Cyber Sentinel Skills Challenge
Security Engineer Job 212 miles from Idaho Falls
Correlation One is hosting the Cyber Sentinel Skills Challenge, a unique, one-day cybersecurity competition sponsored by the U.S. Department of Defense (DoD). Win your share of a $15,000 prize pool, solve fun cybersecurity challenges, and access new job opportunities at the DoD.
This event is designed to help you:
Unlock career opportunities and get on the radar of DoD recruiters
Test your skills and gain experience solving some of the most pressing security threats globally through 20+ Capture the Flag-style simulations
Connect with your peers and build a strong, supportive network of cybersecurity professionals
Competition details:
When: June 14, 2025
Where: Virtual
Duration: 8 hours (11am - 7pm ET)
Cost: Free
Early application deadline: May 6, 2025
Total prize pool: $15,000
Experience required: All levels of cybersecurity are welcome
Challenge categories: Forensics, Malware/ Reverse Engineering, Networking & Reconnaissance, Open-Source Intelligence Gathering (OSINT), Web Security
About you:
You must be a U.S. Citizen or a permanent resident with a valid Green Card.
You must be over the age of 18.
Individuals from all levels of cybersecurity experience, whether you are a seasoned cybersecurity professional or just starting in the field, are welcome to apply.
Security Engineer - Surface Coverage, Detection Engineering
Security Engineer Job 212 miles from Idaho Falls
Meta's security team is the central engine driving data and system security. We work across all parts of the company, from corporate infrastructure to production to external services, interfacing with nearly every team in the company.We are looking for a Security Engineer with experience influencing, mentoring, and contributing alongside teams of engineers who focus on threat modeling, TTP identification, and detection engineering securing Meta's surfaces. You'll work alongside Software Engineers, Offensive Security Engineers, Product Managers, and Data Scientists/Engineers to identify critical assets, assess the top risks, and evaluate potential attacks against Meta systems. You will be working with engineering teams supporting Meta's products (including WhatsApp, Instagram, Horizon Worlds, Threads, and others) serving over 3.2 billion daily active user working to understand existing detection coverage, enumerating gaps, and presenting findings to product, security, and legal senior leaders to drive decisions around multi-year risk mitigation efforts.
**Required Skills:**
Security Engineer - Surface Coverage, Detection Engineering Responsibilities:
1. Influence and align the organization's vision and strategy, while engaging our teams to develop and deliver specific, multi-year roadmaps, programs, and projects
2. Collaborate with various functions, drive engineering initiatives and have an impact at an organizational level
3. Lead technical design and strategy leveraging insights from some of the most advanced infrastructure in the world
4. Partner with leadership to influence and drive org design, contribution and prioritization
5. Coach, mentor, support, and care for the team in a way that enables long-term career development, happiness, and success at scale
6. Leverage state-of-the-art graph-based TTP to asset mapping systems to enumerate transitive detection coverage and develop novel approaches to prioritize and scale Product-specific infrastructure coverage
7. Build, cultivate, and maintain positive relationships with cross-functional partners to enable the team's ability to effectively and efficiently execute on project work
8. Assist with hiring, growing, and building a high performing team capable of achieving the team's mission
9. Work across partners in Product Management, Data Science, and Data Engineering to design and iterate on metrics and goals related to attack enumeration and detection coverage and validation
**Minimum Qualifications:**
Minimum Qualifications:
10. 12+ years of work experience in software or security engineering
11. BS in Computer Science or equivalent experience in Security
12. Demonstrated experience in working across organizational boundaries to achieve company-wide impact
13. Experience leading and managing complex cross-functional programs
14. Knowledge of Windows, MacOS, and Linux operating systems, container orchestration, hypervisors, and distributed system security
15. Experience with an interpreted programming language (PHP, Python, Perl, Ruby, etc.)
16. Experience with attacker tactics, techniques and procedures
**Preferred Qualifications:**
Preferred Qualifications:
17. Demonstrated experience in one or more Security domains such as Detection Engineering, Product Security, Cloud Security - Web Application Security experience across the Software Development Lifecycle is a plus
18. Experience working with Legal and Governance, Risk, and Compliance teams to understand and address complex and emerging regulatory requirements
19. Background in security-focused software engineering, designing large scale systems and data pipelines, or in offensive security
20. Demonstrated experience launching, scaling, and obtaining buy-in from Product VP stakeholders on a complex multi-year security initiative
21. Experience in threat hunting including leveraging intelligence data to proactively identify and iteratively investigates suspicious behavior across networks and systems
**Public Compensation:**
$213,000/year to $293,000/year + bonus + equity + benefits
**Industry:** Internet
**Equal Opportunity:**
Meta is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Meta participates in the E-Verify program in certain locations, as required by law. Please note that Meta may leverage artificial intelligence and machine learning technologies in connection with applications for employment.
Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at accommodations-ext@fb.com.
Security Architect
Security Engineer Job 29 miles from Idaho Falls
Are you someone who never rests on their laurels, always strives to go above and beyond, and is committed to keeping your PROMISES? Do you appreciate a company culture that is open, fosters work-life balance, and a dynamic team environment? Then Old Dominion is the home for you. We take pride in being the best in the industry, and from our humble beginnings we know that our People and our Family Spirit are the main ingredient in our secret sauce to success. At Old Dominion we are looking for individuals to join the OD Family that will provide innovative solutions and exceed expectations to keep OD the premier transportation solutions provider.
As the Cybersecurity Architect at Old Dominion Freight Line, you will play a critical role in designing, implementing, and maintaining a comprehensive cybersecurity architecture to safeguard the integrity, confidentiality, and availability of the organization's information systems and data. You will lead the development of cybersecurity strategies, provide expert guidance on technical security solutions, and ensure the effective implementation of security controls to mitigate risks across the enterprise. This position requires a high level of technical expertise, strategic thinking, and the ability to collaborate across teams to support business continuity and protect the organization from cyber threats.
Primary Responsibilities
* Lead the development and implementation of a comprehensive cybersecurity architecture strategy aligned with Old Dominion's business objectives and security goals.
* Design secure IT environments and systems, including network security, cloud architecture, endpoint security, identity and access management, and data protection, while ensuring compliance with regulatory requirements and industry best practices (NIST, ISO 27001, SOC 2, etc.).
* Architect and implement security controls for on-premises and cloud-based infrastructure, focusing on scalability, resilience, and defense-in-depth principles.
* Conduct thorough risk assessments of current and emerging technologies, systems, and software applications to ensure they meet security standards and policies.
* Develop, implement, and maintain a cybersecurity governance framework, including policies, procedures, and standards to guide security practices across the organization.
* Collaborate with senior leadership to define the organization's cybersecurity strategy, risk appetite, and incident response framework.
* Oversee the integration of security tools and platforms (SIEM, IDS/IPS, vulnerability management, etc.) into the enterprise's existing IT architecture.
* Ensure compliance with relevant security frameworks, including NIST Cybersecurity Framework, CCPA, PCI-DSS, HIPAA, and others applicable to logistics and transportation industries.
* Monitor and assess emerging cybersecurity threats, vulnerabilities, and attack vectors, recommending proactive measures to mitigate risk to business-critical systems.
* Lead vulnerability assessments and penetration testing efforts, working closely with internal teams and third-party security consultants to identify weaknesses and implement corrective actions.
* Establish a robust vulnerability management process, ensuring timely remediation of critical security issues.
* Develop and maintain incident response plans and processes to ensure quick identification, containment, and resolution of cybersecurity incidents, with a focus on minimizing business disruption.
* Lead incident response efforts, providing expert guidance on detection, analysis, forensics, and post-mortem evaluations.
* Work closely with legal, compliance, and communication teams to ensure incidents are managed effectively, with proper escalation, documentation, and reporting procedures in place.
* Collaborate with IT infrastructure, network, and development teams to design secure solutions that align with business requirements and security best practices.
* Provide cybersecurity leadership and training to staff across departments, increasing awareness of cyber risks and promoting security best practices.
* Serve as a technical leader and mentor for cybersecurity engineers and analysts, fostering a collaborative environment focused on continuous improvement.
* Lead the assessment and management of third-party risks, ensuring that external vendors and partners adhere to Old Dominion's cybersecurity requirements.
* Conduct due diligence for third-party software and services, identifying and mitigating potential security risks associated with outsourcing and vendor relationships.
Job Qualifications
Education:
* Bachelor's Degree in Cybersecurity, Information Technology, Computer Science, or a related field. Master's degree preferred.
Experience:
* Minimum of 10+ years of experience in cybersecurity, with at least 5 years in a leadership role or as a cybersecurity architect.
* Extensive experience in security architecture design, particularly in enterprise environments, covering network, cloud, data, and endpoint security.
* Deep understanding of cybersecurity frameworks (e.g., NIST CSF, ISO 27001, CIS) and experience applying them within a large, complex organization.
* Strong knowledge of security technologies such as firewalls, intrusion detection/prevention systems (IDS/IPS), VPNs, SIEM, DLP, endpoint protection, and encryption solutions.
* Proficiency in cloud security (AWS, Azure, Google Cloud), including secure cloud architecture, identity and access management, and cloud-native security services.
* Experience in vulnerability management tools (e.g., Rapid7, Qualys, Nessus), penetration testing methodologies, and risk management platforms.
* Familiarity with regulatory compliance requirements, such as CCPA, HIPAA, PCI-DSS, and others relevant to transportation/logistics.
* Advanced knowledge of threat intelligence and incident response frameworks, including hands-on experience in threat hunting and managing real-time security incidents.
* Strong understanding of the SDLC and secure development practices, with experience in DevSecOps integration.
