Cloud Security Engineer
Security engineer job in Philadelphia, PA
The Cloud Security Engineer will play a pivotal role in the cloud security service delivery model. The role combines deep technical expertise, collaboration across internal and external teams to design, implement, and optimize cloud security controls and service lines. The candidate will support both project-based and continuous security initiatives, focusing on securing HOSPITAL's cloud migration, supporting cloud security tool optimization, cloud security processes for the Information Security team, cloud/hybrid controls, automation, and risk-driven security outcomes.
Proven experience in securing a multi-cloud environment.
Proven experience with Identity and access management in the cloud
Proven experience with all security service lines in a cloud environment and the supporting security tools and processes to be successful.
Demonstrate collaboration with internal stakeholders, vendors, and supporting teams to design, implement, and maintain security technologies across network, endpoint, identity, and cloud infrastructure.
Drive continuous improvement and coverage of cloud security controls by validating alerts, triaging escalations, and working with the MSP to fine-tune detection and prevention capabilities.
Lead or support the development of incident response plans, engineering runbooks, tabletop exercises, and system hardening guides.
Ensure alignment of security architectures with HOSPITAL's policies, standards, and external frameworks such as NIST SP 800-53, HIPAA, PCI-DSS, CISA ZTMM, CIS Benchmarks, and Microsoft CAF Secure Methodology, AWS CAF, AWS Well Architected framework, Google CAF
Participate in design and governance forums to provide security input into infrastructure, DevSecOps, and cloud-native application strategies.
Assist with audits, compliance assessments, risk remediation plans, and evidence collection with internal compliance and external third-party stakeholders.
Mentor and support junior InfoSec engineers through documentation, training, and peer reviews.
Hands-on experience in security engineering, systems integration, and cloud architecture (Azure preferred).
Proficiency in tools and domains such as: EDR (Microsoft Defender), SIEM (Sentinel or Splunk), CSPM (e.g., Wiz), IAM (Entra ID), VPNs/NGFWs, NAC, and encryption protocols.
Demonstrated understanding of secure configuration management, automation pipelines (e.g., Terraform, PowerShell), and vulnerability management platforms.
What you will do
A Principal Information Security Specialist has similar responsibilities to Information Security Specialist III personnel. However, a Principal Information Security Specialist is deemed to be the subject matter expert and in-house advisor on complex problems and issues. A Principal Information Security Specialist also:
Works independently to initiate assignments and draws upon extensive professional knowledge and experience to make independent judgments regarding analysis, evaluation, development, and implementation of enterprise long-term solutions and operating initiatives to ensure that enterprise architectural objectives are aligned with organizational needs and strategic goals.
Skills: Duties (cont'd):
Optimizes information management approaches through an understanding of evolving business needs and technology capabilities and ensures that projects do not duplicate functionality or diverge from each other and business and DTS strategies.
Shapes, designs, and plans specific service lines in product area and manages the risks associated with information and DTS assets through appropriate standards and security policies.
Functions as the Subject Matter Expert (SME) to maintain an understanding of HOSPITAL DTS business and clinical applications and the relationship to InfoSec and compliance solutions; assist Hospital stakeholders in understanding information protection needs that support the Hospital's business.
Works with other architects to provide a consensus based enterprise solution that is scalable, adaptable and in synchronization with ever changing business needs and takes ownership of a particular solution offering.
Works with highly matrixed team of DTS personnel to support enterprise architecture and information security operations including, but not limited to, architecture and InfoSec principles around identity & access management models, cloud identify management providers, security information and event monitoring, and data loss prevention, perimeter (e.g. firewalls, IPS, web filtering), cloud and virtualization environments and network security (host-based firewalls, anti-virus, disk encryption).
Support and/or lead activities around InfoSec standards for business continuity and change management activities (e.g., table tops and change review board) and educates DTS Hospital management on security issues (e.g., Identity and Access Management (IAM), Role Based Access Control (RBAC) models.
Skills:
Demonstrates comprehensive knowledge and understanding of Information security principles, general and IT controls (e.g., access controls, risk management, change management, cloud security) and related information security policies and procedures.
Exhibits knowledge of industry regulatory standards and accreditation requirements or control frameworks (HIPAA, PCI, Joint Commission, NIST, Red Flags, ISO 27000 series).
Comprehensive knowledge of information security regulations, standards and leading practices, including understanding of EHR, cloud frameworks, identity access controls.
Good knowledge of basic database query techniques & data mining to analyze data or other related database functionality.
Knowledge of Microsoft Active Directory, UNIX, and Clinical Applications a plus.
Experience implementing application level security in clinical and financial systems (e.g., Epic, Lawson). ERP experience a plus.
General understanding of networking and communication techniques including WANs, LANs, Internet, Intranet, protocols, such as TCP/IP and their impact on security.
Microsoft, UNIX, Lawson, and Clinical Applications, Experience with industry standard SDLC methodologies; hands-on experience in Project Server methodologies, PMO project management skills, including use of MS productivity tools (Access, Word, PowerPoint, Visio, Project).
Experience with risk management frameworks.
Information Security Requirements
Understand and comply with all enterprise and IS departmental information security policies, procedures and standards.
Support the integration of information security in the development, design, and implementation of Hospital Technology Resources that process, transmit, or store HOSPITAL information.
Support all compliance activities related to state, federal regulatory requirements, healthcare accreditation standards, and all other applicable regulations that govern the use and disclosure of patient, financial, or other confidential information.
Cloud Security Engineer
Security engineer job in Philadelphia, PA
Our client is one of the largest Hospitals in the US. Based out of Philadelphia, they are looking to hire a Cloud Security Engineer on a Contract basis.
Contract Duration: 6 Month Contract (Potential for extension or conversion)
Required Skills & Experience
At least twelve (12) years industry related experience, including experience in one to two IT disciplines (such as technical architecture, network management, application development, middleware, information analysis, database management or operations) in a multitier environment.
CISSP Certification
At least six (6) years experience with information security, regulatory compliance and risk management concepts.
