Post job

Security engineer jobs in Minot, ND

- 50 jobs
All
Security Engineer
Information Security Engineer
Information Security Analyst
Information Security Officer
Senior Information Security Engineer
Manager, Network & Security
Information Systems Security Officer
Senior Security Analyst
  • Information Systems Security Officer

    Clearancejobs

    Security engineer job in Grand Forks, ND

    Information Systems Security officer (ISSO) Full-time, Onsite (Grand Forks, ND) An active Top Secret security clearance is a must to apply! ClearanceJobs is currently partnering with a rapidly growing aerospace company to assist in hiring an Information Systems Security officer (ISSO) to facilitate A&A (Authorization & Assessment) efforts throughout mission systems' RMF lifecycle on a full-time, permanent basis. The ideal candidate will have experience working as an ISSO or security relevant field and must be comfortable operating independently. The selected candidate will be able to speak directly with customers with little to no Information System Security Managers (ISSM) involvement and be the face of security for their selected boundaries. REQUIRED QUALIFICATIONS Experience developing and documenting DoD Assessment and Authorization documentation Knowledge of CNSSI 1253, NIST 800 Series (primarily 800-53, 800-53A, 800-171), RMF 2-5 + years of IA/Cyber Security experience Bachelor's degree or higher in Computer Science or Security Security+/CISM certification or equivalent Experience with DCSA tools such as eMASS, STIGs and SCAP PREFERRED QUALIFICATIONS Well versed with RMF package creation and maintenance artifacts to support A&A decision Experience using DISA Security Technical Implementation Guides (STIGs), Security Requirements Guide (SRGs) and Security Content Automation Protocol (SCAP) to audit and securely configure network-enabled devices Fundamental knowledge of DISA Enterprise Mission Assurance Support Service (eMASS) Proficient with vulnerability tools and audit review tools which include audit log analysis and report generation (Nessus and Splunk experience preferred) Experience conducting risk analysis on products and system components through review of CVEs, plugins, CWEs Experience in conducting software due diligence with COTS and GOTS solutions Strong communication and documentation skills Flexible and able to adapt to a rapidly changing environment Positive, self-motivated individual who can complete tasks independently Working knowledge of system functions, security policies, technical security safeguards, and operational security measures. RESPONSIBILITIES Lead supporting multiple RMF accreditation efforts and will perform tasks that include determining DoD requirements, hardware/software configuration management (to include baseline configuration), risk assessments/vulnerability assessments, testing and documenting security controls, and ensuring overall compliance with DoD Cybersecurity policies. Oversee day-today operations required to perform RMF Manage tasks and create deadlines to meet security requirements Be forward facing for customer interactions which will translate into system requirements Spearhead building RMF packages within eMASS and perform continuous monitoring for the full duration of the information system lifecycle Implement the Risk Management (RMF) process throughout the entire A&A lifecycle of the system(s) or multiple ATOs across different locations, supporting all efforts pre and post Authority to Operate (ATO) determination Assist the ISSM in meeting their duties to support A&A activities and coordinate with system's Security Controls Assessor (SCA) and Authorizing Official (AO) Perform and review technical security assessments of the system(s) to identify points of vulnerability, non-compliance with established cybersecurity standards and regulations, and recommend mitigation strategies to maintain operational security posture for the boundary systems Conduct risk analyses from vulnerability, compliance scans, penetration testing results, and/or other audit activities Create and maintain Plan of Action and Milestones (POA&Ms), System Security Plans (SSPs), Security Control Traceability Matrices (SCTMs), Standard Operating Procedures (SOPs), Configuration Management Plans, Contingency Plans and Test Result/Security Impact Analyses Ensure approved procedures are in place for clearing, sanitizing, and destroying various types of hardware and media Conduct continuous monitoring (ConMon) activities for applicable authorization boundaries Apply and maintain up to date application of Security Technical Implementation Guides (STIGs) to required components of the information systems Maintain inventory and asset configuration to include change management documentation Lead System level change request through formalized Configuration Control boards (CCB) Ensure that the appropriate operational security posture is maintained for the information system, working in close collaboration with the information system owner and the ISSM Notify ISSM when changes occur that might affect the authorization determination of the information system(s) Experience in advising System Administrators and Network Administrator to Remediate system decencies Report all security-related concerns and incidents to the ISSM Able to also handle security concerns in lieu of ISSM to advise on security concerns IAW system procedures Benefits In addition to compensation, a comprehensive benefits package including medical, dental, and vision insurance along with PTO and a 401K.
    $66k-87k yearly est. 3d ago
  • Principal Security Engineer

