Ready to be pushed beyond what you think you're capable of? At Coinbase, our mission is to increase economic freedom in the world. It's a massive, ambitious opportunity that demands the best of us, every day, as we build the emerging onchain platform - and with it, the future global financial system.
To achieve our mission, we're seeking a very specific candidate. We want someone who is passionate about our mission and who believes in the power of crypto and blockchain technology to update the financial system. We want someone who is eager to leave their mark on the world, who relishes the pressure and privilege of working with high caliber colleagues, and who actively seeks feedback to keep leveling up. We want someone who will run towards, not away from, solving the company's hardest problems.
Our ******************************** is intense and isn't for everyone. But if you want to build the future alongside others who excel in their disciplines and expect the same from you, there's no better place to be.
While many roles at Coinbase are remote-first, we are not remote-only. In-person participation is required throughout the year. Team and company-wide offsites are held multiple times annually to foster collaboration, connection, and alignment. Attendance is expected and fully supported.
The Application Security organization at Coinbase is seeking to hire an experienced Offensive SecurityEngineer specializing in Web3 penetration testing and Web3 bug bounty program management and optimization. In this role, you will collaborate with the Bug Bounty Program Lead to drive Web3 bug bounty triage, validation, and strategic initiatives aimed at increasing program efficiency, maturity, and hacker engagement. You will work closely with whitehat hackers, securityengineers, and cross-functional teams to enhance Coinbase's security posture through an effective bug bounty program. Additionally, you will perform penetration tests on Web3 technologies and applications, ensuring the security of Coinbase's blockchain-based products and services.
*What you'll be doing (ie. job duties):*
* Conduct security assessments of Web3 products and services, including smart contracts, DeFi protocols, and blockchain infrastructure.
* Collaborate with partner teams to enhance detection and response capabilities for Web3 vulnerabilities.
* Stay informed on emerging security trends, advisories, and academic research in the Web3 space.
* Lead Web3 bug bounty triage and validation, ensuring timely and accurate assessments of reported vulnerabilities.
* Develop and implement strategies to incentivize high-quality bug bounty submissions and engage with the hacker community.
* Manage the Web3 bug bounty program, including scope updates, researcher communication, and payout disbursements.
* Analyze bug bounty data to identify trends, common vulnerabilities, and areas for improvement.
* Collaborate with engineering teams to prioritize and remediate vulnerabilities identified through the bug bounty program.
* Mentor and train junior securityengineers in Web3 bug bounty triage and analysis.
* Provide on-call support for critical Web3 bug bounty-related incidents.
* Document and report on Web3 bug bounty metrics and program effectiveness.
*What we look for in you (ie. job requirements):*
* Bachelor's or Master's degree in Computer Science, Cybersecurity, Software Engineering, or a related field.
* 3+ years of experience in Web3 application security and penetration testing.
* Proven track record of identifying critical vulnerabilities across the blockchain protocol stack, Web2, and Web3 components.
* Extensive knowledge of the blockchain ecosystem, including L1/L2 networks, DeFi protocols, and staking mechanisms.
* Deep understanding of Web2 security concepts and common vulnerabilities (e.g., OWASP Top 10, SANS Top 25).
* Strong analytical skills to identify trends and patterns in vulnerabilities.
* Excellent communication skills for engaging with internal teams.
* Passion for security and a drive to improve Web3 security posture.
* Ability to work independently and take ownership of penetration testing initiatives.
* Energy and self-drive for continuous learning in the rapidly evolving crypto space.
* Excellence in clear, direct, and kind communication with technical and non-technical stakeholders.
* Experience building relationships with product, engineering, and security teams.
*Nice to haves:*
* Participation in CTFs, bug bounty programs, or open-source security research.
* Expertise in Application Security, Network Security, or Cloud Security.
* Relevant security certifications (e.g., OSCP, GPEN).
* Experience developing and implementing security tooling to support bug bounty triage and analysis.
* Experience with bug bounty programs and platforms, including triage, validation, and researcher communication.
* Strong analytical skills to identify trends and patterns in bug bounty submissions.
* Excellent communication skills to effectively engage with bug bounty researchers.
Position ID: P69494
\#LI-remote
*Pay Transparency Notice:* Depending on your work location, the target annual salary for this position can range as detailed below. Full time offers from Coinbase also include bonus eligibility + equity eligibility**+ benefits (including medical, dental, vision and 401(k)).
Pay Range:
$152,405-$179,300 USD
Please be advised that each candidate may submit a maximum of four applications within any 30-day period. We encourage you to carefully evaluate how your skills and interests align with Coinbase's roles before applying.
Commitment to Equal Opportunity
Coinbase is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, sex, gender expression or identity, sexual orientation or any other basis protected by applicable law. Coinbase will also consider for employment qualified applicants with criminal histories in a manner consistent with applicable federal, state and local law. For US applicants, you may view the *********************************************** in certain locations, as required by law.
Coinbase is also committed to providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please contact us at accommodations***********************************
*Global Data Privacy Notice for Job Candidates and Applicants*
Depending on your location, the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) may regulate the way we manage the data of job applicants. Our full notice outlining how data will be processed as part of the application procedure for applicable locations is available ********************************************************** By submitting your application, you are agreeing to our use and processing of your data as required.
*AI Disclosure*
For select roles, Coinbase is piloting an AI tool based on machine learning technologies to conduct initial screening interviews to qualified applicants. The tool simulates realistic interview scenarios and engages in dynamic conversation. A human recruiter will review your interview responses, provided in the form of a voice recording and/or transcript, to assess them against the qualifications and characteristics outlined in the job description.
For select roles, Coinbase is also piloting an AI interview intelligence platform to transcribe and summarize interview notes, allowing our interviewers to fully focus on you as the candidate.
*The above pilots are for testing purposes and Coinbase will not use AI to make decisions impacting employment*. To request a reasonable accommodation due to disability, please contact accommodations[at]coinbase.com
$152.4k-179.3k yearly 60d+ ago
Looking for a job?
Let Zippia find it for you.
Security Engineer - Airlock
Blue Star Partners 4.5
Columbus, OH
Job Title: SecurityEngineer - Cloud & Endpoint Security
Pay Rate: $50/hr - $85/hr
Duration: 2/10/2025 - 12/31/2025 (Temp-to-Hire)
Contract Type: W2 (must be authorized to work in the US; no sponsorships or C2C)
Job Overview
Our Cloud and Endpoint Security team is looking for a SecurityEngineer to drive the deployment and management of an allowlisting/reverse proxy solution (Airlock). This engineer will collaborate with cross-functional teams to ensure integration with existing infrastructure, refine security policies, and contribute to the enhancement of the organization's cybersecurity posture. The role involves hands-on configuration, monitoring, and ongoing maintenance of security solutions, while remaining adaptable to changing threats and technologies.
Key Responsibilities
Allowlisting & Reverse Proxy Deployment: Lead the deployment and configuration of Airlock, ensuring seamless integration with current systems and networks.
Policy Development: Define and implement allowlisting policies to enhance application security, access control, and threat detection.
Incident Response Collaboration: Work closely with the incident response team to optimize alerting and logging capabilities, ensuring swift detection and remediation of potential security incidents.
Security Strategy & Best Practices: Assist in shaping the broader cybersecurity strategy, aligning it with business objectives and recognized frameworks (e.g., NIST, MITRE, ISO 27001).
Automation & Reporting: Identify opportunities to automate configurations, streamline reporting processes, and enhance visibility into system performance.
Monitoring & Analysis: Track solution performance and review security logs for emerging threats or anomalies; implement proactive measures where necessary.
Research & Continuous Improvement: Stay informed about the latest cybersecurity threats and trends, applying relevant findings to enhance Airlock's configurations.
Documentation & Maintenance: Support the development of incident response plans, secure access protocols, and maintain thorough documentation of all configurations and processes.
Qualifications
Minimum Requirements
Bachelor's Degree in a related field or equivalent work experience.
3+ years of experience in cybersecurity, IT, or related roles.
1+ years of hands-on experience deploying or managing application allowlisting or reverse proxy solutions.
1+ years of experience with security frameworks (e.g., NIST, MITRE, ISO 27001).
Proficiency with Windows and Linux environments, including command-line configurations.
Preferred Skills
Experience using Airlock or similar allowlisting tools.
Familiarity with scripting/automation (Python, PowerShell, Bash) for configuration and reporting.
Industry certifications (e.g., Sec+, CCSP, GIAC).
Strong analytical and problem-solving abilities, especially in process development and root cause analysis.
Additional Information
Temp-to-Hire: This is a W2 contract position with potential to convert to a full-time role, contingent on performance and business needs.
Work Arrangements: Local candidates are preferred; remote candidates will be considered if necessary.
Team Environment: The Cloud & Endpoint Security team collaborates with multiple departments, playing a crucial part in establishing security best practices and ensuring incident response readiness.
$50 hourly 60d+ ago
Network Security Engineer
Noblis 4.9
Columbus, OH
Responsibilities We are looking for highly technical professionals with a strong foundation in network architecture, design, and security - individuals who are ready to step up from traditional network engineering roles to take ownership of strategic, architecture-level responsibilities. Ideal candidates will have deep understanding of networking, security architecture and design, and experience applying Federal security guidelines (e.g, NIST 800-53, FISMA, etc.) to harden and secure systems.
These are the types of professionals who understand both the big-picture architecture and the hands-on technical details, and who are prepared to make security-focused architectural recommendations in complex environments.
The TIS SecurityEngineer will support the FAA Telecommunications and Integrated Services (TIS) Group and provide expert-level securityengineering across the FAA's FTI environment. This includes:
+ Analyzing and guiding network architecture to ensure cybersecurity is built-in from the ground up.
+ Performing hands-on reviews of system configurations, firewall rules, and network paths to align with FAA Orders, NIST 800-53, and federal cybersecurity standards.
+ Leading efforts in transitioning technologies (e.g., IPv4 to IPv6, microwave radio refreshes) from a cybersecurity and network architecture perspective.
+ Supporting the integration of Zero Trust, Software-Defined Networking (SDN), and defense-in-depth strategies into enterprise-level solutions.
+ Acting as a technical bridge between FAA cyber stakeholders and infrastructure providers (network, security, cloud).
+ Evaluating vendor-proposed architectures and making expert-level recommendations based on federal policy, security principles, and industry best practices.
Required Qualifications
+ Experience supporting federal government programs, ideally within the FAA or transportation sector.
+ Proven experience with hands-on network engineer or architecture and understands network design, configurations, firewalls, VPNs, IDS/IPS, and load balancing.
+ Knowledge of telecommunications infrastructure, including IPv4/IPv6, and WAN/LAN environments.
+ Understand federal cybersecurity frameworks (NIST RMF, FISMA, NIST SP 800-53 rev 5).
+ Can evaluate network and system security concepts for large-scale, safety-critical systems like those in the National Airspace System (NAS).
+ Comfortable advising on defense-in-depth architectures, Zero Trust CONOPS, SD-WANs, and emerging tech.
+ Have experience collaborating with engineers, PMs, and cybersecurity stakeholders to support ATO packages and continuous monitoring.
+ Ability to develop system security plans, risk assessments, and related security documentation.
+ U.S. Citizenship or Permanent Residency with 3+ years U.S. residency.
+ Bachelor's degree in Cybersecurity, Information Technology, Telecommunications, or a related field.
+ 12+ years of experience in cybersecurity or network security roles
+ Subsitutions: For anything requiring a substitution, the governemnt customer is subject to further review and either approve or deny the request.
+ A High School degree with a total of 18 years of experience in cybersecurity or network security roles
+ Masters degree with a total of 9 years of experience in cybersecurity or network security roles
**Compensation Ranges** : for D.C., NJ, Remote: $105,100 - $164,125
Desired Qualifications
+ CISSP, Security+, CCNA, or similar certification.
+ FAA or transportation sector experience preferred.
+ Familiarity with Zero Trust Architecture, Security Orchestration, and network virtualization (e.g., NFV).
+ Strong written, verbal, and interpersonal skills.
Overview
Noblis (*********************** and our wholly owned subsidiaries, Noblis ESI , and Noblis MSD tackle the nation's toughest problems and apply advanced solutions to our clients' most critical missions. We bring the best of scientific thought, management, and engineering expertise together in an environment of independence and objectivity to deliver enduring impact on federal missions. Noblis works with a wide range of government clients in the defense, intelligence and federal civil sectors. Learn more at Noblis -About Us (*****************************************
**Why work at a Noblis company?**
Our employees find greater meaning in their work and balance the other things in life that matter to them. Our people are our greatest asset. They are exceptionally skilled, knowledgeable, team-oriented, and mission-driven individuals who want to do work that matters and benefits the public. Noblis has won numerous workplace awards (************************************ . Noblis maintains a drug-free workplace.
