models, etc.
* Proficiency in programming languages such as Python, R, SQL or SAS.
* Excellent written and verbal communication skills to clearly articulate complex technical findings to both technical and non-technical stakeholder.
* Knowledge of model risk management policies, procedures, and relevant regulatory guidance (e.g., from the OCC).
Salary Range- $100,000-$210,000 a year
Chief Information Security Officer - Information Technology
Security engineer job in Ashland, OH
The Chief Information Security Officer ( CISO ) would report to the CITO and is responsible for engineering activities and systems that monitor, detect and alert on potential security threats and vulnerabilities. Also identifying, developing, testing, implementing, and maintaining security compliance, risk and vulnerability management for Ashland University students, staff, and faculty. This position is critical to providing daily support, troubleshooting, and resolution of the Ashland University cyber security infrastructure. Works closely with network engineering and technical operations staff as security threats and vulnerabilities are detected and coordinates the response to contain and mitigate threats or breaches. Leads and coordinates the network penetration process for network security operations and communicate event status to leadership.
Physical Demands
Office environment with some lifting and hauling of equipment up to 60 lbs. Typical work week: 8AM - 5PM, however, some weekend and evening work hours required; remote hybrid work is negotiable Cellphone availability during normal and after work hours required Valid Driver's License and ability to drive to remote campus locations and attend training as assigned.
Required Qualifications
Conduct periodic senior level needs analyses as directed Analyze patterns of non-compliance and take appropriate administrative or programmatic actions to minimize security risks and insider threats. Manage accounts, network rights, and access to systems and equipment. Analyze potential security violations to determine if the network environment has been breached, assess the impact, and preserve evidence. Support, monitor, test, implement, document, and troubleshoot hardware and software problems pertaining to the cyber security infrastructure. Analyze systems and network for potential security problems and recommend resolutions or remediate when necessary. Review access control lists on routers, firewalls, and other network devices. Lead and perform system audits to assess security related factors within the network. environment and recommend or implement improvements to security systems. Evaluate potential security risks and take appropriate corrective and recovery action. Monitor/Manage clients' endpoint security and SIEM . Design, implement, and conduct internal and third-party Security Test and Evaluations Serve as an information security resource on projects. Develop and lead formal and informal education and training for Ashland University Develop and utilize “Case Management” processes for incident and resolution tracking. The processes should also be used for historic recording of all anomalous or suspicious activity. Maintain knowledge of the current security threat level by monitoring related Internet postings, Intelligence reports, and other related documents as necessary. Provides advanced technical expertise, consulting, and support to staff members with security tasks. Recommends appropriate actions to improve project security and designs new monitoring strategies for complex securing systems. Maintain system baselines and configuration management items, including security event monitoring “policies” in a manner determined and agreed to by management. Ensure changes are made using an approval process agreed to in advance.
Preferred Qualifications
Experience: Bachelor's degree in IT Security or closely related field from an accredited college or university with a minimum of three (3) years' experience in high-level technology computing or related technology areas, or a bachelor's degree and other relevant education and training from an accredited college or university with a minimum of five(5) years in high-level technology computing or related technology areas. Must possess professional security management certification such as a Certified Information Systems Security Professional ( CISSP ), Certified Information Security Manager ( CISM ), Certified Information Systems Auditor ( CISA ), or other similar credentials. Must demonstrate knowledge of common information security management frameworks such as ISO / IEC 27001 and ITIL , COBIT and NIST , and an understanding of relevant legal and regulatory requirements such as Payment Card Industry/Data Security. Experience with network, application, and security awareness security concepts, methodologies, processes, & tools. Experience with information risk assessment and mitigation concepts, methodologies, processes, and tools. Experience with forensics concepts, methodologies, processes, and tools. Skills: Expert knowledge of application, network, and system security vulnerabilities and exploits. Ability to adapt to a fast-moving IT landscape and keep pace with latest thinking and new security technologies Forms business partnerships that help drive the IT security strategy forward Can make decisions that are well informed and timely Must have organizational skills and can make sound decisions independently. Must possess excellent interpersonal, communications and collaborative skills and have experience working in a service capacity with direct customer interaction. Must be able to build team support as well as can work cooperatively with all levels of the university community.