    Oracle 4.6company rating

    Security engineer job in Bismarck, ND

    1. Nashville, TN 2. Austin, TX 3. Ireland 4. United Kingdom Security Architecture is comprised of security experts who are focused and specialized in securing all aspects of OCI Cloud. As security experts, we are sought out by our partner engineering organizations to provide guidance on designing their products, services and features. We set OCI wide security standards and hold a high security requirement bar for all services to ensure the highest level of security to our customers. We are currently looking for a highly motivated security engineer with expertise in Cloud security to join our team. This candidate would be involved in architecture, design, prototyping and development of the security aspects of Oracle Cloud's products and services. You should be a security-minded leader who can work with architects and/or a development team as they design new capabilities to ensure that security requirements are set and the design implements the necessary controls to increase security posture for the service. As a member of the Security Architecture team, you will be required to have a firm grasp on security technologies, trends in cloud security practices, and ability to communicate complex technical security requirements clearly to the development teams, risk assessment, risk mitigation and security tools/automation. **Responsibilities** Key responsibilities: + Conduct threat modeling, security architecture reviews, risk assessment and provide guidance on mitigating the identified issues. + Create and maintain technical security standards and patterns and set the benchmark for AI security requirement bar at OCI. + Stay up-to-date on the latest advancements in AI technologies and apply them to improve OCI's security posture. + Provide expert security guidance to service teams to ensure their products, services and feature are secure by default. + Lead OCI-wide cloud security initiatives to enhance overall cloud security posture. + Provide mentorship to junior engineers on the team. Qualifications: + A minimum of 8+ years of experience with at least 5+ years in Cloud Security required and 2+ years in AI and ML is good to have. + Or a BS or MS in Computer Science/Engineering with a focus on AI/Security, or a related field with a minimum of 8 years of experience in the field is required. + Experience in architecture, design, deployment, and handling of standard security practices and policies is required. Preferred qualifications includes, + A strong background in AI, machine learning, and deep learning. + Experience in applying AI technology to security domain. + Experience as a security leader for a cloud product or set of cloud services, with expertise in IaaS, PaaS. + Experience with architecture security reviews for products or services operating in a cloud environment, especially those which are reliant on homegrown or third-party LLMs and APIs is a plus. + Expertise in concepts of Multi-tenancy, Cloud Security and Virtualization, Access Management, OAuth, Cloud SSO, Identity Provisioning, Identity Governance etc. + Expertise in Encryption, Key management, Cybersecurity fundamentals (e.g., access controls, common software vulnerabilities, and security best practices), Deployment Methodologies, and Security Standards Compliance Certification (STIG, FedRAMP, PCI-DSS), etc. + Very good understanding of concepts related to Docker, Container, Serverless Computing, and Kubernetes. + Ability to design large scalable systems for cloud customers with focus on security. + Network security, VPN/Firewalls and software-defined networking experience is a plus. + Experience operating within and supporting a security assurance and assessment program + Excellent written and verbal communication skills, strong analytical and problem-solving skills. Disclaimer: **Certain US customer or client-facing roles may be required to comply with applicable requirements, such as immunization and occupational health mandates.** **Range and benefit information provided in this posting are specific to the stated locations only** US: Hiring Range in USD from: $106,300 to $223,400 per annum. May be eligible for bonus and equity. Oracle maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect Oracle's differing products, industries and lines of business. Candidates are typically placed into the range based on the preceding factors as well as internal peer equity. Oracle US offers a comprehensive benefits package which includes the following: 1. Medical, dental, and vision insurance, including expert medical opinion 2. Short term disability and long term disability 3. Life insurance and AD&D 4. Supplemental life insurance (Employee/Spouse/Child) 5. Health care and dependent care Flexible Spending Accounts 6. Pre-tax commuter and parking benefits 7. 401(k) Savings and Investment Plan with company match 8. Paid time off: Flexible Vacation is provided to all eligible employees assigned to a salaried (non-overtime eligible) position. Accrued Vacation is provided to all other employees eligible for vacation benefits. For employees working at least 35 hours per week, the vacation accrual rate is 13 days annually for the first three years of employment and 18 days annually for subsequent years of employment. Vacation accrual is prorated for employees working between 20 and 34 hours per week. Employees working fewer than 20 hours per week are not eligible for vacation. 9. 11 paid holidays 10. Paid sick leave: 72 hours of paid sick leave upon date of hire. Refreshes each calendar year. Unused balance will carry over each year up to a maximum cap of 112 hours. 11. Paid parental leave 12. Adoption assistance 13. Employee Stock Purchase Plan 14. Financial planning and group legal 15. Voluntary benefits including auto, homeowner and pet insurance The role will generally accept applications for at least three calendar days from the posting date or as long as the job remains posted. Career Level - IC4 **About Us** As a world leader in cloud solutions, Oracle uses tomorrow's technology to tackle today's challenges. We've partnered with industry-leaders in almost every sector-and continue to thrive after 40+ years of change by operating with integrity. We know that true innovation starts when everyone is empowered to contribute. That's why we're committed to growing an inclusive workforce that promotes opportunities for all. Oracle careers open the door to global opportunities where work-life balance flourishes. We offer competitive benefits based on parity and consistency and support our people with flexible medical, life insurance, and retirement options. We also encourage employees to give back to their communities through our volunteer programs. We're committed to including people with disabilities at all stages of the employment process. If you require accessibility assistance or accommodation for a disability at any point, let us know by emailing accommodation-request_************* or by calling *************** in the United States. Oracle is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans' status, or any other characteristic protected by law. Oracle will consider for employment qualified applicants with arrest and conviction records pursuant to applicable law.
    $106.3k-223.4k yearly 48d ago
  • Product Security Engineer, Instagram

