Security Triage Analyst
Security engineer job in Seattle, WA
We are seeking a highly organized and analytical Mid-Level Information Security Triage Analyst to work hybrid in Seattle, Austin, SF, or Sunnyvale. In this critical role, you will be the first point of contact for Tier 2 and Tier 3 information security support requests, responsible for thoroughly investigating and documenting issues before escalating to subject matter experts. You will leverage your critical thinking skills to gather comprehensive background information, ask clarifying questions, and identify potential solutions, minimizing interruptions to specialized teams. In addition, you will analyze trends in support requests to identify areas for improvement in our documentation, processes, and security posture.
Due to client requirement, applicants must be willing and able to work on a w2 basis. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.
Rate: $60 - $68 / hr. w2
Responsibilities:
Ticket Triage: Serve as the initial point of contact for Tier 2 and Tier 3 information security support tickets.
Issue Investigation: Conduct thorough investigations of reported issues, gathering detailed information from users and systems to understand the scope and impact.
Critical Thinking & Questioning: Apply critical thinking skills and have a strategic mindset to analyze reported issues, develop SOPs from common questions, formulate relevant preliminary questions and new canned responses, and proactively seek additional information to ensure a comprehensive understanding of the problem.
Documentation: Meticulously document all findings focusing on processes, workflows, and SOPs.
Escalation Management: Escalate issues to appropriate subject matter experts (SMEs) with complete and well-documented information, minimizing the need for redundant questioning and maximizing SME efficiency.
Communication: Partner with our service and offering owners to design solutions and improve existing workflows to optimize the stakeholders' experience.
Knowledge Base Development: Contribute to the development and maintenance of a comprehensive knowledge base by documenting solutions to common issues and creating troubleshooting guides.
Trend Analysis: Analyze trends in support requests to identify recurring issues, potential security vulnerabilities, and areas for improvement in our security posture.
Process Improvement: Propose and implement improvements to triage processes, documentation, and communication strategies to enhance the efficiency and effectiveness of the security support team.
Response Optimization: Help develop and refine standardized responses to common security-related inquiries, ensuring consistent and accurate information is provided to users.
Documentation Review: Regularly review existing documentation and identify areas where updates or clarifications are needed to better address user needs and reduce support requests.
Qualifications:
Experience in IT support, information security, or a related role.
Excellent analytical and problem-solving skills, with the ability to think critically and ask probing questions.
Exceptional communication and interpersonal skills, with the ability to effectively communicate technical information to both technical and non-technical audiences.
Experience working with ticketing systems (e.g., Jira Service Management, ServiceNow).
Strong documentation skills and attention to detail.
Ability to work independently and as part of a team.
Ability to prioritize tasks and manage time effectively.
Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent experience.
Preferred Qualifications:
Experience with security incident response processes.
Familiarity with common security tools and technologies
Strong understanding of information security principles, practices, and technologies.
Please be advised- If anyone reaches out to you about an open position connected with Eliassen Group, please confirm that they have an Eliassen.com email address and never provide personal or financial information to anyone who is not clearly associated with Eliassen Group. If you have any indication of fraudulent activity, please contact ********************.
Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.
W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.
JOB ID: JN -112025-104376
Security Engineer
Security engineer job in Issaquah, WA
The SAP GRC Engineer supports the values and business goals as they relate to legal, ethical, and regulatory obligations; protect privacy; and maintain a secure technology environment. SAP GRC Engineers develop and execute security controls, defenses, and countermeasures to intercept and prevent internal/external attacks, infiltration of company data, and compromising of systems and accounts. SAP GRC Engineers research attempted/successful efforts to compromise systems security; design countermeasures; implement and maintain physical, technical, and administrative security controls; and provide information to management regarding the negative impact to the business.
The SAP GRC Engineer is responsible for the creation and maintenance of General IT control objectives in the area of SAP GRC. This position will be responsible for ensuring that all SAP GRC IT control objectives are in compliance and running to full efficiency. In addition, this role will assist with the daily and monthly reporting of SOD (Segregation of Duties) activities from SAP GRC in support of meeting applicable compliance objectives. This is a cross-functional role, working closely with the SAP Security team and other functional teams to ensure security requirements and solutions meet compliance objectives.
ROLE
Provides GRC, security, and technical expertise to support the development of GRC objects to satisfy business requirements.
Analyzes and administers GRC policies to control physical and virtual system access.
Identifies and investigates GRC issues and develops solutions that address compliance requirements that can/do impact GRC and security.
Identifies, develops, and implements mechanisms to detect incidents in order to enhance compliance and support of the standards and procedures.
Assesses business role requirements, reviews authorization roles, and supports authorizations.
Demonstrates a comprehensive skill set with testing authorizations for multiple environments and coordinates testing with business/technical users.
Validates system configurations to ensure the safety of information systems assets and protects information systems from intentional or inadvertent access or destruction.
Implements best practice when applying knowledge of information systems security standards/practices (e.g. access control and system hardening, system audit and log file monitoring, security policies, and incident handling).
Identifies GRC gaps that expose Costco to potential exploit and develop short- and long-term prioritized remediation to address those gaps.
Determines strategy and protocol for network behavior, analysis techniques, and tool implementation.
Creates dashboards, configures alerts, implements and supports security software platforms, and monitors tools/apps.
Identifies opportunities for streamlining and increasing effectiveness through continuous process improvement.
Implements practices, processes, and procedures consistent with Costco's information security policy and IT standards.
Develops and documents GRC events and incident handling procedures into Playbooks.
Ensures that incident documentation is comprehensive, accurate, and complete.
Triages, prioritizes, investigates, and coordinates security events and incident handling activities.
Creates and/or remediates GITC (General IT Controls) in support of meeting audit objectives for all SAP modules and their supporting Databases, within the company SAP landscape (i.e. Finance, Retail, Warehouse Management, Payroll, HANA, etc.).
Designs IT testing procedures to identify and evaluate risk exposures and determine the effectiveness and efficiency of controls.
Assists with the creation of effective remediation solutions and/or exception documentation where applicable.
Serves as the subject matter expert and point of contact to Internal and External Auditors.
Assists project teams with creation and implementation of IT controls objectives and integration into SAP-GRC.
Assists with the successful completion of the quarterly UAR (User Access Review) audit process.
Collaborates with Internal Audit in developing, testing, and devising solutions to effectively meet applicable IT control objectives.
Takes responsibility for continued personal growth in the areas of technology, business knowledge, Costco policies, and platforms.
Participates in team activities and team planning in regards to improving team skills, awareness, and quality of work.
REQUIRED
Minimum of 12 years of experience of SAP GRC Access 10.0 and or 12.0 with expertise using the following modules: Account Request Management (ARM), Access Risk Analysis (ARA), Emergency Access Management (EAM), User Access Review (UAR), Process Control (PC), SAP ETD.
Minimum of 7 years work experience in IT Risk Management, SOX compliance, and/or auditing with a strong background in IT controls.
Minimum of 7 years of experience with SAP Security across various applications, including but not limited to, S/4 HANA, ECC, BW, MDG, Fiori, PI/PO, eWM, and Solution Manager.
Minimum of 7 years experience with SOD conflict resolution.
Direct “hands-on” experience in IT audits and functional experience using SAP GRC.
Understanding of SAP cloud security.
Strong understanding of Sarbanes-Oxley (SOX) and other compliance requirements that may impact controls.
Expertise in working with internal and external auditors.
Experience developing SAP GRC solutions that address Sarbanes-Oxley requirements.
Effective communication and technical leadership; ability to fluently speak both technical and business language interchangeably.
Ability to effectively mentor other team members on SAP compliance.
Experience in successful project implementation and follow-up; strong time management skills.
Strong conceptual, analytical, problem-solving, troubleshooting, and resolution skills.
Ability to monitor and manage the progress of tasks and work independently.
Ability to design, develop, and maintain SAP user management and security architecture across SAP environments, including hands-on role design and build across a number of complex SAP applications and databases.
Scheduling flexibility to meet the needs of the business, including 24x7 on call rotational support.
Recommended
Bachelor's degree in Accounting, Business, Information Technology, or Computer Science preferred.
Documentation and presentation skills catered to a diverse technical and business audience.
Technical knowledge of SAP landscapes and roadmaps.
Proficient in Google Workspace applications, including Sheets, Docs, Slides, and Gmail.