* Preferred Experience:
* Professional certifications, such as CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), CISA (Certified Information Systems Auditor), or AWS Certified Security - Specialty.
* Experience with automation and orchestration tools in a security context (e.g., SOAR, Ansible, Terraform).
* Advanced knowledge of networking protocols and technologies (e.g., TCP/IP, VPNs, DNS, HTTP/HTTPS).
* Experience with the logistics and transportation industry and understanding the specific security challenges and regulatory requirements in this sector.
Compensation Range:
The referenced salary range is based on the Company's good faith belief at the time of posting. Actual compensation may vary based on factors such as geographic location, work experience, market conditions, education/training and skill level.
($139,078-$173,826)
Working Days:
Shift and hours to be determined.
Working Shift:
Shift and hours to be determined.
Work Days and Shift are estimates and are subject to change, at any given time, based on job scheduling and/or business levels. Any information listed regarding Days and Shifts shall be considered a guideline of expectations for the specific position at the time of posting.
Application Window:
Ongoing
Candidates are encouraged to apply as soon as possible. Old Dominion plans to screen candidates, conduct interviews, and proceed with hiring candidates to meet its business needs, which may result in filling the role before the current anticipated application window closes.
Join the OD Family Today!
As a Full Time member of our Family, you and your family are eligible to receive:
* Great Health Benefits including a Zero premium medical plan for employee only coverage
* Vision & Dental
* Short Term & Long Term Disability
* Flex Spending Accounts
* 401k Retirement plan with company match and additional company annual discretionary match opportunity
* Life Insurance
* Wellness Program
* 12 Days Paid Time Off
* 9 Paid Holidays including a birthday holiday
* Training and growth opportunities to build a career
* We prioritize our OD family of employees
* Ability to advance through our promote from within philosophy
* National Career Opportunities Available at our 260+ service centers
Old Dominion Freight Line, Inc. is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, gender identity, and/or gender expression, sexual orientation, age, disability, pregnancy, genetic information, military status, Vietnam Era and/or veteran status, or any other characteristic protected by applicable law(s).
If you have questions regarding this posting or require assistance with the application process, please click here for contact information.
Sr Audit Analyst, Info & Cyber Security Risk Mgmt
Security Engineer Job In Idaho Falls, ID
****Candidate must be able to work in the PST timezones. ***** This position will execute the Information and Cybersecurity Risk Management programs, concentrating on internal and third-party risk assessments and audits. Assessment and compliance activities include validating controls in the IT department, managing risk findings, and verifying their remediation. Must have excellent written and verbal communication skills and a strong understanding of IT risks, cloud security, application systems security, and third-party security. Must be results-oriented with the ability to collaborate with multiple process owners and stakeholders simultaneously.
**ESSENTIAL FUNCTIONS**
**Duties and Responsibilities**
+ Lead, plan, and conduct periodic cyber and information security risk assessments and audits of third parties enterprise-wide.
+ Identify, assess, and document cybersecurity risks for Molina and its suppliers.
+ Partner with internal and external auditors to facilitate compliance audits and mitigate findings.
+ Manage documentation (e.g., requesting, reviewing, preparing) for regulatory and compliance audits & assessments.
+ Ensure compliance with applicable regulations (e.g., HIPAA, NYS DFS) and industry standards (e.g., NIST).
+ Develop and maintain security policies, plans, charters, standards, and procedures.
+ Promote security awareness through communication, training, and documentation.
+ Develop and maintain dashboards to manage and communicate risk to relevant stakeholders.
+ Develop and monitor metrics and prepare reports for senior management.
+ Monitor the inventory for vendors and suppliers.
+ Identify risks and recommend process improvements in the third-party risk management and supply chain program.
+ Build strong partnerships and collaborate with cross-functional teams.
+ Lead and execute third-party risk mitigation strategies and corrective action plans.
+ Monitor and manage third-party risks using GRC and security tools.
+ Stay current on developments in the industry and within the company.
**Qualifications**
+ Bachelor's degree in Information Systems/Security, Computer Science, Cybersecurity, or related field.
+ Minimum 5 years relevant experience in cybersecurity with a focus on governance, risk and compliance.
+ Professional certification(s) such as Certified Information Systems Auditor (CISA), Certified Information Systems
+ Security Professional (CISSP), or Certified in Risk and Information Systems Control (CRISC) required.
+ Adaptable to fast-changing environments and comfortable with ambiguity.
+ Excellent verbal, written, and interpersonal skills.
+ Big 4 or consulting experience.
+ Strong proficiency in regulations and industry frameworks (e.g., HIPAA, NIST, HITRUST)
+ Experience with GRC and security performance monitoring tools (e.g., Lockpath, ServiceNow, Prevalent, BitSight).
+ Ability to travel approximately 10%
To all current Molina employees: If you are interested in applying for this position, please apply through the intranet job listing.
Molina Healthcare offers a competitive benefits and compensation package. Molina Healthcare is an Equal Opportunity Employer (EOE) M/F/D/V.
Pay Range: $77,969 - $137,000 / ANNUAL
*Actual compensation may vary from posting based on geographic location, work experience, education and/or skill level.
Network Security Administrator
Security Engineer Job In Idaho Falls, ID
Discover the Westmark Difference!!
Are you looking for a career? Do you want to be valued as an individual on a team? Do you want to learn, grow, and make a difference in your community? Westmark offers outstanding stability, a variety of career opportunities and exceptional work/life balance.
· 60 % of our employees have been part of the Westmark family for 5+ years.
· 71% of our employees who have been part of the Westmark family for one year or more have received at least one promotion.
· 85% of our managers were promoted from within the company.
· Westmark has been in business since 1954 and has recently grown to over $1.2 billion in assets, 15 branches, and over 70,000 members!
We also have some of the most impressive benefits in the industry:
· Paid Time Off (3 to 5 weeks per year, depending on tenure) PLUS 11 paid holidays.
· Excellent health insurance options for employees and family with shared premiums
· 401k with 75% company match and 2% profit sharing contribution
· Tuition Reimbursement and Scholarships
· Employee Assistance Program (Free counseling and legal services)
Position Summary: The Network Security Administrator is responsible for ensuring the protection of sensitive information within the credit union's computer systems, servers, and network devices. This position supports multiple security programs, including internal IT system audits, social engineering testing, and security investigations. The role requires monitoring network traffic, conducting risk assessments, and implementing security procedures to maintain regulatory compliance.
Travel Requirements: Occasional travel for support at company locations or as needed
Schedule: Approximately 40 hours within a Monday through Friday work week
Key Responsibilities:
Install, administer, and troubleshoot security solutions for the credit union.
Collaborate with the Information Security Officer to ensure policies and procedures meet regulatory compliance.
Provide reports for security audits and assessments.
Educate employees on network security through practical testing and awareness programs.
Manage firewall configurations, access control, and security updates.
Configure and maintain Intrusion Detection Systems and Demilitarized Zone (DMZ) security.
Monitor and analyze network traffic to identify potential security threats.
Conduct vulnerability and risk assessments, recommending and implementing remediation measures.
Maintain system event logs and establish baseline activity to detect anomalies.
Test antivirus protections to ensure functionality and effectiveness.
Participate in regulatory examinations, internal audits, and incident response activities.
Stay current on emerging security threats and best practices.
Work with third-party vendors on risk assessments and regulatory compliance testing.
Perform other security-related duties as assigned.
Requirements
Qualifications:
Degree in MIS, Computer Science, or a related field, or equivalent education and experience.
2-3 years of experience in an IT department or data center with network and security responsibilities.
Strong analytical and problem-solving skills.
Self-motivated with the ability to work independently and as part of a team.
Ability to work weekends or after hours as needed.
Valid Driver's License and ability to travel as required.
Technical Skills:
Expertise in data networks, Linux & Microsoft Windows OS, PC software, and hardware.
Proficiency in WAN, LAN, Cisco Firewalls, Routers, Switches, Wireless APs, and Intrusion Detection Systems.
Experience with SIEM solutions, event logging, and DLP solutions.
Ability to analyze and investigate phishing emails and train end users.
Knowledge of scripting languages such as PowerShell and Python.
Familiarity with security tools and industry best practices.
Key Competencies:
Strong communication and interpersonal skills.
Ability to conduct staff awareness training and security testing.
Capacity to identify and troubleshoot security-related issues across various platforms.
Attention to detail and ability to document security activities accurately.
Commitment to continuous learning and staying updated on cybersecurity trends.
Physical Requirements:
Ability to travel to various credit union branches as needed, including overnight stays.
Capability to work extended hours, including weekends, for critical security updates or incidents.
Ability to lift and transport computer hardware as required.
This position plays a crucial role in maintaining the security and integrity of the credit union's network, ensuring compliance with industry standards, and safeguarding sensitive information against potential threats.
Westmark Credit Union is an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.
Senior Security Engineer, Cyber Risk Management
Security Engineer Job 401 miles from Idaho Falls
Headquartered in Dublin, Ohio, Cardinal Health, Inc. (NYSE: CAH) is a global, integrated healthcare services and products company, providing customized solutions for hospitals, health systems, pharmacies, ambulatory surgery centers, clinical laboratories and physician offices worldwide.
The company provides clinically-proven medical products and pharmaceuticals and cost-effective solutions that enhance supply chain efficiency from hospital to home. Cardinal Health connects patients, providers, payers, pharmacists and manufacturers for integrated care coordination and better patient management. Backed by nearly 100 years of experience, with approximately 50,000 employees in 46 countries, Cardinal Health ranks among the top 15 on the Fortune 500.