    Meta 4.8company rating

    Security engineer job in Bismarck, ND

    The Instagram Security Ecosystems team is seeking a product-focused security engineer interesting in enabling Instagram product teams to develop features with a focus on security and user safety. You will be relied upon to directly work with Instagram engineers, hardening both product features and our protective frameworks that make life harder for bad actors on the Instagram platform. **Required Skills:** Product Security Engineer, Instagram Responsibilities: 1. Threat Modeling and Security Architecture: Work directly with product managers and technical leads on threat models and security architecture for novel Instagram features or products 2. Security Reviews: Perform manual design and implementation reviews of web, mobile, and native code 3. Developer Guidance: Provide guidance and education to developers that help prevent the authoring of vulnerabilities 4. Automated Analysis and Secure Frameworks: Work with other security teams to improve Instagram's static and dynamic analysis and frameworks to scale coverage 5. Bug Bounty: Help provide technical guidance to our world class bug bounty program and independent security researchers 6. Industry Impact: Push the industry forward through conference talks and open source projects to contribute broadly to security for the world **Minimum Qualifications:** Minimum Qualifications: 7. B.S. or M.S. in Computer Science, Cybersecurity, or related field, or equivalent experience 8. 8+ years of experience finding vulnerabilities in interpreted languages (Python, PHP) 9. Extensive, proven experience in threat modeling and secure systems design 10. Experience with exploiting common security vulnerabilities **Preferred Qualifications:** Preferred Qualifications: 11. Product software engineering or product management experience 12. Experience in security consulting or other leadership-facing security advisory roles 13. Familiarity with cybersecurity investigations, abuse operations, and/or security incident response 14. Contributions to the security community (public research, blogging, presentations, bug bounty, etc.) **Public Compensation:** $177,000/year to $251,000/year + bonus + equity + benefits **Industry:** Internet **Equal Opportunity:** Meta is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Meta participates in the E-Verify program in certain locations, as required by law. Please note that Meta may leverage artificial intelligence and machine learning technologies in connection with applications for employment. Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at accommodations-ext@fb.com.
    $177k-251k yearly 60d+ ago
  • Lead Adversarial Security Engineer