* _Remote/hybrid status is subject to change based on Noblis and/or government requirements_
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to race, color, ethnicity, sex, age, national origin, religion, physical or mental disability, pregnancy/childbirth and related medical conditions, veteran or military status, or any other characteristics protected by applicable federal, state, or local law.
If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact us (*************************************** .
EEO is the Law (************************************************* | E-Verify (********************************************************************************************************************** | Right to Work (****************************************************************
Total Rewards
At Noblis we recognize and reward your contributions, provide you with growth opportunities, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, and work-life programs. Our award programs acknowledge employees for exceptional performance and superior demonstration of our service standards. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in our benefit programs. Other offerings may be provided for employees not within this category. We encourage you to learn more about our total benefits by visiting the Benefits (************************************* page on our Careers (**************************** site.
Compensation at Noblis is determined by various factors, including but not limited to, the combination of education, certifications, knowledge, skills, competencies, and experience, internal and external equity, location, clearance level, as well as contract-specific affordability, organizational requirements and applicable employment laws. The projected compensation range for this position is based on full time status. For part time or on-call staff, compensation is proportionately adjusted based on hours worked. While monetary compensation is important, it's just one component of Noblis' total compensation package.
Posted Salary Range
USD $105,100.00 - USD $164,125.00 /Yr.
$105.1k-164.1k yearly 18d ago
Cyber Security Engineer
Central Insurance 3.6
Dublin, OH
Location: Van Wert, OH; Dublin, OHWork Model: Hybrid Position type: Full time - salary We're a team of employees passionate about delivering best-in-class customer service and driving innovation in IT support. Integrity, relationships, and excellence are at the heart of everything we do.
Our employees fully utilize their talents and bring their best selves to work. We believe who you are is just as important as what you do!
Looking to make a difference and apply your depth of cyber security knowledge in a variety of security solutions. Join Central's cyber security team. We seek curious and passionate individuals that enjoy being empowered and who can lead within their areas of expertise. The ideal candidate will be responsible for technical expertise and execution in the areas of end point protection, vulnerability management, web security, network security, email security, and penetration testing for Central.
Key Responsibilities of the Role
Develops and executes security controls, defense, and countermeasures to prevent attacks or attempts to infiltrate company devices.
Utilizes digital forensics tools to investigate any possible incidents.
Configures and validates any security tools (EDR, SIEM, etc..) to reduce false positives for intrusion and enable us to detect and respond quicker in case of a compromise.
Provides expert technical advice within IT / Forensics cyber incident tabletop exercises.
Performs root cause analysis, conducts threat analysis, and determines an action plan to remediate any risks identified.
Performs security gap assessments and threat modeling for new and existing IT solutions.
Provides technical advice and collaborates effectively with all IT groups.
Manages and enhances security processes and tools involving email security, collaboration and file sharing, network security, cloud security, and vulnerability management.
Conducts penetration testing for exploitable weaknesses within Central infrastructure and recommends remediations.
Supports compliance initiatives (NIST CSF, PCI-DSS, MAR) and assists with audits.
Stays current with emerging threats, vulnerabilities, and technology trends.
Required Qualifications
Bachelor's degree within Computer Science and 2 year of related experience
Or 4 years of related experience
Preferred Qualifications
Cyber-security coursework or experience
CISSP, CEH, OSCP certifications
Knowledge, Skills, and Abilities
Creativity and passion for cyber security
Curious mind and strong desire to constantly learn.
Excellent communication skills and ability to clearly explain security risks to any audience.
Ability to weigh risks, calculate the costs on a course of action, and propose the optimal path toward mitigation.
Capable of designing and maintaining security KPI metrics to prioritize activities
Experience with security tools such as Defender, Rapid 7, Abnormal, CrowdStrike, Palo Alto.
Experience with scripting languages such as Python, PowerShell, Bash.
Strong knowledge of network protocols and design, operating systems (Windows, Linux, MacOS) and cloud platforms (Azure) and DLP techniques.
Demonstrated ability to produce clear, concise, and technically accurate documentation including visual diagrams to communicate complex security concepts to any audience.
Maximizes the use of AI, automation, computer forensics tools, workflows, and practices.
Capable of participating within table top exercises at the IT or Corporate level.
Knowledgeable with risk assessment methodology.
Knowledgeable and experienced in penetration testing exercises.
Total Rewards
Central establishes base pay based on several factors including labor market data and an evaluation of candidate qualifications relative to role requirements. Base pay is one component of a comprehensive total rewards package designed to support employees' financial, health, career, and retirement objectives. Central provides extensive health and wellness benefits to promote flexibility, work-life balance, and long-term financial security. For more information, see Central Insurance Benefits
$75k-97k yearly est. 60d+ ago
Network Security Engineer
Under Armour, Inc. 4.5
Columbus, OH
**Network SecurityEngineer** **Values & Innovation** At Under Armour, we are committed to empowering those who strive for more, and the company's values - Act Sustainably, Celebrate the Wins, Fight on Together, Love Athletes and Stand for Equality - serve as both a roadmap for our teams and the qualities expected of every teammate.
Our Values define and unite us, the beliefs that are the red thread that connects everyone at Under Armour. Our values are rallying cries, reminding us why we're here, and fueling everything we do.
Our pursuit of better begins with innovation and with our team's mission of being the best. With us, you get the freedom to go further - no matter your role. That means developing, delivering, and selling the state-of-the-art products and digital tools that make top performers even better.
If you are a current Under Armour teammate, apply to this position on the Internal Career Site Here. (***************************************************************************************************************************************************
**Purpose of Role**
The Global Network SecurityEngineer is responsible for proactively identifying security risks and incidents within Under Armour's Corporate, Retail, Distribution House, and Regional Data Center Networks. The Network SecurityEngineer will support a risk centric Global Network Security program that will help reduce our external exposure, while increasing visibility and control across the global environment. The Network SecurityEngineer will overlay Security capabilities across existing technologies on our Enterprise and Cloud networks to reduce attack surface and minimize downtime . The Network SecurityEngineer will be responsible for maintaining and updating our signature-based and behavior-based detection and mitigation capabilities. The Network SecurityEngineer will support strategic business needs by engaging in Architecture Reviews and new technology implementations. The Network SecurityEngineer will consume Threat Intelligence and integrate indicators of compromise (IOCs) relevant to corporate and cloud network defense.
**Your Impact**
+ Support network security design and architecture actions and initiatives
+ Work closely with our Network Engineering team in developing and deploying Infrastructure hardening, Firewall Solutions, Global NAC solutions, Wi-Fi Security and SASE solutions
+ Assist with the development, management, and maintenance of UA's Global Network
+ Assist with development and enforcement of network security policies
+ Maintain visibility and control of UA's global networking environment
+ Review network traffic for suspicious activity using network monitoring tools
+ Test and validate new network deployed hardware technologies
+ Work closely with our IR Team in mitigating network security alerts and anomalies
+ Work with our Threat Intel team in analyzing and integrating relevant IOCs
+ Support the vulnerability management and network teams with mitigations related to security vulnerabilities and patches
+ Leverage experience and computer science background to review and remediate suspected malicious activity
+ Ability to work with very large amounts of network, file and host-based log data
+ Engage and support securityengineering and architecture needs for new enterprise projects
**Qualifications**
+ Bachelor's degree with typically 5 years of relevant cybersecurity experience OR Master's degree with typically 3 years of relevant cybersecurity experience OR typically 9 years of relevant cybersecurity work experience without degree
+ Global Enterprise Network Security, Cybersecurity or Network Engineering experience
+ Working knowledge of popular Firewalls, NAC solutions, Network Intrusion Detection platforms and tools
+ Hands-on experience with network configuration and troubleshooting
+ Hands-on experience with implementing and managing firewalls and security appliances
+ Hands-on experience with scripting languages such as Python, Bash, and PowerShell
+ Working knowledge of common network security tools
+ Understands SD-WAN technology and has worked in an SD-WAN environment
+ Understands Networking and Network Security capabilities in popular cloud platforms
**Workplace Location**
+ **Location:** Remote (East Coast strongly preferred to optimize collaboration with HQ and cross-functional teams)
+ **Work Schedule:** This role follows a hybrid work schedule, requiring 4 days in-office per week.
+ **Travel:** Minimal
+ **Licenses/Certifications:** N/A
+ **Sponsorship Eligibility:** UA does not offer sponsorship of job applicants for employment-based work authorization for this position at this time.
**Relocation**
+ No relocation provided
**Base Compensation**
$97,151.60-$121,439.50 USD
Most new hires fall within this range and have the opportunity to earn more over time. Initial placement within the salary range, however, is based on an individual's relevant knowledge, skills and experience for the position. UA is committed to helping our teammates succeed and advance in their careers. Base salary is only one component of our competitive Total Rewards package.
**Benefits & Perks**
+ Paid "UA Give Back" Volunteer Days: Work alongside your team to support initiatives in your local community
+ Under Armour Merchandise Discounts
+ Competitive 401(k) plan matching
+ Maternity and Parental Leave for eligible and FMLA-eligible teammates
+ Health & fitness benefits, discounts and resources- We offer teammates across the country programs to promote physical activity and overall well-being
**Our Commitment to Equal Opportunity**
At Under Armour, we are committed to providing an environment of mutual respect where equal employment opportunities are available to all applicants and teammates without regard to race, color, religion or belief, sex, pregnancy (including childbirth, lactation and related medical conditions), national origin, age, physical and mental disability, marital status, sexual orientation, gender identity, gender expression, genetic information (including characteristics and testing), military and veteran status, family or paternal status and any other characteristic protected by applicable law. Under Armour seeks to recruit, develop and retain the most talented people representing a wide variety of backgrounds and perspectives. If a reasonable accommodation is needed to participate in the job application or interview process, please contact our Human Resources team via candidateaccommodations@underarmour.com.
Requisition ID: 163925
Location:
Remote, USBaltimore, MD, US, 21230
Business Unit: Corporate
Region: North America
Employee Class: Full Time
Employment Type: Salaried
Learn more about our Benefits here
$97.2k-121.4k yearly 2d ago
Global Security - Command Center Analyst
Jpmorgan Chase & Co 4.8
Columbus, OH
JobID: 210696511 JobSchedule: Full time JobShift: Mid-Day : The Global Security (GS) team protects the firm's people and assets, ensuring the safety of business operations through the implementation of technology, best-in-class talent and client collaboration. Teams are responsible for developing safety policies and procedures, customer safety, pre-employment screening, fraud investigations and security operations on a global basis.
As a Retail GSOC Command Center Specialist within our Global Security Team , you will be responsible for monitoring, researching, reviewing and analyzing data sources for dissemination and reporting purposes, to ensure compliance with standard operating procedures in a fast-paced environment; always ensuring the highest quality and professionalism in service.The Retail Global Security Operations Center (Retail GSOC) is the primary communications and situational awareness hub for the firm's reporting of and response to Workplace Violence and Physical Security incidents across the Consumer Bank Branch network in the US. The Retail GSOC facilitates intake of security-related incident information, interacting directly with employees at retail branches and disseminating that information to other security professionals for response.
This position is based in Columbus, Ohio; Candidates must be able to physically work in office full-time to support the day-to-day operations of the Retail GSOC. The role is performed during nationwide branch business hours: Monday-Friday 8:00 AM to 9:00 PM EST, and Saturday 8:00 AM to 6:00 PM EST. This position will be a fully in-office position.
Job Responsibilities:
* Triage and escalate workplace violence and physical security incidents to consumer security and threat management teams
* Conduct security incident reporting and triage of potential impacts to the firm's employees, assets, and areas of operation
* Conduct proactive and real-time research into potential risks; monitor external media feeds for threats to the firm's employees, assets or areas of operation
* Escalate sensitive or high-impact incidents to senior managers and executives as necessary
* Perform special projects and research as required by GSOC management or as conditions warrant
* Work in office shifts between 8:00 AM to 9:00 PM EST shifts Monday-Saturdays
* Work overnights, weekends, holidays and during crises as needed
Required Qualifications, Capabilities, and Skills:
* 3+ years relevant professional experience in incident management, business resilience or security operations, law enforcement or military experience
* Work and adapt effectively in a fast-paced, fluid environment, to meet tight deadlines and consistently produce high quality products
* Demonstrated ability to effectively communicate
* Excellent written and oral communication skills
* High level of Emotional Intelligence (EQ); ability to display empathy and assist in de-escalating stressful situations
* Strong customer focus; use of discretion in confidential/sensitive matters
* Highly detail-oriented, effective time management skills, proactive nature
* Work in complex situations with a sense of urgency
Preferred Qualifications, Capabilities, and Skills:
* Undergraduate degree, preferably in intelligence studies, criminal justice, business management or related field
* Establish, foster and maintain trust-based relationships with a diverse portfolio of stakeholders
* Confident and collaborative, ability to constructively challenge the status quo and provide diverse perspective
* 3+ year of contact center experience
* Strong understanding of security operations concepts with experience working in a global organization
* ASIS or other professional Security/Crisis Management certifications
$57k-81k yearly est. Auto-Apply 19d ago
Senior Security Analyst
Capgemini Holding Inc. 4.5
Westerville, OH
Choosing Capgemini means choosing a company where you will be empowered to shape your career in the way you'd like, where you'll be supported and inspired by a collaborative community of colleagues around the world, and where you'll be able to reimagine what's possible. Join us and help the world's leading organizations unlock the value of technology and build a more sustainable, more inclusive world.