We currently have a full-time job opening for a Senior Security Engineer of Cyber Risk Management
_Department overview:_
Information Security and Risk Management (ISRM) at Cardinal Health enables Cardinal Health to securely deliver healthcare products and solutions that improve the lives of people every day by ensuring security and controls are embedded into Cardinal Health's people, process and technology. The Cyber Risk and Customer Security Assurance team fulfils our mission to strengthen our shield against cyber threats by providing a framework of processes and methodologies to manage Cardinal Health's cybersecurity risks through issue and exception management, cyber risk management, and customer third party risk assessment engagement.
Job Summary
Sr. Engineer, Cyber Risk Management, applies knowledge of Information Security, Risk Management, and Information Technology to lead the maturity of our Cyber Risk program. The primary responsibility of this role is to collaborate across the enterprise to measure the impact and likelihood of a variety of Cyber Risks.
This role is a senior position within the team and will work with all members of the Information Security team as well as Senior Leadership, Enterprise Risk Management, Business leaders, and IT teams.
Responsibilities:
+ Provide senior leaders and executives with information summarized at the correct level to make efficient, cost-effective, risk management decisions about the technology and information processing supporting their business functions
+ Work with all members of the Information Security team to drive information risk governance processes throughout the Cardinal Health enterprise
+ Implement the information risk management framework and related governance processes to cover not just the IT function, but all technology and information processing regardless of where the processing is in the enterprise (e.g., "shadow IT", manufacturing systems, operational technology, etc.)
+ Leverage and integrate with existing IT risk management and risk escalation / approval processes
+ Create an information risk register that catalogs key IT risks through an ongoing "top-down" risk assessment process
+ Define processes for summarizing "bottom-up" risk identified throughout various risk and compliance activities to add to risk register
+ Define and measure risk metrics that can be used to evaluate risk trends
_Qualifications:_
+ Excellent written and verbal communication skills
+ Experience in Information Technology, Information Security, and Risk Management
+ Experience implementing and maintaining processes at large enterprises
+ Experience with IT security principles, practices, technologies, programs and procedures, accompanied by an understanding of risk management methodologies and cybersecurity assessment frameworks
+ High-quality analytical skills, relationship management competencies
+ Relevant Information Security Certifications
**Anticipated salary range:** $121,600 - $182,385
**Bonus eligible:** Yes
**Benefits:** Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
+ Medical, dental and vision coverage
+ Paid time off plan
+ Health savings account (HSA)
+ 401k savings plan
+ Access to wages before pay day with my FlexPay
+ Flexible spending accounts (FSAs)
+ Short- and long-term disability coverage
+ Work-Life resources
+ Paid parental leave
+ Healthy lifestyle programs
**Application window anticipated to close:** 4/27/2025 *if interested in opportunity, please submit application as soon as possible.
The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.
_Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply._
_Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal_ _Opportunity/Affirmative_ _Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law._
_To read and review this privacy notice click_ here (***************************************************************************************************************************
Security Analyst
Security Engineer Job In Idaho Falls, ID
Description & Requirements Maximus has an exciting opportunity to join their team supporting a Federal financial client. This is a remote position. As a Security Analyst you will have the chance to: - Proactively monitor vulnerability scans from multiple Security tools, ensuring identification as early as possible and generating remediation tickets in Jira
- Support end-to-end ownership of security vulnerabilities from identification through deployment
- Actively engage with client stakeholders (IT and Security Teams), leading discussions and communication on status and remediation for vulnerabilities stemming from injection threats, authentication and access control, data handling, configuration issues, and outdated software,
- Perform evaluations of vulnerability findings to include the ability to effectively detect false positives produced from security scanning tools, and validate the remediation steps performed by development and infrastructure teams
- Conduct investigations into security vulnerabilities and develop remediation actions that a developer or engineer could use in the mitigation of the threat
- Develop and update required security-related documents (System Security Plan, Security Impact Analysis, Privacy Impact Analysis, etc.) and lead cross-team collaboration to fulfill CIO security policies as needed
Maximus TCS (Technology and Consulting Services) Internal Job Profile Code: TCS056, T2, Band 5
Job-Specific Minimum Requirements:
- Due to Fedderal requirements, all candidates must be US citizens and be able to pass a clearance process for a position of Public Trust
- 3+ years of direct experience in IT (preferably Security focused)
- Scripting experience in one or more of the following: Bash, Python, PowerShell
- Operating Systems Experience: Both Linux/Unix and Windows
- Experience reviewing findings in one or more of the following scanning tools: Tenable, BurpSuite, RedHat ACS, Veracode, Contrast, Imperva or similar scanning tools
- Certifications (one or more): Security+, A+, Network+, Certified Ethical Hacker (CEH)
- Excellent analytical and problem-solving skills, particularly as it applies to IT security
- Excellent time management and organizational skills, and ability to handle multiple concurrent tasks and projects with minimal supervision
- Proven ability to coordinate vulnerability fixes across development and infrastructure teams to reach an issue resolution in a timely manner
- Demonstrated ability to build trusted advisor relationships with clients
- Experience leading oral presentations to IT Security stakeholders and senior leadership
- Proficient with technical documentation, especially with experience in write-ups on IT Security topics
Preferred Skills and Qualifications:
- Advanced Excel knowledge (i.e. vlookups, pivot tables)
- Ability to work with Business Intelligence developers in providing requirements for systems and dashboards that normalize security data/findings and lead to efficiencies with vulnerability management through a disciplined prioritization process.
- Experience working in a scaled Agile environment with 10+ teams which include development and shared services, using Jira, Confluence, SharePoint, or similar documentation and ticketing tools
- Familiarity with the key components of the White House's Zero Trust policy
- Bachelor's Degree in Computer Science, Cybersecurity or a related technical field
- Familiarity with the Authority to Operate (ATO) policy which Information systems within government departments/agencies must comply with. Ideally, the candidate would have experience with a continuous ATO (cATO) process.
- Support new business development opportunities at Maximus by lending IT security experience and expertise to proposals and past performance briefs
#techjobs #clearance
Minimum Requirements
TCS056, T2, Band 5
EEO Statement
Maximus is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, age, national origin, disability, veteran status, genetic information and other legally protected characteristics.
Pay Transparency
Maximus compensation is based on various factors including but not limited to job location, a candidate's education, training, experience, expected quality and quantity of work, required travel (if any), external market and internal value analysis including seniority and merit systems, as well as internal pay alignment. Annual salary is just one component of Maximus's total compensation package. Other rewards may include short- and long-term incentives as well as program-specific awards. Additionally, Maximus provides a variety of benefits to employees, including health insurance coverage, life and disability insurance, a retirement savings plan, paid holidays and paid time off. Compensation ranges may differ based on contract value but will be commensurate with job duties and relevant work experience. An applicant's salary history will not be used in determining compensation. Maximus will comply with regulatory minimum wage rates and exempt salary thresholds in all instances.
Minimum Salary
$
110,000.00
Maximum Salary
$
135,000.00
Information System Security Engineer
Security Engineer Job In Idaho Falls, ID
Information System Security Engineer - (22801) Description Idaho National Laboratory is hiring a Classified Information System Security Engineer (ISSE) to work on our Classified Cybersecurity team. Our team works a 9x80 schedule located out of our Research Education Campus (REC) facility in Idaho Falls with or every other Friday off.
As a member of the Classified Cybersecurity organization, the Classified Information System Security Engineer (ISSE) is responsible for the execution of information system security functions and infrastructure maintenance and operations to ensure secure, reliable, uninterrupted availability of the INL National Security Systems in accordance with INL, DOE, DOD, and NIST security guidelines and requirements.
Responsibilities Include:
Responsible for the execution of information security functions and infrastructure maintenance and operations to ensure secure, reliable, uninterrupted availability of the INL National Security Systems in accordance with INL, DOE, DOD, and NIST security guidelines and requirements.
Performs configuration, administration, and maintenance on classified Microsoft Windows Servers (AD, DNS, DHCP, Exchange), Microsoft Windows desktops, VMWare infrastructure, zero-client infrastructure, Splunk infrastructure, RSA infrastructure, End-point Detection and Response (EDR) tools, and PKI management.
Performs NIST 800-53, and CNSSI-1253 information security control implementation and auditing, self-auditing of DISA STIG requirement implementation and remediation, and classified infrastructure formal audit preparation.
Performs NSS infrastructure lifecycle planning/management per NNSA CSSP requirements and is responsible for classified equipment inventory dispositioning (e.g. deployment, auditing, and destruction).
Responsible for CSSP monthly report metrics input, participates in NNSA Enterprise IT Change Control Board, supports Nessus vulnerability scanning and reporting, and Splunk log forensics.
Supports NNSA Cybersecurity Service Provider (CSSP) remote activities at INL IAW CSSP requirements.
Qualifications Minimum Requirements:
Level 2: Bachelor of Science in related field plus 2 years' relevant experience or Masters in related field.
Level 3: Bachelor of Science in related field plus 5 years' relevant experience or Masters in related field plus 2 years' relevant experience.
In leiu of degree, a High School Diploma or equivalent and at least 8 years of direct professional experience, or a High School Diploma or equivalent and at least 11 years of direct professional experience.
Relevant degrees consist of, but not limited to: Cybersecurity, Computer Science, Information Technology.
Must be a US Citizen and have an active DOE “Q” or equivalent DOD/DOJ security clearance.
May be required to obtain and maintain additional security clearance level of Human Reliability Program (HRP) certification.
Ideal Candidate will have:
Relevant certifications: CISA, CEH, CISSP, CISM, Security+, CASP+, Splunk Certified User, Power User, or Administrator, US Navy IT A School
Splunk experience
Direct technical experience working in a classified environment
IT Support
National Security Systems (NSS)
Operational security control implementation (e.g. NIST, CIS, STIG, etc.)