    Trellix 4.1company rating

    Security engineer job in Bismarck, ND

    **_Job Title:_** Lead Adversarial Security Engineer **About** **Trellix:** **Trellix, the trusted CISO ally, is redefining the future of cybersecurity and soulful work.** Our comprehensive, GenAI-powered platform helps organizations confronted by today's most advanced threats gain confidence in the protection and resilience of their operations. Along with an extensive partner ecosystem, we accelerate technology innovation through artificial intelligence, automation, and analytics to empower over 53,000 customers with responsibly architected security solutions. We also recognize the importance of closing the 4-million-person cybersecurity talent gap. We aim to create a home for anyone seeking a meaningful future in cybersecurity and look for candidates across industries to join us in soulful work. More at ************************ . **_Role Overview:_** Trellix is seeking an Adversarial Security Engineer to lead the evolution of its cybersecurity posture. This is a senior, hands-on, remote-first role for a red/blue/purple expert who possesses a valuable blend of offensive tradecraft and defensive-engineering skills. **Role Overview:** As a lead member of the security operations team, and reporting to the Deputy CISO the mission of this role is to bridge the gap between "what if" and "what is" to continuously test the organization's defenses, find gaps, and personally lead the engineering effort to close them. By collaborating with the Security Operations Center (SOC), Threat Intelligence, and infrastructure teams, this expert will act as a force multiplier, mentoring junior security operations staff and providing the technical leadership to measurably improve the ability to detect and respond to advanced threats. **About the role:** + Plan and execute sophisticated, end-to-end red team engagements against our on-premise and cloud infrastructure. + Develop and validate new detection logic, transforming the results of your own attacks into high-fidelity alerts. + Lead continuous purple team exercises, acting as the primary bridge between the SOC, Threat Intelligence, and Detection Engineering teams. + Leverage Attack Surface Management (ASM) data to find "Shadow IT" and prioritize your offensive operations based on the most likely and impactful attack vectors. + Act as a senior technical leader, mentoring SOC analysts and junior engineers on advanced attack chains, detection theory, and defensive best practices. + Communicate complex findings and remediation strategies to a wide range of stakeholders, from highly technical engineers to executive leadership. **About you:** + You have a blended career path of 7+ years, demonstrating experience in both offensive security (like Red Teaming) and defensive operations (like Detection Engineering or Threat Hunting). + You possess exceptional communication skills, with an ability to create reports and presentations for both highly technical and executive audiences. + You are a U.S. citizen. + Your technical expertise is built on a deep, practical understanding of frameworks like MITRE ATT&CK and the Diamond Model. + You have proficiency in modern offensive tools and C2 frameworks (e.g., Cobalt Strike, Metasploit) and/or experience developing custom attack methods to evade EDR and network controls. + You are proficient in writing, tuning, and validating detection logic in SIEM and EDR platforms. + Your knowledge of automation is clear from your proficiency in any scripting languages such as Python or PowerShell. + You have practical experience assessing and defending modern cloud environments. + You may hold advanced offensive (e.g., OSCP, OSEP, GXPN) or defensive (e.g., GCIH, GDAT) certifications. + You may contribute to the community through public-facing research, conference talks, or open-source tools. **_Company Benefits and Perks:_** We believe that the best solutions are developed by teams who embrace each other's unique experiences, skills, and abilities. We work hard to create a dynamic workforce where we encourage everyone to bring their authentic selves to work every day. We offer a variety of social programs, flexible work hours and family-friendly benefits to all of our employees. + Retirement Plans + Medical, Dental and Vision Coverage + Paid Time Off + Paid Parental Leave + Support for Community Involvement We're serious about our commitment to a workplace where everyone can thrive and contribute to our industry-leading products and customer support, which is why we prohibit discrimination and harassment based on race, color, religion, gender, national origin, age, disability, veteran status, marital status, pregnancy, gender expression or identity, sexual orientation or any other legally protected status.
    $75k-97k yearly est. 28d ago
  • Offensive Security Engineer, Assessments (Web3)