Required Documents
Cover Letter
Resume
Pay Range-
$150,000 - $180,000 DOE plus Bonus and Restricted Stock Units (RSU)
Location:
Hybrid onsite 3 days per week in Issaquah, WA
System Engineer
Security engineer job in Redmond, WA
Job Title: Systems Engineer IV
Contract: 6 Months
Pay Rate: $92.20,hr, W2
Benefits: Medical, Dental, Vision and Weekly Pay
This role demands strong technical expertise in infrastructure and network architecture, coupled with excellent communication and collaboration skills to ensure successful project delivery. You will serve as the primary point of contact for designated projects, coordinating internal resources and leveraging support from supervisory and technical teams when necessary.
Key responsibilities include overseeing client-related activities, managing support tickets, and collaborating with cross-functional partners to ensure timely and successful delivery of project milestones and support requests.
Engineer Responsibilities:
Build, scale, and secure environments within *** enterprise infrastructure, which is a heterogeneous environment encompassing a broad range of operating systems (Windows, Windows Server, virtualization platforms, and Linux) and applications.
Apply modern engineering methodologies such as Infrastructure-as-Code, container orchestration, and software-defined storage.
Implement systems that are scalable, automated, monitored, and well-documented, and provide training to others for operational tasks.
Identify and leverage the scale and complexity of *** larger production infrastructure to solve problems for enterprise customers.
Participate in incident root cause analysis across multiple infrastructure layers (compute, storage, network) and implement critical solutions while upholding best standards to maintain high reliability of managed systems.
Minimum Qualifications:
5+ years of experience in systems engineering.
5+ years of experience automating the management of infrastructure and services.
5+ years of experience working with monitoring and configuration management tools such as Chef, Ansible, Puppet, PowerShell DSC, etc.
5+ years of experience coding in an object-oriented or functional language such as Python, Ruby, PHP, Rust, Go, and PowerShell scripting (developing advanced functions & modules).
Thorough understanding of Windows/Windows Server operating system internals and Linux.
Demonstrated experience in completing tasks and small/medium features with minimal guidance.
Experience installing and configuring Kubernetes, Docker, OpenCue, and Slurm.
Prior experience with Linux operating systems and their internals.
Preferred Qualifications:
BS or MS in Computer Science, Engineering, or a related technical discipline.
Prior experience supporting configuration management in a multi-region environment.
Prior experience building services, PaaS, or internal clouds.
Prior experience with APIs to streamline administration, management, and monitoring of services.
Must-Have Skills:
At least 5 Years in Enterprise Environment - Production Level Experience
Compute with Kubernetes and/or Slurm
Thorough understanding of Windows/Windows Server/RHEL operating system internals and Prior experience with Linux operating systems and their internals.
5+ years of experience coding in an object-oriented or functional language such as Python, Ruby, PHP, Rust, Go, and PowerShell scripting (developing advanced functions & modules).
(Additionally, qualified candidates should be comfortable with repetitive tasks, be able to lift 30 lbs, have reliable transportation and type 50 WPM)
Nice to Have Skills:
Prior experience supporting configuration management in a multi-region environment.
Prior experience building services, PaaS, or internal clouds.
Prior experience with APIs to streamline administration, management, and monitoring of services.
Chef is highly preferred
Pursuant to the California Fair Chance Act, Los Angeles County Fair Chance Ordinance for Employers, Los Angeles Fair Chance Initiative for Hiring Ordinance, and San Francisco Fair Chance Ordinance, qualified applicants will be considered for assignment with arrest and conviction records. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness, meet client expectations, standards, and accompanying requirements, and safeguard business operations and company reputation.
#TMN
Network Engineer
Security engineer job in Seattle, WA
Benefits: Health, Vision, Dental, 401(k)
The OT Network Engineer will provide technical infrastructure support for a utility organization, including systems such as the Energy Management System (EMS), distributed network and computing resources at power plants and substations, and physical security networks across all utility locations.
This role requires advanced expertise in networking, switching, firewall configuration, data communications, cybersecurity, and NERC Critical Infrastructure Protection (CIP) standards. Strong communication and collaboration skills are essential.
Key Responsibilities:
Network Design & Compliance
Develop and maintain network support processes and design standards focused on:
High availability, redundancy, operational continuity
Configuration management and NERC compliance
Cybersecurity protection and intrusion detection
Collaboration & Lifecycle Management
Work with internal teams and vendors to:
Design network solutions that meet business and regulatory needs
Act as a central contact for network-related concerns
Manage lifecycle, performance metrics, and reporting
Ensure regulatory compliance
System Changes & Support
Implement and support changes across OT infrastructure:
Apply OS and application patches/upgrades
Configure, test, and deploy network equipment and software
Integrate vendor-supported software for system interfaces and reporting
Operations & Maintenance
Monitor, diagnose, and resolve incidents and user issues
Coordinate deliverables with colleagues and stakeholders
Participate in weekly team meetings
Provide recurring onsite support for field systems
Administer network routes for site communication
Documentation & Asset Management
Maintain asset databases and system design drawings
Network Systems Integration
Design, deploy, configure, and lead tasks involving:
Network switches, firewalls, physical security systems, access control, intrusion detection/protection
Technologies including Cisco Systems, Palo Alto Networks, Fortinet
Tools such as Tripwire, SolarWinds, Dell EMC Avamar/BRM, Rsyslog
Security platforms like IBM QRadar SIEM, Cybereason, Tenable/Nessus
Assess current network design and recommend improvements for reliability and cybersecurity
Required Qualifications:
Bachelor's degree in Computer Science, Computer Engineering, or related field
5+ years of experience in network engineering roles
Hands-on experience with Cisco, Fortinet, Palo Alto, or similar network devices
Strong understanding of firewall rule best practices
Proficiency in network design concepts and best practices
Experience creating complete design and as-built network drawings
Excellent communication and collaboration skills
Network Engineer
Security engineer job in Redmond, WA
Role: Network Deployment engineer - LAN/WAN
Primary Skill : LAN/WAN, Cisco, Juniper
Secondary Skill: Arista, Aruba
Key Responsibilities:
• Design, deploy, and maintain network infrastructure across multiple vendors (Cisco, Juniper, Arista, Aruba).
• Configure and optimize routers, switches, firewalls, and wireless networks for enterprise and data center environments.
• Perform network upgrades, migrations, and expansions while ensuring minimal downtime.
• Implement network security policies, access controls, and monitoring solutions.
• Conduct site surveys and assessments to determine optimal network configurations.
• Troubleshoot and resolve complex Layer 2 and Layer 3 network issues.
• Work closely with cross-functional teams to integrate networking solutions with business applications.
• Provide documentation, network diagrams, and knowledge transfer to operations teams.
• Ensure compliance with industry standards and best practices.
• Support network automation and scripting initiatives (Python, Ansible, etc.).
Required Skills & Qualifications:
• Bachelor's degree in Computer Science, Information Technology, or a related field (or equivalent work experience).
• Min 4+ years of exp. for L2 and 6+ years exp. for L3 in network deployment, administration, and troubleshooting
• Expertise in configuring and managing Cisco, Juniper, Arista, and Aruba network devices.
• Strong understanding of routing protocols (BGP, OSPF, EIGRP, IS-IS) and switching technologies (VLANs, STP, VXLAN, EVPN).
• Proficiency in network security technologies (firewalls, IPS/IDS, VPNs, NAC solutions).
• Hands-on experience with wireless networks (Aruba ClearPass, Cisco Wireless Controllers, 802.1X authentication).
• Experience with network automation (Ansible, Python, Terraform) is a plus.
• Familiarity with cloud networking ( Azure) and scripting knowledge (python) is an advantage.
• Strong problem-solving skills with the ability to work independently and in a team environment.
• Excellent communication and documentation skills.
Certifications (Preferred but Not Mandatory):
Cisco: CCNP, CCIE
Juniper: JNCIP, JNCIE
Arista: ACE-A, ACE-P
Aruba: ACMP, ACDP
Network Automation: DevNet, JNCIA-DevOps, Ansible
Education:
Bachelor of Engineering (Computer Science, Information Technology, Electronics etc.) with CCNA & CCNP (preferred)
Disclaimer
HCL is an equal opportunity employer, committed to providing equal employment opportunities to all applicants and employees regardless of race, religion, sex, color, age, national origin, pregnancy, sexual orientation, physical disability or genetic information, military or veteran status, or any other protected classification, in accordance with federal, state, and/or local law. Should any applicant have concerns about discrimination in the hiring process, they should provide a detailed report of those concerns to ****************** for investigation.