At least three (3) years experience with Identity and Access Management, user provisioning, Role Based Access Control, or control self-assessment methodologies and security awareness training.
Experience with Cloud and/or Virtualization technologies.
Demonstrates comprehensive knowledge and understanding of Information security principles, general and IT controls (e.g., access controls, risk management, change management, cloud security) and related information security policies and procedures.
Exhibits knowledge of industry regulatory standards and accreditation requirements or control frameworks (HIPAA, PCI, Joint Commission, NIST, Red Flags, ISO 27000 series).
Comprehensive knowledge of information security regulations, standards and leading practices, including understanding of EHR, cloud frameworks, identity access controls.
Good knowledge of basic database query techniques & data mining to analyze data or other related database functionality.
Knowledge of Microsoft Active Directory, UNIX, and Clinical Applications a plus.
Experience implementing application level security in clinical and financial systems (e.g., Epic, Lawson). ERP experience a plus.
General understanding of networking and communication techniques including WANs, LANs, Internet, Intranet, protocols, such as TCP/IP and their impact on security.
Microsoft, UNIX, Lawson, and Clinical Applications,
Experience with industry standard SDLC methodologies; hands-on experience in Project Server methodologies, PMO project management skills, including use of MS productivity tools (Access, Word, PowerPoint, Visio, Project).
Experience with risk management frameworks.
Information Security Requirements
Understand and comply with all enterprise and IS departmental information security policies, procedures and standards.
Support the integration of information security in the development, design, and implementation of Hospital Technology Resources that process, transmit, or store information.
Support all compliance activities related to state, federal regulatory requirements, healthcare accreditation standards, and all other applicable regulations that govern the use and disclosure of patient, financial, or other confidential information.
Daily Responsibilities
Optimizes information management approaches through an understanding of evolving business needs and technology capabilities and ensures that projects do not duplicate functionality or diverge from each other and business and DTS strategies.
Shapes, designs, and plans specific service lines in product area and manages the risks associated with information and DTS assets through appropriate standards and security policies.
Functions as the Subject Matter Expert (SME) to maintain an understanding of DTS business and clinical applications and the relationship to InfoSec and compliance solutions; assist Hospital stakeholders in understanding information protection needs that support the Hospital's business.
Works with other architects to provide a consensus based enterprise solution that is scalable, adaptable and in synchronization with ever changing business needs and takes ownership of a particular solution offering.
Works with highly matrixed team of DTS personnel to support enterprise architecture and information security operations including, but not limited to, architecture and InfoSec principles around identity & access management models, cloud identify management providers, security information and event monitoring, and data loss prevention, perimeter (e.g. firewalls, IPS, web filtering), cloud and virtualization environments and network security (host-based firewalls, anti-virus, disk encryption).
Support and/or lead activities around InfoSec standards for business continuity and change management activities (e.g., table tops and change review board) and educates DTS Hospital management on security issues (e.g., Identity and Access Management (IAM), Role Based Access Control (RBAC) models.
You will receive the following benefits:
Medical Insurance - Four medical plans to choose from for you and your family
Dental & Orthodontia Benefits
Vision Benefits
Health Savings Account (HSA)
Health and Dependent Care Flexible Spending Accounts
Voluntary Life Insurance, Long-Term & Short-Term Disability Insurance
Hospital Indemnity Insurance
401(k) including match with pre and post-tax options
Paid Sick Time Leave
Legal and Identity Protection Plans
Pre-tax Commuter Benefit
529 College Saver Plan
Motion Recruitment Partners (MRP) is an Equal Opportunity Employer. All applicants must be currently authorized to work on a full-time basis in the country for which they are applying, and no sponsorship is currently available. Employment is subject to the successful completion of a pre-employment screening. Accommodation will be provided in all parts of the hiring process as required under MRP's Employment Accommodation policy. Applicants need to make their needs known in advance.
Security Incident Response Engineer III
Security engineer job in Philadelphia, PA
Are you considering a new role in Cyber Security and want to work in a company that is helping to change the world? Consider joining an organization serving the global scientific research community, supporting the brightest minds on the planet.
Are you a collaborative Incident Response Engineer looking to work for a mission driven global organization?
About the role, Elsevier is expanding its Global InfoSec Security Incident Response team. As a Security Incident Response Engineer, you will play a crucial role in our internal security support team, assisting with incident response investigations.
This team is entrusted with analyzing, triaging, scoping, containing, and providing guidance for remediation, as well as determining the root cause of security incidents. This team also is empowered by collecting and analyzing security incident-related data to identify indicators of attack and compromise.
Responsibilities:
Assisting in scoping security incidents and identifying indicators of attack and compromise.
Analyzing incident data from threat analytics tools.
Communicating recommendations and guidance based on security incident analysis.
Coordinating responses to security incidents with other security and consulting teams.
Developing, documenting, and implementing runbooks, capabilities, and techniques for Incident Response.
Performing security triage and analysis on endpoint, server, and network infrastructure.
Conducting activities necessary for immediate containment and short-term resolution of incidents.
Maintaining current knowledge of the threat landscape, emerging security threats, and vulnerabilities.
Investigating the root cause of complex security incidents.
Maintaining a high level of confidentiality.
Requirements
Possess experience in cybersecurity incident response or related fields.
Proven ability to analyze, triage, scope, contain, and remediate security incidents.
Have current and extensive knowledge of security technologies, tools, and processes.
Experience with major cloud providers, including cloud security, networking, and multi-cloud or hybrid deployments.
Have current skills in automation using PowerShell, Python, Java, or similar languages.
Experience in Linux and/or Mac administration. Experience in Network Security Administration or Systems Administration.
Experience supporting large, complex, and geographically distributed enterprise environments.
Preferred certifications: CISSP, CISM, SANS, GIAC, ethical hacking/penetration tester, or security risk assessment.