    Coinbase 4.2company rating

    Security engineer job in Bismarck, ND

    Ready to be pushed beyond what you think you're capable of? At Coinbase, our mission is to increase economic freedom in the world. It's a massive, ambitious opportunity that demands the best of us, every day, as we build the emerging onchain platform - and with it, the future global financial system. To achieve our mission, we're seeking a very specific candidate. We want someone who is passionate about our mission and who believes in the power of crypto and blockchain technology to update the financial system. We want someone who is eager to leave their mark on the world, who relishes the pressure and privilege of working with high caliber colleagues, and who actively seeks feedback to keep leveling up. We want someone who will run towards, not away from, solving the company's hardest problems. Our ******************************** is intense and isn't for everyone. But if you want to build the future alongside others who excel in their disciplines and expect the same from you, there's no better place to be. While many roles at Coinbase are remote-first, we are not remote-only. In-person participation is required throughout the year. Team and company-wide offsites are held multiple times annually to foster collaboration, connection, and alignment. Attendance is expected and fully supported. The Application Security organization at Coinbase is seeking to hire an experienced Offensive Security Engineer specializing in Web3 penetration testing and Web3 bug bounty program management and optimization. In this role, you will collaborate with the Bug Bounty Program Lead to drive Web3 bug bounty triage, validation, and strategic initiatives aimed at increasing program efficiency, maturity, and hacker engagement. You will work closely with whitehat hackers, security engineers, and cross-functional teams to enhance Coinbase's security posture through an effective bug bounty program. Additionally, you will perform penetration tests on Web3 technologies and applications, ensuring the security of Coinbase's blockchain-based products and services. *What you'll be doing (ie. job duties):* * Conduct security assessments of Web3 products and services, including smart contracts, DeFi protocols, and blockchain infrastructure. * Collaborate with partner teams to enhance detection and response capabilities for Web3 vulnerabilities. * Stay informed on emerging security trends, advisories, and academic research in the Web3 space. * Lead Web3 bug bounty triage and validation, ensuring timely and accurate assessments of reported vulnerabilities. * Develop and implement strategies to incentivize high-quality bug bounty submissions and engage with the hacker community. * Manage the Web3 bug bounty program, including scope updates, researcher communication, and payout disbursements. * Analyze bug bounty data to identify trends, common vulnerabilities, and areas for improvement. * Collaborate with engineering teams to prioritize and remediate vulnerabilities identified through the bug bounty program. * Mentor and train junior security engineers in Web3 bug bounty triage and analysis. * Provide on-call support for critical Web3 bug bounty-related incidents. * Document and report on Web3 bug bounty metrics and program effectiveness. *What we look for in you (ie. job requirements):* * Bachelor's or Master's degree in Computer Science, Cybersecurity, Software Engineering, or a related field. * 3+ years of experience in Web3 application security and penetration testing. * Proven track record of identifying critical vulnerabilities across the blockchain protocol stack, Web2, and Web3 components. * Extensive knowledge of the blockchain ecosystem, including L1/L2 networks, DeFi protocols, and staking mechanisms. * Deep understanding of Web2 security concepts and common vulnerabilities (e.g., OWASP Top 10, SANS Top 25). * Strong analytical skills to identify trends and patterns in vulnerabilities. * Excellent communication skills for engaging with internal teams. * Passion for security and a drive to improve Web3 security posture. * Ability to work independently and take ownership of penetration testing initiatives. * Energy and self-drive for continuous learning in the rapidly evolving crypto space. * Excellence in clear, direct, and kind communication with technical and non-technical stakeholders. * Experience building relationships with product, engineering, and security teams. *Nice to haves:* * Participation in CTFs, bug bounty programs, or open-source security research. * Expertise in Application Security, Network Security, or Cloud Security. * Relevant security certifications (e.g., OSCP, GPEN). * Experience developing and implementing security tooling to support bug bounty triage and analysis. * Experience with bug bounty programs and platforms, including triage, validation, and researcher communication. * Strong analytical skills to identify trends and patterns in bug bounty submissions. * Excellent communication skills to effectively engage with bug bounty researchers. Position ID: P69494 \#LI-remote *Pay Transparency Notice:* Depending on your work location, the target annual salary for this position can range as detailed below. Full time offers from Coinbase also include bonus eligibility + equity eligibility**+ benefits (including medical, dental, vision and 401(k)). Pay Range: $152,405-$179,300 USD Please be advised that each candidate may submit a maximum of four applications within any 30-day period. We encourage you to carefully evaluate how your skills and interests align with Coinbase's roles before applying. Commitment to Equal Opportunity Coinbase is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, sex, gender expression or identity, sexual orientation or any other basis protected by applicable law. Coinbase will also consider for employment qualified applicants with criminal histories in a manner consistent with applicable federal, state and local law. For US applicants, you may view the *********************************************** in certain locations, as required by law. Coinbase is also committed to providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please contact us at accommodations*********************************** *Global Data Privacy Notice for Job Candidates and Applicants* Depending on your location, the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) may regulate the way we manage the data of job applicants. Our full notice outlining how data will be processed as part of the application procedure for applicable locations is available ********************************************************** By submitting your application, you are agreeing to our use and processing of your data as required. *AI Disclosure* For select roles, Coinbase is piloting an AI tool based on machine learning technologies to conduct initial screening interviews to qualified applicants. The tool simulates realistic interview scenarios and engages in dynamic conversation. A human recruiter will review your interview responses, provided in the form of a voice recording and/or transcript, to assess them against the qualifications and characteristics outlined in the job description. For select roles, Coinbase is also piloting an AI interview intelligence platform to transcribe and summarize interview notes, allowing our interviewers to fully focus on you as the candidate. *The above pilots are for testing purposes and Coinbase will not use AI to make decisions impacting employment*. To request a reasonable accommodation due to disability, please contact accommodations[at]coinbase.com
    $152.4k-179.3k yearly 60d+ ago
  • Senior Information Security Operations Engineer