Cybersecurity
Communication Security (COMSEC)
Public Key Infrastructure (PKI)
Configuration Management
Job Information:
The pay range for this position is: Level 2 ($65,064 - $133,416) / Level 3 ($77,628 - $159,228). At Idaho National Laboratory compensation decisions are determined using factors such as education, relevant experience, and other credentials.
TDP: This is a testing designated position; you will be required to submit to a pre-employment drug screen and periodic drug testing throughout the term of your employment.
Multi-Level: This is a multi-level posting and you will be placed at the appropriate level dependent on depth and breadth of proven experience and skills.
Benefits and Relocation
Medical, Dental, Vision, and Flexible Spending Accounts
401(k) with a 4.2% employer contribution and up to 4.8% match
Paid time off (personal leave)
Employee Education Program (tuition assistance)
Comprehensive Relocation Package
Benefit eligibility subject multiple factors, including employment status and position classification.
INL is a science-based, applied engineering national laboratory dedicated to supporting the U.S. Department of Energy's mission in nuclear energy research, science, and national defense. With more than 5,000 scientists, researchers, and support staff, the laboratory works with national and international governments, universities and industry partners to discover new science and development technologies that underpin the nation's nuclear and renewable energy, national security, and environmental missions.INL MissionOur mission is to discover, demonstrate and secure innovative nuclear energy solutions, other clean energy options and critical infrastructure.
INL VisionOur vision is to change the world's energy future and secure our nation's critical infrastructure.
Selective Service RequirementsTo be eligible for employment at INL males born after December 31, 1959 must have registered with the Selective Service System (SSS). For more information see ************
Equal Employment OpportunityIdaho National Laboratory (INL) is an Equal Employment Opportunity (EEO) employer. It is the policy of INL to provide equal employment opportunities to all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information.
Reasonable AccommodationWe will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.
Other InformationWhen applying to positions please provide a resume and answer all questions on the following screens. Applicants, who fail to provide a resume or answer the questions, may be deemed ineligible for consideration.
INL does not accept resumes from third party vendors unsolicited. Primary Location: US-ID-Idaho FallsJob: Computer Information TechnologyOrganization: Information Technology (Yxxx) Schedule: Full-time Employee Status: RegularJob Posting: Apr 10, 2025, 8:53:48 PMUnposting Date: May 12, 2025, 5:59:00 AMRELOCATION: Position Relocation EligibleTELEWORK: On-Site Worker
Security Engineer 5 - Product & Application Security
Security Engineer Job 401 miles from Idaho Falls
PagerDuty, Inc. (NYSE:PD) is a global leader in digital operations management. Half of the Fortune 500 and nearly 70% of the Fortune 100 trust PagerDuty as essential infrastructure. Join us. (******************************* At PagerDuty, you'll tackle complex problems, collaborate with kind and ambitious people, and help build a more equitable world-all in a flexible, award-winning workplace.
PagerDuty is seeking a **Staff Security Engineer 5** to join our diverse, customer-focused team! As a **Staff Security Engineer 5** , you will bring your rich technical experience securing applications in a cloud native environment. You will be a part of an amazing team that's intensely focused on securing our products, improving our security processes, and building the future of security at PagerDuty.
This is an exciting opportunity to build security solutions that make developers and customers happy. The ideal candidate will have a blend of experiences across large enterprise environments and small or mid-size environments and will have focused on establishing security standards, coordinating with product development teams, developing strategies for secure-by-default architectures, and corresponding process and tooling selection and implementation. Things that make you smile: secure product architectures, providing an engaging Developer Experience for security adoption, and cute animal memes.
**Key Responsibilities**
+ Responsible for leading, designing, implementing, and configuring security controls for SaaS applications in a cloud-based infrastructure environment.
+ Lead complex projects that require in-depth knowledge across technical, solutions, and business, and collaborate across the broader engineering organization.
+ Identify threats and vulnerabilities, security gaps, and recommend enhancements and changes to increase product and infrastructure security posture.
+ Support security operations to provide the protection of the confidentiality, availability, and integrity of customer data and building/maintaining customer trust.
+ Partner with product/engineering, corporate operations, and employees to build and maintain a security-aware culture where everyone understands and plays their part
+ Provide thought leadership on modern security operations and help lead our infrastructure security organization in creating trust through security.
+ Participating in our team's on-call rotation, triaging and addressing security issues as they arise.
+ Mentor and grow application security engineers.
+ You have a desire to stay ahead of the latest industry trends and technologies, a track record of sharing contributions to the wider security engineering community and a commitment to continuous learning.
+ You believe security should make it easy to do the right thing.
+ You are an expert at leading collaborative efforts involving large groups.
+ Expert at building consensus within and across engineering teams.
**Minimum Requirements**
+ 7+ years of experience in infrastructure securing infrastructure, securing infrastructure including IaaS, PaaS, SaaS, including network security.
+ 5+ years experience with cloud-native security experience, cloud-native based application security best practices.
+ Experience with Linux operating systems, scripting languages such as Python, configuration languages like YAML, JSON and technologies such as Terraform and/or Cloudformation, configuration tools such as Chef or Ansible.
+ Experience with AWS cloud security best practices, and AWS security technologies such as AWS IAM, AWS Organizations, AWS Shield, AWS GuardDuty.
+ Excellent written and verbal communication skills.
+ The ability to compress intricate security challenges into concise descriptions.
+ The ability to solve security problems without saying "No".
+ You have a track record of stepping up and leading successful security engineering projects.
+ Past experience with application security, security testing, code reviews and identity and access management
+ Past experience with threat analysis, threat hunting, proactive security practices
+ Prior experience with Application Security, Secure SDL for cloud native services.
+ Experience with containerized applications, and technologies, such as Docker and Kubernetes.
+ Experience working in a continuous delivery/continuous deployment environment.
**Preferred Qualifications**
+ Certifications such as AWS Security Speciality, (ISC)2 Certified Cloud Security Professional (CCSP), (ISC)2 CISSP (Certified Information Systems Security Professional).
The base salary range for this position is 192,000 - 319,000 USD. This role may also be eligible for bonus, commission, equity, and/or benefits.
Our base salary ranges are determined by role, level, and location. The range, which is subject to change based on primary work location, reflects the minimum and maximum base salary we expect to pay newly hired employees for the position. Within the range, we determine pay for an individual based on a number of factors including market location, job-related knowledge, skills/competencies and experience.
Your recruiter can share more about the specific offerings for this role, as well as the salary range for your primary work location during the hiring process.
**Hesitant to apply?**
We encourage you to submit your resume even if you don't meet every requirement. We value potential and consider each candidate's full professional story. Whether you're exploring a career change or taking your next step, we look forward to reviewing your application. If this just isn't the right role or time - sign up for job alerts (**************************************** !
**Where we work**
PagerDuty currently has offices (**************************************** in Atlanta, Lisbon, London, San Francisco, Santiago, Sydney, Tokyo, and Toronto. We offer a hybrid, flexible environment. We also provide ample opportunities for connection, like team offsites and volunteering events.
**How we work**
Our values (************************************** guide how we support customers, collaborate with colleagues, develop products, and foster a culture of belonging. They define not just our actions, but what it means to be Dutonian.
**What we offer**
As a global organization, our total rewards approach is competitive with industry standards and aligned with local laws and regulations. Learn more, including country-specific offerings, on our benefits site (********************************************** .
**Your package may include:**
- Competitive salary
- Comprehensive benefits package from day one
- Flexible work arrangements
- Company equity*
- ESPP (Employee Stock Purchase Program)*
- Retirement or pension plan*
- Generous paid vacation time
- Paid holidays and sick leave
- Dutonian Wellness Days & HibernationDuty - companywide paid days off in addition to PTO
- Paid parental leave: 22 weeks for pregnant parent, 12 weeks for non-pregnant parent (some countries have longer leave standards and we comply with local laws)*
- Paid volunteer time off: 20 hours per year
- Company-wide hack weeks
- Mental wellness programs
*Eligibility may vary by role, region, and tenure
**About PagerDuty**
PagerDuty, Inc. (NYSE:PD) is a global leader in digital operations management, enabling customers to achieve operational efficiency at scale with the PagerDuty Operations Cloud. The PagerDuty Operations Cloud combines AIOps, Automation, Customer Service Operations and Incident Management with a powerful generative AI assistant to create a flexible, resilient and scalable platform to increase innovation velocity, grow revenue, reduce cost, and mitigate the risk of operational failure. Half of the Fortune 500 and nearly 70% of the Fortune 100 rely on PagerDuty as essential infrastructure for the modern enterprise.
PagerDuty is Great Place to Work-certified, a Fortune Best Workplace for Millennials, a Fortune Best Medium Workplace, a Fortune Best Workplace in Technology, and a top rated product on TrustRadius and G2.
Go behind-the-scenes on our careers site (*********************************** and @pagerduty on Instagram.
**Additional Information**
PagerDuty is committed to creating a diverse environment and is an equal opportunity employer. PagerDuty does not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, parental status, veteran status, or disability status.
PagerDuty is committed to providing reasonable accommodations for qualified individuals with disabilities in our job application process. Should you require accommodation, please email accommodation@pagerduty.com and we will work with you to meet your accessibility needs.
PagerDuty uses the E-Verify employment verification program.
Systems Engineer (Windows)
Security Engineer Job 51 miles from Idaho Falls
TMC Technologies is in search of a Systems Engineer (Windows) to support a federal client in Pocatello, ID. The candidate must be a US citizen and possess a TS/SCI clearance with the ability to pass a CI poly to start due to federal contract requirements. The Systems Engineer (Windows) will responsible for engineering, design, integration, deployment, testing, certification, patching, addressing interoperability issues, not only of the base Windows operating system, but for all support libraries, components and application dependencies.