Compensation and Benefits
A candidate's pay within the range will depend on their work location, skills, experience, education, and other factors permitted by law. This role may also be eligible for performance-based bonuses subject to company policies. In addition, this role is eligible for the following benefits subject to company policies: medical, dental, vision, pharmacy, life, accidental death & dismemberment, and disability insurance; employee assistance program; 401(k) retirement plan; 10 days of paid time off per year (some positions are eligible for need-based leave with no designated number of leave days per year); and 10 paid holidays per year.
Routing and Switching Network Engineer
Security engineer job in Redmond, WA
Routing and Switching Network Engineer Duration: Contract The Routing and Switching Network Engineer will be responsible for designing, implementing, and maintaining network infrastructure to ensure optimal performance, security, and scalability. This role requires collaboration with various teams to support business objectives, provide technical guidance, and troubleshoot complex network issues. The position is onsite in Plano, Texas, and requires 10+ years of experience in network engineering.
Responsibilities:
Develop and implement network architectures that align with business objectives.
Oversee the deployment and configuration of network devices, including routers, switches, firewalls, and wireless access points.
Coordinate with customers, SMEs, leads, and managers to understand and document network architecture.
Troubleshoot L2/L3 level issues and handle high-priority tickets (P1/P2), performing root cause analysis and permanent fixes.
Provide hands-on support for wireless networks, including Cisco and Meraki.
Handle P3/P4 tickets and guide offshore teams as needed.
Liaise with service providers for link-related services and coordinate with vendors/OEMs for hardware/software upgrades or replacements.
Train and provide knowledge transfer to other associates as necessary.
Monitor and maintain network performance, ensuring minimal disruptions.
Respond to network-related incidents and provide immediate solutions or escalate as necessary.
Create and maintain comprehensive documentation for network configurations and troubleshooting steps.
Implement and manage network protocols such as TCP/IP, OSPF, BGP, and VLANs.
Ensure network compliance with industry standards and regulations, conducting security assessments and vulnerability scans.
Collaborate with cross-functional teams and communicate effectively with stakeholders.
Qualifications:
Bachelor's degree in Computer Science, Information Technology, or a related field.
10+ years of experience in network engineering.
Active Cisco/Extreme Network equivalent certification (CCNP or CCIE preferred).
Strong understanding of networking protocols and technologies (TCP/IP, BGP, OSPF, VLANs, etc.).
Experience with network hardware and software from vendors such as Cisco, Juniper, or Arista.
Hands-on experience with Extreme network switches, Cisco switches and routers, and Juniper routers.
Proficiency in scripting languages (Python, Perl, etc.) and automation tools (Ansible, Terraform, etc.).
Experience with network monitoring and management tools (e.g., SolarWinds, PRTG, Zabbix).
Strong analytical and problem-solving skills with excellent communication and interpersonal abilities.
Ability to adapt to rapidly changing technologies and work independently or as part of a team.
About PTR Global: PTR Global is a leading provider of information technology and workforce solutions. PTR Global has become one of the largest providers in its industry, with over 5000 professionals providing services across the U.S. and Canada. For more information visit *****************
At PTR Global, we understand the importance of your privacy and security. We NEVER ASK job applicants to:
Pay any fee to be considered for, submitted to, or selected for any opportunity.
Purchase any product, service, or gift cards from us or for us as part of an application, interview, or selection process.
Provide sensitive financial information such as credit card numbers or banking information. Successfully placed or hired candidates would only be asked for banking details after accepting an offer from us during our official onboarding processes as part of payroll setup.
Pay Range: $50 - $55
The specific compensation for this position will be determined by a number of factors, including the scope, complexity and location of the role as well as the cost of labor in the market; the skills, education, training, credentials and experience of the candidate; and other conditions of employment. Our full-time consultants have access to benefits including medical, dental, vision and 401K contributions as well as any other PTO, sick leave, and other benefits mandated by appliable state or localities where you reside or work.
If you receive a suspicious message, email, or phone call claiming to be from PTR Global do not respond or click on any links. Instead, contact us directly at ***************. To report any concerns, please email us at *******************
System Engineer
Security engineer job in Seattle, WA
Title
Senior Systems Administrator
Employment Type
Full Time Direct Hire
Job Site
Onsite
City
Seattle
State
WA
Pay Rate Range (External)
110K - 135K
BENEFITS:
Some of the benefits that our employees enjoy:
Medical / Dental / Vision*
Vacation / Sick/ Holiday Pay
401(k)
100% Fully Pre-Paid College Tuition
Employee Stock Option Program
Employee Assistance Program
Flexible Spending Accounts
Voluntary Term Life and AD&D
Employee Paid Life Insurance
Employer Paid Short Term Disability Insurance
Discounted employee produce purchase program
Free Smoking Cessation Program
Free Wellness Coaching and Healthy Pregnancy Programs
Virtual Office Visits
ROLE & RESPONSIBILITIES
We are seeking a Senior Systems Administrator for a team supporting enterprise Microsoft infrastructure, which would be a great opportunity for someone with experience in Windows Server administration, Intune, Active Directory, and enterprise security looking to further their career in systems engineering and IT operations.
Overview:
The Senior Systems Administrator will manage and secure the organization's Microsoft Windows infrastructure, ensuring high availability, compliance, and operational excellence. This role requires expertise in Windows OS, Intune, Active Directory, and enterprise security standards. The position includes on-call responsibilities and collaboration across IT and business units.
Responsibilities:
Administer and maintain Windows Server environments, Active Directory, Azure Entra ID and Group Policy.
Familiar with container platforms - Docker and/or Kubernetes.
Manage Intune for device compliance, application deployment, and endpoint security.
Implement and monitor security baselines using Microsoft Security Compliance Toolkit.
Apply patches, updates, and vulnerability remediation across systems.
Monitor system performance, uptime, and resource utilization.
Develop and maintain Disaster Recovery plans and participate in regular testing.
Develop and maintain documentation for systems, processes, and policies.
Provide Tier 2/3 support for escalated issues.
Handle backup and recovery procedures for critical systems.
Work with cross-functional teams on deployments and upgrades.
Mentor junior IT staff and enforce best practices.
Additional Tasks/Duties as they are assigned.
ESSENTIAL QUALIFICATIONS
Bachelor's Degree in Computer Science, Information Technology, or equivalent on-the-job experience.
7+ years' experience in Windows Server administration and enterprise environments.
Expertise in Microsoft Intune and Endpoint Manager, Active Directory, Entra ID, Windows OS (10/11) and security hardening.
Strong knowledge of backup/recovery systems and documentation standards.
Familiarity with compliance frameworks and security baselines.
Certifications such as MCSE, MCSA, or Microsoft Certified: Modern Desktop Administrator.
Experience with cloud platforms including Microsoft Azure and hybrid cloud environments.
BONUS QUALIFICATIONS
Experience with virtualization (Hyper-V).
PowerShell scripting and automation.
Knowledge of O365, SharePoint, and cloud-based email systems.
Expertise in O365 integration and administration.
Participated in large Enterprise based projects and Digital Transformation.
Soft Skills
Strong communication and interpersonal skills.
Excellent problem-solving and analytical abilities.
Leadership and team collaboration capabilities.
Vendor management and negotiation skills.
Ability to work under pressure and manage multiple priorities.
On-Call Expectations
This position requires participation in on-call rotation to provide after-hours support for critical systems and respond to incidents promptly. Candidates must be able to troubleshoot and resolve issues under pressure and ensure minimal downtime.
WHY AVERRO?
Averro is an equal opportunity employer, and we are committed to diversity, equity, and inclusion in the workplace. All qualified applicants will receive consideration for employment, regardless of criminal histories, consistent with legal obligations. All employment decisions shall be made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status or any other basis as protected by federal, state, or local law.
View our privacy policy here: *******************************************
Offensive Security Researcher
Security engineer job in Seattle, WA
NVIDIA is looking for security researchers passionate about offensive research across different platforms. Do you have experience with identifying hardware and software vulnerabilities, developing PoC, and tools for automation in vulnerability research? Are you creative and devious in your offensive approach? We want to hear from you!
You should demonstrate ability to excel in an environment with innovative and fast paced development on the worlds most powerful integrated software and hardware computing platform.
What you'll be doing:
* Core job duties will identify vulnerabilities in our embedded firmware and critical system software, building proof of concepts, and collaborating with development teams to remediate them.
* Candidates will invest in improving current tools and offensive practices for bug discovery and evaluation while supporting remediation efforts. We expect team members to exercise modern tools for modeling new attack vectors on unreleased and emerging technology platforms.
* The most impactful candidates can simulate real attacker behaviors, break systems by exploiting design assumption and effectively communicate their findings for action. Focus will be to increase resilience of the end products against all forms of attack through close collaboration with extended SW and HW offensive security teams.