    Sanford Health 4.2company rating

    Security engineer job in Fargo, ND

    **Careers With Purpose** **Sanford Health is one of the largest and fastest-growing not-for-profit health systems in the United States. We're proud to offer many development and advancement opportunities to our nearly 50,000 members of the Sanford Family who are dedicated to the work of health and healing across our broad footprint.** **Facility:** 501 Place Bldg **Location:** Fargo, ND **Address:** 501 4th St N, Fargo, ND 58102, USA **Shift:** 8 Hours - Day Shifts **Job Schedule:** Full time **Weekly Hours:** 40.00 **Salary Range:** $43.00 - $71.00 **Pay Info:** Pay starts at $43 and increases according to years of applicable experience. **Department Details** Lead day-to-day vulnerability operations (scan scheduling, authenticated coverage, agent health) and engineer improvements across tooling workflows. Develop and mature the Vulnerability Management program: define SLAs, priorities, exception guardrails, and reporting; design playbooks for zero-day/KEV response. Drive remediation campaigns with asset owners; convert findings into work items with clear scope, owners, and due dates; track to closure. Partner with Technology Solutions teams to reduce exposure footprint (consult on configuration baselines, conditional access, system hardening). Produce executive metrics and service reporting (exposure trends, SLA compliance, coverage, time-to-remediate). Project management exposure preferred (owning cross-team initiatives, roadmaps, and deliverables). **Job Summary** Responsible for the technical and operational delivery of enterprise cybersecurity; focusing on the development and implementation of processes and tools that support Vulnerability Management threat prevention, threat hunting, vulnerability assessments, and incident response. Also responsible for minimizing identified threats and risks to the organization through collaboration with other Information Security and Sanford technological groups. Perform and coordinate, with other team members, real-time and forensic log and EDR monitoring and analysis to provide network, data, and asset security for Sanford Health. Complete, configure, and tune vulnerability assessments and report results to application and asset owners. Provide consulting services to owners relating to response activities. Perform, lead, and coordinate on Incident Response activities including the collection, preservation, and interpretation of digital evidence. Build, administer, and support the IS Vulnerability Management tools, processes, and services. Identify and complete improvements and metrics to Vulnerability Management processes and services. Manage the IS Vulnerability Management ticket queue. Prioritize and complete tickets according to impact to Sanford Health business functions. Provide security consulting services to other Sanford Health groups. Mentor other Vulnerability Management team members on tools, processes, and Sanford Health areas. Coordinate and participate in activities with other IT Security groups by providing aid and consulting when needed. Works under limited guidance due to previous experience/breadth of knowledge of processes and organizational knowledge. Acts independently to determine methods and procedures on new assignments. Regularly presented with new assignments and projects that require the application of independent judgement/interpretation of policies/practices. Checks own work and the work of other team members. **Qualifications** Bachelor's degree required, in lieu of education, leadership may consider an Associates degree plus 3 years of applicable experience in computer science, cyber security or an information technology related field. Minimum of 4 years' experience working in Cyber Security required. Advanced security training is desired. Strong working knowledge of the information security standards and procedures including HIPAA and PCI. Security Certifications are desired. **Benefits** Sanford Health offers an attractive benefits package for qualifying full-time and part-time employees. Depending on eligibility, a variety of benefits include health insurance, dental insurance, vision insurance, life insurance, a 401(k) retirement plan, work/life balance benefits, and a generous time off package to maintain a healthy home-work balance. For more information about Total Rewards, visit *********************************** . Sanford is an EEO/AA Employer M/F/Disability/Vet. If you are an individual with a disability and would like to request an accommodation for help with your online application, please call ************** or send an email to ************************ . Sanford Health has a Drug Free Workplace Policy. An accepted offer will require a drug screen and pre-employment background screening as a condition of employment. **Req Number:** R-0232476 **Job Function:** Information Technology **Featured:** No
    $43-71 hourly 60d+ ago
  • Engineer, Information Security and Risk

