Firmware Security Engineer: 25-07341
Security engineer job in Seattle, WA
Primary Skills: Chips Security (Expert), Cryptography (Proficient), C++ (Advanced), Hardware Security (Intermediate), Embedded Systems (Intermediate) Contract Type: W2 Duration: 12 months with possible extension Pay Range: $105.00 - $120.00 per hour
#LP
Job Summary:
We are seeking a highly skilled Security Engineer IV to join our Devices and Services Security team, dedicated to ensuring the security integrity of hardware for emerging products. This position will focus on hardware security assessments, secure boot implementations, and cryptography to protect the privacy and integrity of our devices. The ideal candidate will work closely with third-party manufacturers to update and assess designs, ensuring compliance and protection against vulnerabilities.
Key Responsibilities:
Conduct hardware security assessments and audits of emerging products.
Design and implement secure boot solutions for embedded systems.
Utilize expertise in cryptography to enhance device security.
Collaborate with third-party manufacturers to ensure secure and compliant designs.
Analyze and assess hardware security architectures and debug interfaces.
Must-Have Skills:
Bachelor's degree in Computer Engineering, Computer Science, or related technical field
5+ years of experience in hardware security, embedded systems security, or similar
Experience programming in at least one modern language such as C, C++, or Rust
Strong knowledge of secure boot implementations, cryptography (RSA, AES, HMAC, PQC), and hardware security architectures (e.g. ARM TrustZone or Client SGX)
ABOUT AKRAYA
Akraya is an award-winning IT staffing firm consistently recognized for our commitment to excellence and a thriving work environment. Most recently, we were recognized Inc's Best Workplaces 2024 and Silicon Valley's Best Places to Work by the San Francisco Business Journal (2024) and Glassdoor's Best Places to Work (2023 & 2022)!
Industry Leaders in IT Staffing
As staffing solutions providers for Fortune 100 companies, Akraya's industry recognitions solidify our leadership position in the IT staffing space. We don't just connect you with great jobs, we connect you with a workplace that inspires!
Join Akraya Today!
Let us lead you to your dream career and experience the Akraya difference. Browse our open positions and join our team!
Systems Engineer - Systems Engineer II
Security engineer job in Bellevue, WA
We're seeking a hybrid SDE + Systems Engineer profile
The successful engineer in this role will:
Understand how commodity servers, operating systems and networks function, perform and scale.
Possess superb troubleshooting, project management and problem analysis skills.
Drive technical innovation and efficiency in infrastructure operations via automation.
Design server monitoring and management solutions using automation and self-repair.
Create processes that enhance operational workflow and provide positive customer impact.
Dive deep to resolve problems at their root, looking for failure patterns amenable to long-term solutions via simplification and automation.
Avoid re-inventing the wheel and prefer appropriately simple, repeatable solutions over more complex and failure prone ones.
Recognize and adopt best practices in documentation, testing, security, operational support at scale, and efficient use of resources.
Develop appropriate metrics to demonstrate performance at improving operational efficiency.
Core Requirements:
In depth knowledge of & experience deploying and operating Linux or other UNIX variants in a datacenter environment.
Relentless passion for frugality and out-of-the-box engineering.
Strong system troubleshooting skills.
Proficiency and experience in automation via Perl/Python programming and shell scripting.
Good understanding of standard internet protocols (Ethernet, ARP, IP, ICMP, UDP, TCP, SSL, DNS, HTTP, etc.)
Demonstrable grasp of security best practices in server configuration, tool development, and access controls.
Experience in building SQL queries.
Typical Task Breakdown:
Understand how commodity servers, operating systems and networks function, perform and scale.
Possess superb troubleshooting, project management and problem analysis skills.
Drive technical innovation and efficiency in infrastructure operations via automation.
Design server monitoring and management solutions using automation and self-repair.
Create processes that enhance operational workflow and provide positive customer impact.
Dive deep to resolve problems at their root, looking for failure patterns amenable to long-term solutions via simplification and automation.
Avoid re-inventing the wheel and prefer appropriately simple, repeatable solutions over more complex and failure prone ones.
Recognize and adopt best practices in documentation, testing, security, operational support at scale, and efficient use of resources.
Develop appropriate metrics to demonstrate performance at improving operational efficiency.
Degrees / Certs and/or Experience Required:
In depth knowledge of & experience deploying and operating Linux or other UNIX variants in a datacenter environment.
Relentless passion for frugality and out-of-the-box engineering.
Strong system troubleshooting skills.
Proficiency and experience in automation via Perl/Python programming and shell scripting.
Good understanding of standard internet protocols (Ethernet, ARP, IP, ICMP, UDP, TCP, SSL, DNS, HTTP, etc.)
Demonstrable grasp of security best practices in server configuration, tool development, and access controls.
Experience in building SQL queries.
Preferred Qualifications:
Knowledge of C, C++ or Java.
Knowledge of VCS (git, mercurial, svn).
Understanding of AWS technologies.
Experience deploying or managing servers in large-scale, geographically diverse environments.
Understanding & experience of managing and monitoring large scale disk sub-systems.
Operational knowledge of common enterprise switching and routing platforms
About US Tech Solutions:
US Tech Solutions is a global staff augmentation firm providing a wide range of talent on-demand and total workforce solutions. To know more about US Tech Solutions, please visit ************************
US Tech Solutions is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Recruiter Details:
Name: Shweta
Email: ***********************************
Internal Id: 25-54454
Network Engineer
Security engineer job in Redmond, WA
Role: Network Deployment engineer - LAN/WAN
Primary Skill : LAN/WAN, Cisco, Juniper
Secondary Skill: Arista, Aruba
Key Responsibilities:
• Design, deploy, and maintain network infrastructure across multiple vendors (Cisco, Juniper, Arista, Aruba).
• Configure and optimize routers, switches, firewalls, and wireless networks for enterprise and data center environments.
• Perform network upgrades, migrations, and expansions while ensuring minimal downtime.
• Implement network security policies, access controls, and monitoring solutions.
• Conduct site surveys and assessments to determine optimal network configurations.
• Troubleshoot and resolve complex Layer 2 and Layer 3 network issues.
• Work closely with cross-functional teams to integrate networking solutions with business applications.
• Provide documentation, network diagrams, and knowledge transfer to operations teams.
• Ensure compliance with industry standards and best practices.
• Support network automation and scripting initiatives (Python, Ansible, etc.).
Required Skills & Qualifications:
• Bachelor's degree in Computer Science, Information Technology, or a related field (or equivalent work experience).
• Min 4+ years of exp. for L2 and 6+ years exp. for L3 in network deployment, administration, and troubleshooting
• Expertise in configuring and managing Cisco, Juniper, Arista, and Aruba network devices.
• Strong understanding of routing protocols (BGP, OSPF, EIGRP, IS-IS) and switching technologies (VLANs, STP, VXLAN, EVPN).
• Proficiency in network security technologies (firewalls, IPS/IDS, VPNs, NAC solutions).
• Hands-on experience with wireless networks (Aruba ClearPass, Cisco Wireless Controllers, 802.1X authentication).
• Experience with network automation (Ansible, Python, Terraform) is a plus.
• Familiarity with cloud networking ( Azure) and scripting knowledge (python) is an advantage.
• Strong problem-solving skills with the ability to work independently and in a team environment.
• Excellent communication and documentation skills.