The Senior Security Analyst supports the governance of service provider activities in the enterprise security program, monitoring and escalating problems and providing information on security issues. Undertakes security assurance and audit activities to ensure compliance and to identify risks and opportunities. Provides information to senior managers and executives to ensure that they are aware of any security-related risks or opportunities. Provides subject matter expertise, consultancy and training in security-related matters. Must be able to function in a fast-paced, multi-vendor outsourced environment, facilitating conference calls among other subject matter experts and the client.
Your Responsibilities:
Handles monthly reporting duties for the Information Risk Management team;
Facilitates audit planning and audit remediation activities of the service providers, leading calls and documenting and reporting progress;
Has familiarity with Security technologies and controls; Expertise not required, but ability to escalate to more senior subject matter experts is important.
Develops work plans to structure solutions and communications;
Able to involve client and vendor staff appropriately in resolving Security problems;
Participates effectively within the business' Security governance framework;
Tracks the corrective and preventive actions being taken to improve Security to closure.
Possess strong communication skills to communicate technical and security risk information to management.
Your Experience:
Ability to self-manage with little interaction from other management staff.
Flexible and able to adapt to manage a fast-changing environment.
Ability to solve complex issues and provide recommendations and advice regarding remediations.
Security architecture, security software, or security policy experience
Ability to organize agendas, lead conference calls, and track action items to completion.
Security and Audit certifications such as SSCP, CISSP, CISA, CISM, CGEIT, CRISC, Security + are preferred.
Job Description - Grade Specific
The base compensation range for this role in the posted location is: $65,586-121,980.
Capgemini provides compensation range information in accordance with applicable national, state, provincial, and local pay transparency laws. The base compensation range listed for this position reflects the minimum and maximum target compensation Capgemini, in good faith, believes it may pay for the role at the time of this posting. This range may be subject to change as permitted by law.
The actual compensation offered to any candidate may fall outside of the posted range and will be determined based on multiple factors legally permitted in the applicable jurisdiction.
These may include, but are not limited to: Geographic location, Education and qualifications, Certifications and licenses, Relevant experience and skills, Seniority and performance, Market and business consideration, Internal pay equity.
It is not typical for candidates to be hired at or near the top of the posted compensation range.
In addition to base salary, this role may be eligible for additional compensation such as variable incentives, bonuses, or commissions, depending on the position and applicable laws.
Capgemini offers a comprehensive, non-negotiable benefits package to all regular, full-time employees. In the U.S. and Canada, available benefits are determined by local policy and eligibility and may include:
* Paid time off based on employee grade (A-F), defined by policy: Vacation: 12-25 days, depending on grade, Company paid holidays, Personal Days, Sick Leave
* Medical, dental, and vision coverage (or provincial healthcare coordination in Canada)
* Retirement savings plans (e.g., 401(k) in the U.S., RRSP in Canada)
* Life and disability insurance
* Employee assistance programs
* Other benefits as provided by local policy and eligibility
Important Notice: Compensation (including bonuses, commissions, or other forms of incentive pay) is not considered earned, vested, or payable until it becomes due under the terms of applicable plans or agreements and is subject to Capgemini's discretion, consistent with applicable laws. The Company reserves the right to amend or withdraw compensation programs at any time, within the limits of applicable legislation.
Disclaimers
Capgemini is an Equal Opportunity Employer encouraging inclusion in the workplace. Capgemini also participates in the Partnership Accreditation in Indigenous Relations (PAIR) program which supports meaningful engagement with Indigenous communities across Canada by promoting fairness, accessibility, inclusion and respect. We value the rich cultural heritage and contributions of Indigenous Peoples and actively work to create a welcoming and respectful environment. All qualified applicants will receive consideration for employment without regard to race, national origin, gender identity/expression, age, religion, disability, sexual orientation, genetics, veteran status, marital status or any other characteristic protected by law.
This is a general description of the Duties, Responsibilities and Qualifications required for this position. Physical, mental, sensory or environmental demands may be referenced in an attempt to communicate the manner in which this position traditionally is performed. Whenever necessary to provide individuals with disabilities an equal employment opportunity, Capgemini will consider reasonable accommodations that might involve varying job requirements and/or changing the way this job is performed, provided that such accommodation does not pose an undue hardship. Capgemini is committed to providing reasonable accommodation during our recruitment process. If you need assistance or accommodation, please reach out to your recruiting contact.
Please be aware that Capgemini may capture your image (video or screenshot) during the interview process and that image may be used for verification, including during the hiring and onboarding process.
Click the following link for more information on your rights as an Applicant in the United States. **************************************************************************
Capgemini is a global business and technology transformation partner, helping organizations to accelerate their dual transition to a digital and sustainable world, while creating tangible impact for enterprises and society. It is a responsible and diverse group of 340,000 team members in more than 50 countries. With its strong over 55-year heritage, Capgemini is trusted by its clients to unlock the value of technology to address the entire breadth of their business needs. It delivers end-to-end services and solutions leveraging strengths from strategy and design to engineering, all fueled by its market leading capabilities in AI, generative AI, cloud and data, combined with its deep industry expertise and partner ecosystem.
$65.6k-122k yearly 10d ago
Information Technology Manager 1 - Security & Compliance Manager- 20078290
Dasstateoh
Columbus, OH
Information Technology Manager 1 - Security & Compliance Manager- 20078290 (250008DD) Organization: CommerceAgency Contact Name and Information: ************************ or **************Unposting Date: OngoingPrimary Location: United States of America-OHIO-Franklin County-Columbus Compensation: Pay range 16, step 1 $47.50/hr.Schedule: Full-time Work Hours: 8:00 am - 5:00 pm (Hours subject to change) Classified Indicator: UnclassifiedUnion: Exempt from Union Primary Job Skill: Information TechnologyTechnical Skills: Risk Management, CybersecurityProfessional Skills: Analyzation, Collaboration, Consultation, InnovationPrimary Technology: Security Monitoring Agency Overview This is a re-post. If you applied to posting 250006TA, you do not need to re-apply to be considered. The Mission of the Ohio Department of Commerce is promoting prosperity by protecting what matters most. The Division of Administration provides overall leadership and administrative support for all Divisions. The Division includes the Office of Director, Communications, Fiscal, Human Resources, IT, Legal and Legislative Affairs. As the state's chief regulator, the Department of Commerce impacts Ohioans every day. We are motivated by our mission to promote prosperity for businesses and licensees by protecting what matters most to the residents of our state. We ensure compliance through proactive outreach, education, and customer-focused service.Commerce is comprised of eight operating divisions and one standalone program that span a variety of industries including real estate, liquor, banking, securities, firefighting, construction and skilled trades, and cannabis. Through exceptional compliance practices and oversight, Commerce has a direct role in protecting Ohioans.Our Guiding PrinciplesMaking an IMPACT for the customer:InclusiveMotivatedProactiveAccountableCustomer-FocusedTeamwork Job DescriptionThe IT Security Manager will serve in a management role with technical capabilities and strategic planning oversight; responsible for overseeing and managing security programs, projects, personnel, logical/technical administration, and security acquisitions. Our preferred candidate possesses the ability and experience to focus on reducing security risks throughout the infrastructure to an acceptable level, in alignment with the organizations business needs and requirements. They will be capable of identifying, establishing, and adhering to tactical plans for achieving set goals within a dynamic fast-paced environment.
Duties include but are not limited to:
Lead the team responsible for security assessments, developing risk-based solutions and controls frameworks.
Serve as the subject matter expert for control validation in the Security team.
Create/Update/Maintain IT Security Guidelines and Standards.
Develop System Policies and establish system standards.
Communicate security controls and remediate any concerns.
Collaborate with various departments to safeguard our adherence to policies and other undertakings that influence the security, confidentiality, integrity, and accessibility of our application, infrastructure, and business operations.
Conduct, document, and report on internal and third-party risk program.
Collaborate with the DAS OISP team to ensure successful delivery of security & business objectives.
Lead the coordination of data gathering needed for internal and external audits, regulatory requirements, and other compliance and risk management needs requirements.
Be a highly analytical and effective communicator capable of influencing other teams and departments.
Why Work for the State of OhioAt the State of Ohio, we take care of the team that cares for Ohioans. We provide a variety of quality, competitive benefits to eligible full-time and part-time employees*. For a list of all the State of Ohio Benefits, visit our Total Rewards website! Our benefits package includes:
Medical Coverage
Free Dental, Vision and Basic Life Insurance premiums after completion of eligibility period
Paid time off, including vacation, personal, sick leave and 11 paid holidays per year
Childbirth, Adoption, and Foster Care leave
Education and Development Opportunities (Employee Development Funds, Public Service Loan Forgiveness, and more)
Public Retirement Systems (such as OPERS, STRS, SERS, and HPRS) & Optional Deferred Compensation (Ohio Deferred Compensation)
*Benefits eligibility is dependent on a number of factors. The Agency Contact listed above will be able to provide specific benefits information for this position.Qualifications8 1/2 years (102 mos.) exp. commensurate with job duties to be performed & knowledges & skills required as outlined in approved position description on file for position to be filled as advertised in job posting; 18 months exp. in performing project management functions as defined in series purpose. -Or completion of undergraduate core coursework in computer science, or completion of undergraduate core coursework in any academic major which included at least one course in each of the following: advanced-level computer programming language (for example, COBOL, Delphi, Java, Powerbuilder, Visual Basic, Pl 1, SAS PCS, Pacbase, Full Visual Suite, Designer 2000, Developer 2000, C, C++, Visual C, ECL, or Visual Studio), logic-based mathematics, data base concepts (for example, Oracle, Microsoft Access, Paradox, Sybase, IMS DB, DB2, Cache, DMS, or RDMS), computer systems analysis & design, & basic data processing concepts; additional 6 1/2 years (78 mos.) exp. commensurate with job duties to be performed & knowledges & skills required as outlined in approved position description on file for position to be filled as advertised in job posting.; 18 mos. exp. in performing project management functions as defined in series purpose. -Or 12 mos. exp. as Information Technology Supervisor 3, 64119, or equivalent. Or in offices of statewide information technology policy & planning, positions require completion of undergraduate core coursework in computer science, or completion of undergraduate core coursework in any academic major which included at least one course in each of the following: advanced-level computer programming language (for example, COBOL, Delphi, Java, Powerbuilder, Visual Basic, Pl 1, SAS PCS, Pacbase, Full Visual Suite, Designer 2000, Developer 2000, C, C++, Visual C, ECL, or Visual Studio), logic-based mathematics, data base concepts (for example, Oracle, Microsoft Access, Paradox, Sybase, IMS DB, DB2, Cache, DMS, or RDMS), computer systems analysis & design, & basic data processing concepts; 3 yrs. exp. in utilizing word processing software; 3 yrs. exp. in utilizing internet browser(s) for research; 54 mos. exp. which included following: knowledge of information technology architecture components, developing information technology strategic plans, preparing & making presentations/public speaking, writing information technology related policy & procedures, preparing & monitoring budget, providing cost & resources estimates, & contract management; 2 yrs. exp. in utilizing e-mail system; 18 mos. exp. in project management or lead role on information technology project;12 mos. exp. in utilizing spreadsheet software; 12 mos. exp. as Information Technology Supervisor 3, 64119, or equivalent. -Or equivalent of Minimum Class Qualifications For Employment noted above. Job Skills: Information TechnologySupplemental InformationApplications must clearly indicate how the applicant meets the minimum qualification for the position. If you meet minimum qualification due to educational achievement, please submit a copy of your unofficial transcript(s) with your application. All answers to the supplemental questions must be supported by information provided in the work experience &/or education sections on your civil service application. Please do not use “see resume” as a substitution for the completed application; assumptions will not be made. Application Status: You can check the status of your application online by signing into your profile. Careers to which you've applied will be listed. The application status is shown to the right of the position title and application submission details. The final candidate selected for this position will be required to undergo a criminal background check as well as other investigative reviews. Criminal convictions do not necessarily preclude an applicant from consideration for a position, unless restricted under state or federal law or federal restrictions. An individual assessment of an applicant's prior criminal convictions will be made before excluding an applicant from consideration.All final applicants tentatively selected for this position will be required to submit to urinalysis to test for illegal drug use prior to appointments. Testing will also be performed for the presence of marijuana. An applicant with a positive test shall not be offered employment unless the applicant submits medical documentation of legally prescribed medications or a recommendation for medical marijuana. Also, an applicant with a positive test will not be considered for any position with the State of Ohio for a period of one year.ADA StatementOhio is a Disability Inclusion State and strives to be a model employer of individuals with disabilities. The State of Ohio is committed to providing access and inclusion and reasonable accommodation in its services, activities, programs and employment opportunities in accordance with the Americans with Disabilities Act (ADA) and other applicable laws.Drug-Free WorkplaceThe State of Ohio is a drug-free workplace which prohibits the use of marijuana (recreational marijuana/non-medical cannabis). Please note, this position may be subject to additional restrictions pursuant to the State of Ohio Drug-Free Workplace Policy (HR-39), and as outlined in the posting.