SAP Security Architect
Security engineer job in Mayfield Heights, OH
Wright Technical Services is proud to represent a highly respected global manufacturing company for this role. We are looking for an experienced SAP Security Architect to join our team. The role involves designing, implementing, and managing SAP security architecture, ensuring secure access, data protection, and compliance with regulations like SOX, ITAR, and GDPR. Key tasks include conducting risk assessments, implementing SAP GRC modules, designing user provisioning processes, and collaborating with teams to integrate security throughout the SAP lifecycle.
Qualifications
Bachelor's degree in Computer Science, Information Technology or related field required, advanced degree preferred.
Minimum 8 years of experiences in SAP Security, including role design, implementation and management.
In-depth knowledge of SAP security concepts, including user administration, role-based access control, and authorization objects.
Strong understanding of ITAR and SOX compliance requirements and experience implementing controls to meet these regulations.
Experience with SAP GRC (Governance, Risk, and Compliance) solutions is highly desirable.
Extensive experience with SAP BASIS administration, including system installations, upgrades, patches, and performance tuning.
Excellent analytical, problem-solving, and communication skills.
Ability to work independently and collaboratively in a fast-paced environment.
Relevant certifications such as SAP Certified Technology Professional - System Security Architect, Certified Technology Associate - System Administration (SAP BASIS), CISSP, CISM, or CISA are a plus.
Key Responsibilities
SAP Security Design and Roadmap Implementation:
Design and implement SAP security solutions and roadmaps for both cloud and on-premises systems.
Integrate security into the SAP lifecycle with development, engineering, and IT operations teams.
Conduct security assessments and audits, develop security policies, and manage SAP IAM solutions, including single sign-on (SSO) and multi-factor authentication (MFA), and integrate them with enterprise-wide IAM systems.
Role Design and Management:
Implement SAP Governance, Risk and Compliance (GRC) modules to manage user roles and access reviews, ensuring separation of duties (SoD).
Develop and manage SAP role designs, create and maintain security roles, and collaborate with business and IT teams to define and implement role-based access controls (RBAC).
Regularly review and update SAP roles to meet business and compliance standards.
Risk and Compliance Management:
Conduct risk assessments, identify vulnerabilities and ensure compliance with regulations like SOX, ITAR and GDPR, and develop policies, procedures and controls to meet regulatory standards.
Leadership and Team Management:
Lead, mentor and develop a team of SAP security professionals, fostering a collaborative and high-performance environment.
Provide guidance and support to team members on SAP security best practices, compliance requirements, and role design.
Incident Response and Management:
Lead and coordinate the response to SAP security incidents, including investigation, containment, and remediation.
Develop and maintain incident response plans and procedures for SAP environments.
SAP BASIS Administration:
Perform SAP BASIS tasks such as system installations, upgrades, patches, and performance tuning.
Ensure the health and performance of SAP systems, collaborating with infrastructure teams to manage SAP landscapes.
Eligibility: Due to federal contract requirements, candidates must be U.S. citizens residing in the United States.
Wright Technical Services and our client are Equal Opportunity Employers. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.
Cyber and Information Security Analyst - Cyber Security & TSOC
Security engineer job in Wadsworth, OH
About the Opportunity
We are a forward-thinking electric utility powered by a diverse team of employees committed to making customers' lives brighter, the environment better and our communities stronger.
FirstEnergy (NYSE: FE) is dedicated to integrity, safety, reliability and operational excellence. Headquartered in Akron, Ohio, FirstEnergy includes one of the nation's largest investor-owned electric systems, more than 24,000 miles of transmission lines that connect the Midwest and Mid-Atlantic regions, and a regulated generating fleet with a total capacity of more than 3,500 megawatts.
Location: Position may be filled at Akron, OH or Wadsworth, OH. Position is currently remote but may work at or visit a facility based on business need.
This position is within FirstEnergy Service Company, a subsidiary of FirstEnergy Corp.
This position's base reporting location is in Wadsworth Township, Ohio with significant flexible work location opportunities. This position is part of FirstEnergy's Cyber Security Governance department reporting to the Manager of Cyber Security Policy.
The Cyber and Information Security Analyst works across all FirstEnergy subsidiaries and business units to protect the cyber assets of FirstEnergy. We seek a knowledgeable individual well-versed in current cyber security and information security strategies with skills to effectively apply such strategies to a large, dynamic, heterogeneous landscape.