Certifications (Preferred but Not Mandatory):
Cisco: CCNP, CCIE
Juniper: JNCIP, JNCIE
Arista: ACE-A, ACE-P
Aruba: ACMP, ACDP
Network Automation: DevNet, JNCIA-DevOps, Ansible
Education:
Bachelor of Engineering (Computer Science, Information Technology, Electronics etc.) with CCNA & CCNP (preferred)
Disclaimer
HCL is an equal opportunity employer, committed to providing equal employment opportunities to all applicants and employees regardless of race, religion, sex, color, age, national origin, pregnancy, sexual orientation, physical disability or genetic information, military or veteran status, or any other protected classification, in accordance with federal, state, and/or local law. Should any applicant have concerns about discrimination in the hiring process, they should provide a detailed report of those concerns to ****************** for investigation.
Compensation and Benefits
A candidate's pay within the range will depend on their work location, skills, experience, education, and other factors permitted by law. This role may also be eligible for performance-based bonuses subject to company policies. In addition, this role is eligible for the following benefits subject to company policies: medical, dental, vision, pharmacy, life, accidental death & dismemberment, and disability insurance; employee assistance program; 401(k) retirement plan; 10 days of paid time off per year (some positions are eligible for need-based leave with no designated number of leave days per year); and 10 paid holidays per year.
Routing and Switching Network Engineer
Security engineer job in Redmond, WA
Routing and Switching Network Engineer Duration: Contract The Routing and Switching Network Engineer will be responsible for designing, implementing, and maintaining network infrastructure to ensure optimal performance, security, and scalability. This role requires collaboration with various teams to support business objectives, provide technical guidance, and troubleshoot complex network issues. The position is onsite in Plano, Texas, and requires 10+ years of experience in network engineering.
Responsibilities:
Develop and implement network architectures that align with business objectives.
Oversee the deployment and configuration of network devices, including routers, switches, firewalls, and wireless access points.
Coordinate with customers, SMEs, leads, and managers to understand and document network architecture.
Troubleshoot L2/L3 level issues and handle high-priority tickets (P1/P2), performing root cause analysis and permanent fixes.
Provide hands-on support for wireless networks, including Cisco and Meraki.
Handle P3/P4 tickets and guide offshore teams as needed.
Liaise with service providers for link-related services and coordinate with vendors/OEMs for hardware/software upgrades or replacements.
Train and provide knowledge transfer to other associates as necessary.
Monitor and maintain network performance, ensuring minimal disruptions.
Respond to network-related incidents and provide immediate solutions or escalate as necessary.
Create and maintain comprehensive documentation for network configurations and troubleshooting steps.
Implement and manage network protocols such as TCP/IP, OSPF, BGP, and VLANs.
Ensure network compliance with industry standards and regulations, conducting security assessments and vulnerability scans.
Collaborate with cross-functional teams and communicate effectively with stakeholders.
Qualifications:
Bachelor's degree in Computer Science, Information Technology, or a related field.
10+ years of experience in network engineering.
Active Cisco/Extreme Network equivalent certification (CCNP or CCIE preferred).
Strong understanding of networking protocols and technologies (TCP/IP, BGP, OSPF, VLANs, etc.).
Experience with network hardware and software from vendors such as Cisco, Juniper, or Arista.
Hands-on experience with Extreme network switches, Cisco switches and routers, and Juniper routers.
Proficiency in scripting languages (Python, Perl, etc.) and automation tools (Ansible, Terraform, etc.).
Experience with network monitoring and management tools (e.g., SolarWinds, PRTG, Zabbix).
Strong analytical and problem-solving skills with excellent communication and interpersonal abilities.
Ability to adapt to rapidly changing technologies and work independently or as part of a team.
About PTR Global: PTR Global is a leading provider of information technology and workforce solutions. PTR Global has become one of the largest providers in its industry, with over 5000 professionals providing services across the U.S. and Canada. For more information visit *****************
At PTR Global, we understand the importance of your privacy and security. We NEVER ASK job applicants to:
Pay any fee to be considered for, submitted to, or selected for any opportunity.
Purchase any product, service, or gift cards from us or for us as part of an application, interview, or selection process.
Provide sensitive financial information such as credit card numbers or banking information. Successfully placed or hired candidates would only be asked for banking details after accepting an offer from us during our official onboarding processes as part of payroll setup.
Pay Range: $50 - $55
The specific compensation for this position will be determined by a number of factors, including the scope, complexity and location of the role as well as the cost of labor in the market; the skills, education, training, credentials and experience of the candidate; and other conditions of employment. Our full-time consultants have access to benefits including medical, dental, vision and 401K contributions as well as any other PTO, sick leave, and other benefits mandated by appliable state or localities where you reside or work.
If you receive a suspicious message, email, or phone call claiming to be from PTR Global do not respond or click on any links. Instead, contact us directly at ***************. To report any concerns, please email us at *******************
GCP System Engineer
Security engineer job in Issaquah, WA
Key Details: Contract Role
Title :: GCP System Engineer - AI Contact Center
Duration :: Long Term Contract
We are seeking a highly skilled GCP System Engineer to manage the operational stability, configuration, and deep-level integration of the Google Contact Center AI (CCAI) platform and its related ecosystem. This role is crucial for implementing and maintaining core contact center functionalities, including call routing, WFM integration, and seamless channel connectivity between Google CES and Salesforce.
Required Skills and Experience
12+ years of hands-on experience in a System Engineering or CTI/Telephony-focused role within a Contact Center environment.
Direct experience with the technical configuration of Google Contact Center AI (CCAI) / Customer Engagement Suite (CES).
Proven expertise in setting up and troubleshooting call routing, queueing, and CTI integration logic.
Experience with the technical setup and data mapping for Verint Workforce Management (WFM) or a similar enterprise WFM system.
Strong understanding of API integration concepts (REST/SOAP) and secure data transmission protocols.
Proficiency with GCP services relevant to operations (e.g., Compute Engine, Cloud Load Balancing, Monitoring/Logging).
System Engineer
Security engineer job in Seattle, WA
Title
Senior Systems Administrator
Employment Type
Full Time Direct Hire
Job Site
Onsite
City
Seattle
State
WA
Pay Rate Range (External)
110K - 135K
BENEFITS:
Some of the benefits that our employees enjoy:
Medical / Dental / Vision*
Vacation / Sick/ Holiday Pay
401(k)
100% Fully Pre-Paid College Tuition
Employee Stock Option Program
Employee Assistance Program
Flexible Spending Accounts
Voluntary Term Life and AD&D
Employee Paid Life Insurance
Employer Paid Short Term Disability Insurance
Discounted employee produce purchase program
Free Smoking Cessation Program
Free Wellness Coaching and Healthy Pregnancy Programs
Virtual Office Visits
ROLE & RESPONSIBILITIES
We are seeking a Senior Systems Administrator for a team supporting enterprise Microsoft infrastructure, which would be a great opportunity for someone with experience in Windows Server administration, Intune, Active Directory, and enterprise security looking to further their career in systems engineering and IT operations.
Overview:
The Senior Systems Administrator will manage and secure the organization's Microsoft Windows infrastructure, ensuring high availability, compliance, and operational excellence. This role requires expertise in Windows OS, Intune, Active Directory, and enterprise security standards. The position includes on-call responsibilities and collaboration across IT and business units.
Responsibilities:
Administer and maintain Windows Server environments, Active Directory, Azure Entra ID and Group Policy.
Familiar with container platforms - Docker and/or Kubernetes.
Manage Intune for device compliance, application deployment, and endpoint security.
Implement and monitor security baselines using Microsoft Security Compliance Toolkit.
Apply patches, updates, and vulnerability remediation across systems.
Monitor system performance, uptime, and resource utilization.
Develop and maintain Disaster Recovery plans and participate in regular testing.
Develop and maintain documentation for systems, processes, and policies.
Provide Tier 2/3 support for escalated issues.
Handle backup and recovery procedures for critical systems.
Work with cross-functional teams on deployments and upgrades.