$47.5 hourly Auto-Apply 8h ago
Information Technology Manager 1 - Security & Compliance Manager- 20078290
State of Ohio 4.5
Columbus, OH
Information Technology Manager 1 - Security & Compliance Manager- 20078290 (250008DD) Organization: CommerceAgency Contact Name and Information: ************************ or **************Unposting Date: OngoingPrimary Location: United States of America-OHIO-Franklin County-Columbus Compensation: Pay range 16, step 1 $47.50/hr.Schedule: Full-time Work Hours: 8:00 am - 5:00 pm (Hours subject to change) Classified Indicator: UnclassifiedUnion: Exempt from Union Primary Job Skill: Information TechnologyTechnical Skills: Risk Management, CybersecurityProfessional Skills: Analyzation, Collaboration, Consultation, InnovationPrimary Technology: Security Monitoring Agency Overview This is a re-post. If you applied to posting 250006TA, you do not need to re-apply to be considered. The Mission of the Ohio Department of Commerce is promoting prosperity by protecting what matters most. The Division of Administration provides overall leadership and administrative support for all Divisions. The Division includes the Office of Director, Communications, Fiscal, Human Resources, IT, Legal and Legislative Affairs. As the state's chief regulator, the Department of Commerce impacts Ohioans every day. We are motivated by our mission to promote prosperity for businesses and licensees by protecting what matters most to the residents of our state. We ensure compliance through proactive outreach, education, and customer-focused service.Commerce is comprised of eight operating divisions and one standalone program that span a variety of industries including real estate, liquor, banking, securities, firefighting, construction and skilled trades, and cannabis. Through exceptional compliance practices and oversight, Commerce has a direct role in protecting Ohioans.Our Guiding PrinciplesMaking an IMPACT for the customer:InclusiveMotivatedProactiveAccountableCustomer-FocusedTeamwork Job DescriptionThe IT Security Manager will serve in a management role with technical capabilities and strategic planning oversight; responsible for overseeing and managing security programs, projects, personnel, logical/technical administration, and security acquisitions. Our preferred candidate possesses the ability and experience to focus on reducing security risks throughout the infrastructure to an acceptable level, in alignment with the organizations business needs and requirements. They will be capable of identifying, establishing, and adhering to tactical plans for achieving set goals within a dynamic fast-paced environment.
Duties include but are not limited to:
Lead the team responsible for security assessments, developing risk-based solutions and controls frameworks.
Serve as the subject matter expert for control validation in the Security team.
Create/Update/Maintain IT Security Guidelines and Standards.
Develop System Policies and establish system standards.
Communicate security controls and remediate any concerns.
Collaborate with various departments to safeguard our adherence to policies and other undertakings that influence the security, confidentiality, integrity, and accessibility of our application, infrastructure, and business operations.
Conduct, document, and report on internal and third-party risk program.
Collaborate with the DAS OISP team to ensure successful delivery of security & business objectives.
Lead the coordination of data gathering needed for internal and external audits, regulatory requirements, and other compliance and risk management needs requirements.
Be a highly analytical and effective communicator capable of influencing other teams and departments.
Why Work for the State of OhioAt the State of Ohio, we take care of the team that cares for Ohioans. We provide a variety of quality, competitive benefits to eligible full-time and part-time employees*. For a list of all the State of Ohio Benefits, visit our Total Rewards website! Our benefits package includes:
Medical Coverage
Free Dental, Vision and Basic Life Insurance premiums after completion of eligibility period
Paid time off, including vacation, personal, sick leave and 11 paid holidays per year
Childbirth, Adoption, and Foster Care leave
Education and Development Opportunities (Employee Development Funds, Public Service Loan Forgiveness, and more)
Public Retirement Systems (such as OPERS, STRS, SERS, and HPRS) & Optional Deferred Compensation (Ohio Deferred Compensation)
*Benefits eligibility is dependent on a number of factors. The Agency Contact listed above will be able to provide specific benefits information for this position.Qualifications8 1/2 years (102 mos.) exp. commensurate with job duties to be performed & knowledges & skills required as outlined in approved position description on file for position to be filled as advertised in job posting; 18 months exp. in performing project management functions as defined in series purpose. -Or completion of undergraduate core coursework in computer science, or completion of undergraduate core coursework in any academic major which included at least one course in each of the following: advanced-level computer programming language (for example, COBOL, Delphi, Java, Powerbuilder, Visual Basic, Pl 1, SAS PCS, Pacbase, Full Visual Suite, Designer 2000, Developer 2000, C, C++, Visual C, ECL, or Visual Studio), logic-based mathematics, data base concepts (for example, Oracle, Microsoft Access, Paradox, Sybase, IMS DB, DB2, Cache, DMS, or RDMS), computer systems analysis & design, & basic data processing concepts; additional 6 1/2 years (78 mos.) exp. commensurate with job duties to be performed & knowledges & skills required as outlined in approved position description on file for position to be filled as advertised in job posting.; 18 mos. exp. in performing project management functions as defined in series purpose. -Or 12 mos. exp. as Information Technology Supervisor 3, 64119, or equivalent. Or in offices of statewide information technology policy & planning, positions require completion of undergraduate core coursework in computer science, or completion of undergraduate core coursework in any academic major which included at least one course in each of the following: advanced-level computer programming language (for example, COBOL, Delphi, Java, Powerbuilder, Visual Basic, Pl 1, SAS PCS, Pacbase, Full Visual Suite, Designer 2000, Developer 2000, C, C++, Visual C, ECL, or Visual Studio), logic-based mathematics, data base concepts (for example, Oracle, Microsoft Access, Paradox, Sybase, IMS DB, DB2, Cache, DMS, or RDMS), computer systems analysis & design, & basic data processing concepts; 3 yrs. exp. in utilizing word processing software; 3 yrs. exp. in utilizing internet browser(s) for research; 54 mos. exp. which included following: knowledge of information technology architecture components, developing information technology strategic plans, preparing & making presentations/public speaking, writing information technology related policy & procedures, preparing & monitoring budget, providing cost & resources estimates, & contract management; 2 yrs. exp. in utilizing e-mail system; 18 mos. exp. in project management or lead role on information technology project;12 mos. exp. in utilizing spreadsheet software; 12 mos. exp. as Information Technology Supervisor 3, 64119, or equivalent. -Or equivalent of Minimum Class Qualifications For Employment noted above. Job Skills: Information TechnologySupplemental InformationApplications must clearly indicate how the applicant meets the minimum qualification for the position. If you meet minimum qualification due to educational achievement, please submit a copy of your unofficial transcript(s) with your application. All answers to the supplemental questions must be supported by information provided in the work experience &/or education sections on your civil service application. Please do not use “see resume” as a substitution for the completed application; assumptions will not be made. Application Status: You can check the status of your application online by signing into your profile. Careers to which you've applied will be listed. The application status is shown to the right of the position title and application submission details. The final candidate selected for this position will be required to undergo a criminal background check as well as other investigative reviews. Criminal convictions do not necessarily preclude an applicant from consideration for a position, unless restricted under state or federal law or federal restrictions. An individual assessment of an applicant's prior criminal convictions will be made before excluding an applicant from consideration.All final applicants tentatively selected for this position will be required to submit to urinalysis to test for illegal drug use prior to appointments. Testing will also be performed for the presence of marijuana. An applicant with a positive test shall not be offered employment unless the applicant submits medical documentation of legally prescribed medications or a recommendation for medical marijuana. Also, an applicant with a positive test will not be considered for any position with the State of Ohio for a period of one year.ADA StatementOhio is a Disability Inclusion State and strives to be a model employer of individuals with disabilities. The State of Ohio is committed to providing access and inclusion and reasonable accommodation in its services, activities, programs and employment opportunities in accordance with the Americans with Disabilities Act (ADA) and other applicable laws.Drug-Free WorkplaceThe State of Ohio is a drug-free workplace which prohibits the use of marijuana (recreational marijuana/non-medical cannabis). Please note, this position may be subject to additional restrictions pursuant to the State of Ohio Drug-Free Workplace Policy (HR-39), and as outlined in the posting.
$47.5 hourly Auto-Apply 10h ago
Security Analyst
Sonsoft 3.7
Marysville, OH
Sonsoft , Inc. is a USA based corporation duly organized under the laws of the Commonwealth of Georgia. Sonsoft Inc. is growing at a steady pace specializing in the fields of Software Development, Software Consultancy and Information Technology Enabled Services.
Job Description
Wants:
Ø In-depth knowledge and understanding of information risk concepts and principles, as a means of relating business needs to security controls
Ø Knowledge of an experience in developing and documenting security controls and test plans/scripts.
Ø Experience with SOX 404, HIPPA, GLBA, PCI, foreign and domestic privacy laws.
Ø Experience with common Information security management frameworks, such as [International Organization for Standardization (ISO) 2700x and the ITIL, COBIT and National Institute of Standards and Technology (NIST) frameworks.
Ø Knowledge of the fundamentals of project management In-depth knowledge of risk assessment methods and technologies.
Ø Proficiency in performing risk, business impact, control and vulnerability assessments.
Ø Strong understanding of business applications, including ERP and financial systems, Excellent technical knowledge of mainstream operating systems [for example, Microsoft Windows and Oracle Solaris) and a wide range of security technologies, such as network security appliances, identity end access management (IAM) system, anti-malware solutions, automated policy compliance tools, and desktop security tools.
Ø Knowledge of network infrastructure. including routers. switches.
Ø firewalls, and the associated network protocols and concepts.
Ø Experience In developing, documenting and maintaining security policies, processes, procedures and standards.
Ø Audit, compliance or governance experience is required.
Musts:
Ø Bachelor's degree in Information Systems or equivalent work experience in IS auditing, governance, compliance.
Business Experience:
Ø 3 to 5 years of combined IT and security work experience with a broad range of exposure to systems analysis, applications development, database design and administration; one to two years of experience with information security.
Daily Tasks Performed:
Ø Developing a single control framework to streamline the audit process into a Singular audit.
Ø Documenting controls and test procedures surrounding privacy and financial audit assessments Reforming independent assessments of various IT systems based on the newly defined control framework, Work with various business unit managers, application teams, and team managers to obtain testing evidence and execute lest scripts.
Ø Formally document test results and communicate findings to management and auditee/group/team.
Ø Assisting with remediation activities as identified within the assessment Actively reporting on progress and keeping management informed of the current status.
Ø Review processes and Identify areas where efficiency can be gained.
Ø Assist with risk mitigation strategies and framework development as needed.
Ø Assist in other areas of the department and organization as needed based on management direction.
Qualifications
Description:
Responsibilities
Pivotal team member in developing a compliance framework including controls development, test scripts, conducting assessments, reporting evaluations performed, and providing metrics on the progress made Works with business units and with other risk functions to identify security requirements, using methods that may include risk and business impact assessments.