Responsibilities and experience of the Systems Engineer (Windows) may include:
- Design, implement and provide ongoing support of the Windows Infrastructure.
- Serve as the expert for all Windows environments.
- Engineer, integrate, design and deploy various Windows components and expert knowledge in Active Directory, Group Policy, digital certificates, multi factor Integration, DNS and DHCP.
- Create and maintain bare-metal and virtual machines with the appropriate distribution of Windows and network configuration, using tools that include Windows Deployment Services, Microsoft Endpoint Configuration Manager, System Center Configuration Manager, Hyper-V, SQL Server, Windows 2019/2022, and Windows 11.
- Provision/configure required software onto servers, such as web servers and databases such as SQL Server.
- Possess proficient understanding of networks, storage, and LAN/WAN systems and applications as well as their dependencies.
- Evaluate, improve, and maintain the information security throughout the Windows infrastructure.
- Work in hybrid environment of virtualized and cloud platforms.
- Monitor and correct critical server issues and create recovery processes for failures and performance bottlenecks. The Contractor shall use native, add on tools, and third party tools to troubleshoot malfunctions, optimizations. The Contractor shall use tools include Resource Kits, Development Kits, and commercial tools.
- Maintain security, backup, and redundancy strategies.
- Write and maintain custom scripts to increase system efficiency and lower the human intervention time on any tasks
- Provide 3rd level support.
- Ensure technical documentation exists for all systems and is kept up to date to include inventory and patch levels of all systems to include hostnames, property numbers, IP addresses, enclave, number of cores, and number of processors, admin passwords, certificates, and service accounts on a monthly interval.
- Integrate systems with Windows as it applies to authentication and core services dependencies such single sign-on and Active Directory. Engineer and implement solutions for multi factor authentication with FBI standardized software and hardware.
Requirements
US Citizenship and TS/SCI clearance required; CI poly preferred but can be administered after hire.
Minimum of 5 years' experience required; Bachelor's degree is preferred.
Storage Systems Engineer III
Security Engineer Job 51 miles from Idaho Falls
At Agile Defense we know that action defines the outcome and new challenges require new solutions. That's why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next. Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility-leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation's vital interests.
Location: Pocatello, ID, Clarksburg, WV, or Huntsville, AL
Overview:
Agile Defense is looking for a Storage Systems Engineer III to support a federal agency by designing, deploying, testing, certifying, patching, and addressing interoperability issues for all features, components, and application dependencies. To include Storage Area Network (SAN), Network Attached Storage (NAS), Fibre Channel, iSCSI, Direct Attached Storge, etc. to meet the needs and support the missions of the agency. This is a hybrid opportunity.
Clearance: Active TS Required
Responsibilities/DutiesMinimum of ten (10) years of experience with SAN, NAS, tape, local disk, fibre channel, iSCSI, etc. technologies.Design, implement and provide ongoing support of the storage infrastructure.Serve as the subject matter expert (SME) for all storage environments.Create and maintain storage infrastructure for both bare-metal and virtual machines with the appropriate SAN, network, or local storage configurations, using both OEM and third-party tools that include virtual storage tools and services.Provision/configure required storage servers.Evaluate, improve, and maintain the information security posture throughout the storage infrastructure.Monitor, prevent, and correct all storage issues and create recovery processes for hardware failures and performance bottlenecks and configure alerts for proactive response times.Install, configure, test, and maintain system management tools, SAN infrastructure and server plugins with the latest hardware and software patch and firmware versions.Proactively ensure the highest levels of systems and infrastructure availability to include verification of the replication of data, fail over copies, redundant data sets.Monitor and test application performance for potential bottlenecks, identify possible solutions, and work with developers to implement those fixes.Test and maintain security, backup, and redundancy strategies.Write and maintain custom scripts to increase system efficiency and lower the human intervention time on any tasks, such as automated provisioning storage with Infrastructure as a Service (IaaS).Participate in the design of information and operational support systems.Provide 4th level support.Be a liaison with vendors and other IT personnel for problem resolution.Ensure technical documentation exists for all systems and is kept up to date to include inventory and patch levels of all systems to include hostnames, property numbers, IP addresses, enclave, number of cores, number of processors, admin passwords, certificates, and service accounts on a monthly interval.Integrate systems with Windows and Linux as it applies to core service dependencies. Engineer and implement solutions for multi factor authentication with FBI standardized software and hardware.Document system configurations to include passwords, access controls, version number, and revision numbers, patch levels, and inventory to include hostnames, TCP/IP addresses, number of processors, and number of cores, memory, and license keys.Continually transition knowledge to the government staff through training and assistance on how to use the technology using industry best practices.Provide real-time reporting of storage provisioned and utilized resources to include performance metrics for disk space consumption, storage availability, performance, and trends.
Preferred Qualifications Bachelor's DegreeA professional storage vendor certification
Employees of Agile Defense are our number one priority, and the importance we place on our culture here is fundamental. Our culture is alive and evolving, but it always stays true to its roots. Here, you are valued as a family member, and we believe that we can accomplish great things together. Agile Defense has been highly successful in the past few years due to our employees and the culture we create together.
What makes us Agile? We call it the 6Hs, the values that define our culture and guide everything we do. Together, these values infuse vibrancy, integrity, and a tireless work ethic into advancing the most important national security and critical civilian missions. It's how we show up every day. It's who we are.
We also believe in supporting our employees by offering a competitive and comprehensive benefits package. To explore the benefits we offer, please visit our website under the Careers section.
Happy - Be Infectious.
Happiness multiplies and creates a positive and connected environment where motivation and satisfaction have an outsized effect on everything we do.
Helpful - Be Supportive.
Being helpful is the foundation of teamwork, resulting in a supportive atmosphere where collaboration flourishes, and collective success is celebrated.
Honest - Be Trustworthy.
Honesty serves as our compass, ensuring transparent communication and ethical conduct, essential to who we are and the complex domains we support.
Humble - Be Grounded.
Success is not achieved alone, humility ensures a culture of mutual respect, encouraging open communication, and a willingness to learn from one another and take on any task.
Hungry - Be Eager.
Our hunger for excellence drives an insatiable appetite for innovation and continuous improvement, propelling us forward in the face of new and unprecedented challenges.
Hustle - Be Driven.
Hustle is reflected in our relentless work ethic, where we are each committed to going above and beyond to advance the mission and achieve success.
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
Cyber Sentinel Skills Challenge
Security Engineer Job In Idaho Falls, ID
Correlation One is hosting the Cyber Sentinel Skills Challenge, a unique, one-day cybersecurity competition sponsored by the U.S. Department of Defense (DoD). Win your share of a $15,000 prize pool, solve fun cybersecurity challenges, and access new job opportunities at the DoD.
This event is designed to help you:
Unlock career opportunities and get on the radar of DoD recruiters
Test your skills and gain experience solving some of the most pressing security threats globally through 20+ Capture the Flag-style simulations
Connect with your peers and build a strong, supportive network of cybersecurity professionals
Competition details:
When: June 14, 2025
Where: Virtual
Duration: 8 hours (11am - 7pm ET)
Cost: Free
Early application deadline: May 6, 2025
Total prize pool: $15,000
Experience required: All levels of cybersecurity are welcome
Challenge categories: Forensics, Malware/ Reverse Engineering, Networking & Reconnaissance, Open-Source Intelligence Gathering (OSINT), Web Security
About you:
You must be a U.S. Citizen or a permanent resident with a valid Green Card.
You must be over the age of 18.
Individuals from all levels of cybersecurity experience, whether you are a seasoned cybersecurity professional or just starting in the field, are welcome to apply.
Security Detection Engineer, Insider Trust
Security Engineer Job 212 miles from Idaho Falls
As part of Meta Security, our Insider Trust team is focused on identifying and responding to insider threats to data. The team's mission is to identify malicious use of otherwise legitimate access to data from people inside the company and respond to it before damage is done. We investigate across a broad spectrum of abuse including abuse of user data, intellectual property, and leaks of sensitive information. We collaborate with software engineering teams to build advanced detection capabilities and understand how abuse happens so that we can stay ahead of those who are interested in misusing their access. The Insider Trust team is looking for a highly motivated Security Engineer to build and improve internal tools and systems to detect malicious activities related to insider threats. Candidates are expected to analyze and monitor internal tools, hunt for insider threats against company data and infrastructure, and have the ability to carry out complex internal investigations from collection to reporting. As part of the role, this person will work side by side with our engineering teams to build advanced detection solutions to help keep systems and information safe, and partner closely with our Human Resources and Legal teams to carry out complex investigations.