Mentor junior IT staff and enforce best practices.
Additional Tasks/Duties as they are assigned.
ESSENTIAL QUALIFICATIONS
Bachelor's Degree in Computer Science, Information Technology, or equivalent on-the-job experience.
7+ years' experience in Windows Server administration and enterprise environments.
Expertise in Microsoft Intune and Endpoint Manager, Active Directory, Entra ID, Windows OS (10/11) and security hardening.
Strong knowledge of backup/recovery systems and documentation standards.
Familiarity with compliance frameworks and security baselines.
Certifications such as MCSE, MCSA, or Microsoft Certified: Modern Desktop Administrator.
Experience with cloud platforms including Microsoft Azure and hybrid cloud environments.
BONUS QUALIFICATIONS
Experience with virtualization (Hyper-V).
PowerShell scripting and automation.
Knowledge of O365, SharePoint, and cloud-based email systems.
Expertise in O365 integration and administration.
Participated in large Enterprise based projects and Digital Transformation.
Soft Skills
Strong communication and interpersonal skills.
Excellent problem-solving and analytical abilities.
Leadership and team collaboration capabilities.
Vendor management and negotiation skills.
Ability to work under pressure and manage multiple priorities.
On-Call Expectations
This position requires participation in on-call rotation to provide after-hours support for critical systems and respond to incidents promptly. Candidates must be able to troubleshoot and resolve issues under pressure and ensure minimal downtime.
WHY AVERRO?
Averro is an equal opportunity employer, and we are committed to diversity, equity, and inclusion in the workplace. All qualified applicants will receive consideration for employment, regardless of criminal histories, consistent with legal obligations. All employment decisions shall be made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status or any other basis as protected by federal, state, or local law.
View our privacy policy here: *******************************************
GCP System Engineer - AI Contact Center
Security engineer job in Issaquah, WA
Position : GCP System Engineer - AI Contact Center:: Issaquah, WA (Hybrid, 3 days onsite per week):: Hire Type: Contract (C2C/W2)
Project description
We are seeking a highly skilled GCP System Engineer to manage the operational stability, configuration, and deep-level integration of the Google Contact Center AI (CCAI) platform and its related ecosystem. This role is crucial for implementing and maintaining core contact center functionalities, including call routing, WFM integration, and seamless channel connectivity between Google CES and Salesforce.
Key Responsibilities
Contact Center Operations & Telephony
Call Setup & Routing Implementation: Configure, test, and maintain the end-to-end call setup process within the Google Contact Center AI Platform, ensuring high availability and low latency.
Routing Logic Deployment: Implement complex, skill-based, and data-driven call and chat routing logic based on directives from the Architecture team and business requirements, ensuring optimal customer experience.
Voice and CTI Management: Manage the integration points between the Google CES platform and underlying CTI/telephony infrastructure, troubleshooting connectivity and quality issues (e.g., SIP, web RTC).
Workforce Management (WFM) Setup: Lead the technical setup, configuration, and ongoing maintenance of the Verint WFM integration with the Google CES platform, ensuring accurate data exchange for forecasting, scheduling, and adherence monitoring.
Channel & Application Integration
Salesforce Channel Integration: Implement and manage the technical channels (e.g., APIs, connectors) that enable real-time and historical data exchange between Google CES (Dialogflow, CCAI) and Salesforce Service Cloud for unified agent views and case creation.
External API Integration: Configure and secure API endpoints to facilitate the real-time consumption of data from external systems (e.g., knowledge bases, order systems) to enrich conversational flows.
System Health & Monitoring: Establish and manage comprehensive monitoring, alerting, and logging systems (using GCP Operations Suite/Stackdriver) for all contact center components, proactively identifying performance bottlenecks and stability risks.
Agentic AI Configuration & Support
Agentic AI Setup: Execute the configuration and deployment of core AI agents (Dialogflow CX/ES) and other Agentic AI components, ensuring they meet operational standards for reliability and performance.
AI Integration & Tuning: Configure and maintain the technical integration of Agentic AI with enterprise knowledge bases (via Vertex AI Search/Gen AI) and the designated external APIs to provide accurate and relevant responses.
Incident Response: Serve as the Tier 2/3 escalation point for operational issues related to call routing failures, integration errors, and WFM data discrepancies.
Required Skills and Experience
12+ years of hands-on experience in a System Engineering or CTI/Telephony-focused role within a Contact Center environment.
Direct experience with the technical configuration of Google Contact Center AI (CCAI) / Customer Engagement Suite (CES).
Proven expertise in setting up and troubleshooting call routing, queueing, and CTI integration logic.
Experience with the technical setup and data mapping for Verint Workforce Management (WFM) or a similar enterprise WFM system.
Strong understanding of API integration concepts (REST/SOAP) and secure data transmission protocols.
Proficiency with GCP services relevant to operations (e.g., Compute Engine, Cloud Load Balancing, Monitoring/Logging).
Offensive Security Researcher
Security engineer job in Seattle, WA
NVIDIA is looking for security researchers passionate about offensive research across different platforms. Do you have experience with identifying hardware and software vulnerabilities, developing PoC, and tools for automation in vulnerability research? Are you creative and devious in your offensive approach? We want to hear from you!
You should demonstrate ability to excel in an environment with innovative and fast paced development on the worlds most powerful integrated software and hardware computing platform.
What you'll be doing:
* Core job duties will identify vulnerabilities in our embedded firmware and critical system software, building proof of concepts, and collaborating with development teams to remediate them.
* Candidates will invest in improving current tools and offensive practices for bug discovery and evaluation while supporting remediation efforts. We expect team members to exercise modern tools for modeling new attack vectors on unreleased and emerging technology platforms.
* The most impactful candidates can simulate real attacker behaviors, break systems by exploiting design assumption and effectively communicate their findings for action. Focus will be to increase resilience of the end products against all forms of attack through close collaboration with extended SW and HW offensive security teams.
* Products targets span HPC data centers, consumer electronics, autonomous platforms, AI/cloud solutions, and a variety of embedded/IOT platforms providing a rich and complex target space to exercise your skills.
What we need to see:
* We'd like to see proven experience and offensive security research (CVE's, publications, patents, tools, bounties) with demonstrated responsible disclosure practices.
* Strong skills in reverse engineering and automation (IDA, Ghidra), fuzzing (AFL, WinAFL, Syzcaller) and exploitation (ROP, memory corruption) are important to success; as well as understanding of modern embedded cryptography and common security issues.
* Experience with ARM/X86/RISCV assembly (include shellcode development) and low-level C programming paired with understanding and experience with micro-architectural attacks (side channels, fault injection, etc) is critical.
* Demonstrated skill for secure code reviews of complex source projects, and exposure to code quality practices (SDL, threat modeling) that support development goals.
* Candidates should be comfortable working collaboratively and remotely with others to accomplish complex team goals, enabling delivery of outstanding security for our products.
* BS/BA degree or equivalent experience
* 12+ years in a security related field
Ways to stand out from the crowd:
* Navigating complex platform concerns and ability to analyze composed systems to identify high risk components and established testing targets and objectives.
* Practical skills using Hex-Rays IDA Pro and plugin/loaders development (or similar experience with Ghidra) is valuable
* Leveraging innovative strategies and AI advancements to accelerate discovery and resolution of security risks.
* Experience with enclave models such as NVIDIA CC, ARM TEE, Intel SGX/TDX, AMD SEV-SNP and other isolation technologies.
* Development and integration of AI tooling and skills to accelerate and improve activities and or experience with offensive actions targeting AI models (LLM or other) components within those platforms.