* Products targets span HPC data centers, consumer electronics, autonomous platforms, AI/cloud solutions, and a variety of embedded/IOT platforms providing a rich and complex target space to exercise your skills.
What we need to see:
* We'd like to see proven experience and offensive security research (CVE's, publications, patents, tools, bounties) with demonstrated responsible disclosure practices.
* Strong skills in reverse engineering and automation (IDA, Ghidra), fuzzing (AFL, WinAFL, Syzcaller) and exploitation (ROP, memory corruption) are important to success; as well as understanding of modern embedded cryptography and common security issues.
* Experience with ARM/X86/RISCV assembly (include shellcode development) and low-level C programming paired with understanding and experience with micro-architectural attacks (side channels, fault injection, etc) is critical.
* Demonstrated skill for secure code reviews of complex source projects, and exposure to code quality practices (SDL, threat modeling) that support development goals.
* Candidates should be comfortable working collaboratively and remotely with others to accomplish complex team goals, enabling delivery of outstanding security for our products.
* BS/BA degree or equivalent experience
* 12+ years in a security related field
Ways to stand out from the crowd:
* Navigating complex platform concerns and ability to analyze composed systems to identify high risk components and established testing targets and objectives.
* Practical skills using Hex-Rays IDA Pro and plugin/loaders development (or similar experience with Ghidra) is valuable
* Leveraging innovative strategies and AI advancements to accelerate discovery and resolution of security risks.
* Experience with enclave models such as NVIDIA CC, ARM TEE, Intel SGX/TDX, AMD SEV-SNP and other isolation technologies.
* Development and integration of AI tooling and skills to accelerate and improve activities and or experience with offensive actions targeting AI models (LLM or other) components within those platforms.
NVIDIA has continuously reinvented itself over two decades. Our invention of the GPU in 1999 fueled the growth of the PC gaming market, redefined modern computer graphics, and revolutionized parallel computing. More recently, GPU deep learning ignited modern AI - the next era of computing. NVIDIA is a "learning machine" that constantly evolves by adapting to new opportunities that are hard to solve, that only we can pursue, and that matter to the world. This is our life's work, to amplify creativity and intelligence. Make the choice to join us today!
Your base salary will be determined based on your location, experience, and the pay of employees in similar positions. The base salary range is 224,000 USD - 356,500 USD for Level 5, and 272,000 USD - 425,500 USD for Level 6.
You will also be eligible for equity and benefits.
Applications for this job will be accepted at least until October 5, 2025.
NVIDIA is committed to fostering a diverse work environment and proud to be an equal opportunity employer. As we highly value diversity in our current and future employees, we do not discriminate (including in our hiring and promotion practices) on the basis of race, religion, color, national origin, gender, gender expression, sexual orientation, age, marital status, veteran status, disability status or any other characteristic protected by law.
Auto-ApplyCyber Security Analyst
Security engineer job in Seattle, WA
Job Description
We is seeking a talented Cyber Security Analyst. As a Cyber Security Analyst, you will play a key role in ensuring the security and integrity of our organization's data and systems.
Requirements
Responsibilities:
Monitor, detect, and respond to cyber threats and security incidents,
Conduct vulnerability assessments and penetration testing to identify potential weaknesses in our systems,
Develop and implement security measures and best practices to protect against cyber attacks,
Stay up-to-date with the latest cyber security trends and technologies,
Collaborate with cross-functional teams to identify security risks and implement appropriate solutions,
Provide training and guidance to employees on cyber security awareness and best practices.
Requirements:
Bachelor's degree in Computer Science, Information Security, or a related field,
Proven experience in cyber security or a related role,
Strong knowledge of security protocols and tools,
Ability to analyze and interpret complex data and make informed decisions,
Excellent problem-solving and communication skills,
Relevant certifications (e.g. CISSP, CISM) are preferred but not required.
Benefits
About Us
Zone IT Solutions is an Australia-based Recruitment Company. We specialise in Digital, ERP and larger IT Services. We offer flexible, efficient and collaborative solutions to any organisation that requires IT, experts. Our agile, agnostic and flexible solutions will help you source the IT Expertise you need. If you are looking for new opportunities, your profile at *******************************.
Also, follow our LinkedIn page for new job opportunities and more.
Zone IT Solutions is an equal-opportunity employer, and our recruitment process focuses on essential skills and abilities.
Easy ApplySenior Manual Ethical Hacker
Security engineer job in Seattle, WA
Denver, Colorado;Seattle, Washington; Jacksonville, Florida; Addison, Texas; Jersey City, New Jersey; Boston, Massachusetts; Charlotte, North Carolina; Chicago, Illinois **To proceed with your application, you must be at least 18 years of age.** Acknowledge
Refer a friend
**To proceed with your application, you must be at least 18 years of age.**
Acknowledge (***********************************************************************************************
**:**
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day.
One of the keys to driving Responsible Growth is being a great place to work for our teammates around the world. We're devoted to being a diverse and inclusive workplace for everyone. We hire individuals with a broad range of backgrounds and experiences and invest heavily in our teammates and their families by offering competitive benefits to support their physical, emotional, and financial well-being.
Bank of America believes both in the importance of working together and offering flexibility to our employees. We use a multi-faceted approach for flexibility, depending on the various roles in our organization.
Working at Bank of America will give you a great career with opportunities to learn, grow and make an impact, along with the power to make a difference. Join us!
**Job Description:**
Manual Ethical Hacking is part of the Application Development Security Framework Program within Bank of America's Cyber Security Assurance Offensive Security group. The program provides services to assess the security resilience of the bank's applications to malicious hacking activity.
This senior technical role is responsible performing and leading ethical hacking assessments of the bank's technologies, applications, and cyber security controls while adapting testing methods to evolving and emerging threats. Key responsibilities include leading and performing research, understanding the bank's security policies, working with appropriate partners to complete assessments and simulations, identifying misconfigurations and vulnerabilities, and reporting on associated risk. These individuals partner closely with security partners, CIO clients and multiples lines of business. These individuals are expected to perform application security-oriented dynamic and static assessments across a multitude of technologies including web UI, web APIs, mobile and cloud, including associated source code.
Key Responsibilities in order of importance:
+ Perform assigned analysis of internal and external threats on information systems and predict future threat behavior.
+ Incorporate threat actors' tactics, techniques, and procedures into offensive security testing to identify high-value vulnerabilities/chained attacks.
+ Developing Proof-of-concepts for exploitation.
+ Perform assessments of the security, effectiveness, and practicality of multiple technology systems.
+ Leverage innovative thinking to help solve problems or introduce new ideas to processes or products applicable to offensive security.
+ Prepare and present detailed technical information for various media including documents, reports, and notifications.
+ Provide clear and practical advice regarding managing risks.
+ Learn and develop advanced technical and leadership skills, mentor Junior and Intermediate assessors in technical tradecraft and soft skills.
+ Respond to security incidents and provide technical assistance to leadership across the Information Security organization.
Required Skills:
+ Minimum of 5+ years of professional pentesting, application security or ethical hacking experience, preferably in a large, complex, enterprise environment
+ Detailed technical knowledge in at least 5 of the following areas:
+ security engineering
+ application architecture
+ authentication and security protocols
+ application session management
+ applied cryptography
+ common communication protocols
+ mobile frameworks
+ single sign-on technologies
+ exploit automation platforms
+ Web APIs
+ Cloud environments
+ LLM security
+ Able to manually identify and reproduce findings, discuss remediation concepts, develop PoCs for vulnerabilities, use scripting/coding techniques, proficiently execute common penetration testing tools, triage, and support incidents, and produce high value findings
+ Experience performing manual web application assessments i.e., must be able to simulate a OWASP Top 10 vulnerabilities without the use of tools
+ Experience performing manual code reviews for security relevant issues
+ Experience working with DAST and SAST tools to identify vulnerabilities
+ Knowledge of network and Web related protocols/technologies (e.g., UNIX/LINUX, TCP/IP, Cookies)
+ Experience with vulnerability assessment tools and penetration testing techniques.
+ Solid programming/debugging skills, development frameworks, CVE and CWE research/reproduction
+ Threat Analysis, threat modelling and SBOM analysis
+ Innovative thinking, threat actor simulation
+ Technology Systems Assessment
+ Technical Documentation
+ Advisory
Desired:
+ CEH, OSCP/OSCE/OSWE/GXPN/GPEN/GWAPT/GMOB/All Practitioner Certs [Port Swigger BSP Academy]/Cloud Cert(s)/ eWPT; eWPTX; eMAPT [INE Pentester Academy]
+ Strong programming/scripting skills
This job will be open and accepting applications for a minimum of seven days from the date it was posted.