Components of this activity include but are not limited to:
Business system analysis
Communication, facilitation and consensus building Assists in the coordination and completion of information security operations documentation Works with information security leadership to develop strategies and plans to enforce security requirements and address identified risks Reports to management concerning residual risk, vulnerabilities and other security exposures, including misuse assets and noncompliance Plays an advisory role in application development or acquisition projects to assess security requirements and controls and to ensure that security controls are implemented as planned Collaborates on critical IT projects to ensure that security controls are implemented as planned Works with IT throughout the project life cycle as directed by management Works with IT department and members of the information security team to identify, select and implement technical controls Develops security processes and procedures, and supports service-level agreements (SLAB) to ensure that security controls are managed and maintained Address security administration on a normal and exception-based processing of security authorization requests Researches new compliance requirements, works with other team members to incorporate existing process to reduce risk exposure.
Additional Information
**
U.S. citizens and those authorized to work in the U.S. are encouraged to apply
. We are unable to sponsor at this time.
Note:-
This is a FULL TIME job oppurtunity.
Only US Citizen, Green Card Holder, GC-EAD, H4-EAD, L2-EAD, TN VIsa can apply.
No OPT-EAD & H1-B for this position.
Please mention your Visa Status in your email or resume.
$57k-71k yearly est. 60d+ ago
Systems Engineer - Wright-Patterson AFB, OH
Serco 4.2
Columbus, OH
Dayton, Ohio, US Ohio, US Beavercreek, Ohio, US Fairborn, Ohio, US Columbus, Ohio, US Wright-Patterson AFB, Ohio, US Engineering 12354 Full-Time $103977.88 - $173296.47 Description & Qualifications** Description & Qualifications**
If you want to work on cutting edge Air Force programs, Serco has a great opportunity for you! Serco is seeking a talented System Engineer to join the team onsite at Wright-Patterson AFB, Ohio **(No telework/remote work at this location)** .
**This position is contingent upon your ability to maintain/transfer an active DoD Secret security clearance.**
This position supports the Positioning, Navigation, and Timing (PNT) Program Office (PNT PO) with cutting edge modernization / development, and ongoing sustainment of a variety of GPS receivers and user equipment to meet DoD and national-level priorities.
In this role, you will:
+ Duties will include planning, guiding, and executing technical aspects of acquisition programs.
+ Will work with senior government personnel on a regular basis and will frequently be called on to provide technical briefings to program leadership.
+ Will also serve as a technical advisor to government personnel.
+ Provide expertise in support of the overall project lead, Integrated Product Teams, conferences, and meetings.
+ Responsible for providing technical management and engineering support services to ensure the effective and efficient delivery of multiple PNT PO GPS modernization programs. Services include some or all of the following:
+ Sys Engineering planning, requirements generation, and task development / execution for multiple GPS modernization programs
+ Assessing civil and military mandates associated with Assured Positioning, Navigation, and Timing requirements
+ Developing / evaluating technical requirements, program strategies, statements of work and system engineering plans
+ Conducting engineering trade studies and technical analyses
+ Evaluating development, integration, and fielding of modernized GPS systems onto Joint Service platforms
+ Evaluating OEM technical performance and proposed solutions.
Visit the following link for more information about how Serco supports our Veterans **************************************************
To be successful in this role, you will have:
+ **A U.S. citizenship**
+ **An active DoD Secret security clearance**
+ A Bachelor's Degree in Engineering
+ At least 8 years related experience
+ Experience with defense acquisition management processes as contained in the DoD 5000 series directives
+ An excellent written and verbal communication skills
+ A clear understanding of the OSD and USAF Acquisition organization
+ The ability to travel 10%
Additional desired skills and qualifications:
+ 10 years related experience; 4assigned to a System Program Office
+ Familiarization and understanding of MBSE and Digital Engineering concepts/principles
+ Experience with GPS integration on military platforms
+ Level II DAWIA Certification in Systems Planning, Research, Development & Engineering
If you are interested in supporting and working with our Air Force and airmen and a dedicated Serco team, then submit your application now for immediate consideration. It only takes a few minutes!
Military Veterans and Spouses encouraged to apply.
Serco Inc. is using this posting for the purpose of building a talent pipeline of qualified candidates for future anticipated growth. This position is not a funded/active opening. Should the position become funded/active, qualified candidates will be invited to re-apply to the updated posting.
**Company Overview**
Serco Inc. (Serco) is the Americas division of Serco Group, plc. In North America, Serco's 9,000+ employees strive to make an impact every day across 100+ sites in the areas of Defense, Citizen Services, and Transportation. We help our clients deliver vital services more efficiently while increasing the satisfaction of their end customers. Serco serves every branch of the U.S. military, numerous U.S. Federal civilian agencies, the Intelligence Community, the Canadian government, state, provincial and local governments, and commercial clients. While your place may look a little different depending on your role, we know you will find yours here. Wherever you work and whatever you do, we invite you to discover your place in our world. Serco is a place you can count on and where you can make an impact because every contribution matters.
To review Serco benefits please visit: ************************************************ . If you require an accommodation with the application process please email: ******************** or call the HR Service Desk at ************, option 1. Please note, due to EEOC/OFCCP compliance, Serco is unable to accept resumes by email.
Candidates may be asked to present proof of identify during the selection process. If requested, this will require presentation of a government-issued I.D. (with photo) with name and address that match the information entered on the application. Serco will not take possession of or retain/store the information provided as proof of identity. For more information on how Serco uses your information, please see our Applicant Privacy Policy and Notice.
Serco does not accept unsolicited resumes through or from search firms or staffing agencies without being a contracted approved vendor. All unsolicited resumes will be considered the property of Serco and will not be obligated to pay a placement or contract fee. If you are interested in becoming an approved vendor at Serco, please email ********************* .
Serco is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, and other legally protected characteristics.
**Pay Transparency**
Our Total Rewards package includes competitive pay, performance-based incentives, and benefits that promote well-being and work-life balance-so you can thrive both professionally and personally. Eligible employees also gain access to a wide range of benefits from comprehensive health coverage and health savings accounts to retirement plans, life and disability insurance, and time-off programs that support work-life balance. Program availability may vary based on factors such as contract type, location, hire date, and applicable collective bargaining agreements.
Salary range: The range for this position can be found at the top of this posting. This range is provided as a general guideline and represents a good faith estimate across all experience levels. Actual base salary will be determined by a variety of factors, including but not limited to, the scope of the role, relevant experience, job-related knowledge, education and training, key skills, and geographic market considerations. For roles available in multiple states, the range may vary to reflect differences in local labor markets. In addition to base salary, eligible positions may include other forms of compensation such as annual bonuses or long-term incentive opportunities.
Benefits - Comprehensible benefits for full-time employees (part-time employees receive a limited package tailored to their role):
+ Medical, dental, and vision insurance
+ Robust vacation and sick leave benefits, and flexible work arrangements where permitted by role or contract
+ 401(k) plan that includes employer matching funds
+ Tuition reimbursement program
+ Life insurance and disability coverage
+ Optional coverages that can be purchased, including pet insurance, home and auto insurance, additional life and accident insurance, critical illness insurance, group legal, ID theft protection
+ Birth, adoption, parental leave benefits
+ Employee Assistance Plan
To review all Serco benefits please visit: ******************************************* .
Serco complies with all applicable state and local leave laws, including providing time off under the Colorado Healthy Families and Workplaces Act for eligible Colorado residents, in alignment with our policies and benefit plans. The application window for this position is for no more than 60 days. We encourage candidates to apply promptly after the posting date, as the position may close earlier if filled or if the application volume exceeds expectations. Please submit applications exclusively through Serco's external (or internal) career site. If an applicant has any concerns with job posting compliance, please send an email to: ******************** .
$104k-173.3k yearly Easy Apply 2d ago
Contractor - Network Engineering
Situsamc
Columbus, OH
SitusAMC is where the best and most passionate people come to transform our client's businesses and their own careers. Whether you're a real estate veteran, a passionate technologist, or looking to get your start, join us as we work together to realize opportunities for everyone, we proudly serve.
At SitusAMC, we are looking to match your unique experience with one of our amazing careers, so that we can help you realize your potential and career growth within the Real Estate Industry. If you are someone who can be yourself, advocate for others, stay nimble, dream big, own every outcome, and think global but act local - come join our team!
Contractor
Essential Job Functions:
+ Tests and supports new network hardware and topologies under Change Management
+ Performs expert level diagnostics assessments on fixing or improving network communications for cooperate systems.
+ Assist Network Engineering team when required.
+ Provides network support to the business, troubleshoots problems, answers hardware and software questions, and provides technical assistance
+ Creates network documentation for the firm.
+ Builds new connections to partner companies or new acquisitions based on requirement
+ Work with cross functional teams providing education guidance and assistance on tools utilized in the organization.
+ Maintains current knowledge of technology by attending appropriate educational training seminars or reading related documentation.
+ Maintains a good working knowledge of all corporate owned hardware and software
+ Works with 3rd party vendors and ISP providers
+ Creates and maintains up to date network diagrams for the firm.
+ Responsible for maintaining network inventory in Configuration Inventory Database
+ Conducts equipment patching/upgrades and office refresh
+ Works directly with Information Security to ensure the network is locked down and secure
+ Deals effectively with people and clearly communicates verbally and in writing
+ Plans, organizes, and coordinates work assignments and prioritizes workload
+ Knowledge and understanding of ITIL
+ Participates in on-call rotation to support 24/7 business support
+ Other activities as may be assigned by your manager
Qualifications/ Requirements:
+ 2-year degree in related field or equivalent combination of education and experience to complete assigned duties
+ Minimum of 6+ years of industry and/or relevant experience, typically with 1+ years in a Senior Associate level role or external equivalent
+ Preferred experience in Network Operations and Design
+ Preferred experience with Windows operation systems
+ Preferred experience with Linux operating systems
+ Current Certifications preferred, CCNA R&S, CCPN, AWS Solutions Architect
+ Excellent communication, interpersonal skills, and professional appearance.
+ Strong understanding of general Firewall, Router and Switching principals
+ Strong understanding of Cisco ASA Firewalls, ISR Routers, Nexus and Catalyst Switches, Meraki MX, MS, and MR Equipment.
+ Experience with HSRP and Dynamic Routing protocols such as BGP, EIGRP, OSPF
+ Extensive knowledge of route-based and Policy based IPsec VPN, Remote Access VPN tunnels.
+ Working knowledge of Monitoring tools such as SolarWinds NPM/NCM, PRTG
+ Knowledge working with Rancid, NPS servers, LDAP, RADIUS, TACACS, SCP, SNMP, SSH, DNS
+ Strong understanding of Wireless, Design/Implementation/troubleshooting and 802.1x
+ Experience working with MPLS, QOS, Zone Based Firewall
+ Experience working with Cisco Umbrella, AnyConnect, and WLAN controller
+ Familiarity with AWS Cloud native services: Deployment of VPCs Subnets, Route Tables, Transit Gateway, IGW, NACLs, Security Groups, Multi-Region Peering.
+ Experience with Multi-Cloud, Multi-Vendor network connectivity using, VPNs, Direct Connects, MPLS and SDWAN.
+ Experience with Load Balancer technologies and principals
+ Strong knowledge troubleshooting L2/L3 issues including voice, speed, and fragmentation.
+ Knowledge interconnecting physical networking to Virtualized environments such as VMWare.
+ Basic knowledge of Windows and Linux server administration
+ Self-motivated, with the ability to work in both a team environment and individually
+ Ability to understand and comply with the relevant department and/or corporate policies, procedures, and guidelines as they pertain to customer support
+ Knowledge of relevant commonly used concepts, best practices, and procedures
+ Strong analytical ability, good judgment, strategic and multidimensional thinker
+ Detail oriented and organized
Note: This job description is not intended to be all inclusive or exclusive. At any time, employees may perform other related duties as required to meet the ongoing needs of the organization and participate in additional trainings. SitusAMC does not accept unsolicited resumes from staffing agencies, search firms or any third parties. Any unsolicited resume submitted to SitusAMC in any manner will be considered SitusAMC property, and SitusAMC will not pay a fee for any placement resulting from the receipt of an unsolicited resume.
The annual full time base salary range for this role is
$50,000.00 - $100,000.00
Specific compensation is determined through interviews and a review of relevant education, experience, training, skills, geographic location and alignment with market data. Additionally, certain positions may be eligible to receive a discretionary bonus as determined by bonus program guidelines, position eligibility and SitusAMC Senior Management approval. SitusAMC offers PTO and paid holidays, the terms of which are set forth in the program policies. All full time employees also are eligible to participate in various benefit plans, including medical, dental, vision, life, disability insurance and 401K; in each case in accordance with the terms of the applicable plans.
Pay Transparency Nondiscrimination Provision (******************************************************************************************************
SitusAMC is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, national origin, disability, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.