NVIDIA has continuously reinvented itself over two decades. Our invention of the GPU in 1999 fueled the growth of the PC gaming market, redefined modern computer graphics, and revolutionized parallel computing. More recently, GPU deep learning ignited modern AI - the next era of computing. NVIDIA is a "learning machine" that constantly evolves by adapting to new opportunities that are hard to solve, that only we can pursue, and that matter to the world. This is our life's work, to amplify creativity and intelligence. Make the choice to join us today!
Your base salary will be determined based on your location, experience, and the pay of employees in similar positions. The base salary range is 224,000 USD - 356,500 USD for Level 5, and 272,000 USD - 425,500 USD for Level 6.
You will also be eligible for equity and benefits.
Applications for this job will be accepted at least until October 5, 2025.
NVIDIA is committed to fostering a diverse work environment and proud to be an equal opportunity employer. As we highly value diversity in our current and future employees, we do not discriminate (including in our hiring and promotion practices) on the basis of race, religion, color, national origin, gender, gender expression, sexual orientation, age, marital status, veteran status, disability status or any other characteristic protected by law.
Auto-ApplyCyber Security Analyst
Security engineer job in Seattle, WA
Job Description
We is seeking a talented Cyber Security Analyst. As a Cyber Security Analyst, you will play a key role in ensuring the security and integrity of our organization's data and systems.
Requirements
Responsibilities:
Monitor, detect, and respond to cyber threats and security incidents,
Conduct vulnerability assessments and penetration testing to identify potential weaknesses in our systems,
Develop and implement security measures and best practices to protect against cyber attacks,
Stay up-to-date with the latest cyber security trends and technologies,
Collaborate with cross-functional teams to identify security risks and implement appropriate solutions,
Provide training and guidance to employees on cyber security awareness and best practices.
Requirements:
Bachelor's degree in Computer Science, Information Security, or a related field,
Proven experience in cyber security or a related role,
Strong knowledge of security protocols and tools,
Ability to analyze and interpret complex data and make informed decisions,
Excellent problem-solving and communication skills,
Relevant certifications (e.g. CISSP, CISM) are preferred but not required.
Benefits
About Us
Zone IT Solutions is an Australia-based Recruitment Company. We specialise in Digital, ERP and larger IT Services. We offer flexible, efficient and collaborative solutions to any organisation that requires IT, experts. Our agile, agnostic and flexible solutions will help you source the IT Expertise you need. If you are looking for new opportunities, your profile at *******************************.
Also, follow our LinkedIn page for new job opportunities and more.
Zone IT Solutions is an equal-opportunity employer, and our recruitment process focuses on essential skills and abilities.
Easy ApplySenior Manual Ethical Hacker
Security engineer job in Seattle, WA
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day.
One of the keys to driving Responsible Growth is being a great place to work for our teammates around the world. We're devoted to being a diverse and inclusive workplace for everyone. We hire individuals with a broad range of backgrounds and experiences and invest heavily in our teammates and their families by offering competitive benefits to support their physical, emotional, and financial well-being.
Bank of America believes both in the importance of working together and offering flexibility to our employees. We use a multi-faceted approach for flexibility, depending on the various roles in our organization.
Working at Bank of America will give you a great career with opportunities to learn, grow and make an impact, along with the power to make a difference. Join us!
Job Description:
Manual Ethical Hacking is part of the Application Development Security Framework Program within Bank of America's Cyber Security Assurance Offensive Security group. The program provides services to assess the security resilience of the bank's applications to malicious hacking activity.
This senior technical role is responsible performing and leading ethical hacking assessments of the bank's technologies, applications, and cyber security controls while adapting testing methods to evolving and emerging threats. Key responsibilities include leading and performing research, understanding the bank's security policies, working with appropriate partners to complete assessments and simulations, identifying misconfigurations and vulnerabilities, and reporting on associated risk. These individuals partner closely with security partners, CIO clients and multiples lines of business. These individuals are expected to perform application security-oriented dynamic and static assessments across a multitude of technologies including web UI, web APIs, mobile and cloud, including associated source code.
Key Responsibilities in order of importance:
* Perform assigned analysis of internal and external threats on information systems and predict future threat behavior.
* Incorporate threat actors' tactics, techniques, and procedures into offensive security testing to identify high-value vulnerabilities/chained attacks.
* Developing Proof-of-concepts for exploitation.
* Perform assessments of the security, effectiveness, and practicality of multiple technology systems.
* Leverage innovative thinking to help solve problems or introduce new ideas to processes or products applicable to offensive security.
* Prepare and present detailed technical information for various media including documents, reports, and notifications.
* Provide clear and practical advice regarding managing risks.
* Learn and develop advanced technical and leadership skills, mentor Junior and Intermediate assessors in technical tradecraft and soft skills.
* Respond to security incidents and provide technical assistance to leadership across the Information Security organization.
Required Skills:
* Minimum of 5+ years of professional pentesting, application security or ethical hacking experience, preferably in a large, complex, enterprise environment
* Detailed technical knowledge in at least 5 of the following areas:
* security engineering
* application architecture
* authentication and security protocols
* application session management
* applied cryptography
* common communication protocols
* mobile frameworks
* single sign-on technologies
* exploit automation platforms
* Web APIs
* Cloud environments
* LLM security
* Able to manually identify and reproduce findings, discuss remediation concepts, develop PoCs for vulnerabilities, use scripting/coding techniques, proficiently execute common penetration testing tools, triage, and support incidents, and produce high value findings
* Experience performing manual web application assessments i.e., must be able to simulate a OWASP Top 10 vulnerabilities without the use of tools
* Experience performing manual code reviews for security relevant issues
* Experience working with DAST and SAST tools to identify vulnerabilities
* Knowledge of network and Web related protocols/technologies (e.g., UNIX/LINUX, TCP/IP, Cookies)
* Experience with vulnerability assessment tools and penetration testing techniques.
* Solid programming/debugging skills, development frameworks, CVE and CWE research/reproduction
* Threat Analysis, threat modelling and SBOM analysis
* Innovative thinking, threat actor simulation
* Technology Systems Assessment
* Technical Documentation
* Advisory
Desired:
* CEH, OSCP/OSCE/OSWE/GXPN/GPEN/GWAPT/GMOB/All Practitioner Certs [Port Swigger BSP Academy]/Cloud Cert(s)/ eWPT; eWPTX; eMAPT [INE Pentester Academy]
* Strong programming/scripting skills
This job will be open and accepting applications for a minimum of seven days from the date it was posted.
Shift:
1st shift (United States of America)
Hours Per Week:
40
Security Engineer
Security engineer job in Seattle, WA
Artech is the 10th Largest IT Staffing Company in the US, according to Staffing Industry Analysts' 2012 annual report. Artech provides technical expertise to fill gaps in clients' immediate skill-sets availability, deliver emerging technology skill-sets, refresh existing skill base, allow for flexibility in project planning and execution phases, and provide budgeting/financial flexibility by offering contingent labor as a variable cost.
Job Title: Security Engineer/ System Security Engineer
Location: Seattle WA
Duration: 12 Months (Chances for extension)
Job Description:
Develops and manages security for more than one IT functional area (e.g., data, systems, network and/or Web) across the enterprise.
Assists in the development and implementation of security policies and procedures (e.g., user log-on and authentication rules, security breach escalation procedures, security auditing procedures and use of firewalls and encryption routines).
Prepares status reports on security matters to develop security risk analysis scenarios and response procedures.
Responsible for the tracking and monitoring of software viruses.
Enforces security policies and procedures by administering and monitoring security profiles, reviews security violation reports and investigates possible security exceptions, updates, and maintains and documents security controls.
Involved in the evaluation of products and/or procedures to enhance productivity and effectiveness. Provides direct support to the business and IT staff for security related issues.