Qualifications
Bachelor's Degree in Computer Science, Information Security, or similar discipline is preferred
Ability to identify and assess the severity and potential impact of risks. Communicate risk assessment findings to risk owners outside the cybersecurity program in a way that consistently drives objective, fact-based decisions about risk that optimize the trade-off between risk mitigation and business performance
Familiarity with common cyber security related tools such as vulnerability scanners (Tenable preferred), ServiceNow IRM and GRC, Microsoft Power Automate, Microsoft Power BI, and other similar toolchains
Strong decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate one
An ability to work on several tasks simultaneously and pay attention to sources of information from inside and outside one's network within an organization
An ability to effectively influence others by informing their opinions, plans or behaviors
Ability to communicate complex and technical issues to diverse audiences, orally and in writing, in an easily understood, authoritative and actionable manner
Infrequent business travel to Akron, OH may be required
Able to participate in an on-call rotation (cycling daily; on-call once every ~6-8 days) responding to out-of-hours calls and alerts in support of security response
Benefits, Compensation & Workforce Diversity
At FirstEnergy, employees are key to our success. We depend on their talents to meet the challenges of our changing business environment. We are committed to rewarding individual and team efforts through our total rewards philosophy which includes competitive pay plus incentive compensation, a company-sponsored pension plan, 401(k) savings plan with matching employer contribution, a choice of medical, prescription drug, dental, vision, and life insurance programs, as well as skills development training with tuition reimbursement. Please visit our website at *********************** to learn more about all of our employee rewards programs. FirstEnergy proudly supports workforce diversity. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, sex, sexual orientation, gender identity, age, status as a protected veteran, or status as a qualified individual with a disability. No recruiters or agencies without a previously signed contract. Unable to sponsor or transfer H-1B visas at this time.
Safety
Safety is a core value for FirstEnergy and is essential to all of our business activities. We ensure employees have the tools, information, and processes to perform their duties in a manner that assures safety for themselves, their co-workers, our customers and the public. Our goals are to provide a safe work environment, to maintain an accident-free, injury-free workplace, and to promote and maintain public safety. To meet these goals, we dedicate ourselves to achieving world-class safety standards.
Position Classification
Exempt
Auto-ApplySenior Security Engineer - SSO / Web Security
Security engineer job in Strongsville, OH
Pittsburgh Pennsylvania Strongsville, OH Exp 5-7 yrs Deg Bachelors Occasional Travel Job Description As an Infrastructure Engineer Senior and a member of our Information Technology, you will be part of a diversified financial services firm that reflects the needs, values and goals of our customers, employees, communities and shareholders. You will be institutional in helping to maintain our reputation for technology excellence in both business applications and new innovations.
As an Infrastructure Engineer you will provide accurate and cost efficient security maintenance and support services to internal & external clients. Responsibilities include ongoing management and support of security infrastructure in a large environment. Must be able to analyze situations, assess risk and determine appropriate actions necessary to remediate risk. This individual must be able to work with internal technology groups to coordinate deployment of solutions. Must exercise good judgment in the handling of security related matters, must be sensitive to both legal and personnel related ramifications of their actions. Provide consulting support in area of responsibility to other internal teams. Participate in providing 24/7 support of security systems as necessary to proactively protect the integrity, confidentiality, and availability of information of the company. Perform administrative tasks including updating and maintaining trouble logs, metrics, time reporting, Change Control records, production documentation, etc. Maintains expertise on the security products and functions supported through continued education and training.
Work hours 8-5 with 24x7 on call rotation duties.
Summary:
This position will be responsible for supporting systems and solutions within Cyber Security specifically authentication and authorization. Support will not be limited to break-fix situations, but also includes implementation activities and day-to-day administration of devices & solutions. Opportunities to cross train on other security platforms.
Requirements:
• 4-7 years experience in Information Technology
• Possess an expert level and thorough understanding of IT concepts including network structures, operating system capabilities, and application architecture requirements
• Strong understanding of web based applications
• Unix / Linux, TCP/IP networking proficiency
• Strong verbal and written communication skills
• Programming / scripting experience preferred
Additional Information
All your information will be kept confidential according to EEO guidelines.
Direct Staffing Inc
Senior Security Analyst
Security engineer job in Aurora, OH
Job DescriptionDescription:
LOCATED IN AURORA, OHIO***
About Us:
LayerZero Power Systems Inc. is a globally recognized leader in providing state-of-the-art power distribution solutions for critical industries. With a strong focus on reliability, innovation, and customer satisfaction, we deliver advanced power systems products that ensure uninterrupted and dependable power supply in mission-critical environments. Our customer base is comprised of companies in the transaction processing, financial, computer service provision and semiconductor manufacturing sectors. LayerZero Power Systems is on a trajectory of sustained growth, with a loyal customer base of existing Fortune 100 customers and an expanding portfolio of new customers.