Know Your Rights, Workplace Discrimination is Illegal (***********************************************************************************************
$50k-100k yearly 4d ago
Power System Studies Engineer - Data Center
Olsson 4.7
Columbus, OH
Arizona - Remote; Arkansas - Remote; Florida - Remote; Georgia - Remote; Idaho - Remote; Illinois - Remote; Indiana - Remote; Iowa - Remote; Kansas - Remote; Kentucky - Remote; Louisiana - Remote; Michigan - Remote; Minnesota - Remote; Mississippi - Remote; Missouri - Remote; Montana - Remote; Nebraska - Remote; Nevada - Remote; New Mexico - Remote; North Carolina - Remote; North Dakota - Remote; Ohio - Remote; Oklahoma - Remote; South Carolina - Remote; South Dakota - Remote; Tennessee - Remote; Texas - Remote; Utah - Remote; Virginia - Remote; West Virginia - Remote; Wisconsin - Remote; Wyoming - Remote
**Company Description**
We are Olsson. We engineer and design solutions that improve the world around us. As a company, we promise to always be responsive, transparent, and focused on results - for our people, our clients, and our company.
We're a people-centric firm, so it's no surprise our greatest asset is our people. The impact this creates is an environment that encourages our people to grow and be creative with their talents. This approach builds a culture that is uniquely Olsson. It allows us to grow our people as we grow our business. This, in turn, creates a lasting impact on the world around us.
**Job Description**
As a Electrical Engineer, on the Power Systems Studies group you will work directly with some of the world's largest technology companies and other mission-critical clients. You will serve as an electrical engineer on projects, design calculations, write technical reports, and prepare documents. Experience in performing short circuit analysis and producing arc flash studies is required. You will also coordinate with other Olsson teams, professional staff, technical staff, and clients. You may travel to job sites for observation and attend client meetings.
_We currently have one opening and will consider candidates interested in being located in most locations across the United States._
**Qualifications**
**You are passionate about:**
+ Working collaboratively with others.
+ Having ownership in the work you do.
+ Using your talents to positively affect communities.
**You bring to the team:**
+ Strong communication skills
+ Ability to contribute and work well on a team
+ Ability to be a self-starter to take on a variety of tasks to best serve the client and their project work
+ Investigation and troubleshooting of problems to find solutions
+ Ability to contribute and work well on a team
+ Bachelor's Degree in electrical engineering
+ 2+ years or related electrical engineering experience
+ EIT required
+ SKM and ETAP software experience is preferred
\#LI-DD1
**Additional Information**
Olsson specializes in engineering and design, client advisory services, planning, field services, and environmental. Improving the world has been our mindset from the very beginning, back when Olsson first opened for business in 1956. And it will be our mindset for years to come.
As an Olsson employee, you will:
+ Receive a competitive 401(k) match
+ Be empowered to build your career with tailored development paths
+ Have the possibility for flexible work arrangements
+ Engage in work that has a positive impact on communities
+ Participate in a wellness program promoting balanced lifestyles
In addition, full-time employees will receive our traditional benefits package (health care, vision, dental, paid time off, etc.) and the opportunity to participate in a bonus system that rewards performance.
Olsson is an Equal Opportunity Employer. We encourage qualified minority, female, veteran, and disabled candidates to apply and be considered for open positions. We do not discriminate against any applicant for employment or any employee because of race, color, religion, national origin, sex, sexual orientation, gender identity, gender, disability, age, military status, or other protected status.
Olsson understands the importance of privacy and is committed to protecting job applicants' personal information. Pursuant to the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the "CCPA"), this notice explains Olsson's practices regarding the collection, use, and disclosure of personal information for job applicants residing in California. Please read this Notice carefully to understand our privacy practices.
For more information about the types of information we collect and how we use it in connection with your general access and use of our website, please review our general California Privacy Noticehere (************************************** .
Create a Job Alert
Interested in building your career at Olsson? Get future opportunities sent straight to your email.
$63k-81k yearly est. 56d ago
Senior Analyst, Security Compliance (SOX IT)
Coinbase 4.2
Columbus, OH
Ready to be pushed beyond what you think you're capable of? At Coinbase, our mission is to increase economic freedom in the world. It's a massive, ambitious opportunity that demands the best of us, every day, as we build the emerging onchain platform - and with it, the future global financial system.
To achieve our mission, we're seeking a very specific candidate. We want someone who is passionate about our mission and who believes in the power of crypto and blockchain technology to update the financial system. We want someone who is eager to leave their mark on the world, who relishes the pressure and privilege of working with high caliber colleagues, and who actively seeks feedback to keep leveling up. We want someone who will run towards, not away from, solving the company's hardest problems.
Our ******************************** is intense and isn't for everyone. But if you want to build the future alongside others who excel in their disciplines and expect the same from you, there's no better place to be.
While many roles at Coinbase are remote-first, we are not remote-only. In-person participation is required throughout the year. Team and company-wide offsites are held multiple times annually to foster collaboration, connection, and alignment. Attendance is expected and fully supported.
Coinbase stores more digital currency than any company in the world, making us a top tier target on the internet. Security is core to our mission and has been a key competitive differentiator for us as we scale worldwide. Essential to scaling is building and running a security compliance program that reflects how we protect the data and assets in our care, to open the doors with customers, regulators, auditors, and other external stakeholders. If you love working with fast moving companies to grow and scale security compliance engines and create positive change across the business, we'd like to speak with you about joining our team. Coinbase is looking for a Security Compliance Senior Analyst to drive the second line of defense IT SOX initiatives and help mature the IT SOX program.
*What you'll be doing (ie. job duties):*
* Lead Security and IT initiatives to support the SOX roadmap and advance program maturity
* Assist with SOX planning activities, including scoping of IT systems and creating training material to owners in preparation for SOX audit
* Lead security control gap assessments over SOX control environment, recommend remediation plans and track through completion
* Assess SOX implications of new products, update relevant controls, and communicate requirements to product organization and other stakeholders
* Provide ongoing reporting to stakeholders and leadership on above responsibilities and communicate progress and escalations management
* Perform SOX audit and control impact analysis as a result of security and technology incidents and partner with owning teams on control uplift activities
* Build close relationships with stakeholder teams including Security, IT, Infrastructure, Engineering, Data, and Finance to advise on SOX requirements and ensure excellence in control ownership
* Create and improve SOX procedural documentation, including process documentation, data flow diagrams, and uplifting templates
* Work closely with internal and external auditors to educate them about a complex technology control environment
* Oversee quality of audit initiatives, identify and analyze process gaps, provide guidance and expertise to team members
* Develop creative solutions to prove risk mitigation and solve for complex audit problems faced by the crypto industry
* Identify opportunities to address systemic program challenges, recommend solutions and drive efficiency through AI and automation
*What we look for in you (ie. job requirements):*
* Minimum of 5+ years of security/IT compliance or equivalent experience
* Strong knowledge and hands-on experience in Internal Controls over Financial Reporting, SOX 404 frameworks, and testing to support compliance
* Prior experience at a big 4 accounting firm
* Experience leading compliance initiatives from start to finish
* Proven understanding and audit experience of cloud technologies, AWS preferred
* Ability to effectively and autonomously accomplish outcomes across cross-functional teams in ambiguous situations with minimal supervision
* Strong oral and written communication skills
* Ability to multitask, direct cross functional work, and hold others accountable to committed deadlines in a fast paced environment
* Ability to communicate with technical / non-technical stakeholders to align on shared outcomes
* Experience in Financial services, Big Tech, or FinTech
*Nice to haves:*
* BA or BS in a technical field or equivalent experience
* Security certifications e.g. CISA, CISSP, CISM or other relevant certifications
* Experience auditing in Crypto space
Position ID: P73675
\#LI-Remote
*Pay Transparency Notice:* Depending on your work location, the target annual salary for this position can range as detailed below. Full time offers from Coinbase also include bonus eligibility + equity eligibility**+ benefits (including medical, dental, vision and 401(k)).
Pay Range:
$167,280-$196,800 USD
Please be advised that each candidate may submit a maximum of four applications within any 30-day period. We encourage you to carefully evaluate how your skills and interests align with Coinbase's roles before applying.
Commitment to Equal Opportunity
Coinbase is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, sex, gender expression or identity, sexual orientation or any other basis protected by applicable law. Coinbase will also consider for employment qualified applicants with criminal histories in a manner consistent with applicable federal, state and local law. For US applicants, you may view the *********************************************** in certain locations, as required by law.
Coinbase is also committed to providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please contact us at accommodations***********************************
*Global Data Privacy Notice for Job Candidates and Applicants*
Depending on your location, the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) may regulate the way we manage the data of job applicants. Our full notice outlining how data will be processed as part of the application procedure for applicable locations is available ********************************************************** By submitting your application, you are agreeing to our use and processing of your data as required.
*AI Disclosure*
For select roles, Coinbase is piloting an AI tool based on machine learning technologies to conduct initial screening interviews to qualified applicants. The tool simulates realistic interview scenarios and engages in dynamic conversation. A human recruiter will review your interview responses, provided in the form of a voice recording and/or transcript, to assess them against the qualifications and characteristics outlined in the job description.
For select roles, Coinbase is also piloting an AI interview intelligence platform to transcribe and summarize interview notes, allowing our interviewers to fully focus on you as the candidate.
*The above pilots are for testing purposes and Coinbase will not use AI to make decisions impacting employment*. To request a reasonable accommodation due to disability, please contact accommodations[at]coinbase.com
$167.3k-196.8k yearly 60d+ ago
Security Engineer - Airlock
Blue Star Partners LLC 4.5
Columbus, OH
Job Description
Job Title: SecurityEngineer - Cloud & Endpoint Security
Pay Rate: $50/hr - $85/hr
Duration: 2/10/2025 - 12/31/2025 (Temp-to-Hire)
Contract Type: W2 (must be authorized to work in the US; no sponsorships or C2C)
Job Overview
Our Cloud and Endpoint Security team is looking for a SecurityEngineer to drive the deployment and management of an allowlisting/reverse proxy solution (Airlock). This engineer will collaborate with cross-functional teams to ensure integration with existing infrastructure, refine security policies, and contribute to the enhancement of the organization's cybersecurity posture. The role involves hands-on configuration, monitoring, and ongoing maintenance of security solutions, while remaining adaptable to changing threats and technologies.
Key Responsibilities
Allowlisting & Reverse Proxy Deployment: Lead the deployment and configuration of Airlock, ensuring seamless integration with current systems and networks.
Policy Development: Define and implement allowlisting policies to enhance application security, access control, and threat detection.
Incident Response Collaboration: Work closely with the incident response team to optimize alerting and logging capabilities, ensuring swift detection and remediation of potential security incidents.
Security Strategy & Best Practices: Assist in shaping the broader cybersecurity strategy, aligning it with business objectives and recognized frameworks (e.g., NIST, MITRE, ISO 27001).
Automation & Reporting: Identify opportunities to automate configurations, streamline reporting processes, and enhance visibility into system performance.
Monitoring & Analysis: Track solution performance and review security logs for emerging threats or anomalies; implement proactive measures where necessary.
Research & Continuous Improvement: Stay informed about the latest cybersecurity threats and trends, applying relevant findings to enhance Airlock's configurations.
Documentation & Maintenance: Support the development of incident response plans, secure access protocols, and maintain thorough documentation of all configurations and processes.
Qualifications
Minimum Requirements
Bachelor's Degree in a related field or equivalent work experience.
3+ years of experience in cybersecurity, IT, or related roles.
1+ years of hands-on experience deploying or managing application allowlisting or reverse proxy solutions.
1+ years of experience with security frameworks (e.g., NIST, MITRE, ISO 27001).
Proficiency with Windows and Linux environments, including command-line configurations.
Preferred Skills
Experience using Airlock or similar allowlisting tools.
Familiarity with scripting/automation (Python, PowerShell, Bash) for configuration and reporting.
Industry certifications (e.g., Sec+, CCSP, GIAC).
Strong analytical and problem-solving abilities, especially in process development and root cause analysis.
Additional Information
Temp-to-Hire: This is a W2 contract position with potential to convert to a full-time role, contingent on performance and business needs.
Work Arrangements: Local candidates are preferred; remote candidates will be considered if necessary.
Team Environment: The Cloud & Endpoint Security team collaborates with multiple departments, playing a crucial part in establishing security best practices and ensuring incident response readiness.
$50 hourly 17d ago
Lead Security Engineer - DevOps
Jpmorgan Chase & Co 4.8
Columbus, OH
JobID: 210701359 JobSchedule: Full time JobShift: : Take on a crucial role where you'll be a key part of a high-performing team delivering secure software solutions. Make a real impact as you help shape the future of software security at one of the world's largest and most influential companies.