Elsevier employs 10,000 people worldwide, including over 2,500 technologists. We have supported the work of our research and health partners for more than 140 years. Growing from our roots in publishing, we offer knowledge and valuable analytics that help our users make breakthroughs and drive societal progress.
Product Security Engineer
Security engineer job in Cleveland, OH
We are looking for a Contract Product Security Engineer to support vulnerability management initiatives within a product security organization. This role is ideal for a security professional who enjoys hands-on analysis, structured problem-solving, and improving security processes through automation and collaboration. You will work closely with engineering and security teams to help identify, assess, and prioritize security risks across software components.
The focus of this project is vulnerability management through Software Bill of Materials (SBOM) analysis. The engineer will review and triage vulnerabilities identified by SBOM scanning tools, assess risk and severity, and support remediation efforts in partnership with cross-functional teams. The role also includes enhancing vulnerability management workflows through scripting and automation, as well as maintaining clear documentation to ensure traceability and compliance within a structured development environment.
What we offer you in USA
We honor the contract terms you prefer.
20 paid vacation days per year
40 working hours per week
Retirement Plan 401(K)
Medical, Dental, Vision Insurance Plan for you and your Family
100% On-Site position in Newton
Responsibilities
Review, analyze, and triage vulnerabilities from SBOM scanning tools
Assess severity and support risk-based prioritization of remediation
Collaborate with engineering, security, and product teams to drive resolution
Track vulnerability status for timely closure
Develop or use scripts/automation to improve vulnerability management
Maintain clear documentation of findings and actions
Requirements
Experience in product security
Proficiency in Python or other scripting languages
Strong analytical skills and attention to detail
Effective collaboration with cross-functional teams
Nice to Have
Experience with vulnerability management programs
Exposure to regulated industries
Familiarity with SBOM management tools (e.g., Dependency Track)
OT Security Engineer
Security engineer job in Collegeville, PA
Must have an OT background with life sciences experience
Deliver OT security firewall policy design and document
Investigate and deliver appropriate OT architectures for RD systems
Troubleshoot connectivity issues experienced during migration activities
Must be proficient in Palo Alto
Must have an OT background with life sciences experience
Knowledge of supporting technologies, Zscaler, Cisco network infrastructure, Azure, and Google cloud
Good to have
Experience using ServiceNow Preferred RD lab experience, knowledge of lab systems, such as LIMS. HPLC etc
Experience with project software (ADO) Generic US or UK based (US preferred)
Good communicator, role requires frequent conversations with the business
Note : If you are interested please share me your resumes to ********************* or else reach me at **********.
Cloud Security Engineer - SRE
Security engineer job in Columbus, OH
Job Posting Title: Cloud Security Engineer - SRE
We are seeking a skilled and motivated Cloud Security Engineer - SRE to join our dynamic team. The ideal candidate will possess a strong technical background in systems administration, cloud computing, and infrastructure as code, with a particular focus on solution engineering/site reliability. This role will involve collaborating with cross-functional teams to enhance our security posture and streamline processes through automation.
Technical Skills
• Programming and Scripting: Strong proficiency in languages like Python, Go, Bash, or Ruby. SREs often need to write automation scripts and build tooling.
• Systems Administration: Deep understanding of operating systems (Linux/Unix), file systems, processes, and system configurations.
• Infrastructure as Code (IaC): Experience with IaC tools like Terraform, Ansible, or Chef to manage infrastructure.
• Cloud Computing: Knowledge of cloud platforms such as AWS, Azure, or Google Cloud Platform, including services like EC2, S3, Kubernetes, and serverless functions.
• Containers and Orchestration: Expertise in containerization (Docker) and container orchestration (Kubernetes, OpenShift).
• Networking: Understanding of networking concepts, including DNS, firewalls, load balancing, and VPNs.
• Monitoring and Observability: Experience with monitoring and observability tools like Prometheus, Grafana, Datadog, or New Relic. Ability to set up and maintain monitoring dashboards, alerts, and logs.
• Continuous Integration/Continuous Deployment (CI/CD): Familiarity with CI/CD tools like Jenkins, GitLab CI, GitHub Actions, or CircleCI.
• A strong understanding of HashiCorp Vault and Terraform will make you stand out.
2. Problem-Solving and Troubleshooting
• Incident Management: Ability to manage and respond to incidents, perform root cause analysis, and implement post-mortem reviews.
• Automation: Focus on automating repetitive tasks to improve efficiency and reduce human error.
• Performance Tuning: Skills in identifying and resolving performance bottlenecks in systems and applications.
3. Collaboration and Communication
• Teamwork: Ability to work closely with cross-functional teams, including software engineers, product managers, and DevOps teams.
• Documentation: Skill in creating clear and comprehensive documentation for systems, processes, and incident reports.
• Communication: Effective communication skills for interacting with stakeholders and explaining technical concepts to non-technical audiences.
4. Reliability and Scalability
• Service-Level Objectives (SLOs) and Service-Level Agreements (SLAs): Understanding of setting, monitoring, and maintaining SLOs and SLAs for system reliability.
• Scalability: Knowledge of best practices for designing and scaling systems to handle increased loads and demands.
• Redundancy and Resilience: Experience in designing systems with redundancy and fault tolerance to minimize downtime.
5. Security and Compliance
• Security Best Practices: Understanding of security principles, such as access control, data encryption, and secure coding practices.
• Compliance: Familiarity with compliance standards like GDPR, HIPAA, or PCI-DSS, depending on the industry.
Minimum Job Qualifications:
• Bachelor degree in business or equivalent work experience
• 10 years of previous program leadership and/or relevant consulting experience
• Knowledge of and demonstrated experience in program management framework, knowledge groups & life cycle
• 5+ years' experience in driving large scale data center consolidation efforts
• Minimum 5 years' experience with matrix management of cross-functional processes and teams
• Proficient with Project Management tools
Cyber Security Engineer
Security engineer job in Pittsburgh, PA
Title: Sr. Cloud Security Engineer
Seeking an experienced and dedicated Senior Cloud Security Engineer to join our team. This role is crucial for ensuring the security and compliance of our cloud infrastructure in a highly regulated financial environment. The ideal candidate will have a strong background in cloud security, a deep understanding of regulatory requirements, and the ability to design, implement, and maintain secure cloud solutions.