Educates IT and the business about security policies and consults on security issues regarding user built/managed systems.
Represents the security needs of the organization by providing expertise and assistance in all IT projects with regard to security issues.
Must have extensive knowledge in networking, databases, systems and/or Web operations.
More junior level position primarily focuses on security administration; a more senior level position is involved in developing enterprise security strategies, management of security projects and the most complicated security issues.
Bachelor's Degree in Computer Science, Information Systems, or other related field. Or equivalent work experience.
Typically has 3 - 6 years of combined IT and security work experience with a broad range of exposure to systems analysis, application development, database design and administration; 3+ years of experience with information security.
Requires knowledge of security issues, techniques and implications across all existing computer platforms.
Position Comments: This is a security jack of all trades that will help with hardware patching, web app security, policy, RFP response, audits, facility security, etc.
Additional Skill: Linux experience required MPAA, Privacy Shield or Safe Harbour experience a plus
Additional Information
For more information, Please contact
Pankhuri Razada
Associate Recruiter
Artech information Systems LLC
360 Mt. Kemble Avenue, Suite 2000 Morristown, NJ 07960
************
[email protected] om
Enterprise Security Engineer
Security engineer job in Seattle, WA
About the Team Within the OpenAI Security organization, our IT team works to ensure our team of researchers, engineers, and staff have the tools they need to work comfortably, securely, and with minimal interruptions. As an Enterprise Security Engineer, you will work in a highly technical and employee-focused environment.
Our IT team is a small and nimble team, where you'll have the opportunity to dive into a wide breadth of areas and build from the ground up. We're well supported and well resourced, and have a mandate to deliver a world-class enterprise security program to our teams.
About the Role
As an Enterprise Security Engineer, you will be responsible for implementing and managing the security of OpenAI's internal information systems' infrastructure and processes. You will work closely with our IT and Security teams to develop security capabilities, enforce security policies, and monitor internal systems for security threats.
This role is open to remote employees, or relocation assistance is available to Seattle.
In this role, you will:
* Develop and implement security measures to protect our company's information assets against unauthorized access, disclosure, or misuse.
* Monitor internal and external systems for security threats and respond to alerts.
* Contribute to and enforce our company's IT and Security policies and procedures.
* Work closely with our IT department to harden our infrastructure using best practices in AzureAD, GSuite, Github, and other SaaS tooling.
* Advise our employees on best practices for maintaining the security of their endpoints, and office AV and network infrastructure.
* Devise novel sharing controls and associated monitoring to protect company data, including intelligent groups management, Data Loss Prevention (DLP) and other security controls as appropriate.
* Employ forward-thinking models like "secure by default" and "zero trust" to create sustainably secure environments for knowledge workers and developers.
* Identify and remediate vulnerabilities in our internal systems, adhering to best practices for data security.
* Use our own AI-driven models to develop systems for improved security detection and response, data classification, and other security-related tasks.
* Educate employees on the importance of data security, and advise them on best practices for maintaining a secure environment.
* Contribute to OpenAI's endpoint and cloud security roadmaps by staying up to date with the latest security threats, and making recommendations for improving our security posture.
You might thrive in this role if you have:
* Experience in protecting and managing mac OS fleets.
* Experience deploying and managing endpoint security solutions (e.g. management frameworks, EDR tools).
* Experience with public cloud service providers (e.g. Amazon AWS, Microsoft Azure).
* Experience with identity and access management frameworks and protocols, including SAML, OAUTH, and SCIM.
* Experience with e-mail security protocols (e.g. SPF, DKIM, DMARC) and controls.
* Intermediate or advanced proficiency with a scripting language (e.g. Python, Bash, or similar).
* Knowledge of modern adversary tactics, techniques, and procedures.
* Ability to empathize and collaborate with colleagues, independently manage and run projects, and prioritize efforts for risk reduction.
.
About OpenAI
OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.
We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.
For additional information, please see OpenAI's Affirmative Action and Equal Employment Opportunity Policy Statement.
Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.
To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance.
We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link.
OpenAI Global Applicant Privacy Policy
At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.
Security Engineer
Security engineer job in Bellevue, WA
About the Role
Responsibilities:
Design and implement security architectures for Azure cloud environments, hybrid infrastructure, and edge computing solutions
Develop and maintain security policies, standards, and procedures aligned with industry best practices and compliance requirements
Lead security incident response efforts and conduct thorough post-incident reviews
Perform security assessments, vulnerability scanning, and penetration testing across all environments
Implement and manage security tools for continuous monitoring and threat detection
Secure DevOps pipelines and CI/CD workflows, emphasizing "security as code" principles
Address unique security challenges related to AI/ML development, deployment, and operations
Collaborate with development teams to implement secure coding practices and conduct code reviews
Design and implement security architectures for Azure cloud environments, hybrid infrastructure, and edge computing solutions
Develop and maintain security policies, standards, and procedures aligned with industry best practices and compliance requirements
Lead security incident response efforts and conduct thorough post-incident reviews
Perform security assessments, vulnerability scanning, and penetration testing across all environments
Implement and manage security tools for continuous monitoring and threat detection
Secure DevOps pipelines and CI/CD workflows, emphasizing "security as code" principles
Address unique security challenges related to AI/ML development, deployment, and operations
Collaborate with development teams to implement secure coding practices and conduct code reviews
Design and implement robust identity and access management solutions
Stay current with emerging security threats and technologies
Qualifications:
Bachelor's degree in Computer Science, Cybersecurity, or related field (or equivalent experience)
5+ years of experience in information security, with at least 3 years focused on cloud security
Strong experience with Azure security services and best practices
Familiarity with security tools such as Microsoft Defender for Cloud, Sentinel, etc.
Knowledge of compliance frameworks (NIST, ISO 27001, SOC2, etc.)
Proficient in using vulnerability scanners such as Nexpose and Nessus.
Knowledge of Python and SQL for scripting and database analysis.
Familiarity with Azure environments is preferred.
Security Engineering certifications (CISSP, CCSP, Azure Security Engineer) - at least one is preferred.
Offensive Security Certifications (OSCP, OSWP, OSEE, OSWE, CEH,) - at least one is preferred.
US Citizenship required
Equal Opportunity Statement
At Armada, we are committed to fostering a work environment where everyone is given equal opportunities to thrive. As an equal opportunity employer, we strictly prohibit discrimination or harassment based on race, color, gender, religion, sexual orientation, national origin, disability, genetic information, pregnancy, or any other characteristic protected by law. This policy applies to all employment decisions, including hiring, promotions, and compensation. Our hiring is guided by qualifications, merit, and the business needs at the time.
Citizenship Requirements
For select roles, due to the nature of our clientele and the technologies involved, there may be specific nationality or citizenship indicated in the required qualifications section. These roles may involve access to sensitive information that is subject to export control regulations or other legal restrictions. In such cases, employment offers will be contingent upon your ability to comply with these requirements.
Compensation & Benefits
For U.S. Based candidates: To ensure fairness and transparency, the
starting
base salary range for this role for candidates in the U.S. are listed below, varying based on location experience, skills, and qualifications. In addition to base salary, this role will also be offered equity and subsidized benefits
(details available upon request)
.
Security Engineer, Operating Systems
Security engineer job in Seattle, WA
Anthropic's mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.
About the Role
We're looking for an Operating Systems Security Engineer to harden and secure the OS layer of our infrastructure. You'll be responsible for designing and implementing OS-level security controls, from kernel hardening to runtime protection, ensuring our systems can withstand sophisticated attacks while maintaining the performance required for AI model training.
This is a hands-on role where you'll work with cutting-edge hardware and implement novel security solutions for environments that don't exist anywhere else in the world. You'll need to balance extreme security requirements with the operational needs of researchers training models at unprecedented scale.