**Shift:**
1st shift (United States of America)
**Hours Per Week:**
40
Bank of America and its affiliates consider for employment and hire qualified candidates without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote the concept of equal employment opportunity, in accordance with all applicable federal, state, provincial and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our teammates.
View your **"Know your Rights (************************************************************************************** "** poster.
**View the LA County Fair Chance Ordinance (************************************************************************************************** .**
Bank of America aims to create a workplace free from the dangers and resulting consequences of illegal and illicit drug use and alcohol abuse. Our Drug-Free Workplace and Alcohol Policy ("Policy") establishes requirements to prevent the presence or use of illegal or illicit drugs or unauthorized alcohol on Bank of America premises and to provide a safe work environment.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations. Should you be offered a role with Bank of America, your hiring manager will provide you with information on the in-office expectations associated with your role. These expectations are subject to change at any time and at the sole discretion of the Company. To the extent you have a disability or sincerely held religious belief for which you believe you need a reasonable accommodation from this requirement, you must seek an accommodation through the Bank's required accommodation request process before your first day of work.
This communication provides information about certain Bank of America benefits. Receipt of this document does not automatically entitle you to benefits offered by Bank of America. Every effort has been made to ensure the accuracy of this communication. However, if there are discrepancies between this communication and the official plan documents, the plan documents will always govern. Bank of America retains the discretion to interpret the terms or language used in any of its communications according to the provisions contained in the plan documents. Bank of America also reserves the right to amend or terminate any benefit plan in its sole discretion at any time for any reason.
Security Engineer -Level L2
Security engineer job in Bellevue, WA
Arete Technologies, Inc. offers set of innovative Consulting and Outsourcing services, bridging the gap between requirements and outputs of various dexterous and facile companies worldwide. The thrust of providing global deliverables with focus on providing paramount and unsurpassed services combined with cost saving solutions to the clients
We understand the business requirements in the present day corporate scenario and aspire to provide world-class services enabling the organization to burgeon and flourish while keeping the work-life balance intact. The Global delivery mechanism followed at Arete Technologies, Inc. saddles proficient schemas and unconventional channels to provide one-stop solutions for all your workforce needs.
our Team is an exquisite amalgamation of vast experiences of over 30 years in IT Consulting and Staffing industry. Connoisseurs in the field of staff augmentation for IT, we operate on 24 by 7 model with an aim of providing affordable and adept professionals with an assurance of satisfaction for both Consultants and Clients.
We are pre-eminent service providers in the field of staff augmentation, IT Consultancy, Software development, Web Development providing unexcelled services and focusing on both the employers and employees.
L2: Job Description
Resource should be able to perform security assessments of different IT functional areas (e.g., applications, systems, network and/or Web) in conformance with industry wide best practices. He should be able to work on multiple projects as a team member and make assessment reports on different standards.
He should work cohesively with senior team members
to gathera full understanding of projectscope and business requirements.
Responsibility & technical skills
: -
Participate in security planning and analyst activities.
Performs security assessments andsecurity attestations.
Participates in security investigations and compliancereviews as requested.
Make security analysis reports for security vulnerabilities and recommends feasible andappropriate options.
Evaluate all design documentations and perform design assessments to ensure appropriate security controls are implemented within designs.
Additional Information
Best Regards
Alka Bhatia
Security Engineer
Security engineer job in Seattle, WA
Artech is the 10th Largest IT Staffing Company in the US, according to Staffing Industry Analysts' 2012 annual report. Artech provides technical expertise to fill gaps in clients' immediate skill-sets availability, deliver emerging technology skill-sets, refresh existing skill base, allow for flexibility in project planning and execution phases, and provide budgeting/financial flexibility by offering contingent labor as a variable cost.
Job Title:
Security Engineer/ System Security Engineer
Location:
Seattle WA
Duration:
12 Months (Chances for extension)
Job Description:
Develops and manages security for more than one IT functional area (e.g., data, systems, network and/or Web) across the enterprise.
Assists in the development and implementation of security policies and procedures (e.g., user log-on and authentication rules, security breach escalation procedures, security auditing procedures and use of firewalls and encryption routines).
Prepares status reports on security matters to develop security risk analysis scenarios and response procedures.
Responsible for the tracking and monitoring of software viruses.
Enforces security policies and procedures by administering and monitoring security profiles, reviews security violation reports and investigates possible security exceptions, updates, and maintains and documents security controls.
Involved in the evaluation of products and/or procedures to enhance productivity and effectiveness. Provides direct support to the business and IT staff for security related issues.
Educates IT and the business about security policies and consults on security issues regarding user built/managed systems.
Represents the security needs of the organization by providing expertise and assistance in all IT projects with regard to security issues.
Must have extensive knowledge in networking, databases, systems and/or Web operations.
More junior level position primarily focuses on security administration; a more senior level position is involved in developing enterprise security strategies, management of security projects and the most complicated security issues.
Bachelor's Degree in Computer Science, Information Systems, or other related field. Or equivalent work experience.
Typically has 3 - 6 years of combined IT and security work experience with a broad range of exposure to systems analysis, application development, database design and administration; 3+ years of experience with information security.
Requires knowledge of security issues, techniques and implications across all existing computer platforms.
Position Comments: This is a security jack of all trades that will help with hardware patching, web app security, policy, RFP response, audits, facility security, etc.
Additional Skill: Linux experience required MPAA, Privacy Shield or Safe Harbour experience a plus
Additional Information
For more information, Please contact
Pankhuri Razada
Associate Recruiter
Artech information Systems LLC
360 Mt. Kemble Avenue, Suite 2000 Morristown, NJ 07960
************
[email protected]
om
Security Engineer
Security engineer job in Federal Way, WA
* Bot Attacks Analytics. Akamai hands on experience. * Experience on security tools like OWASP ZAP, Burp Suite, Nessus, or others. Roles & Responsibilities: * Analyze Bot Attacks: Independently analyze and respond to bot attacks in real-time, ensuring minimal disruption to our services.
* Pattern Analysis: Identify and analyze attack patterns using Akamai, security logs, and other tools. Query data across various systems to gain comprehensive insights into attack vectors.
* Technical Expertise: Utilize your deep understanding of e-commerce applications to contribute to the design and implementation of security features on our platform.
* SRE Practices: Apply Site Reliability Engineering (SRE) principles to enhance the reliability, scalability, and security of our infrastructure.
* Technology Proficiency: Work with technologies such as Java, Python, SQL. work with monitoring tools like Dataset (centralized logging) and New Relic (observability)
* Continuous Learning: Stay updated with the latest security trends, SRE practices, and technologies. Be willing to learn and implement new tools and techniques.
* Analytical Skills: Employ strong analytical skills to dissect complex security issues and develop effective mitigation strategies. Create detailed reports and alerts based on system logs and data analysis.
* Security Assessment: Conduct thorough security assessments to identify potential vulnerabilities in our features and infrastructure. Propose and drive conversations on necessary feature changes to enhance security.
* Vendor Collaboration: Lead discussions with vendors like Akamai and Riskified, ensuring that we leverage their solutions effectively to bolster our security posture.
TCS Employee Benefits Summary:
* Discretionary Annual Incentive.
* Comprehensive Medical Coverage: Medical & Health, Dental & Vision, Disability Planning & Insurance, Pet Insurance Plans.
* Family Support: Maternal & Parental Leaves.
* Insurance Options: Auto & Home Insurance, Identity Theft Protection.
* Convenience & Professional Growth: Commute r Benefits & Certification & Training Reimbursement.
* Time Off: Vacation, Time Off, Sick Leave & Holidays.
* Legal & Financial Assistance: Legal Assistance, 401K Plan, Performance Bonus, College Fund, Student Loan Refinancing.
# LI-RJ2
Salary Range - $100,000-$125,000 a year
Enterprise Security Engineer
Security engineer job in Seattle, WA
About the Team
Within the OpenAI Security organization, our IT team works to ensure our team of researchers, engineers, and staff have the tools they need to work comfortably, securely, and with minimal interruptions. As an Enterprise Security Engineer, you will work in a highly technical and employee-focused environment.
Our IT team is a small and nimble team, where you'll have the opportunity to dive into a wide breadth of areas and build from the ground up. We're well supported and well resourced, and have a mandate to deliver a world-class enterprise security program to our teams.