Primary Success Factors
Design, develop, and deploy scalable cloud-based security solutions to protect sensitive financial data and ensure compliance with industry regulations.
Perform comprehensive vulnerability testing, risk analyses, and security assessments to identify and mitigate potential threats.
Develop and coordinate robust cloud security procedures
Monitor for and respond to security incidents in the cloud environment, utilizing advanced security tools and techniques.
Collaborate with IT and development teams to ensure cloud solutions are securely integrated with existing software and infrastructure, following best practices and security standards.
Keep abreast of the latest security issues, regulatory changes, and industry trends to proactively address emerging threats.
Assist with the design of security training and awareness programs to educate staff about cloud security risks and responsibilities, fostering a culture of security within the organization.
Regularly report on the status of cloud security, including any breaches or vulnerabilities, to senior management and stakeholders.
Work with third-party vendors to ensure that security requirements are met and maintain strong relationships with external security partners.
Maintain compliance with all relevant security and privacy laws and regulations, including PCI-DSS, GDPR, SOX, and other industry-specific standards
Required Experience
Bachelor's or Master's degree in Computer Science, Information Security, or a related field. Specific experience will be considered in lieu of a degree.
Minimum of 7 years of experience
Relevant certifications in Cyber Security, with Cloud specific certifications a plus.
Proven experience in cloud security engineering, preferably in a financial institution, with a track record of successfully implementing secure cloud solutions.
Strong knowledge of cloud platforms and cloud security best practices, including identity and access management, encryption, and network security.
Experience with regulatory compliance frameworks such as PCI-DSS, GDPR, and SOX, and the ability to navigate complex regulatory environments.
Excellent problem-solving skills and the ability to work under pressure, with a proactive and detail-oriented approach to security.
Strong communication and collaboration skills, with the ability to effectively convey complex security concepts to both technical and non-technical audiences.
Experience with DevSecOps practices and tools, including continuous integration and continuous deployment (CI/CD) pipelines.
Knowledge of infrastructure as code (IaC) and automation tools, such as Terraform, Ansible, or CloudFormation.
Familiarity with security monitoring and incident response tools, such as SIEM, IDS/IPS, and EDR solutions.
Ability to deliver with minimal management oversight
Senior Cloud Security Engineer
Security engineer job in Pittsburgh, PA
Seeking an experienced and dedicated Senior Cloud Security Engineer to join our team. This role is crucial for ensuring the security and compliance of our cloud infrastructure in a highly regulated financial environment. The ideal candidate will have a strong background in cloud security, a deep understanding of regulatory requirements, and the ability to design, implement, and maintain secure cloud solutions.
Primary Success Factors
Design, develop, and deploy scalable cloud-based security solutions to protect sensitive financial data and ensure compliance with industry regulations.
Perform comprehensive vulnerability testing, risk analyses, and security assessments to identify and mitigate potential threats.
Develop and coordinate robust cloud security procedures
Monitor for and respond to security incidents in the cloud environment, utilizing advanced security tools and techniques.
Collaborate with IT and development teams to ensure cloud solutions are securely integrated with existing software and infrastructure, following best practices and security standards.
Keep abreast of the latest security issues, regulatory changes, and industry trends to proactively address emerging threats.
Assist with the design of security training and awareness programs to educate staff about cloud security risks and responsibilities, fostering a culture of security within the organization.
Regularly report on the status of cloud security, including any breaches or vulnerabilities, to senior management and stakeholders.
Work with third-party vendors to ensure that security requirements are met and maintain strong relationships with external security partners.
Maintain compliance with all relevant security and privacy laws and regulations, including PCI-DSS, GDPR, SOX, and other industry-specific standards
Required Experience
Bachelor's or Master's degree in Computer Science, Information Security, or a related field. Specific experience will be considered in lieu of a degree.
Minimum of 7 years of experience
Relevant certifications in Cyber Security, with Cloud specific certifications a plus.
Proven experience in cloud security engineering, preferably in a financial institution, with a track record of successfully implementing secure cloud solutions.
Strong knowledge of cloud platforms and cloud security best practices, including identity and access management, encryption, and network security.
Experience with regulatory compliance frameworks such as PCI-DSS, GDPR, and SOX, and the ability to navigate complex regulatory environments.
Excellent problem-solving skills and the ability to work under pressure, with a proactive and detail-oriented approach to security.
Strong communication and collaboration skills, with the ability to effectively convey complex security concepts to both technical and non-technical audiences.
Experience with DevSecOps practices and tools, including continuous integration and continuous deployment (CI/CD) pipelines.
Knowledge of infrastructure as code (IaC) and automation tools, such as Terraform, Ansible, or CloudFormation.
Familiarity with security monitoring and incident response tools, such as SIEM, IDS/IPS, and EDR solutions.
Ability to deliver with minimal management oversight
Senior Security Engineer
Security engineer job in Columbus, OH
We are looking for a Senior Security Engineer to work for our client. The ideal candidate aligns with the responsibilities and qualifications outlined below.
Responsibilities:
Design, implement, and maintain security solutions to protect enterprise systems and data
Conduct vulnerability assessments, penetration testing, and risk analysis
Develop and enforce security policies, standards, and best practices
Collaborate with IT and development teams to integrate security into system architecture
Monitor and respond to security incidents, ensuring timely resolution
Qualifications:
5+ years of experience in cybersecurity engineering or related roles
Strong knowledge of network security, application security, and cloud security principles
Experience with security tools such as SIEM, IDS/IPS, and endpoint protection
Familiarity with compliance frameworks (ISO, NIST, SOC, HIPAA)
Excellent problem-solving and communication skills
What Our Client Offers:
A critical role in safeguarding enterprise systems and sensitive data
Opportunities to work with cutting-edge security technologies and methodologies
A collaborative environment focused on innovation and resilience
Competitive compensation and comprehensive benefits
AI Security Analyst
Security engineer job in Allentown, PA
IT Security Analyst II - AI & Emerging Technology Security (Contract)
We are seeking a Junior to Mid-Level IT Security Analyst with hands-on exposure to AI, Generative AI, and Agentic AI security. This role supports a Product Security organization focused on implementing security guardrails for AI-enabled applications. You will work closely with Data, AI, and Product teams to secure machine learning pipelines, large language models, and agent-based systems in a cloud-native enterprise environment.