What You'll Do:
Design and implement hardened OS configurations for AI workloads across diverse hardware platforms
Minimize attack surfaces by removing as many unnecessary components as possible from kernelspace and userspace
Develop kernel security policies using SELinux, AppArmor, and custom Linux Security Modules and runtime enforcement mechanisms
Implement and maintain full-disk encryption solutions for diverse storage systems
Build security infrastructure for AI systems, research environments, and production services
Create OS-level attestation and integrity monitoring systems
Apply security patches, develop patches for custom kernel modules, and kernel hardening configurations
Design secure boot processes and trusted execution environments
Work with container teams to ensure proper workload isolation at the kernel level
Design privilege separation and mandatory access control policies
Implement secure update mechanisms for OS components
Build tooling for security configuration management and compliance verification
Serve as a subject matter expert for OS security questions and designs
Who You Are:
5+ years of experience in operating systems security or kernel development
Deep knowledge of Linux internals, including kernel subsystems and security frameworks (SELinux, AppArmor, seccomp, etc.)
Experience with kernel hardening techniques and exploit mitigation
Strong programming skills in C and systems programming languages
Experience with eBPF for security monitoring and enforcement
Understanding of virtualization and containerization security
Track record of identifying and fixing OS-level security vulnerabilities
Experience with security-focused Linux distributions
Strong candidates may also have:
Kernel development experience or contributions to Linux kernel
Experience with real-time or embedded operating systems
Knowledge of hardware security features and their OS integration
Experience with secure boot technologies
Experience with confidential computing and memory encryption technologies (SEV, TDX, SGX)
Background in vulnerability research, exploit development, or fuzzing
Experience with formal methods for OS verification
Knowledge of hardware security features and their OS integration (TPM, HSM, secure enclaves)
Deadline to apply: None. Applications will be reviewed on a rolling basis.
The expected base compensation for this position is below. Our total compensation package for full-time employees includes equity, benefits, and may include incentive compensation.
Annual Salary:$300,000-$405,000 USDLogistics
Education requirements: We require at least a Bachelor's degree in a related field or equivalent experience.
Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.
Visa sponsorship: We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.
We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you're interested in this work. We think AI systems like the ones we're building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team.
How we're different
We believe that the highest-impact AI research will be big science. At Anthropic we work as a single cohesive team on just a few large-scale research efforts. And we value impact - advancing our long-term goals of steerable, trustworthy AI - rather than work on smaller and more specific puzzles. We view AI research as an empirical science, which has as much in common with physics and biology as with traditional efforts in computer science. We're an extremely collaborative group, and we host frequent research discussions to ensure that we are pursuing the highest-impact work at any given time. As such, we greatly value communication skills.
The easiest way to understand our research directions is to read our recent research. This research continues many of the directions our team worked on prior to Anthropic, including: GPT-3, Circuit-Based Interpretability, Multimodal Neurons, Scaling Laws, AI & Compute, Concrete Problems in AI Safety, and Learning from Human Preferences.
Come work with us!
Anthropic is a public benefit corporation headquartered in San Francisco. We offer competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and a lovely office space in which to collaborate with colleagues. Guidance on Candidates' AI Usage: Learn about our policy for using AI in our application process
Auto-ApplyInformation Security Specialist (Cyber security analysis)
Security engineer job in Bellevue, WA
Job Title: “Information Security Specialist” (Cyber security analysis)
Duration: 9+ Months (with high possibility of extending into full time)
Job Description:
This position is in Corporate Information Security and under the direction of the Manager, Third-Party Cybersecurity Assessments. The Cybersecurity Assessment Analyst will perform cybersecurity assessments on new and existing third parties. The Analyst will construct detailed and summary reports of assessments, including customized reports, as needed. The Analyst will work with Subject Matter Experts (SME) to develop and apply risk assessment criteria (aligned with Policy) to new and existing suppliers using internal and external business intelligence. The Analyst will work with Third-Party Risk Management, Privacy and Legal Counsel, Procurement and Contract Managers, Compliance, and Business Owners to develop and maintain an internal service model that informs the business of key risks in a timely manner to limit unnecessary impediments and avoid bureaucracy.
Specific responsibilities:
- Coordinate the development of information security policies, standards and procedures. Work with key IT offices, data custodians and governance groups in the development of such policies. Ensure that company policies support compliance with external requirements. Oversee the dissemination of policies, standards and procedures to the user community
- Coordinate the development and delivery of an education and training program on information security and privacy matters for employees, other authorized users, and vendors
- Serve as the company compliance officer with respect to state and federal information security policies and regulations. Work with the -designated internal audit, SOX compliance, legal, and HR on compliance issues as necessary. Prepare and submit and submit required reports to external agencies.
- Develop and implement an Incident Reporting and Response System to address security incidents (breaches), respond to alleged policy violations, or complaints from external parties.
- Serve as the official company contact point for information security, privacy and copyright infringement incidents, including relationships with law enforcement entities.
- Develop and implement an ongoing risk assessment program targeting information security and privacy matters; recommend methods for vulnerability detection and remediation, and oversee vulnerability testing.
Required Qualifications:
Talent management, results focus and inspirational leadership.
Essential Functions
• Conduct third-party cybersecurity risk assessments, applying established criteria
• Support assessment team with quality assurance reviews over work product and reporting
• Collaborate with internal partners and third parties to mitigate and otherwise resolve third-party cyber risks
• Consistently deliver on commitments, deadlines and objectives while remaining in scope and leveraging appropriate tools, methods, frameworks, and professional standards
• Demonstrate consistent credibility with business partners and leadership while recommending initiatives, identifying gaps, and potential issues
• Continuously demonstrate the ability to work independently while representing the services of the department with the highest level of professionalism
• Demonstrate the ability to appropriately influence business decisions, and the professional judgment for selecting the appropriate methods and techniques to do so
Preferred Qualifications:
• Solid background both educationally and via professional experience. No less than 3 years' professional experience in business operations, project/program management, finance, risk management, information security, business analytics or similar.
• Experience in large companies and/or complex environments, or providing professional consulting services for them.
• Demonstrated abilities in problem-solving and analysis: identifies issues, analyses information to assess root cause and relationships, risks, and potential risk responses. Proven ability to synthesize and summarize complex data into concise recommendations and reports.
• Demonstrated strong business writing and professional oral communication skills.
• Proven ability to balance multiple priorities, adapt to a constantly changing business environment, work independently, drive projects to completion, and meet deadlines in a fast-paced environment-with only periodic supervision.
• Ability to work collaboratively and manage and initiate effective cross-functional relationships.
• Strong computer skills, including MS Office products (e.g. Word, Excel, PowerPoint, Visio) and other business software to prepare reports, memos, summaries, and analyses.
Desired
• Analytical - Synthesizes complex or diverse information; Collects and researches data; employs intuition and experience to complement data; Designs work flows and procedures.
• Quality Management - Looks for ways to improve and promote quality; Demonstrates accuracy and thoroughness. Applies feedback to improve performance; Monitors own work to ensure quality
• Planning/Organizing - Prioritizes and plans work activities to achieve success; Sets and achieves goals and objectives; Develops realistic action plans
• Professionalism - Reacts well under pressure; Keeps commitments; Accepts responsibility for own actions.
• Career Growth: Focus on cyber security auditing with potential advancement goals in engineering or threat analysis roles
• Self-directed team player with Agile environment experience
Education
Minimum Required
• Bachelor's Degree
• Equivalent experience is acceptable.