**Required Skills:**
Security Detection Engineer, Insider Trust Responsibilities:
1. Lead cross-functional projects to improve our GenAI capabilities to effectively detect and respond to internal threats and security incidents
2. Leverage threat modeling and analysis to build event and/or behavioral based detections to protect our critical GenAI assets and infrastructure
3. Perform analysis of logs from a variety of sources (e.g., individual host logs, network traffic logs) to identify potential insider threats
4. Build operational workflows and actions that auto-resolve false positives and provide context scaling our ability to investigate
5. Identify gaps in our infrastructure, and work with software engineers, product managers, and business partners to gain visibility through logging and detection
**Minimum Qualifications:**
Minimum Qualifications:
6. Bachelor's degree in Computer Science, Engineering, or equivalent experience
7. 5+ years of experience in Detection & Response Engineering or similar Security Engineering role
8. Experience developing detections using event or anomaly based methods
9. Experience interpreting information from multiple sources and working with data sets
10. Experience with database tools/systems such as SQL, HQL
11. Coding proficiency in Python
**Preferred Qualifications:**
Preferred Qualifications:
12. M.S. or PhD in Computer Science or related field, or equivalent experience
13. Experience conducting technical security investigations (response, forensics, log analysis)
14. Experience with anomaly detection applicable to the insider threat detection space
15. Experience in system, network, and/or application security
16. Coding proficiency in OOP languages, e.g. PHP, C++, etc.
17. Coding proficiency in Pandas, NumPy, Scikit-learn, TensorFlow
**Public Compensation:**
$147,000/year to $208,000/year + bonus + equity + benefits
**Industry:** Internet
**Equal Opportunity:**
Meta is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Meta participates in the E-Verify program in certain locations, as required by law. Please note that Meta may leverage artificial intelligence and machine learning technologies in connection with applications for employment.
Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at accommodations-ext@fb.com.
Senior Security Engineer, Cyber Risk Management
Security Engineer Job 212 miles from Idaho Falls
Headquartered in Dublin, Ohio, Cardinal Health, Inc. (NYSE: CAH) is a global, integrated healthcare services and products company, providing customized solutions for hospitals, health systems, pharmacies, ambulatory surgery centers, clinical laboratories and physician offices worldwide.
The company provides clinically-proven medical products and pharmaceuticals and cost-effective solutions that enhance supply chain efficiency from hospital to home. Cardinal Health connects patients, providers, payers, pharmacists and manufacturers for integrated care coordination and better patient management. Backed by nearly 100 years of experience, with approximately 50,000 employees in 46 countries, Cardinal Health ranks among the top 15 on the Fortune 500.
We currently have a full-time job opening for a Senior Security Engineer of Cyber Risk Management
_Department overview:_
Information Security and Risk Management (ISRM) at Cardinal Health enables Cardinal Health to securely deliver healthcare products and solutions that improve the lives of people every day by ensuring security and controls are embedded into Cardinal Health's people, process and technology. The Cyber Risk and Customer Security Assurance team fulfils our mission to strengthen our shield against cyber threats by providing a framework of processes and methodologies to manage Cardinal Health's cybersecurity risks through issue and exception management, cyber risk management, and customer third party risk assessment engagement.
Job Summary
Sr. Engineer, Cyber Risk Management, applies knowledge of Information Security, Risk Management, and Information Technology to lead the maturity of our Cyber Risk program. The primary responsibility of this role is to collaborate across the enterprise to measure the impact and likelihood of a variety of Cyber Risks.
This role is a senior position within the team and will work with all members of the Information Security team as well as Senior Leadership, Enterprise Risk Management, Business leaders, and IT teams.
Responsibilities:
+ Provide senior leaders and executives with information summarized at the correct level to make efficient, cost-effective, risk management decisions about the technology and information processing supporting their business functions
+ Work with all members of the Information Security team to drive information risk governance processes throughout the Cardinal Health enterprise
+ Implement the information risk management framework and related governance processes to cover not just the IT function, but all technology and information processing regardless of where the processing is in the enterprise (e.g., "shadow IT", manufacturing systems, operational technology, etc.)
+ Leverage and integrate with existing IT risk management and risk escalation / approval processes
+ Create an information risk register that catalogs key IT risks through an ongoing "top-down" risk assessment process
+ Define processes for summarizing "bottom-up" risk identified throughout various risk and compliance activities to add to risk register
+ Define and measure risk metrics that can be used to evaluate risk trends
_Qualifications:_
+ Excellent written and verbal communication skills
+ Experience in Information Technology, Information Security, and Risk Management
+ Experience implementing and maintaining processes at large enterprises
+ Experience with IT security principles, practices, technologies, programs and procedures, accompanied by an understanding of risk management methodologies and cybersecurity assessment frameworks
+ High-quality analytical skills, relationship management competencies
+ Relevant Information Security Certifications
**Anticipated salary range:** $121,600 - $182,385
**Bonus eligible:** Yes
**Benefits:** Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
+ Medical, dental and vision coverage
+ Paid time off plan
+ Health savings account (HSA)
+ 401k savings plan
+ Access to wages before pay day with my FlexPay
+ Flexible spending accounts (FSAs)
+ Short- and long-term disability coverage
+ Work-Life resources
+ Paid parental leave
+ Healthy lifestyle programs
**Application window anticipated to close:** 4/27/2025 *if interested in opportunity, please submit application as soon as possible.
The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.
_Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply._
_Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal_ _Opportunity/Affirmative_ _Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law._
_To read and review this privacy notice click_ here (***************************************************************************************************************************
Security Engineer 4 - FedRAMP Compliance Architect
Security Engineer Job 212 miles from Idaho Falls
PagerDuty, Inc. (NYSE:PD) is a global leader in digital operations management. Half of the Fortune 500 and nearly 70% of the Fortune 100 trust PagerDuty as essential infrastructure. Join us. (******************************* At PagerDuty, you'll tackle complex problems, collaborate with kind and ambitious people, and help build a more equitable world-all in a flexible, award-winning workplace.
PagerDuty is seeking a **Security Engineer 4 - FedRAMP Compliance Architect** to join our diverse, customer-focused team! This **Security Engineer 4 - FedRAMP Compliance Architect** will design, implement, and maintain secure architectures that meet FedRAMP requirements in a multi-tenant cloud environment. This role combines deep technical expertise with FedRAMP compliance knowledge to create scalable, secure solutions. You'll be the glue between security compliance requirements and technical implementation, ensuring our cloud infrastructure meets federal security standards while enabling business objectives.
**Key Responsibilities:**
+ Design, implement, and maintain system architectures to align with FedRAMP requirements.
+ Serve as the subject matter expert (SME) on FedRAMP, advising internal teams on security best practices, control implementations, and risk mitigation strategies.
+ Collaborate with engineering, operations, product, and corporate IT teams to develop secure cloud-based architectures that meet federal compliance mandates.
+ Implement governance strategy on technical security controls, including access management, configuration, encryption, logging, monitoring, and vulnerability management.
+ Support annual assessments, security control reviews, and audits, coordinating with third-party assessors (3PAO) and government sponsors.
+ Technical support for external stakeholders on customer responsibilities.
+ Key contributor to the development and maintenance of the System Security Plan (SSP), Policies and Procedures, Configuration Management Plan, Secure System Development Life Cycle, and other FedRAMP documentation
+ Partner with the GRC (Governance, Risk, and Compliance) team to efficiently track and resolve security findings.
**Basic Qualifications:**
+ 5+ years of experience in cloud security architecture, compliance, or cybersecurity engineering, with at least 3 years of experience supporting FedRAMP Moderate or High authorization.
+ Deep expertise in FedRAMP, NIST 800-53, FISMA, and cloud security best practices.
+ Strong ability to assess security risks and recommend technical and procedural mitigations.
+ Experience working with AWS GovCloud, Azure Government, or other federal cloud environments.
+ Experience with audit preparation, risk assessments, and working with third-party assessors (3PAOs).
+ Exceptional written and verbal communication skills for creating and managing FedRAMP documentation.
**Preferred Qualifications:**
+ Experience supporting DoD IL 4 or 5 environments.
+ Experience with data governance frameworks, secure data storage, and data lifecycle management in multi-tenant cloud environments.
+ Understanding of NIST AI Risk Management Framework (AI RMF) and its implications for secure AI adoption in government environments.
+ Familiar with SaaS security tools (such as Sumo Logic, Datadog, Crowdstrike, Wiz, Lucidchart, Snyk, and Qualys).
+ Familiarity with Cloud Native and SaaS constructs, including architectures, DevOps, CI/CD, and SecOps disciplines.
+ Relevant certifications, such as:
+ Certified Information Systems Security Professional (CISSP)
+ AWS Security Specialty, or equivalent
+ CompTIA Advanced Security Practitioner (CASP+)
+ Certificate of Cloud Security Knowledge (CCSK)]]
The successful applicant will be performing work in FedRAMP environments, and therefore, must be a U.S. Person (i.e. U.S. citizen, U.S. national, lawful permanent resident, asylee, or refugee). **This position may also perform work that the U.S. government has specified can only be performed by a U.S. citizen on U.S. soil.**
The base salary range for this position is 172,000 - 289,000 USD. This role may also be eligible for bonus, commission, equity, and/or benefits.
Our base salary ranges are determined by role, level, and location. The range, which is subject to change based on primary work location, reflects the minimum and maximum base salary we expect to pay newly hired employees for the position. Within the range, we determine pay for an individual based on a number of factors including market location, job-related knowledge, skills/competencies and experience.
Your recruiter can share more about the specific offerings for this role, as well as the salary range for your primary work location during the hiring process.
**Hesitant to apply?**
We encourage you to submit your resume even if you don't meet every requirement. We value potential and consider each candidate's full professional story. Whether you're exploring a career change or taking your next step, we look forward to reviewing your application. If this just isn't the right role or time - sign up for job alerts (**************************************** !
**Where we work**
PagerDuty currently has offices (**************************************** in Atlanta, Lisbon, London, San Francisco, Santiago, Sydney, Tokyo, and Toronto. We offer a hybrid, flexible environment. We also provide ample opportunities for connection, like team offsites and volunteering events.
**How we work**
Our values (************************************** guide how we support customers, collaborate with colleagues, develop products, and foster a culture of belonging. They define not just our actions, but what it means to be Dutonian.
**What we offer**
As a global organization, our total rewards approach is competitive with industry standards and aligned with local laws and regulations. Learn more, including country-specific offerings, on our benefits site (********************************************** .