Key Responsibilities
Embed security controls into AI/ML models, LLM-based applications, and agentic workflows across the SDLC
Conduct security reviews of Generative AI, traditional ML models, and supporting data pipelines
Identify and mitigate AI-specific threats such as prompt injection, data poisoning, model abuse, and insecure agents
Support and apply AI security standards aligned with NIST, ISO, and emerging AI governance frameworks
Partner with legal, compliance, and privacy teams on AI risk management and regulatory requirements
Assist in evaluating and operating AI security and observability tools for model monitoring and data protection
Contribute to internal guidance and training on secure AI development practices
Required Qualifications
Bachelor's degree in Computer Science, Information Security, or related discipline
2+ years of experience in cybersecurity, with exposure to AI/ML environments
Experience with cloud-native security concepts and threat modeling
Understanding of AI/ML concepts including model training, inference, data labeling, and adversarial attacks
Familiarity with core security domains such as authentication, encryption, network security, and IAM
Strong communication and collaboration skills within agile or SAFe-based teams
Preferred / Nice-to-Have Skills
Experience with AI security platforms such as Zenity or HiddenLayer
Familiarity with Microsoft security and AI governance tooling, including:
Microsoft Defender for Cloud
Microsoft Defender for Cloud Apps
Azure AI Content Safety
Microsoft Purview (data governance / DLP)
Exposure to Power Platform, Power BI, or low-code environments, especially implementing DLP or data governance controls
Experience with AI model governance or AI security programs
Security or cloud certifications (e.g., CCSK, CEH, or AI-focused credentials)
Scripting or automation experience for security testing and validation
Senior Information Security Engineer
Security engineer job in Columbus, OH
Must Haves :
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field (Master's degree preferred).
- Minimum of 5-7 years of experience in cybersecurity or information security roles, preferably in a manufacturing or construction environment.
- Relevant certifications such as CISSP, CISM, CEH, or CompTIA Security+ are highly desirable.
- Strong knowledge of network protocols, firewalls, intrusion detection/prevention systems, and encryption technologies.
- Experience with security tools such as Splunk, CrowdStrike, Cisco Umbrella, Artic Wolf, or similar platforms.
- Proficiency in cloud security (e.g., AWS, Azure) and securing industrial control systems (ICS) is a plus.
- Familiarity with scripting languages (e.g., Power BI, Python, PowerShell) for automation and analysis.
Job Summary
The Senior Cybersecurity/Information Security Analyst will be responsible for overseeing all aspects of information security within the organization. This role involves designing, implementing, and monitoring security measures to protect systems, networks, and data from cyber threats. The ideal candidate will have extensive experience in cybersecurity, working with security SaaS providers, a proactive approach to identifying vulnerabilities, and the ability to collaborate across departments to ensure a secure enterprise environment.
Information Security Engineer - Infrastructure & Compliance(Only w2)
Security engineer job in King of Prussia, PA
Minimum Experience: 10+ Years
Key Responsibilities
Security & Compliance
Serve as divisional lead for NIST 800-171 control alignment, tracking, and remediation.
Partner with Internal Audit and Enterprise Security to review non-compliance findings and drive resolution.
Maintain and improve Defender for Cloud posture management across Azure infrastructure.
Identify, prioritize, and remediate vulnerabilities across infrastructure, networks, and systems.
Develop and implement Linux patch management strategy and compliance reporting.
Contribute to policy documentation and control evidence collection for SOX and NIST readiness.
Infrastructure & Cloud Security Operations
Work closely with Infrastructure, Cloud Ops, and Application teams to assess risk and prevent operational disruption.
Integrate security best practices into Azure, network, and datacenter operations.
Utilize Defender, Azure Security Center, and related tools to monitor and report on environment health.
Coordinate with Cloud and Systems Engineers to validate patch success, compliance metrics, and configuration baselines.
Automate recurring security validation and compliance tasks using scripting (PowerShell, Python, Bash).
Governance, Reporting, and Training
Maintain centralized tracking for security initiatives, audit remediations, and policy adherence.
Partner with PMs to ensure remediation workstreams are integrated into project schedules.
Support KnowBe4 phishing campaign analysis and contribute to security awareness reinforcement.
Report key risk indicators (KRIs) and compliance metrics to leadership.
Required Qualifications
8 years of experience in Information Security, Infrastructure Engineering, or Cloud Operations.
Proven experience with Defender for Cloud, Azure Security Center, or equivalent platforms (e.g., Tanium, Nessus, Qualys).
Working knowledge of NIST 800-171, NIST CSF, or ISO 27001 frameworks.
Experience managing patching and vulnerability remediation across Windows and Linux environments.
Proficiency with scripting or automation tools (PowerShell, Python, Bash).
Familiarity with Active Directory, Azure AD, and network security principles.
Preferred Qualifications
Experience with Fortify or similar static code analysis tools.
Familiarity with KnowBe4, VRX, or patch compliance tracking systems.
Exposure to Azure DevOps, IaC, and configuration-as-code methodologies.
Security or cloud certifications (e.g., AZ-500, Security+, CISSP, or equivalent).
Success Measures
Reduction in open audit findings and non-compliant controls.
Establishment of measurable Linux and infrastructure patch compliance reporting.
Defender for Cloud secure score improvement over baseline.
Defined and repeatable NIST alignment process for divisional systems.
Improved coordination between Infrastructure, Cloud, and Security teams during vulnerability remediation.