Position Description: Senior Security Analyst
Responsible for monitoring, analyzing, and responding to security events across LayerZero's IT environment. This role requires a proactive professional with strong technical skills who can identify risks, investigate incidents, and support the implementation of security controls and best practices.
Primary Duties:
• Monitoring & Incident Response
• Monitor security alerts, logs, and dashboards for potential threats.
• Investigate and respond to security incidents, escalating as needed.
• Perform root cause analysis and recommend corrective actions.
• Risk Management & Compliance
• Assist with vulnerability assessments, penetration testing, and remediation efforts.
• Support compliance initiatives and audits (e.g., ISO, NIST, SOC).
• Maintain documentation of policies, procedures, and incident reports.
• Security Operations
• Manage endpoint protection, firewalls, intrusion detection/prevention systems, and SIEM tools.
• Ensure timely patching and updates across systems.
• Collaborate with IT teams to enforce access controls and data protection practices.
• Continuous Improvement
• Stay current on emerging threats, tools, and best practices.
• Recommend improvements to security architecture and processes.
• Provide training and awareness to employees on cybersecurity practices.
Requirements:
Skills & Experience
• Familiarity with SIEM platforms, firewalls, IDS/IPS, and endpoint protection tools.
• Knowledge of security frameworks (NIST, ISO, CIS).
• Strong analytical and problem-solving skills.
• Excellent communication and documentation abilities.
Education:
• Bachelor's degree in Information Security, Computer Science, or related field (preferred).
• 2-4 years of experience in IT security or systems administration.
What We Offer:
Competitive pay with performance incentives
100% company-paid medical, dental, and vision
401(k) with company match
3 weeks PTO, 8 paid holidays, and 2 floating holidays
Why You Will Love Working with Us:
Impact: Develop your skills and expertise in a rapidly growing industry, with your work directly influencing the success of mission-critical projects.
Innovation: Immerse yourself in an environment that celebrates forward-thinking and continuous improvement.
Collaborative spirit: Work closely with engineers, marketers, and other professionals to bring ideas to life.
Grow with us: We are committed to your personal and professional development, offering endless opportunities to improve your skills and advance your career.
At LayerZero, we are proud to be an Equal Opportunity Employer. We welcome and celebrate diversity, and we are committed to creating an inclusive environment for all employees.
Security Architect
Security engineer job in Mayfield, OH
Roles & Responsibilities * Design and implement scalable security architectures across hybrid environments (on-prem, cloud, multi-cloud). * Design secure network architectures including micro-segmentation, zero trust, and firewall zoning. * Evaluate and implement endpoint protection, DLP, and vulnerability management solutions.
* Conduct risk assessments and recommend mitigation strategies for infrastructure components
* Define security controls and frameworks aligned with BFSI regulatory standards (e.g., ISO 27001, PCI-DSS).
* Architect security controls for Azure, AWS, and GCP environments.
* Implement cloud-native security tools and posture management (CSPM, CWPP).
* Ensure secure onboarding of cloud workloads and services.
* Lead IAM strategy including role-based access control, identity lifecycle, and privileged access management.
* Architect and implement various IAM solutions in the enterprise.
* Integrate IAM with enterprise applications and cloud platforms.
* Provide architectural oversight for SOC operations including SIEM, SOAR, and threat detection workflows.
* Provide vision for integration of threat intelligence feeds and identify uses cases to be deployed in SOC on proactive manner.
* Collaborate with SOC teams to enhance detection logic and incident response capabilities.
TCS Employee Benefits Summary:
* Discretionary Annual Incentive.
* Comprehensive Medical Coverage: Medical & Health, Dental & Vision, Disability Planning & Insurance, Pet Insurance Plans.
* Family Support: Maternal & Parental Leaves.
* Insurance Options: Auto & Home Insurance, Identity Theft Protection.
* Convenience & Professional Growth: Commuter Benefits & Certification & Training Reimbursement.
* Time Off: Vacation, Time Off, Sick Leave & Holidays.
* Legal & Financial Assistance: Legal Assistance, 401K Plan, Performance Bonus, College Fund, Student Loan Refinancing.
Salary Range: $122,000 - $130,000 a year