**Your package may include:**
- Competitive salary
- Comprehensive benefits package from day one
- Flexible work arrangements
- Company equity*
- ESPP (Employee Stock Purchase Program)*
- Retirement or pension plan*
- Generous paid vacation time
- Paid holidays and sick leave
- Dutonian Wellness Days & HibernationDuty - companywide paid days off in addition to PTO
- Paid parental leave: 22 weeks for pregnant parent, 12 weeks for non-pregnant parent (some countries have longer leave standards and we comply with local laws)*
- Paid volunteer time off: 20 hours per year
- Company-wide hack weeks
- Mental wellness programs
*Eligibility may vary by role, region, and tenure
**About PagerDuty**
PagerDuty, Inc. (NYSE:PD) is a global leader in digital operations management, enabling customers to achieve operational efficiency at scale with the PagerDuty Operations Cloud. The PagerDuty Operations Cloud combines AIOps, Automation, Customer Service Operations and Incident Management with a powerful generative AI assistant to create a flexible, resilient and scalable platform to increase innovation velocity, grow revenue, reduce cost, and mitigate the risk of operational failure. Half of the Fortune 500 and nearly 70% of the Fortune 100 rely on PagerDuty as essential infrastructure for the modern enterprise.
PagerDuty is Great Place to Work-certified, a Fortune Best Workplace for Millennials, a Fortune Best Medium Workplace, a Fortune Best Workplace in Technology, and a top rated product on TrustRadius and G2.
Go behind-the-scenes on our careers site (*********************************** and @pagerduty on Instagram.
**Additional Information**
PagerDuty is committed to creating a diverse environment and is an equal opportunity employer. PagerDuty does not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, parental status, veteran status, or disability status.
PagerDuty is committed to providing reasonable accommodations for qualified individuals with disabilities in our job application process. Should you require accommodation, please email accommodation@pagerduty.com and we will work with you to meet your accessibility needs.
PagerDuty uses the E-Verify employment verification program.
Systems Engineer (Windows)
Security Engineer Job 51 miles from Idaho Falls
TMC Technologies is in search of a Systems Engineer (Windows) to support a federal client in Pocatello, ID. The candidate must be a US citizen and possess a TS/SCI clearance with the ability to pass a CI poly to start due to federal contract requirements. The Systems Engineer (Windows) will responsible for engineering, design, integration, deployment, testing, certification, patching, addressing interoperability issues, not only of the base Windows operating system, but for all support libraries, components and application dependencies.
Responsibilities and experience of the Systems Engineer (Windows) may include:
* Design, implement and provide ongoing support of the Windows Infrastructure.
* Serve as the expert for all Windows environments.
* Engineer, integrate, design and deploy various Windows components and expert knowledge in Active Directory, Group Policy, digital certificates, multi factor Integration, DNS and DHCP.
* Create and maintain bare-metal and virtual machines with the appropriate distribution of Windows and network configuration, using tools that include Windows Deployment Services, Microsoft Endpoint Configuration Manager, System Center Configuration Manager, Hyper-V, SQL Server, Windows 2019/2022, and Windows 11.
* Provision/configure required software onto servers, such as web servers and databases such as SQL Server.
* Possess proficient understanding of networks, storage, and LAN/WAN systems and applications as well as their dependencies.
* Evaluate, improve, and maintain the information security throughout the Windows infrastructure.
* Work in hybrid environment of virtualized and cloud platforms.
* Monitor and correct critical server issues and create recovery processes for failures and performance bottlenecks. The Contractor shall use native, add on tools, and third party tools to troubleshoot malfunctions, optimizations. The Contractor shall use tools include Resource Kits, Development Kits, and commercial tools.
* Maintain security, backup, and redundancy strategies.
* Write and maintain custom scripts to increase system efficiency and lower the human intervention time on any tasks
* Provide 3rd level support.
* Ensure technical documentation exists for all systems and is kept up to date to include inventory and patch levels of all systems to include hostnames, property numbers, IP addresses, enclave, number of cores, and number of processors, admin passwords, certificates, and service accounts on a monthly interval.
* Integrate systems with Windows as it applies to authentication and core services dependencies such single sign-on and Active Directory. Engineer and implement solutions for multi factor authentication with FBI standardized software and hardware.
Job Requirements
US Citizenship and TS/SCI clearance required; CI poly preferred but can be administered after hire.
Minimum of 5 years' experience required; Bachelor's degree is preferred.
We are equal opportunity/affirmative action employers, committed to diversity in the workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity, sexual orientation, national origin, disability, or protected veteran status, or any other protected characteristic under state or local law.
Cyber Sentinel Skills Challenge
Security Engineer Job 220 miles from Idaho Falls
Correlation One is hosting the Cyber Sentinel Skills Challenge, a unique, one-day cybersecurity competition sponsored by the U.S. Department of Defense (DoD). Win your share of a $15,000 prize pool, solve fun cybersecurity challenges, and access new job opportunities at the DoD.
This event is designed to help you:
Unlock career opportunities and get on the radar of DoD recruiters
Test your skills and gain experience solving some of the most pressing security threats globally through 20+ Capture the Flag-style simulations
Connect with your peers and build a strong, supportive network of cybersecurity professionals
Competition details:
When: June 14, 2025
Where: Virtual
Duration: 8 hours (11am - 7pm ET)
Cost: Free
Early application deadline: May 6, 2025
Total prize pool: $15,000
Experience required: All levels of cybersecurity are welcome
Challenge categories: Forensics, Malware/ Reverse Engineering, Networking & Reconnaissance, Open-Source Intelligence Gathering (OSINT), Web Security
About you:
You must be a U.S. Citizen or a permanent resident with a valid Green Card.
You must be over the age of 18.
Individuals from all levels of cybersecurity experience, whether you are a seasoned cybersecurity professional or just starting in the field, are welcome to apply.
Security Engineer, Incident Response
Security Engineer Job 212 miles from Idaho Falls
Meta Security is looking for an Incident Response Engineer with experience in the identification, containment, and mitigation of security incidents. You will be analyzing different data sources to detect, investigate and respond to internal and external threats. You will also be working with our software and production engineering teams to develop scalable systems to automate detection and remediation and help us build the next generation of security operations and response platforms.
**Required Skills:**
Security Engineer, Incident Response Responsibilities:
1. Lead security incident response in a cross-functional environment and drive incident resolution
2. Lead and develop incident response initiatives that improve Meta's capabilities to effectively respond and remediate security incidents
3. Perform digital forensic acquisition and analysis of a wide variety of assets including endpoints, mobile, servers and networking equipment
4. Perform log analysis from a variety of sources (e.g., individual host logs, network traffic logs) to identify potential threats
5. Perform root cause analysis and drive implementation of containment and mitigation strategies
6. Build automation for response and remediation of malicious activity
**Minimum Qualifications:**
Minimum Qualifications:
7. 7+ years of experience in Security Incident Response, Investigations and Response Engineering
8. Knowledge of networking technologies and experience analyzing network-based security events
9. Knowledge of operating systems, file systems, and memory structures as well as experience in host and memory forensics (including live response) on Windows, mac OS and Linux
10. Experience investigating and responding to both external and insider threats
11. Coding/scripting experience in one or more general purpose languages
12. Experience with attacker tactics, techniques, and procedures
13. Bachelor's degree or equivalent experience in Security
**Preferred Qualifications:**
Preferred Qualifications:
14. Experience as a Lead Security Incident Responder and Investigator in a large and regulated organization
15. Background in malware analysis, digital forensics, intrusion detection, and/or threat intelligence
16. Experience in threat hunting including leveraging intelligence data to proactively identify and iteratively investigates suspicious behavior across networks and systems
17. Broad knowledge across the Security domain, as well as deep focus in one (or more) areas such as Logs and events processing, Incident Management, Digital Forensics, Detection and/or response tool development
**Public Compensation:**
$147,000/year to $208,000/year + bonus + equity + benefits
**Industry:** Internet
**Equal Opportunity:**
Meta is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Meta participates in the E-Verify program in certain locations, as required by law. Please note that Meta may leverage artificial intelligence and machine learning technologies in connection with applications for employment.
Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at accommodations-ext@fb.com.
Senior Information Security & Risk Engineer
Security Engineer Job 212 miles from Idaho Falls
Headquartered in Dublin, Ohio, Cardinal Health, Inc. (NYSE: CAH) is a global, integrated healthcare services and products company, providing customized solutions for hospitals, health systems, pharmacies, ambulatory surgery centers, clinical laboratories and physician offices worldwide.
The company provides clinically-proven medical products and pharmaceuticals and cost-effective solutions that enhance supply chain efficiency from hospital to home. Cardinal Health connects patients, providers, payers, pharmacists and manufacturers for integrated care coordination and better patient management. Backed by nearly 100 years of experience, with approximately 50,000 employees in 46 countries, Cardinal Health ranks among the top 20 on the Fortune 500.
We currently have a full-time career opening within Information Security to support the growth of our Navista Application Suite and the Integrated Oncology Network (IoN).
**Department overview**
The Information Security department at Cardinal Health enables Cardinal Health to securely deliver healthcare products and solutions that improve the lives of people every day by ensuring security practices and controls are embedded into Cardinal Health's people, process and technology. We are a remote-first team and are excited to offer full-time remote opportunities.
**Functional Overview**
The Senior Information Security & Risk Engineer is a new capability for Cardinal Health and will be executed by the Product Security team. The primary goal of this position is to ensure delivery of best-in-class cybersecurity, risk management, and compliance for Navista, an oncology Managed Service Offering hosted by Cardinal Health.