About the Role
As an Enterprise Security Engineer, you will be responsible for implementing and managing the security of OpenAI's internal information systems' infrastructure and processes. You will work closely with our IT and Security teams to develop security capabilities, enforce security policies, and monitor internal systems for security threats.
This role is open to remote employees, or relocation assistance is available to Seattle.
In this role, you will:
Develop and implement security measures to protect our company's information assets against unauthorized access, disclosure, or misuse.
Monitor internal and external systems for security threats and respond to alerts.
Contribute to and enforce our company's IT and Security policies and procedures.
Work closely with our IT department to harden our infrastructure using best practices in AzureAD, GSuite, Github, and other SaaS tooling.
Advise our employees on best practices for maintaining the security of their endpoints, and office AV and network infrastructure.
Devise novel sharing controls and associated monitoring to protect company data, including intelligent groups management, Data Loss Prevention (DLP) and other security controls as appropriate.
Employ forward-thinking models like “secure by default” and “zero trust” to create sustainably secure environments for knowledge workers and developers.
Identify and remediate vulnerabilities in our internal systems, adhering to best practices for data security.
Use our own AI-driven models to develop systems for improved security detection and response, data classification, and other security-related tasks.
Educate employees on the importance of data security, and advise them on best practices for maintaining a secure environment.
Contribute to OpenAI's endpoint and cloud security roadmaps by staying up to date with the latest security threats, and making recommendations for improving our security posture.
You might thrive in this role if you have:
Experience in protecting and managing mac OS fleets.
Experience deploying and managing endpoint security solutions (e.g. management frameworks, EDR tools).
Experience with public cloud service providers (e.g. Amazon AWS, Microsoft Azure).
Experience with identity and access management frameworks and protocols, including SAML, OAUTH, and SCIM.
Experience with e-mail security protocols (e.g. SPF, DKIM, DMARC) and controls.
Intermediate or advanced proficiency with a scripting language (e.g. Python, Bash, or similar).
Knowledge of modern adversary tactics, techniques, and procedures.
Ability to empathize and collaborate with colleagues, independently manage and run projects, and prioritize efforts for risk reduction.
.
About OpenAI
OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.
We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.
For additional information, please see OpenAI's Affirmative Action and Equal Employment Opportunity Policy Statement.
Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.
To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance.
We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link.
OpenAI Global Applicant Privacy Policy
At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.
Auto-ApplyInformation Security Analyst
Security engineer job in Bellevue, WA
Aditi Staffing is an MBE certified, IT Staffing firm in the US offering contract, contract-to-hire & direct hire career opportunities with Fortune Firms. Recently recognized as one of the fastest growing staffing firms and top diversity firm by the Staffing Industry Analysts, Aditi Staffing has been a partner of choice for candidates and clients.
Visit our website: http://www.aditistaffing.com/
Job Description
Role: Information Security Analyst
Location: Information Security Analyst
6-8 years of experience in information security / technology or related field. Advanced verbal and communication skills with diverse cross functioning groups.
Strong background and experience in policy development, program administration. In depth knowledge and experience in incident response activities and compliance. Ability to plan, organize and prioritize tasks to complete independently and within time frame established.
While technical knowledge of information technology and security issues is highly desirable, technical expertise and resources will be available from units such as Security Operations to support the information security and privacy program.
Strong technical writing abilities. Very good understanding of security controls, control systems, and business drivers that impact security controls.
Knowledge of SEC, FFC, Sarbanes-Oxley (SOX) and or Gramm-Leach Bliley Act regulatory policies & guidelines.
Strong background in security authentication, security applications development methodologies, security architecture and operational procedures, organization, business continuity skills, disaster recovery skills, identity management skills and hands on experience implementing products / solutions e.g. NetIQ, Entrust, Netegrity, Oblix, PKI, and some director service, RSA, strong understanding of the development and maintenance of RBAC s (Role Based Access Controls).
Ability to work collaboratively with a broad range of constituencies essential. A demonstrated ability to work with diverse cross functional groups of people is required.
Good to Have:
Knowledge of the following technologies a plus: Intrusion Detection / Prevention Systems for networks and hosts Security Event Management Systems Vulnerability Assessment Systems
Secure transfer protocols such as SSH, SCP and Connect Direct Secure Plus Diagnostic tools such as packet capture/decode and WAN probes IP Networking Windows Systems administration and security tools
Experience with remote access, terminal servers, etc a plus Experience in the administration of UNIX Solaris, HP/UX, or Linux and Windows operating systems a plus
Experience in developing and administering an information security program desirable
Working knowledge of and experience in the policy and regulatory environment of information security, especially in higher education is desirable
Additional Information
Regards,
Arun Kumar R
arunkr(AT)aditistaffing.com
D: 425-457-7916
Security Engineer, Operating Systems
Security engineer job in Seattle, WA
Anthropic's mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.
About the Role
We're looking for an Operating Systems Security Engineer to harden and secure the OS layer of our infrastructure. You'll be responsible for designing and implementing OS-level security controls, from kernel hardening to runtime protection, ensuring our systems can withstand sophisticated attacks while maintaining the performance required for AI model training.
This is a hands-on role where you'll work with cutting-edge hardware and implement novel security solutions for environments that don't exist anywhere else in the world. You'll need to balance extreme security requirements with the operational needs of researchers training models at unprecedented scale.
What You'll Do:
Design and implement hardened OS configurations for AI workloads across diverse hardware platforms
Develop kernel security policies using SELinux, AppArmor, and custom Linux Security Modules and runtime enforcement mechanisms
Implement and maintain full-disk encryption solutions for diverse storage systems
Build security infrastructure for AI systems, research environments, and production services
Build secure network stacks with appropriate isolation and segmentation
Create OS-level attestation and integrity monitoring systems
Develop security patches, custom kernel modules, and kernel hardening configurations
Design secure boot processes and trusted execution environments
Work with container teams to ensure proper workload isolation at the kernel level
Design privilege separation and mandatory access control policies
Implement secure update mechanisms for OS components
Build tooling for security configuration management and compliance verification
Who You Are:
5+ years of experience in operating systems security or kernel development
Deep knowledge of Linux internals, including kernel subsystems and security frameworks (SELinux, AppArmor, seccomp, etc.)
Experience with kernel hardening techniques and exploit mitigation
Strong programming skills in C and systems programming languages
Experience with eBPF for security monitoring and enforcement
Understanding of virtualization and containerization security
Track record of identifying and fixing OS-level security vulnerabilities
Experience with security-focused Linux distributions
Strong candidates may also have:
Kernel development experience or contributions to Linux kernel
Experience with real-time or embedded operating systems
Knowledge of hardware security features and their OS integration
Experience with confidential computing and memory encryption technologies (SEV, TDX, SGX)
Background in vulnerability research, exploit development, or fuzzing
Experience with formal methods for OS verification
Knowledge of hardware security features and their OS integration (TPM, HSM, secure enclaves)
Deadline to apply: None. Applications will be reviewed on a rolling basis.
The expected base compensation for this position is below. Our total compensation package for full-time employees includes equity, benefits, and may include incentive compensation.
Annual Salary:$300,000-$405,000 USDLogistics
Education requirements: We require at least a Bachelor's degree in a related field or equivalent experience.
Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.
Visa sponsorship: We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.
We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you're interested in this work. We think AI systems like the ones we're building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team.
How we're different
We believe that the highest-impact AI research will be big science. At Anthropic we work as a single cohesive team on just a few large-scale research efforts. And we value impact - advancing our long-term goals of steerable, trustworthy AI - rather than work on smaller and more specific puzzles. We view AI research as an empirical science, which has as much in common with physics and biology as with traditional efforts in computer science. We're an extremely collaborative group, and we host frequent research discussions to ensure that we are pursuing the highest-impact work at any given time. As such, we greatly value communication skills.
The easiest way to understand our research directions is to read our recent research. This research continues many of the directions our team worked on prior to Anthropic, including: GPT-3, Circuit-Based Interpretability, Multimodal Neurons, Scaling Laws, AI & Compute, Concrete Problems in AI Safety, and Learning from Human Preferences.
Come work with us!
Anthropic is a public benefit corporation headquartered in San Francisco. We offer competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and a lovely office space in which to collaborate with colleagues. Guidance on Candidates' AI Usage: Learn about our policy for using AI in our application process
Auto-ApplySecurity Engineer
Security engineer job in Seattle, WA
At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation.
Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive.