License or Certification
Desired: (one of the following):
CISA (Certified Information Systems Auditor)
GSEC (GIAC Security Essentials Certification)
CompTIA - Security+
ECSA - EC-Council Certified Security Analyst
SSCP (Systems Security Certified Practitioner)
Other:
Six Sigma, PMP or Agile certificates
Other comments - suppliers:
Organizational skills; office suite knowledge; and good communication skills are “must haves”. Cyber security analysis experience is preferred.
Additional Information
All your information will be kept confidential according to EEO guidelines.
Hardware Security Engineer IV (Electrical): 25-07342
Security engineer job in Seattle, WA
Primary Skills: Circuit Design (Expert), Embedded Security (Expert), Testing Equipment (Proficient), Cryptography (Knowledgeable), PCB Analysis (Intermediate) Contract Type: W2 Duration: 12 months with possible extension Pay Range: $105.00 - $120.00 per hour
#LP
Job Summary:
We are seeking a highly skilled Hardware Security Engineer IV with extensive experience in electrical engineering and hardware security for role which is fully onsite in Seattle, WA, US. This role involves collaboratively working on hardware security assessments for emerging devices, ensuring robust privacy and security protocols. The ideal candidate will bring a deep understanding of electrical engineering principles to spearhead our efforts in maintaining and enhancing the security of our devices and services.
Key Responsibilities:
Conduct thorough hardware security assessments and provide actionable insights.
Design, test, and analyze circuit designs and PCB layouts with an eye on security.
Develop and implement secure boot solutions and cryptography measures.
Collaborate with third-party manufacturers to update and secure device designs.
Utilize common electronics test equipment for testing, debugging, or hacking hardware.
Must-Have Skills:
5+ years of experience in hardware security, embedded systems security, or similar
Bachelor's degree in Electrical Engineering, Computer Engineering, Computer Science, or related technical field.
hands-on experience with common test equipment: Oscilloscopes, multimeters, microscopes, logic analyzers, soldering
Industry Experience:
Experience with manufacturing security processes, including secrets provisioning and secure production flows, is highly desirable.
Previous work in a team environment focusing on hardware security for telecom or consumer electronics industries.
ABOUT AKRAYA
Akraya is an award-winning IT staffing firm consistently recognized for our commitment to excellence and a thriving work environment. Most recently, we were recognized Inc's Best Workplaces 2024 and Silicon Valley's Best Places to Work by the San Francisco Business Journal (2024) and Glassdoor's Best Places to Work (2023 & 2022)!
Industry Leaders in IT Staffing
As staffing solutions providers for Fortune 100 companies, Akraya's industry recognitions solidify our leadership position in the IT staffing space. We don't just connect you with great jobs, we connect you with a workplace that inspires!
Join Akraya Today!
Let us lead you to your dream career and experience the Akraya difference. Browse our open positions and join our team!
Manual Ethical Hacker
Security engineer job in Seattle, WA
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day.
One of the keys to driving Responsible Growth is being a great place to work for our teammates around the world. We're devoted to being a diverse and inclusive workplace for everyone. We hire individuals with a broad range of backgrounds and experiences and invest heavily in our teammates and their families by offering competitive benefits to support their physical, emotional, and financial well-being.
Bank of America believes both in the importance of working together and offering flexibility to our employees. We use a multi-faceted approach for flexibility, depending on the various roles in our organization.
Working at Bank of America will give you a great career with opportunities to learn, grow and make an impact, along with the power to make a difference. Join us!
Job Description:
Manual Ethical Hacking is part of the Application Development Security Framework Program within Bank of America's Cyber Security Assurance Offensive Security group. The program provides services to assess the vulnerability of the bank's applications to malicious hacking activity.
This intermediate technical role is responsible for performing application security assessments of the bank's technologies, applications, and cyber security controls while adapting testing methods to evolving and emerging threats. Key responsibilities include performing research, understanding the bank's security policies, working with the appropriate partners to complete assessments and simulations, identifying misconfigurations and vulnerabilities, and reporting on associated risk. These individuals partner closely with security partners, CIO clients and multiples lines of business.
Key Responsibilities in order of importance:
* Perform assigned analysis of internal and external threats on information systems and predict future threat behavior
* Incorporate threat actors' tactics, techniques, and procedures into offensive security testing
* Perform assessments of the security, effectiveness, and practicality of multiple technology systems
* Leverage innovative thinking to help solve problems or introduce new ideas to processes or products applicable to offensive security.
* Prepare and present detailed technical information for various media including documents, reports, and notifications
* Provide clear and practical advice regarding managed risks
* Learn and develop advanced technical and leadership skills, Mentor Junior assessors in technical tradecraft and soft skills
Required Skills:
* Minimum of 4 years of professional pentesting, application security or ethical hacking experience, preferably in a large, complex, enterprise environment
* Detailed technical knowledge in at least 3 of the following areas: security engineering; application architecture; authentication and security protocols; application session management; applied cryptography; common communication protocols; mobile frameworks; single sign-on technologies; exploit automation platforms; RESTful web services
* SQL injection/XSS attack without the use of tools
* Experience performing manual code reviews for security relevant issues
* Experience working with SAST tools to identify vulnerabilities
* Able to manually identify and reproduce findings, discuss remediation concepts, develop PoCs for vulnerabilities, use scripting/coding techniques, proficiently execute common penetration testing tools, triage, and support incidents, and produce high value findings
* Experience performing manual web application assessments i.e., must be able to simulate a
* Knowledge of network and Web related protocols/technologies (e.g., UNIX/LINUX, TCP/IP, Cookies)
* Experience with vulnerability assessment tools and penetration testing techniques
* Solid programming/debugging skills
* Experience of using a variety of tools, included, but not limited to, IBM AppScan, Burp and SQL Map
* Threat Analysis
* Innovative Thinking
* Technology Systems Assessment
* Technical Documentation
* Advisory
Desired:
* CISSP, CEH, OSCP, OSWE, GPEN, PenTest+ or similar
* Strong programming/scripting skills
This job will be open and accepting applications for a minimum of seven days from the date it was posted.
Shift:
1st shift (United States of America)
Hours Per Week:
40
Enterprise Security Engineer
Security engineer job in Seattle, WA
About the Team
Within the OpenAI Security organization, our IT team works to ensure our team of researchers, engineers, and staff have the tools they need to work comfortably, securely, and with minimal interruptions. As an Enterprise Security Engineer, you will work in a highly technical and employee-focused environment.
Our IT team is a small and nimble team, where you'll have the opportunity to dive into a wide breadth of areas and build from the ground up. We're well supported and well resourced, and have a mandate to deliver a world-class enterprise security program to our teams.
About the Role
As an Enterprise Security Engineer, you will be responsible for implementing and managing the security of OpenAI's internal information systems' infrastructure and processes. You will work closely with our IT and Security teams to develop security capabilities, enforce security policies, and monitor internal systems for security threats.
This role is open to remote employees, or relocation assistance is available to Seattle.
In this role, you will:
Develop and implement security measures to protect our company's information assets against unauthorized access, disclosure, or misuse.
Monitor internal and external systems for security threats and respond to alerts.
Contribute to and enforce our company's IT and Security policies and procedures.
Work closely with our IT department to harden our infrastructure using best practices in AzureAD, GSuite, Github, and other SaaS tooling.
Advise our employees on best practices for maintaining the security of their endpoints, and office AV and network infrastructure.
Devise novel sharing controls and associated monitoring to protect company data, including intelligent groups management, Data Loss Prevention (DLP) and other security controls as appropriate.
Employ forward-thinking models like “secure by default” and “zero trust” to create sustainably secure environments for knowledge workers and developers.
Identify and remediate vulnerabilities in our internal systems, adhering to best practices for data security.
Use our own AI-driven models to develop systems for improved security detection and response, data classification, and other security-related tasks.