**Job Overview**
The Information Security & Risk Engineer will be responsible for day-to-day activities in implementing the corporate information security and compliance program. The individual will be a front-line partner to technical teams and work across the organization to deliver security and compliance initiatives aligning to corporate policies, standards, procedures and audit activities. Success in the role will be measured by the effectiveness of the implementation of information security, risk management and compliance directives.
This role will work with various IT and business teams to drive both information security and compliance initiatives. The individual will assist with internal and external security compliance monitoring activities, review client audits, IT control audits, architecture reviews, threat modeling and security risk assessments. Good interpersonal and relationship building skills are essential for success.
**Job Responsibilities Include:**
+ Maintain governance program that ensures that the security policies, standards and process are in place
+ Serve as liaison to other Cardinal Health teams to ensure knowledge share and best practices
+ Partner with the engineering, architecture and operations teams to ensure delivery of infrastructure design and threat models which prove security requirements
+ Monitor security trends and drive security best practices throughout the organization via threat models and risk analysis
+ Evaluate, design, test, and recommend new or improved controls
+ Work with third party firms and consultants to conduct independent security audits, vulnerability scans, and penetration tests
+ Partner with developers to mentor and advise on secure coding and SDLC practices, define test cases and ensure appropriate testing, remediations, and mitigations
+ Investigate, drive resolution and document security incidents
+ Travel to various Integrated Oncology Network (IoN) sites may be required
**Qualifications**
+ Bachelors Degree in related field, or equivalent work experience leading cybersecurity or information security initiatives
+ Have 5+ years information security related work experience, preferably within the healthcare industry
+ Extensive experience with network and infrastructure design and security, ideally within the Azure cloud
+ Experience in vulnerability management programs, vulnerability assessments and advanced understanding of risk management
+ Familiarity with at least one common programming language, software development pipelines, and system lifecycles
+ Familiarity with standards such as HIPAA/HITECH, ISO, ITIL, NIST, PCI DSS, & SOX, CCPA, OWASP
+ Professional security certification (CISSP or CISM preferred)
+ Experience advising and mentoring diverse teams where you do not have direct authority
+ Strong written and verbal communication skills
**Anticipated salary range:** $121,600 - $182,385
**Bonus eligible:** Yes
**Benefits:** Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
+ Medical, dental and vision coverage
+ Paid time off plan
+ Health savings account (HSA)
+ 401k savings plan
+ Access to wages before pay day with my FlexPay
+ Flexible spending accounts (FSAs)
+ Short- and long-term disability coverage
+ Work-Life resources
+ Paid parental leave
+ Healthy lifestyle programs
**Application window anticipated to close:** 4/7/2025 *if interested in opportunity, please submit application as soon as possible.
The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.
_Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply._
_Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal_ _Opportunity/Affirmative_ _Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law._
_To read and review this privacy notice click_ here (***************************************************************************************************************************
Security Engineer 5 - Product & Application Security
Security Engineer Job 212 miles from Idaho Falls
PagerDuty, Inc. (NYSE:PD) is a global leader in digital operations management. Half of the Fortune 500 and nearly 70% of the Fortune 100 trust PagerDuty as essential infrastructure. Join us. (******************************* At PagerDuty, you'll tackle complex problems, collaborate with kind and ambitious people, and help build a more equitable world-all in a flexible, award-winning workplace.
PagerDuty is seeking a **Staff Security Engineer 5** to join our diverse, customer-focused team! As a **Staff Security Engineer 5** , you will bring your rich technical experience securing applications in a cloud native environment. You will be a part of an amazing team that's intensely focused on securing our products, improving our security processes, and building the future of security at PagerDuty.
This is an exciting opportunity to build security solutions that make developers and customers happy. The ideal candidate will have a blend of experiences across large enterprise environments and small or mid-size environments and will have focused on establishing security standards, coordinating with product development teams, developing strategies for secure-by-default architectures, and corresponding process and tooling selection and implementation. Things that make you smile: secure product architectures, providing an engaging Developer Experience for security adoption, and cute animal memes.
**Key Responsibilities**
+ Responsible for leading, designing, implementing, and configuring security controls for SaaS applications in a cloud-based infrastructure environment.
+ Lead complex projects that require in-depth knowledge across technical, solutions, and business, and collaborate across the broader engineering organization.
+ Identify threats and vulnerabilities, security gaps, and recommend enhancements and changes to increase product and infrastructure security posture.
+ Support security operations to provide the protection of the confidentiality, availability, and integrity of customer data and building/maintaining customer trust.
+ Partner with product/engineering, corporate operations, and employees to build and maintain a security-aware culture where everyone understands and plays their part
+ Provide thought leadership on modern security operations and help lead our infrastructure security organization in creating trust through security.
+ Participating in our team's on-call rotation, triaging and addressing security issues as they arise.
+ Mentor and grow application security engineers.
+ You have a desire to stay ahead of the latest industry trends and technologies, a track record of sharing contributions to the wider security engineering community and a commitment to continuous learning.
+ You believe security should make it easy to do the right thing.
+ You are an expert at leading collaborative efforts involving large groups.
+ Expert at building consensus within and across engineering teams.
**Minimum Requirements**
+ 7+ years of experience in infrastructure securing infrastructure, securing infrastructure including IaaS, PaaS, SaaS, including network security.
+ 5+ years experience with cloud-native security experience, cloud-native based application security best practices.
+ Experience with Linux operating systems, scripting languages such as Python, configuration languages like YAML, JSON and technologies such as Terraform and/or Cloudformation, configuration tools such as Chef or Ansible.
+ Experience with AWS cloud security best practices, and AWS security technologies such as AWS IAM, AWS Organizations, AWS Shield, AWS GuardDuty.
+ Excellent written and verbal communication skills.
+ The ability to compress intricate security challenges into concise descriptions.
+ The ability to solve security problems without saying "No".
+ You have a track record of stepping up and leading successful security engineering projects.
+ Past experience with application security, security testing, code reviews and identity and access management
+ Past experience with threat analysis, threat hunting, proactive security practices
+ Prior experience with Application Security, Secure SDL for cloud native services.
+ Experience with containerized applications, and technologies, such as Docker and Kubernetes.
+ Experience working in a continuous delivery/continuous deployment environment.
**Preferred Qualifications**
+ Certifications such as AWS Security Speciality, (ISC)2 Certified Cloud Security Professional (CCSP), (ISC)2 CISSP (Certified Information Systems Security Professional).
The base salary range for this position is 192,000 - 319,000 USD. This role may also be eligible for bonus, commission, equity, and/or benefits.
Our base salary ranges are determined by role, level, and location. The range, which is subject to change based on primary work location, reflects the minimum and maximum base salary we expect to pay newly hired employees for the position. Within the range, we determine pay for an individual based on a number of factors including market location, job-related knowledge, skills/competencies and experience.
Your recruiter can share more about the specific offerings for this role, as well as the salary range for your primary work location during the hiring process.
**Hesitant to apply?**
We encourage you to submit your resume even if you don't meet every requirement. We value potential and consider each candidate's full professional story. Whether you're exploring a career change or taking your next step, we look forward to reviewing your application. If this just isn't the right role or time - sign up for job alerts (**************************************** !
**Where we work**
PagerDuty currently has offices (**************************************** in Atlanta, Lisbon, London, San Francisco, Santiago, Sydney, Tokyo, and Toronto. We offer a hybrid, flexible environment. We also provide ample opportunities for connection, like team offsites and volunteering events.
**How we work**
Our values (************************************** guide how we support customers, collaborate with colleagues, develop products, and foster a culture of belonging. They define not just our actions, but what it means to be Dutonian.
**What we offer**
As a global organization, our total rewards approach is competitive with industry standards and aligned with local laws and regulations. Learn more, including country-specific offerings, on our benefits site (********************************************** .
**Your package may include:**
- Competitive salary
- Comprehensive benefits package from day one
- Flexible work arrangements
- Company equity*
- ESPP (Employee Stock Purchase Program)*
- Retirement or pension plan*
- Generous paid vacation time
- Paid holidays and sick leave
- Dutonian Wellness Days & HibernationDuty - companywide paid days off in addition to PTO
- Paid parental leave: 22 weeks for pregnant parent, 12 weeks for non-pregnant parent (some countries have longer leave standards and we comply with local laws)*
- Paid volunteer time off: 20 hours per year
- Company-wide hack weeks
- Mental wellness programs
*Eligibility may vary by role, region, and tenure
**About PagerDuty**
PagerDuty, Inc. (NYSE:PD) is a global leader in digital operations management, enabling customers to achieve operational efficiency at scale with the PagerDuty Operations Cloud. The PagerDuty Operations Cloud combines AIOps, Automation, Customer Service Operations and Incident Management with a powerful generative AI assistant to create a flexible, resilient and scalable platform to increase innovation velocity, grow revenue, reduce cost, and mitigate the risk of operational failure. Half of the Fortune 500 and nearly 70% of the Fortune 100 rely on PagerDuty as essential infrastructure for the modern enterprise.
PagerDuty is Great Place to Work-certified, a Fortune Best Workplace for Millennials, a Fortune Best Medium Workplace, a Fortune Best Workplace in Technology, and a top rated product on TrustRadius and G2.
Go behind-the-scenes on our careers site (*********************************** and @pagerduty on Instagram.
**Additional Information**
PagerDuty is committed to creating a diverse environment and is an equal opportunity employer. PagerDuty does not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, parental status, veteran status, or disability status.
PagerDuty is committed to providing reasonable accommodations for qualified individuals with disabilities in our job application process. Should you require accommodation, please email accommodation@pagerduty.com and we will work with you to meet your accessibility needs.
PagerDuty uses the E-Verify employment verification program.