Join a team using leading edge security technology and processes to protect the F5 enterprise
and product environment. The Security Engineer position will execute strategic processes
and implement technical solutions to enable our information security program and address day-to-day security challenges amidst the industry's evolving technology landscape.
Primary Responsibilities
* Build and implement new security controls, processes and tools.
* Identify organizational risks to confidentiality, integrity, and availability, and determine appropriate mitigations.
* Leverage native Azure, GCP, and AWS cloud services to automate and improve existing security and control activities.
* Develop or implement open-source/third-party tools to assist in detection, prevention and analysis of security threats.
* Perform technical security assessments against product and enterprise cloud hosted, virtual, and on-premise systems including static and dynamic analysis, and threat modeling.
* Review and test changes to services, applications, and networks for potential security impacts.
* Collaborate with Architecture, Site Reliability Engineering and Operations teams to develop and implement technical solutions and security standards.
* Stay abreast on security best practices and secure design principles.
* Review changes to and ongoing operations of enterpise environments and supporting systems for security and compliance impacts.
* Assist in incident detection and response efforts.
* Implement zero-trust patterns with cloud agnostic tools to support enterprise business units.
* Implement, design, develop, administer, and manage enterprise security tooling.
Knowledge, Skills and Abilities
* Experience working with high-availability enterprise production environments
* Familiarity with scripting languages (e.g., (Go, Python, Ruby, Rust,etc.). and building scripts for process improvements
* Experience automating security testing and reporting outputs
* Technical knowledge and hands-on experience with security and networking security, basic networking protocols, cloud security, network security design, intrusion prevention/detection, and firewall architecture
* Experience assessing and implementing technical security controls
* Willingness to innovate and learn new technologies
* Excellent interpersonal and relationship skills with a collaborative mindset
* Knowledge or familiarity with technological stack (Big-IP, Azure, AWS, GCP, CentOS, Hashicorp Vault, Palo Alto, Qualys).
* Experience with network and application vulnerability and penetration testing tools.
* Baseline competency in administration of Microsoft Azure Cloud, Amazon Web Services (AWS), Google Cloud Platform (GCP) or equivalent public cloud infrastructure.
* Exposure to DevOps tooling, CI/CD pipelines, container orchestration, and infrastructure as code approach (e.g. Puppet, Chef, Ansible, Terraform, Jenkins, CircleCI, Artifactory, Git)
* Strong written and verbal cowimmunication skills.
* Strong self-directed work habits, exhibiting initiative, drive, creativity, maturity, self-assurance and professionalism.
* Agile, tactful, and proactive attitude that can manage prioritization and know when to escalate.
Qualifications
* B.S. or M.S. in Computer Science, Engineering, or related field, or equivalent experience.
* 3+ years of relevant security and networking experience
LI-KT1
The Job Description is intended to be a general representation of the responsibilities and requirements of the job. However, the description may not be all-inclusive, and responsibilities and requirements are subject to change.
The annual base pay for this position is: $120,000.00 - $180,000.00
F5 maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, geographic locations, and market conditions, as well as to reflect F5's differing products, industries, and lines of business. The pay range referenced is as of the time of the job posting and is subject to change.
You may also be offered incentive compensation, bonus, restricted stock units, and benefits. More details about F5's benefits can be found at the following link: ******************************************** F5 reserves the right to change or terminate any benefit plan without notice.
Please note that F5 only contacts candidates through F5 email address (ending with @f5.com) or auto email notification from Workday (ending with f5.com or @myworkday.com).
Equal Employment Opportunity
It is the policy of F5 to provide equal employment opportunities to all employees and employment applicants without regard to unlawful considerations of race, religion, color, national origin, sex, sexual orientation, gender identity or expression, age, sensory, physical, or mental disability, marital status, veteran or military status, genetic information, or any other classification protected by applicable local, state, or federal laws. This policy applies to all aspects of employment, including, but not limited to, hiring, job assignment, compensation, promotion, benefits, training, discipline, and termination. F5 offers a variety of reasonable accommodations for candidates. Requesting an accommodation is completely voluntary. F5 will assess the need for accommodations in the application process separately from those that may be needed to perform the job. Request by contacting accommodations@f5.com.
Auto-ApplySenior Security Engineer - Edge Team
Security engineer job in Bellevue, WA
Job Description
About the Company
Armada is an edge computing startup that provides computing infrastructure to remote areas where connectivity and cloud infrastructure is limited, as well as areas where data needs to be processed locally for real-time analytics and AI at the edge. We're looking to bring on the most brilliant minds to help further our mission of bridging the digital divide with advanced technology infrastructure that can be rapidly deployed
anywhere
.
About the role
We are seeking a highly skilled and motivated Senior Security Engineer to join our Edge Team. In this role, you will be responsible for securing our cloud and edge computing environments, with a focus on our Galleon mobile data centers and their integration with our Atlas cloud platform. You will play a crucial role in designing, implementing, and managing security controls across our infrastructure, ensuring the confidentiality, integrity, and availability of our systems and data.
Location. This role is office-based at our Bellevue, Washington office.
What You'll Do (Key Responsibilities)
Design, implement, and manage security controls across our cloud platforms (AWS, Azure, GCP), Kubernetes environments, and Galleon mobile data centers, ensuring secure deployment practices and platform security for microservices and APIs
Integrate security components within our CI/CD pipelines, including automated security testing (SAST, DAST, container image scanning), vulnerability scanning, and compliance checks. Ensure that security is embedded throughout the software development lifecycle
Define and implement security configurations for infrastructure, including Kubernetes, using IaC tools (Terraform, Ansible) to ensure consistent enforcement of security policies
Monitor and respond to security events, develop and maintain security monitoring tools, and participate in incident response activities
Architect and implement security solutions that protect our cloud-native, hybrid, and on-premises infrastructure, including our Galleon data centers. Conduct security architecture reviews, threat modeling, and risk assessments to identify and mitigate vulnerabilities
Partner with engineering teams to integrate security tooling into the SDLC, enabling DevSecOps adoption and fostering a culture of shared security responsibility
Ensure compliance with relevant security standards and regulations (e.g., SOC 2, ISO 27001) through regular audits and implementing necessary controls. Stay up-to-date with cybersecurity threats, trends, and industry standards
Data Center Security Responsibilities
Implement robust perimeter security for Galleon data centers, including physical access controls, intrusion detection systems, and video surveillance
Design and implement network segmentation within data centers to isolate critical systems and limit the impact of security breaches
Utilize micro-segmentation techniques to enforce security policies at the workload level, controlling communication between individual applications and services
Implement data loss prevention (DLP) solutions to prevent sensitive data from leaving the data center environment
Securely manage and store cryptographic keys used for encryption and authentication within the data center
Implement robust logging and monitoring systems to track security-related events and detect anomalies
Regularly conduct vulnerability assessments and penetration testing to identify and remediate security weaknesses
Develop and maintain incident response plans specific to data center security incidents
Required Qualifications
7+ years of experience in security engineering, with a focus on cloud-native technologies, distributed systems, and edge computing, including securing Kubernetes environments
Strong understanding of security best practices across the SDLC, including secure coding principles, threat modeling, and vulnerability management
Experience securing cloud platforms (AWS, Azure, GCP) and Kubernetes environments, including implementing RBAC, network policies, and container security
Proficiency in scripting and automation (Python, Bash, Go) for security tooling and infrastructure-as-code (Terraform, Ansible)
Experience with security monitoring, threat detection, and incident response in cloud and containerized environments
Excellent communication and collaboration skills, with the ability to work effectively with engineering teams and advocate for security best practices
Bachelor's degree in a relevant field or equivalent practical experience
Compensation
For U.S. Based candidates: To ensure fairness and transparency, the starting base salary range for this role for candidates in the U.S. are listed below, varying based on location experience, skills, and qualifications.
In addition to base salary,
this role will also be offered equity and subsidized benefits
(details available upon request).
Benefits
Competitive base salary and equity
Medical, dental, and vision (subsidized cost)
Health savings accounts (HSA), flexible spending accounts (FSA), and dependent care FSAs (DCFSA)
Retirement plan options, including 401(k) and Roth 401(k)
Unlimited paid time off (PTO)
15 paid company holidays per year
#LI-ST1
#LI-Onsite
#439
Compensation$128,000-$160,000 USD
You're a Great Fit if You're
A go-getter with a growth mindset. You're intellectually curious, have strong business acumen, and actively seek opportunities to build relevant skills and knowledge
A detail-oriented problem-solver. You can independently gather information, solve problems efficiently, and deliver results with a "get-it-done" attitude
Thrive in a fast-paced environment. You're energized by an entrepreneurial spirit, capable of working quickly, and excited to contribute to a growing company
A collaborative team player. You focus on business success and are motivated by team accomplishment vs personal agenda
Highly organized and results-driven. Strong prioritization skills and a dedicated work ethic are essential for you
Equal Opportunity Statement
At Armada, we are committed to fostering a work environment where everyone is given equal opportunities to thrive. As an equal opportunity employer, we strictly prohibit discrimination or harassment based on race, color, gender, religion, sexual orientation, national origin, disability, genetic information, pregnancy, or any other characteristic protected by law. This policy applies to all employment decisions, including hiring, promotions, and compensation. Our hiring is guided by qualifications, merit, and the business needs at the time.