Educate employees on the importance of data security, and advise them on best practices for maintaining a secure environment.
Contribute to OpenAI's endpoint and cloud security roadmaps by staying up to date with the latest security threats, and making recommendations for improving our security posture.
You might thrive in this role if you have:
Experience in protecting and managing mac OS fleets.
Experience deploying and managing endpoint security solutions (e.g. management frameworks, EDR tools).
Experience with public cloud service providers (e.g. Amazon AWS, Microsoft Azure).
Experience with identity and access management frameworks and protocols, including SAML, OAUTH, and SCIM.
Experience with e-mail security protocols (e.g. SPF, DKIM, DMARC) and controls.
Intermediate or advanced proficiency with a scripting language (e.g. Python, Bash, or similar).
Knowledge of modern adversary tactics, techniques, and procedures.
Ability to empathize and collaborate with colleagues, independently manage and run projects, and prioritize efforts for risk reduction.
.
About OpenAI
OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.
We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.
For additional information, please see OpenAI's Affirmative Action and Equal Employment Opportunity Policy Statement.
Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.
To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance.
We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link.
OpenAI Global Applicant Privacy Policy
At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.
Auto-ApplyInformation Security Analyst
Security engineer job in Bellevue, WA
Aditi Staffing is an MBE certified, IT Staffing firm in the US offering contract, contract-to-hire & direct hire career opportunities with Fortune Firms. Recently recognized as one of the fastest growing staffing firms and top diversity firm by the Staffing Industry Analysts, Aditi Staffing has been a partner of choice for candidates and clients.
Visit our website: http://www.aditistaffing.com/
Job Description
Role: Information Security Analyst
Location: Information Security Analyst
6-8 years of experience in information security / technology or related field. Advanced verbal and communication skills with diverse cross functioning groups.
Strong background and experience in policy development, program administration. In depth knowledge and experience in incident response activities and compliance. Ability to plan, organize and prioritize tasks to complete independently and within time frame established.
While technical knowledge of information technology and security issues is highly desirable, technical expertise and resources will be available from units such as Security Operations to support the information security and privacy program.
Strong technical writing abilities. Very good understanding of security controls, control systems, and business drivers that impact security controls.
Knowledge of SEC, FFC, Sarbanes-Oxley (SOX) and or Gramm-Leach Bliley Act regulatory policies & guidelines.
Strong background in security authentication, security applications development methodologies, security architecture and operational procedures, organization, business continuity skills, disaster recovery skills, identity management skills and hands on experience implementing products / solutions e.g. NetIQ, Entrust, Netegrity, Oblix, PKI, and some director service, RSA, strong understanding of the development and maintenance of RBAC s (Role Based Access Controls).
Ability to work collaboratively with a broad range of constituencies essential. A demonstrated ability to work with diverse cross functional groups of people is required.
Good to Have:
Knowledge of the following technologies a plus: Intrusion Detection / Prevention Systems for networks and hosts Security Event Management Systems Vulnerability Assessment Systems
Secure transfer protocols such as SSH, SCP and Connect Direct Secure Plus Diagnostic tools such as packet capture/decode and WAN probes IP Networking Windows Systems administration and security tools
Experience with remote access, terminal servers, etc a plus Experience in the administration of UNIX Solaris, HP/UX, or Linux and Windows operating systems a plus
Experience in developing and administering an information security program desirable
Working knowledge of and experience in the policy and regulatory environment of information security, especially in higher education is desirable
Additional Information
Regards,
Arun Kumar R
arunkr(AT)aditistaffing.com
D: 425-457-7916
Senior Security Platform Engineer
Security engineer job in Bellevue, WA
About the Role
We are seeking a highly skilled and motivated Senior Security Platform Engineer to join our Edge Team. In this role, you will be responsible for securing our cloud and edge computing environments, with a focus on our Galleon mobile data centers and their integration with our Commander cloud platform. You will play a crucial role in designing, implementing, and managing security controls across our infrastructure, ensuring the confidentiality, integrity, and availability of our systems and data
Responsibilities:
Design, implement, and manage security controls across our cloud platforms (AWS, Azure, GCP), Kubernetes environments, and Galleon mobile data centers, ensuring secure deployment practices and platform security for microservices and APIs
Integrate security components within our CI/CD pipelines, including automated security testing (SAST, DAST, container image scanning), vulnerability scanning, and compliance checks. Ensure that security is embedded throughout the software development lifecycle
Define and implement security configurations for infrastructure, including Kubernetes, using IaC tools (Terraform, Ansible) to ensure consistent enforcement of security policies
Monitor and respond to security events, develop and maintain security monitoring tools, and participate in incident response activities
Architect and implement security solutions that protect our cloud-native, hybrid, and on-premises infrastructure, including our Galleon data centers. Conduct security architecture reviews, threat modeling, and risk assessments to identify and mitigate vulnerabilities
Partner with engineering teams to integrate security tooling into the SDLC, enabling DevSecOps adoption and fostering a culture of shared security responsibility
Ensure compliance with relevant security standards and regulations (e.g., SOC 2, ISO 27001) through regular audits and implementing necessary controls. Stay up-to-date with cybersecurity threats, trends, and industry standards
Data Center Security Responsibilities:
Implement robust perimeter security for Galleon data centers, including physical access controls, intrusion detection systems, and video surveillance
Design and implement network segmentation within data centers to isolate critical systems and limit the impact of security breaches
Utilize micro-segmentation techniques to enforce security policies at the workload level, controlling communication between individual applications and services
Implement data loss prevention (DLP) solutions to prevent sensitive data from leaving the data center environment
Securely manage and store cryptographic keys used for encryption and authentication within the data center
Implement robust logging and monitoring systems to track security-related events and detect anomalies
Regularly conduct vulnerability assessments and penetration testing to identify and remediate security weaknesses
Develop and maintain incident response plans specific to data center security incidents
Qualifications:
7+ years of experience in security engineering, with a focus on cloud-native technologies, distributed systems, and edge computing, including securing Kubernetes environments
Strong understanding of security best practices across the SDLC, including secure coding principles, threat modeling, and vulnerability management
Experience securing cloud platforms (AWS, Azure, GCP) and Kubernetes environments, including implementing RBAC, network policies, and container security
Proficiency in scripting and automation (Python, Bash, Go) for security tooling and infrastructure-as-code (Terraform, Ansible)
Experience with security monitoring, threat detection, and incident response in cloud and containerized environments
Excellent communication and collaboration skills, with the ability to work effectively with engineering teams and advocate for security best practices
Bachelor's degree in a relevant field or equivalent practical experience
Why Join Armada?
Be part of a team building the future of distributed computing and AI, impacting our innovative Galleon data center deployments and their integration with Commander
Work with the latest technologies in edge computing, mobile data centers, AI infrastructure, and cloud integration
We are a rapidly growing company with ample opportunities for advancement
Work with talented and passionate individuals dedicated to pushing boundaries
We offer competitive compensation and benefits, including health insurance
Equal Opportunity Statement
At Armada, we are committed to fostering a work environment where everyone is given equal opportunities to thrive. As an equal opportunity employer, we strictly prohibit discrimination or harassment based on race, color, gender, religion, sexual orientation, national origin, disability, genetic information, pregnancy, or any other characteristic protected by law. This policy applies to all employment decisions, including hiring, promotions, and compensation. Our hiring is guided by qualifications, merit, and the business needs at the time.
Compensation & Benefits
For U.S. Based candidates: To ensure fairness and transparency, the
starting
base salary range for this role for candidates in the U.S. are listed below, varying based on location experience, skills, and qualifications. In addition to base salary, this role will also be offered equity and subsidized benefits
(details available upon request)
.