    Cardinal Health 4.4company rating

    Security engineer job in Bismarck, ND

    Cardinal Health, Inc. (NYSE: CAH) is a global healthcare services and products company. We provide customized solutions for hospitals, healthcare systems, pharmacies, ambulatory surgery centers, clinical laboratories, physician offices and patients in the home. We are a distributor of pharmaceuticals and specialty products; a global manufacturer and distributor of medical and laboratory products; an operator of nuclear pharmacies and manufacturing facilities; and a provider of performance and data solutions. Working to be healthcare's most trusted partner, our customer-centric focus drives continuous improvement and leads to innovative solutions that improve the lives of people every day. With approximately 50,000 employees worldwide, Cardinal Health ranks among the top fifteen in the Fortune 500. **_Department Overview:_** **Information Technology** oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value. **Information Security and Risk** develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure, or destruction. This job family develops system back-up and disaster recovery plans, conducts incident responses, threat management, vulnerability scanning, virus management and intrusion detection as well as completes risk assessments. We are seeking a highly skilled and experienced Identity and Access Management (IAM) Engineer to join our team. In this pivotal role, you will be instrumental in designing, implementing, and managing IAM solutions that secure our enterprise applications and facilitate the secure, efficient, and seamless integration of identity and access systems in context of our rapid growth through Mergers and Acquisitions. You will ensure robust access controls, streamline user experiences, and maintain operational continuity across our diverse IT landscape. The ideal candidate will have deep technical expertise in modern IAM principles, protocols and products along with strong management and communication skills. **Responsibilities:** + **Application Integration Leadership:** Lead the integration of various enterprise applications (SaaS, on-premise, custom-built) with our core IAM infrastructure, ensuring secure authentication, authorization, and user provisioning/de-provisioning. + **M&A Integration Strategy & Execution:** Lead the planning, design, and execution of IAM integration strategies for M&A activities, ensuring alignment with overall business and security objectives. This includes assessing the IAM landscapes of merging entities to identify challenges and solutions. + **Identity System Merging & Consolidation:** Manage the complex process of merging disparate identity providers, user directories (e.g., Active Directory, Azure AD, LDAP), and access management systems from acquired companies into the existing infrastructure. + **User Lifecycle Management:** Streamline and automate user provisioning, de-provisioning, and periodic access reviews for employees, contractors, and partners across all integrated systems, ensuring smooth onboarding and offboarding during M&A transitions. + **Solution Design & Implementation:** Design, implement, and maintain IAM solutions including Single Sign-On (SSO), Multi-Factor Authentication (MFA), Privileged Access Management (PAM), and Role-Based Access Control (RBAC) frameworks. + **Security & Compliance:** Ensure IAM systems and processes comply with regulatory requirements (e.g., GDPR, HIPAA, SOX) and internal security policies, providing auditable records of access activities. Protect against data breaches by ensuring only authorized personnel can access sensitive information. + **Technical Troubleshooting & Support:** Troubleshoot, identify, and resolve technical identity and access management-related issues, providing expert support to internal teams and end-users during and after integration. + **Collaboration & Communication:** Coordinate cross-functional teams, including Information Security, IT Operations, HR, and Application Development, to ensure effective IAM implementation and seamless integration with business processes. Communicate complex security concepts to technical and non-technical stakeholders. + **Documentation & Best Practices:** Develop, review, and maintain comprehensive technical documentation, including architecture diagrams, configuration guides, and operational procedures. Stay up-to-date with IAM best practices, regulatory requirements, and security trends. **Qualifications:** + **Education:** Bachelor's degree in Computer Science, Information Technology, Information Security, or a related field, or equivalent practical experience. + **Experience:** 5+ years of progressive experience as an IAM Engineer, designing and implementing enterprise scale solutions with significant experience in supporting M&A integration projects preferred. + **Technical Expertise:** + Proficiency in directory services (e.g., Active Directory, Azure AD, LDAP). + Extensive knowledge and experience with authentication standards and technologies such as SSO (SAML, OAuth, OpenID Connect), MFA, and privileged access management (PAM). + Hands-on experience with leading IAM platforms (e.g., Okta, Microsoft Azure AD, CyberArk, ForgeRock, Ping Identity, SailPoint). + Experience with scripting languages (e.g., PowerShell, Python) for automation and integration. + Strong understanding of security principles, risk management, and access control models (e.g., RBAC). + Understanding of DevOps practices. + Familiarity with Zero Trust architecture principles. + Familiarity with AI/ML concepts and their practical application in security and risk management, especially in IAM context. + **M&A Specific Skills:** Proven track record of managing complex integration projects, including assessing existing IAM capabilities, workflow, systems, and processes of acquired entities. Ability to navigate the complexities of integrating diverse identity infrastructures. + Strong communication and interpersonal skills to collaborate effectively with various teams and stakeholders. + Detail-oriented mindset to ensure precise access control configurations and compliance. + Excellent problem-solving and analytical abilities to troubleshoot access issues and design solutions for unique business requirements + Must be a self-starter who takes full ownership of projects from inception to completion , holding oneself accountable for the security and operation integrity of IAM platform. + Ability to manage multiple priorities and meet tight deadlines in a fast-paced M&A environment. + Adaptability to stay ahead of evolving IAM technologies and security threats. **Anticipated salary range:** $94,900 - $135,600 **Bonus eligible:** No **Benefits:** Cardinal Health offers a wide variety of benefits and programs to support health and well-being. + Medical, dental and vision coverage + Paid time off plan + Health savings account (HSA) + 401k savings plan + Access to wages before pay day with my FlexPay + Flexible spending accounts (FSAs) + Short- and long-term disability coverage + Work-Life resources + Paid parental leave + Healthy lifestyle programs **Application window anticipated to close:** 12/20/2025 *if interested in opportunity, please submit application as soon as possible. The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity. _Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply._ _Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal_ _Opportunity/Affirmative_ _Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law._ _To read and review this privacy notice click_ here (***************************************************************************************************************************
    $94.9k-135.6k yearly 28d ago
  • Information Security Analyst