As a Lead SecurityEngineer at JP Morgan Chase within the Cybersecurity & Technology Controls, you are an integral part of team that works to deliver software solutions that satisfy pre-defined functional and user requirements with the added dimension of preventing misuse, circumvention, and malicious behavior. As a core technical contributor, you are responsible for carrying out critical technology solutions with tamper-proof, audit defensible methods across multiple technical areas within various business functions.
* Specific experience deploying commercial software at scale into an enterprise environment.
* Develop and enforce robust change management practices to ensure system integrity and security.
* Show strong experience defining and implementing infrastructure as Code (IaC), working with CI/CD pipelines, and associated automation tooling.
* Function in systems engineering, systems integrations, and systems administration roles. Demonstrate strong working knowledge of Windows and Linux systems internals.
* Execute on key deliverables in the securityengineering space. Design and develop production deployments with the ability to think beyond routine or conventional approaches in order to deliver technology solutions for key stakeholders.
* Develop secure and high-quality production code and review and debug code written by others. Able to implement complex business logic in Python, Bash, PowerShell, and other scripting languages.
* Engage effectively with third-party vendors and communicate and collaborate with a broad range of internal teams.
* Minimize security vulnerabilities by following industry insights and government regulations to continuously evolve security protocols, including creating processes to determine the effectiveness of current controls.
* Work with stakeholders and business leaders to understand security needs and recommend business modifications during periods of vulnerability.
* Add to team culture of diversity, equity, inclusion, and respect.
Required qualifications, capabilities, and skills
* Formal training or certification on Engineering and/or Cybersecurity concepts and 5+ years applied experience as a cloud engineer, deployment engineer, DevOps engineer, or equivalent role.
* Experience with cloud engineering, deployment engineering, DevOps engineering, or equivalent
* Demonstrated skills in planning, designing, and implementing enterprise level security solutions.
* Strong experience defining and implementing infrastructure as Code (IaC), working with CI/CD pipelines, and associated automation tooling
* Commanding knowledge of a programming/scripting language for automation and integration tasks.
* Proficiency in all aspects of the Software Development Life Cycle.
* Strong analytical experience with problem solving mindset and the ability to solve complex challenges.
* Advanced understanding of agile methodologies such as CI/CD, Application Resiliency, and Security.
Preferred qualifications, capabilities, and skills
* Cloud computing related certifications with an AWS focus are strongly preferred, such as Certified Solutions Architect, DevOps Engineer, or similar.
* Experience effectively communicating with senior business leaders.
$86k-112k yearly est. Auto-Apply 4d ago
Agency Information Security Professional 1 (20101539)
Dasstateoh
Columbus, OH
Agency Information Security Professional 1 (20101539) (26000062) Organization: Rehabilitation & Correction - Operation Support CenterAgency Contact Name and Information: ************************** Unposting Date: Jan 24, 2026, 4:59:00 AMWork Location: DRC Central Office-Fran-ODOT 1980 West Broad Street Columbus 43223Primary Location: United States of America-OHIO-Franklin County-Columbus Compensation: 36.90Schedule: Full-time Classified Indicator: ClassifiedUnion: OCSEA Primary Job Skill: CybersecurityTechnical Skills: Forensics, Information Technology, Investigation, Security, CybersecurityProfessional Skills: Decision Making, Problem Solving, Results Oriented, Strategic Thinking, Written CommunicationPrimary Technology: Security Monitoring Agency Overview Who We Are… Guided by a single mission “To reduce recidivism among those we touch,” the Ohio Department of Rehabilitation and Correction believes that everyone is capable of positive change. Our staff embrace these core values and serves as role models for pro-social behavior conveying an attitude of dignity and respect in the treatment of others. What We Do… The Ohio Department of Rehabilitation and Correction has been tasked with front line crime reduction through rehabilitative treatment and programming efforts provided in a safe, secure and humane correctional environment and effective community supervision. Our goal is to protect the public through helping individuals turn away from crime and become productive, contributing members of our communities, ensuring a safer Ohio for all Ohioans now and in the future. To learn more about our agency, please visit our website at **************** Are You Ready? We are thrilled to see that you are interested in beginning your career with the Ohio Department of Rehabilitation and Correction! Without a doubt, this will be the most rewarding and meaningful work you'll ever find with a work family that is second to none! Job DescriptionLocation TBDThe full performance level class works under general supervision and requires considerable knowledge of electronic data processing, computer science and systems analysis to configure, support and monitor enterprise security tools such as endpoint protection, Security Information and Event Management (SIEM), Intrusion Detection Systems (IDS) to safeguard State assets against malicious activity Characterize and monitor network traffic to identify anomalous activity and potential threats to network resources and analyze identified malicious activity to determine weaknesses exploited, exploitation methods and effects on system and information Evaluate and support documentation, validation and accreditation processes necessary to assure that new IT systems meet organization's information assurance and security requirements and/or support security audit activities and review security logs to validate access levels and activity Supports vulnerability scanning, remote support software and packet capture to ensure endpoints are patched and updated Responds to alerts of malicious activity and work with OISP as a member of the agency Security Point of Contact (SPOC) team Support the development of tools and assist with responses, and help support training for the agency Security Incident Response Team (SIRT) Works with IT Security Operations Team to evaluate solutions to meet organization's information assurance and security requirements Creates documentation for security initiatives Works with inter-agency contacts to develop solutions for agency initiatives Safeguards the organization's information assets and ensures confidentiality, integrity, and availability of systems and data Assists in the development, implementation, and maintenance of the enterprise-wide information security program Provides input in the creation and enforcement of information security policies, standards, and guidelines Ensures security policies align with industry's best practices and regulatory requirements Assists with promoting security awareness by helping staff with understanding security policies and best practices Provides input with risk assessments that identifies vulnerabilities and assesses the potential impact on the organization Collaborates with various teams to develop and implement risk mitigation strategies Participates in the development and execution of incident response plans Analyzes and responds to security incidents, providing timely resolution and analysis Monitors and manages vulnerability scanning tools Coordinates remediation efforts and ensure timely closure of identified vulnerabilities Ensure compliance with relevant laws, regulations, and industry standards Assists in preparing for and participating in audits and assessments Monitors security alerts and incidents Analyzes and responds to security events Proactively utilizes security information and event management (SIEM) systems Maintains comprehensive documentation related to security policies, procedures, and incidents Provides regular reports on the status of the information security program Functions as mentor and primary contact for Security Analyst, Apprentice, and/or interns assigning work, developing, and assigning training, developing work structure and tasks for security initiatives, and evaluating deliverables Stays current regarding new technologies in area of IT assigned Why Work for the State of OhioAt the State of Ohio, we take care of the team that cares for Ohioans. We provide a variety of quality, competitive benefits to eligible full-time and part-time employees*. For a list of all the State of Ohio Benefits, visit our Total Rewards website! Our benefits package includes:
Medical Coverage
Free Dental, Vision and Basic Life Insurance premiums after completion of eligibility period
Paid time off, including vacation, personal, sick leave and 11 paid holidays per year
Childbirth, Adoption, and Foster Care leave
Education and Development Opportunities (Employee Development Funds, Public Service Loan Forgiveness, and more)
Public Retirement Systems (such as OPERS, STRS, SERS, and HPRS) & Optional Deferred Compensation (Ohio Deferred Compensation)
*Benefits eligibility is dependent on a number of factors. The Agency Contact listed above will be able to provide specific benefits information for this position.Qualifications36 mos. exp. in computer data security either through monitoring system/network traffic for anomalous activity, systems development or controlling accessibility of data. -Or completion of associate core program in computer science; 18 mos. trg. or 18 mos. exp. in computer data security either through monitoring system/network traffic for anomalous activity, systems development or controlling accessibility of data. -Or completion of undergraduate core program in computer science; 12 mos. trg. or 12 mos. exp. in computer data security either through monitoring system/network traffic for anomalous activity, systems development or controlling accessibility of data. -Or 12 mos. exp. as Information Technology Apprentice, 69910; successful completion of Ohio Cyber Apprenticeship program; additional 12 mos. trg. or exp. in Information Systems/Information Technology with a focus in one of the following areas: Software Engineering/Development, Data Analytics/Business Intelligence, Database Administration, Network, or IT Security. -Or equivalent of Minimum Class Qualifications for Employment noted above. Note: The Ohio Cyber Apprenticeship program is a program offered by the Department Administrative Services. 2000 hrs. of on-the-job experience and 200 certified instructional credits must be earned in order to complete this program. Job Skill: Cybersecurity Supplemental InformationApplication Procedures: In order to be considered for this position, you must apply on-line through this posting website. (We no longer accept paper applications.) When completing your on-line Ohio Civil Service Application, be sure to clearly describe how you meet the minimum qualifications outlined on this job posting. We cannot give you credit for your qualifications, experience, education and training in the job selection process if you do not provide it in your on-line application.You can check the status of your application by signing into your profile on this website.We will communicate with you through the email you provided in your profile and job application. Be sure to check your email often.If you require a reasonable accommodation for the application process, please contact the Human Resources Office so proper arrangements can be made. Otherwise, you will be given specific instructions on requesting an accommodation if you are invited to an assessment and/or interview.The Ohio Department of Rehabilitation and Correction is a tobacco-free workplace.Pre-Employment Drug Testing:All final applicants tentatively selected for this position will be required to submit to urinalysis to test for illegal drug use prior to appointments. Testing will also be performed for the presence of marijuana. An applicant with a positive test shall not be offered employment unless the applicant submits medical documentation of legally prescribed medications or a recommendation for medical marijuana.Pre-Employment Background Investigation:The final applicant selected for the position will be required to undergo a criminal background check. An individual assessment of an applicant's prior criminal convictions will be made before excluding an applicant from consideration.The Ohio Department of Rehabilitation and Correction is prohibited from hiring: Individuals under a federal or state weapons disability if the position requires firearms certification/recertification and use;Individuals who have engaged in sexual abuse in a prison or other confinement facility; have been civilly or administratively adjudicated, or convicted of engaging or attempting to engage in sexual activity in the community facilitated by force, implied threats of force, or if the victim did not or was unable to consent; Individuals convicted of soliciting or providing support for an act of terrorism, terrorism, or money laundering to support terrorism; Individuals who have been convicted of or pled guilty to a felony where a direct correlation exists between the position and prior criminal behavior. ADA StatementOhio is a Disability Inclusion State and strives to be a model employer of individuals with disabilities. The State of Ohio is committed to providing access and inclusion and reasonable accommodation in its services, activities, programs and employment opportunities in accordance with the Americans with Disabilities Act (ADA) and other applicable laws.Drug-Free WorkplaceThe State of Ohio is a drug-free workplace which prohibits the use of marijuana (recreational marijuana/non-medical cannabis). Please note, this position may be subject to additional restrictions pursuant to the State of Ohio Drug-Free Workplace Policy (HR-39), and as outlined in the posting.
$70k-94k yearly est. Auto-Apply 8h ago
Security Analyst
Sonsoft 3.7
Marysville, OH
Sonsoft , Inc. is a USA based corporation duly organized under the laws of the Commonwealth of Georgia. Sonsoft Inc. is growing at a steady pace specializing in the fields of Software Development, Software Consultancy and Information Technology Enabled Services.
Job Description
MUSTS:-
Bachelor's degree in Information Systems or equivalent work experience of a minimum of 3-5 years as an information security risk management practitioner, preferably in the financial, consulting, and/or global organizations.
Prior work experience of risk management disciplines, security policies and standards, technology risk assessment, and third party supplier risk process and requirements.
Current or previous experience with risk assessment methodologies and conducting risk analysis in a regulated environment or related IT audit background.
Knowledge of security and control frameworks, such as ISO 27002, NIST, CobiT, COSO and ITIL.
Experience with implementation of information security best practices for key areas such as access control, data protection, systems development life cycle, PCI DSS, and cloud services.
Professional certification in risk management, and/or audit is preferred (e.g., CISSP, CRISC, CISA, or CISM).
WANTS:-
Demonstrate broad competency and understanding in a variety of IT security areas.
Security Policy Development and Management.
Assist with documenting security policies, standards, and guidelines.
based on the organization's requirements, maturity level, and compliance objectives.
Facilitate, coordinate, and maintain project schedules, plans, and scope using standard project management methodologies.
BUSINESS EXPERIENCE:-
Proven ability to work with and across all levels of the organizations and navigate organizational boundaries.
Excellent organizational, interpersonal and communication skills with strong written, oral, and presentation skills; both delivery and creation of power points (must be able to distill complex topics into simple concepts).
Ability to effectively communicate with technical and executive audiences and develop and maintain strong peer/client/customer relationships underpinned by a service oriented approach to work.