If I missed your call ! Please drop me a mail.
Thank you,
Harish
Accounts Manager/Talent Acquisition
Astir IT Solutions, Inc - An E-Verified Company
Email:*******************
Direct : ***********788
50 Cragwood Rd. Suite # 219, South Plainfield, NJ 07080
***************
Senior Cloud Security Engineer -- MAZDC5698278
Security engineer job in Pittsburgh, PA
Sales Representative -- Anindya Mazumdar
Role:
Not looking for an Architect - require individual heavy on engineering side / looking for a builder.
Strong background in cloud security, a deep understanding of regulatory requirements, and the ability to design, implement, and maintain secure cloud solutions
Design, develop, and deploy scalable cloud-based security solutions to protect sensitive financial data and ensure compliance with industry regulations.
Perform comprehensive vulnerability testing, risk analyses, and security assessments to identify and mitigate potential threats.
Develop and coordinate robust cloud security procedures
Monitor for and respond to security incidents in the cloud environment, utilizing advanced security tools and techniques.
Required:
Minimum of 7 years of experience
Relevant certifications in Cyber Security, with Cloud specific certifications a plus.
Proven experience in cloud security engineering, preferably in a financial institution, with a track record of successfully implementing secure cloud solutions.
Strong knowledge of cloud platforms and cloud security best practices, including identity and access management, encryption, and network security.
Experience with regulatory compliance frameworks such as PCI-DSS, GDPR, and SOX, and the ability to navigate complex regulatory environments.
Experience with DevSecOps practices and tools, including continuous integration and continuous deployment (CI/CD) pipelines.
Knowledge of infrastructure as code (IaC) and automation tools, such as Terraform, Ansible, or CloudFormation.
Familiarity with security monitoring & incident response tools, such as SIEM, IDS/IPS, and EDR solutions.
Information Security Specialist
Security engineer job in Horsham, PA
Delta Information Systems, Inc. is seeking a highly skilled Information Security Specialist to protect and secure critical systems, data, and intellectual property in a fast-paced Aerospace & Defense environment.
This role is responsible for implementing and managing security controls, ensuring compliance with strict regulatory requirements, and defending against advanced cyber threats. The ideal candidate will bring deep technical knowledge, strong problem-solving skills, and the ability to work across teams to maintain the confidentiality, integrity, and availability of sensitive information that supports our national security mission.
This is a fully onsite position located in Horsham, PA.
Key Responsibilities
Implement, monitor, and maintain security tools, including firewalls, intrusion detection/prevention systems, endpoint protection, and SIEM platforms.
Perform continuous monitoring, vulnerability assessments, penetration testing, and risk analysis of systems and networks.
Ensure compliance with DoD, NIST 800-171, CMMC, ITAR, DFARS, and other regulatory frameworks.
Champion the company's certification to CMMC Level 2.
Develop, document, and enforce cybersecurity policies, procedures, and incident response plans.
Support Government and customer security audits, preparing evidence and remediation plans as required.
Investigate and respond to cybersecurity incidents, performing root-cause analysis and recommending corrective actions.
Collaborate with IT, Engineering, Program Management, and Security teams to embed cybersecurity best practices into operations and product development.
Provide cybersecurity awareness training to employees with a focus on handling sensitive defense-related data.
Stay current on emerging cyber threats, nation-state tactics, and evolving compliance regulations impacting aerospace and defense.
Qualifications
Required:
Bachelor's degree in Information Security, Computer Science, or related field (or equivalent experience).
5+ years of experience in information security, IT security operations, or cybersecurity.
Strong knowledge of NIST 800-171, CMMC, and DFARS cybersecurity requirements.
Experience developing, implementing and achieving CMMC compliance.
Experience supporting DoD or government contracts with cybersecurity compliance needs.
Hands-on experience with security infrastructure: SIEM, IDS/IPS, endpoint security, and network monitoring tools.
Strong understanding of Windows, Linux, and cloud environments (Microsoft Office 365, Deltek Costpoint).
Excellent analytical, documentation, and communication skills.
U.S. Citizenship (required due to defense industry regulations).
Preferred:
Active security clearance (Secret or higher), or ability to obtain one.
Relevant certifications: CISSP, CISM, Security+, CEH, or GIAC.
Experience with RMF (Risk Management Framework) and STIG compliance.
Familiarity with secure software development, DevSecOps practices, or classified system security.
Compensation
Competitive salary
Outstanding benefits package
100% Paid Coverage for Medical, Dental, and Vision
401(k) Employer Match
Employee Stock Ownership Program (company funded)
Life Insurance (company funded)
Short-Term Disability (company funded)
Long-Term Disability (company funded)
Vacation & Sick
Holidays: 11 days
HealthCare FSA
Dependent Care FSA
What We Offer
Opportunities for training, certifications, and career growth.
A mission-driven culture where your work contributes to national security.
Exposure to advanced technologies and programs critical to the aerospace and defense sector.
About Delta Information Systems, Inc.
Delta Information Systems (DIS) is an industry-leading supplier of high-quality aerospace telemetry products for Flight Test, Missile Test, Range Safety, Launch Support and Satellite Command and Control applications. Their products address the complete telemetry chain from Data Acquisition, Storage, Transport and Distribution to Telemetry Processing and Display. DIS customers include all DoD entities, all Major Primes, Integrators, Gov Labs, Aircraft & Missile Manufacturers, & Launch Facilities.
In addition, Delta Information Systems (DIS) designs and develops sophisticated electronic equipment that is specifically designed to reliably operate in harsh environments. They deliver critical video communications capability for manned and unmanned Intelligence, Surveillance and Reconnaissance (ISR) programs.
Senior Lead Information Security Office (ISO) Consultant
Security engineer job in York, PA
At Capital One, you will help consult on initiatives, programs, and projects to raise their game in Information Security. You are pragmatic and practical in your understanding of risk and security, but also willing to know when to pull in experts and escalate. You collaborate and innovate with other teams within Capital One to push the envelope. You are comfortable with Cloud Service technologies like Security & Access Control Management, Identity & Access management and API Implementation and Management. You are familiar with various Cloud computing models to include IaaS, PaaS, and SaaS along with their architectural differences. Security is essential to what we do here, from protecting our customers to our associates.