Unsolicited Resumes and Candidates
Armada does not accept unsolicited resumes or candidate submissions from external agencies or recruiters. All candidates must apply directly through our careers page. Any resumes submitted by agencies without a prior signed agreement will be considered unsolicited and Armada will not be obligated to pay any fees.
Network Engineer
Security engineer job in Redmond, WA
Skills Required:
Experience Required - 7 to 9 years in IT Operations.
Relevant Experience - Minimum 4 -5 Years in Networking
Technical Skills -OSPF, BGP, Switching and Routing, VRF's, Multicast, DMVPN, VxLan, BGP/EVPN, 802.1x, Palo Alto and RADIUS
Technical Certification - CCNA and Palo Alto Certification (Preferred)
Job Responsibilities:
Design, implement, and support network infrastructure for large scale networks.
Experience with Palo Alto firewalls.
Monitor firewall logs, network traffic, and security events to detect and respond to security incidents in a timely manner.
Troubleshoot and resolve complex network security issues, including firewall misconfigurations, connectivity problems, and performance bottlenecks.
Design, deploy, configure, and manage Palo Alto Networks' firewall solutions, including Panorama management platform, Global Protect VPN, and Threat Prevention subscriptions.
Develop and implement network security policies, rules, and access controls based on industry best practices and regulatory compliance requirements.
Experience in Deploying Cisco and Palo Alto Devices.
Administrate Network Access Control Solutions such as Cisco ISE and Cisco DUO.
Experience with Cisco Nexus and Catalyst Series switches and Arista switches.
Deep understanding of various network protocols and technologies such as OSPF, BGP, MP-BGP, VRFs, multicast, DMVPN, VxLAN, BGP/EVPN, 802.1x and RADIUS
Escalation points for network support engineers.
Disclaimer
HCL is an equal opportunity employer, committed to providing equal employment opportunities to all applicants and employees regardless of race, religion, sex, color, age, national origin, pregnancy, sexual orientation, physical disability or genetic information, military or veteran status, or any other protected classification, in accordance with federal, state, and/or local law. Should any applicant have concerns about discrimination in the hiring process, they should provide a detailed report of those concerns to ****************** for investigation.
Compensation and Benefits
A candidate's pay within the range will depend on their skills, experience, education, and other factors permitted by law. This role may also be eligible for performance-based bonuses subject to company policies. In addition, this role is eligible for the following benefits subject to company policies: medical, dental, vision, pharmacy, life, accidental death & dismemberment, and disability insurance; employee assistance program; 401(k) retirement plan; 10 days of paid time off per year (some positions are eligible for need-based leave with no designated number of leave days per year); and 10 paid holidays per year
Manual Ethical Hacker
Security engineer job in Seattle, WA
Denver, Colorado;Seattle, Washington; Addison, Texas; Jersey City, New Jersey; Boston, Massachusetts; Charlotte, North Carolina; Washington, District of Columbia; Jacksonville, Florida; Chicago, Illinois **To proceed with your application, you must be at least 18 years of age.**
Acknowledge
Refer a friend
**To proceed with your application, you must be at least 18 years of age.**
Acknowledge (******************************************************************************************
**:**
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day.
One of the keys to driving Responsible Growth is being a great place to work for our teammates around the world. We're devoted to being a diverse and inclusive workplace for everyone. We hire individuals with a broad range of backgrounds and experiences and invest heavily in our teammates and their families by offering competitive benefits to support their physical, emotional, and financial well-being.
Bank of America believes both in the importance of working together and offering flexibility to our employees. We use a multi-faceted approach for flexibility, depending on the various roles in our organization.
Working at Bank of America will give you a great career with opportunities to learn, grow and make an impact, along with the power to make a difference. Join us!
**Job Description:**
Manual Ethical Hacking is part of the Application Development Security Framework Program within Bank of America's Cyber Security Assurance Offensive Security group. The program provides services to assess the vulnerability of the bank's applications to malicious hacking activity.
This intermediate technical role is responsible for performing application security assessments of the bank's technologies, applications, and cyber security controls while adapting testing methods to evolving and emerging threats. Key responsibilities include performing research, understanding the bank's security policies, working with the appropriate partners to complete assessments and simulations, identifying misconfigurations and vulnerabilities, and reporting on associated risk. These individuals partner closely with security partners, CIO clients and multiples lines of business.
Key Responsibilities in order of importance:
+ Perform assigned analysis of internal and external threats on information systems and predict future threat behavior
+ Incorporate threat actors' tactics, techniques, and procedures into offensive security testing
+ Perform assessments of the security, effectiveness, and practicality of multiple technology systems
+ Leverage innovative thinking to help solve problems or introduce new ideas to processes or products applicable to offensive security.
+ Prepare and present detailed technical information for various media including documents, reports, and notifications
+ Provide clear and practical advice regarding managed risks
+ Learn and develop advanced technical and leadership skills, Mentor Junior assessors in technical tradecraft and soft skills
Required Skills:
+ Minimum of 4 years of professional pentesting, application security or ethical hacking experience, preferably in a large, complex, enterprise environment
+ Detailed technical knowledge in at least 3 of the following areas: security engineering; application architecture; authentication and security protocols; application session management; applied cryptography; common communication protocols; mobile frameworks; single sign-on technologies; exploit automation platforms; RESTful web services
+ SQL injection/XSS attack without the use of tools
+ Experience performing manual code reviews for security relevant issues
+ Experience working with SAST tools to identify vulnerabilities
+ Able to manually identify and reproduce findings, discuss remediation concepts, develop PoCs for vulnerabilities, use scripting/coding techniques, proficiently execute common penetration testing tools, triage, and support incidents, and produce high value findings
+ Experience performing manual web application assessments i.e., must be able to simulate a
+ Knowledge of network and Web related protocols/technologies (e.g., UNIX/LINUX, TCP/IP, Cookies)
+ Experience with vulnerability assessment tools and penetration testing techniques
+ Solid programming/debugging skills
+ Experience of using a variety of tools, included, but not limited to, IBM AppScan, Burp and SQL Map
+ Threat Analysis
+ Innovative Thinking
+ Technology Systems Assessment
+ Technical Documentation
+ Advisory
Desired:
+ CISSP, CEH, OSCP, OSWE, GPEN, PenTest+ or similar
+ Strong programming/scripting skills
This job will be open and accepting applications for a minimum of seven days from the date it was posted.
**Shift:**
1st shift (United States of America)
**Hours Per Week:**
40
Bank of America and its affiliates consider for employment and hire qualified candidates without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote the concept of equal employment opportunity, in accordance with all applicable federal, state, provincial and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our teammates.
View your **"Know your Rights (************************************************************************************** "** poster.
**View the LA County Fair Chance Ordinance (************************************************************************************************** .**
Bank of America aims to create a workplace free from the dangers and resulting consequences of illegal and illicit drug use and alcohol abuse. Our Drug-Free Workplace and Alcohol Policy ("Policy") establishes requirements to prevent the presence or use of illegal or illicit drugs or unauthorized alcohol on Bank of America premises and to provide a safe work environment.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations. Should you be offered a role with Bank of America, your hiring manager will provide you with information on the in-office expectations associated with your role. These expectations are subject to change at any time and at the sole discretion of the Company. To the extent you have a disability or sincerely held religious belief for which you believe you need a reasonable accommodation from this requirement, you must seek an accommodation through the Bank's required accommodation request process before your first day of work.
This communication provides information about certain Bank of America benefits. Receipt of this document does not automatically entitle you to benefits offered by Bank of America. Every effort has been made to ensure the accuracy of this communication. However, if there are discrepancies between this communication and the official plan documents, the plan documents will always govern. Bank of America retains the discretion to interpret the terms or language used in any of its communications according to the provisions contained in the plan documents. Bank of America also reserves the right to amend or terminate any benefit plan in its sole discretion at any time for any reason.