Adept with time management, tasks and projects prioritization, and multi-tasking.
High level of personal integrity, and the ability to professionally handle confidential matters and exude the appropriate level of judgment and maturity.
High degree of initiative, attention to detail, follow-up skills, deliver on commitments, dependability and ability to work with little supervision.
Demonstrated problem-solving skills and capability to drive process improvements.
Proficient with Microsoft Office Suite especially Excel and Power point.
DESCRIPTION:-
Implement the overall risk management framework and processes, tools, and reporting methodologies on a continuous cycle.
Develop and standardize processes and procedures for ongoing risk identification, tracking, monitoring, and evaluating security measures and remediation efforts; communicate security control deficiencies and recommend mitigation plans, report status progress and with non-compliance issues; measure adherence to the security controls from a policy, governance and risk standpoint.
Perform third party supplier risk assessments by reviewing contracts for compliance with security policies, standards and practices; document security gaps and recommend appropriate remediation actions as necessary to minimize risks to the business.
Assist with documenting security policies, standards, and guidelines based on the organization's requirements, maturity level, and compliance objectives.
Facilitate, coordinate, and maintain project schedules, plans, and scope using standard project management methodologies.
Qualifications
Planning, designing and implementing an overall risk management process for the organization.
Risk identification, analysis, tracking, monitoring, documenting exceptions, and communicating risks to owners.
Risk assessment, which involves analyzing risks as well as identifying, describing and estimating the risks affecting the business.
Risk evaluation, which involves comparing estimated risks with criteria established by the organization such as costs, legal requirements and environmental factors, and evaluating the organization's previous handling of risks.
Establishing and quantifying the organization's 'risk appetite', i.e. the level of risk they are prepared to accept.
Risk reporting in an appropriate way for different audiences, for example, to the board of directors so they understand the most significant risks, to business heads to ensure they are aware of risks
relevant to their parts of the business and to individuals to understand their accountability for individual risks.
Corporate governance involving external risk reporting to stakeholders.
Carrying out processes such as purchasing insurance, implementing health and safety measures and making business continuity plans to limit risks and prepare for if things go wrong.
Conducting audits of policy and compliance to standards, including liaison with internal and external auditors.
Providing support, education and training to staff to build risk awareness within the organization.
Additional Information
**
U.S. citizens and those authorized to work in the U.S. are encouraged to apply
. We are unable to sponsor at this time.
Note:-
This is a Full-Time Permanent job opportunity for you.
Only US Citizen, Green Card Holder, TN Visa, GC-EAD, H4-EAD & L2-EAD can apply.
No OPT-EAD & H1B Consultants please.
Please mention your Visa Status in your email or resume.
$57k-71k yearly est. 60d+ ago
Information Technology Manager 1 - Security & Compliance Manager- 20078290
State of Ohio 4.5
Columbus, OH
The IT Security Manager will serve in a management role with technical capabilities and strategic planning oversight; responsible for overseeing and managing security programs, projects, personnel, logical/technical administration, and security acquisitions. Our preferred candidate possesses the ability and experience to focus on reducing security risks throughout the infrastructure to an acceptable level, in alignment with the organizations business needs and requirements. They will be capable of identifying, establishing, and adhering to tactical plans for achieving set goals within a dynamic fast-paced environment.
Duties include but are not limited to:
Lead the team responsible for security assessments, developing risk-based solutions and controls frameworks.
Serve as the subject matter expert for control validation in the Security team.
Create/Update/Maintain IT Security Guidelines and Standards.
Develop System Policies and establish system standards.
Communicate security controls and remediate any concerns.
Collaborate with various departments to safeguard our adherence to policies and other undertakings that influence the security, confidentiality, integrity, and accessibility of our application, infrastructure, and business operations.
Conduct, document, and report on internal and third-party risk program.
Collaborate with the DAS OISP team to ensure successful delivery of security & business objectives.
Lead the coordination of data gathering needed for internal and external audits, regulatory requirements, and other compliance and risk management needs requirements.
Be a highly analytical and effective communicator capable of influencing other teams and departments.
At the State of Ohio, we take care of the team that cares for Ohioans. We provide a variety of quality, competitive benefits to eligible full-time and part-time employees*. For a list of all the State of Ohio Benefits, visit our Total Rewards website! Our benefits package includes:
Medical Coverage
Free Dental, Vision and Basic Life Insurance premiums after completion of eligibility period
Paid time off, including vacation, personal, sick leave and 11 paid holidays per year
Childbirth, Adoption, and Foster Care leave
Education and Development Opportunities (Employee Development Funds, Public Service Loan Forgiveness, and more)
Public Retirement Systems (such as OPERS, STRS, SERS, and HPRS) & Optional Deferred Compensation (Ohio Deferred Compensation)
*Benefits eligibility is dependent on a number of factors. The Agency Contact listed above will be able to provide specific benefits information for this position.
Ohio is a Disability Inclusion State and strives to be a model employer of individuals with disabilities. The State of Ohio is committed to providing access and inclusion and reasonable accommodation in its services, activities, programs and employment opportunities in accordance with the Americans with Disabilities Act (ADA) and other applicable laws.
This is a re-post. If you applied to posting 250006TA, you do not need to re-apply to be considered.
The Mission of the Ohio Department of Commerce
is promoting prosperity by protecting what matters most.
The Division of Administration provides overall leadership and administrative support for all Divisions. The Division includes the Office of Director, Communications, Fiscal, Human Resources, IT, Legal and Legislative Affairs.
As the state's chief regulator, the Department of Commerce impacts Ohioans every day. We are motivated by our mission to promote prosperity for businesses and licensees by protecting what matters most to the residents of our state. We ensure compliance through proactive outreach, education, and customer-focused service.
Commerce is comprised of eight operating divisions and one standalone program that span a variety of industries including real estate, liquor, banking, securities, firefighting, construction and skilled trades, and cannabis. Through exceptional compliance practices and oversight, Commerce has a direct role in protecting Ohioans.
Our Guiding Principles
Making an IMPACT for the customer:
Inclusive
Motivated
Proactive
Accountable
Customer-Focused
Teamwork
The State of Ohio is a drug-free workplace which prohibits the use of marijuana (recreational marijuana/non-medical cannabis). Please note, this position may be subject to additional restrictions pursuant to the State of Ohio Drug-Free Workplace Policy (HR-39), and as outlined in the posting.
Applications must clearly indicate how the applicant meets the minimum qualification for the position. If you meet minimum qualification due to educational achievement, please submit a copy of your unofficial transcript(s) with your application. All answers to the supplemental questions must be supported by information provided in the work experience &/or education sections on your civil service application. Please do not use “see resume” as a substitution for the completed application; assumptions will not be made.
Application Status: You can check the status of your application online by signing into your profile. Careers to which you've applied will be listed. The application status is shown to the right of the position title and application submission details.
The final candidate selected for this position will be required to undergo a criminal background check as well as other investigative reviews. Criminal convictions do not necessarily preclude an applicant from consideration for a position, unless restricted under state or federal law or federal restrictions. An individual assessment of an applicant's prior criminal convictions will be made before excluding an applicant from consideration.
All final applicants tentatively selected for this position will be required to submit to urinalysis to test for illegal drug use prior to appointments. Testing will also be performed for the presence of marijuana. An applicant with a positive test shall not be offered employment unless the applicant submits medical documentation of legally prescribed medications or a recommendation for medical marijuana. Also, an applicant with a positive test will not be considered for any position with the State of Ohio for a period of one year.
8 1/2 years (102 mos.) exp. commensurate with job duties to be performed & knowledges & skills required as outlined in approved position description on file for position to be filled as advertised in job posting; 18 months exp. in performing project management functions as defined in series purpose.
-Or completion of undergraduate core coursework in computer science, or completion of undergraduate core coursework in any academic major which included at least one course in each of the following\: advanced-level computer programming language (for example, COBOL, Delphi, Java, Powerbuilder, Visual Basic, Pl 1, SAS PCS, Pacbase, Full Visual Suite, Designer 2000, Developer 2000, C, C++, Visual C, ECL, or Visual Studio), logic-based mathematics, data base concepts (for example, Oracle, Microsoft Access, Paradox, Sybase, IMS DB, DB2, Cache, DMS, or RDMS), computer systems analysis & design, & basic data processing concepts; additional 6 1/2 years (78 mos.) exp. commensurate with job duties to be performed & knowledges & skills required as outlined in approved position description on file for position to be filled as advertised in job posting.; 18 mos. exp. in performing project management functions as defined in series purpose.
-Or 12 mos. exp. as Information Technology Supervisor 3, 64119, or equivalent. Or in offices of statewide information technology policy & planning, positions require completion of undergraduate core coursework in computer science, or completion of undergraduate core coursework in any academic major which included at least one course in each of the following\: advanced-level computer programming language (for example, COBOL, Delphi, Java, Powerbuilder, Visual Basic, Pl 1, SAS PCS, Pacbase, Full Visual Suite, Designer 2000, Developer 2000, C, C++, Visual C, ECL, or Visual Studio), logic-based mathematics, data base concepts (for example, Oracle, Microsoft Access, Paradox, Sybase, IMS DB, DB2, Cache, DMS, or RDMS), computer systems analysis & design, & basic data processing concepts; 3 yrs. exp. in utilizing word processing software; 3 yrs. exp. in utilizing internet browser(s) for research; 54 mos. exp. which included following\: knowledge of information technology architecture components, developing information technology strategic plans, preparing & making presentations/public speaking, writing information technology related policy & procedures, preparing & monitoring budget, providing cost & resources estimates, & contract management; 2 yrs. exp. in utilizing e-mail system; 18 mos. exp. in project management or lead role on information technology project;12 mos. exp. in utilizing spreadsheet software; 12 mos. exp. as Information Technology Supervisor 3, 64119, or equivalent.
-Or equivalent of Minimum Class Qualifications For Employment noted above.
Job Skills: Information Technology
$54k-75k yearly est. Auto-Apply 60d+ ago
Sr Lead Security Engineer - WFT
Jpmorgan Chase & Co 4.8
Columbus, OH
JobID: 210686675 JobSchedule: Full time JobShift: : Join a team where you can play a crucial role in shaping the future of a world-renowned company and make a direct and meaningful impact in a space designed for top performers.
As a Senior Lead SecurityEngineer at JPMorganChase within Cyber Technology & Controls you are an integral part of an agile team that works to deliver software solutions that satisfy pre-defined functional and user requirements with the added dimension of preventing misuse, circumvention, and malicious behavior. Drive significant business impact through your capabilities and contributions and apply deep technical expertise and problem-solving methodologies to tackle a diverse array of cybersecurity challenges that span multiple technology domains.
Job responsibilities
* Architect, implement, and maintain security control objectives and procedures to ensure alignment with industry best practices and JPMorgan Chase (JPMC) security standards.
* Partner in the design and actively participate in building security applications and technical solutions that enforce control objectives and address recurring HR security challenges.
* Systematically identify gaps in vendor security offerings, and design and build in-house solutions to effectively mitigate these deficiencies.
* Collaborate with HR and other stakeholders to understand business processes and security pain points, translating requirements into actionable engineering solutions.
* Conduct comprehensive threat modeling for HR systems and processes; when threat models reveal security gaps, support the design and building of tailored security controls or applications.
* Develop scripts, automation, and custom code to streamline security processes, enhance monitoring, and improve the efficiency and effectiveness of security controls.
Required qualifications, capabilities, and skills
* Formal training or certification on software engineering concepts and 5+ years applied experience.
* Experience planning, designing, building and implementing enterprise level securityengineering products and solutions in a public cloud environment (i.e. AWS, GCP, Azure)
* Experience working with vendors to assess the sufficiency of their security practices and controls meet industry standards.
* Extensive experience with threat modelling of applications or architectures using models such as STRIDE.
* Advanced in one or more programming languages/scripts (i.e. C/C#, Python, PowerShell)
* Advanced knowledge of secure software application development and technical processes with considerable in-depth knowledge in one or more technical disciplines (e.g., cloud, artificial intelligence, machine learning, mobile, etc.)
* Experience with continuous integration and continuous deployment (CI/CD) tools (Jenkins), version control tools (BitBucket, Git), managing and tracking work using management tools like Jira
* Ability to tackle design and functionality problems independently with little to no oversight
Preferred qualifications, capabilities, and skills
* Experience within Cyber Security is preferred with good understanding of industry frameworks like MITRE ATT&CK, NIST, CIS etc.
* Certified Secure Software Lifecycle Professional or similar industry certification
* Excellent communication and presentation skills
* Prior experience in finance industry is a huge plus
* Willingness to learn and drive to excel