Responsibilities:
Act as a central Information Security point of contact for Platform Messaging Services
Coordinate and execute proactive Information Security consulting to the business and technology teams covering Infrastructure Security, Data Security, Vulnerability Management, Network Architecture and Design, API security, and User Access Management
Serve as an expert in Capital One's Information Security capabilities, solutions, policies, procedures and standards
Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes
Escalate and manage cyber security risk
Provide ad hoc support on special Information Security hot topics for the business
Provide regular updates to executive leadership with your line of business on the overall Information Security health and risk environment
Work with line of business leadership to anticipate their objectives and needs to better serve the line of business
Work with line of business to identify risks with new and existing vendor relationships
Develop strategic objectives curated towards the line of business to support Cyber initiatives
About You:
You have a desire to work in a very fast moving, forward leaning, and modern computing environment
You have a deep passion for Securing modern computing platforms
You have a strong desire to continually learn about new technologies
You possess strong conceptual thinking and communication skills
You are able to work well under minimal supervision
You are a demonstrated leader with team-oriented interpersonal skills and the ability to interface effectively with a broad range of people and roles, including upper management, IT leaders, and technology vendors
You maintain calmness and clarity of thought under pressure and ability to maintain confidentiality
You have a deep understanding of strategic business objectives and the ability to drive results toward those objectives
Basic Qualifications:
High School Diploma, GED or equivalent certification
At least 6 years of experience working in cyber security or information technology
At least 5 years of experience providing guidance and oversight of cyber security concepts
At least 5 years of experience performing cyber security risk assessments or cyber security architecture reviews
At least 5 years of experience with software design, networking, or cloud infrastructure
Preferred Qualifications:
Bachelor's Degree
7+ years of experience in securing a public cloud environment (e.g. AWS, GCP, Azure)
At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, E-2, E-3, L-1 and O-1, or any EADs or other forms of work authorization that require immigration support from an employer).
The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.
McLean, VA: $225,400 - $257,200 for Sr Manager, Cyber Technical
Plano, TX: $204,900 - $233,800 for Sr Manager, Cyber Technical
Richmond, VA: $204,900 - $233,800 for Sr Manager, Cyber Technical
Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter.
This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.
Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website . Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.
This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections ; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.
If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1- or via email at . All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
For technical support or questions about Capital One's recruiting process, please send an email to
Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.
Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).
Network Engineer
Security engineer job in Maumee, OH
This position will work with team members to identify the needs of the business and partner with IT leadership to develop solutions to address those needs. In addition, this role will help plan and manage network related projects and will serve as a liaison between the business and technical aspects of assigned projects.
Our company believes in the Ideal Team Player. We follow the model behaviors of Humble (quick to point out the contributions of others), Hungry (self-motivated and diligent), Smart (socially appropriate and aware), Safety-Minded (works to lower safety risks, Quality-Minded (take pride in their work) and Attendance (recognizes their presence is important).
ESSENTIAL JOB DUTIES & RESPONSIBILITIES:
Duties may include the proposal, design, configuration, implementation, and maintenance of all aspects of The McAlear Group's computer networks. Including but not limited to routers, switches, access points, wireless, VPNs, firewalls, and telecommunications devices.
Monitoring of systems to assess or improve performance, reliability, and security.
Troubleshoot, resolve, and communicate issues in a timely and effective manner.
Display and maintain current knowledge and insight of networking and security best practices.
Create and update documentation critical to the operation of the network.
Effectively collaborate with team members and outside technology vendors.
Participate and assist in the development of disaster recovery procedures.
Responsible for updating and patching of network hardware and/or related software to mitigate security vulnerabilities and maintain stable operations of equipment.
Follow IT polices of incident management, change management, backup, upgrade, and maintenance.
Implement standards and operating procedures to ensure the integrity, consistency, security, quality, and performance of the network technology.
Provide configuration and support to virtual networking for VMware, vSphere, and MS Azure.
NON-ESSENTIAL JOB DUTIES & RESPONSIBILITIES:
Performs other related duties as assigned.
Ensure work area is clean and organized.
Attending team building events.
PHYSICAL DEMANDS & WORK ENVIRONMENT:
Prolonged periods sitting at a desk and working on a computer.
Must be able to lift fifteen pounds at times.
COMPENTENCY, KNOWLEDGE, SKILLS & ABILITIES:
Strong knowledge of Cisco, Meraki, and Aruba networking products and operating systems.
Ability to analyze, evaluate, identify, and rectify network issues.
In-depth understanding and practical knowledge of the OSI networking model required.
Excellent time management skills.
Ability to manage multiple projects simultaneously.
Experience and knowledge of on-premises network integration with cloud networks such as Microsoft Azure is strongly preferred.
Experience in a manufacturing environment with industrial specific network devices such as PLCs and production machinery will be considered a strong plus.
Ability to communicate technical information effectively to both technical and non-technical coworkers and management.
Ability to work independently and exceptionally with minimal direction and supervision.
EDUCATION & EXPERIENCE:
REQUIRED:
Associate degree or greater in a technology related field of study.
Industry certifications such as Cisco Certified Network Associate (CCNA), Cisco Certified Network Professional (CCNP), and CompTIA Security +
An equivalent combination of degree, certification, and/or relevant work experience will be considered.
Three to five years of professional experience.
PREFERRED:
BSc degree in Computer Science or relevant field
The McAlear Group offers a full range of benefits for eligible employee including 401k, health and life insurance, Employee Assistance Program (EAP), disability coverage, and PTO
Network Engineer
Security engineer job in Morgantown, WV
Our Client is headquartered in Morgantown, WV. The organization is committed to operational excellence, responsible energy development, and environmental stewardship. With expanding operations across Ohio and Pennsylvania, Our Client fosters a collaborative culture built on innovation, safety, and a deep connection to the communities they serve.
The Role
Our Client is seeking a skilled Network Engineer to take ownership of designing, securing, and maintaining the core network infrastructure that supports both corporate offices and remote field operations. This is not just about keeping systems running-it's about building a resilient, future-ready network environment that supports critical IT and OT systems. From cybersecurity to connectivity in rugged field locations, you'll be a trusted expert ensuring seamless and secure operations across the business.
Location
This role is hybrid, based in Morgantown, WV, with three days onsite each week. Up to 20% travel is expected to field locations, where you'll occasionally work outdoors in varied weather conditions and challenging terrain.
Key Responsibilities
Architect, deploy, and support network infrastructure across LAN, WAN, and cloud environments.
Ensure high availability and resilience of business-critical networks.
Configure, manage, and troubleshoot devices including routers, switches, firewalls, VPNs, and modems.
Monitor, analyze, and optimize performance to maintain secure and efficient connectivity.
Collaborate with telecom providers and vendors to ensure cost-effective, reliable service.
Deliver on-call support for mission-critical operations.
Document network diagrams, IP address management, and change control records.
Ensure compliance with IT policies, procedures, and security standards.
What You Bring
Bachelor's degree in Computer Science, Networking, or related field (or equivalent experience).
5+ years of hands-on experience in enterprise or industrial network engineering roles.
Expertise in Cisco, Juniper, or equivalent platforms.
Strong foundation in network security principles, including firewalls, ACLs, and secure remote access.
Experience supporting field infrastructure such as VSAT, LTE, or long-range wireless networks.
Oil and gas industry experience preferred.
Why This Opportunity?
As a Network Engineer with Our Client, you'll be more than a troubleshooter-you'll be a builder, innovator, and protector of the systems that keep a fast-paced energy company running. If you want a role where your work directly strengthens critical operations and cybersecurity, this opportunity is designed for you.
Network Engineer
Security engineer job in Pittsburgh, PA
OpenArc - Empowering Your Career. As a leading IT staffing firm, we are dedicated to connecting talented professionals with your ideal opportunities. We are currently seeking a qualified Network Engineer II to join our client's organization and contribute to their ongoing success.
Job summary
As the Network Engineer II, you are a part of a Global Engineering Operations Center helping multiple environments ranging in industries on their networking needs. This position requires you to have or obtain technical proficiencies within Cisco Route / Switch, Cisco ASA, F5, Riverbed, Citrix Netscaler, and more.
Responsibilities:
Troubleshooting experience with WAN technologies (MPLS, MetroE, VPLS, DMVPN)
Troubleshooting experience with various routing protocols (EIGRP, OSPF, BGP)
Troubleshooting experience with switching and Layer 2 issues (STP, MST, HSRP)
Requirements:
Knowledge and hands-on experience with designing and implementing hub-and-spoke networking configurations
Knowledge and hands-on experience with designing and implementing security devices (Cisco ASA, Cisco FirePower, Palo Alto, Checkpoint, Fortinet)
Knowledge and hands-on experience with load balancers and WAN optimization devices (F5, NetScaler, SilverPeak, Riverbed)
At OpenArc, we prioritize your career success and strive to build exceptional technical teams for our clients. By understanding your experience and aspirations, we ensure to present you with rewarding and fulfilling opportunities.
As an employee of OpenArc and our clients, you will be eligible to participate in a comprehensive benefits package.
OpenArc is an equal opportunity employer and will consider all applications without regards to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.
Network Engineer
Security engineer job in Columbus, OH
Senior Network Engineer - Hybrid (Columbus, OH) | Contract to Hire
We are seeking a Senior Network Engineer to design, implement, and manage enterprise network infrastructure across on-premises and cloud environments. This hybrid role requires candidates to live in Columbus, OH or the surrounding area. This is a contract-to-hire opportunity.
Key Responsibilities:
Design robust, scalable LAN, WAN, data center, wireless, and hybrid cloud networks.
Select appropriate networking protocols, technologies, and hardware (routers, switches, firewalls).
Implement network security best practices: segmentation, VPNs, ACLs, IDS/IPS, and encryption.
Integrate network infrastructure with servers, storage, virtualization, and cloud platforms.
Leverage network automation, APIs, and scripting to streamline processes.
Collaborate with stakeholders to deliver scalable, secure IT services.
Provide L4 production infrastructure support and document network designs and procedures.
Qualifications:
Bachelor's degree in Computer Science, IT, or related field (or equivalent experience).
5+ years of experience designing and implementing IT network solutions.
Expertise in VLANs, OSPF, BGP, VPN, DNS/DHCP/IPAM, and security systems.
Experience with Agile, ITSM/ITIL, and enterprise architecture practices.
Strong collaboration, problem-solving, and communication skills.
Skills:
Network architecture, cloud networking (SaaS/PaaS), and security.
System development lifecycle methodologies (Agile, DevOps, Waterfall).
Technology evaluation, budgeting, and process improvement.
WiFi Network Engineer || Only USC and Green Card
Security engineer job in Philadelphia, PA
Wi-Fi Network Engineer
Duration: 06+ Months
**Only US Citizen and Green Cad Required**
Skills required:
• Expert Level understanding of 802.11 networks and protocols 802.11n/ac/ax
• Good Wi-Fi knowledge (Tx pwr, MBR, OFDMA, AFC etc)
• Understanding 5 & 6GHz channels
• Hands on experience working on Wi-Fi tools like Ekahau, Hamina, WiFi explorer, Airtool
• Device log collection using Wi-Fi mega profile and other
• Understanding WiFi packet capture flow & ability to capture PCAPs
• Basic core networking knowledge
• POE standard awareness
• Controller based network experience.
• Reporting using Excel, power point
• Google earth knowledge (good to have)
• Good to have: if that person has worked with Extreme gears before but not a big deal, any controller based network experience should work
Thank You
Aakash Dubey
************************