    Bravera Careers

    Security engineer job in Bismarck, ND

    Bravera is hiring for an Information Security Analyst at any Bravera Bank location (MT, ND or MN). The Information Security Analyst supports the Information Security Officer (ISO) in safeguarding the bank's information assets by assisting in the development, implementation, and monitoring of security policies, procedures, and controls. This role is critical in helping maintain the confidentiality, integrity, and availability of the bank's information systems and data. In addition, this position will assist with performing audits for Bravera Holdings Corp. & Subsidiaries, remaining independent and objective while assessing compliance with controls, policies/procedures, and regulations. MEASURES OF SUCCESS: Contribution to successful regulatory or external audit outcomes. Security awareness training to prevent cybersecurity incidents. Attention to detail Strong Communication - written and verbal Willingness to learn, work independently, and ask questions DUTIES AND RESPONSIBILITIES: Assist the ISO in implementing and maintaining the bank's information security program. This includes Information Security, Information Systems, Access Control, Incident Response Plan and Vendor Management Program. Assist with vendor risk assessments and third-party due diligence. (includes vendor risk assessment, due diligence, ongoing monitoring, proper documentation and reporting, and contracts) Ensure appropriate administrative, physical, and technical safeguards are in place to protect information assets from internal and external threats. Information Security Monitoring (Firewall, core system, internet banking platforms, etc.) Coordinate phishing simulations, security awareness campaigns, and training for security awareness month. Evaluate and recommend information security technologies to countermeasures against threats to information or privacy. Monitor, analyze and report on internal/external threats, cyber-crimes, and critical third-party vendor risks. Stay updated on the latest security trends and technologies to enhance the organization's security posture. Assist with annual access control review. Assist with Incident Response functional testing for appropriate staff. Assist with Information Technology Risk Assessments. Assist with CRI Profile, CIS Controls, and PCI compliance reviews/updates. Lead Clean Desk and Fedline Audit. Monitor Phishlabs, Information Security Committee & Abuse email accounts. Will assist with examinations of Federal Regulators, external and internal audits, and investigations of fraud as requested. (Including evidence collection and remediation tracking) Work with IT teams to ensure security measures are integrated into the organization's infrastructure. Must maintain a high level of confidentiality and professionalism regarding all employee and customer issues and information. The employee will adhere to all rules and regulations, including but not limited to the requirements of the Bank Secrecy Act. In addition, the employee will be proactive in the prevention of illegal activities, will vigilantly look for activities that may constitute any type of fraud including money laundering, and will report any suspicious activity to the BSA Officer. Will assist with special projects and new technology initiatives, as requested. Stay current on emerging threats, vulnerabilities, and regulatory changes. Contribute to the overall success of the organization. Responsibilities require a high degree of accuracy and strong communication skills. Earn and maintain the respect and trust of people. Display honesty, integrity, and morality. Must be able to efficiently organize work assignments in order to meet deadlines. SECONDARY DUTIES AND RESPONSIBLITIES: Create a monthly/quarterly fraud report. Will assist with internal audits and FDICIA Testing. QUALIFICATIONS (KNOWLEDGE, SKILLS AND ABILITIES): Education: Bachelor's degree in Computer Science, Information Technology, Management Information Systems, Cybersecurity or related field (or equivalent experience). 2+ years of experience in cybersecurity, Information Security, or Information Technology (banking or financial services preferred). Familiarity with cybersecurity/regulatory frameworks such as FFIEC, GLBA, NIST, or CRI Profile. Obtain and keep current professional certification and training, as required. (Certified Community Bank Technology Officer, Certified Banking Vendor Manager) LOCATION: Any of Bravera's locations in Montana, North Dakota or Minnesota. BENEFITS: To support this, we provide a competitive and rewarding compensation package which includes a competitive salary, incentive compensation opportunities, retirement plan with company match, health insurance, paid holidays, paid time off (PTO), paid community volunteer time and stock opportunities. As a learning organization, we are committed to investing in the growth and development of our team members, offering training opportunities and tuition reimbursement. Our Values Give and earn trust. We support and empower one another to earn trust through accountable performance. Learn, teach and mentor. We are a learning organization that invests in growth and development. Collaborate and innovate. We work together to drive continuous improvement to enhance your experience. Want to learn more about careers with Bravera? Go to bravera.bank/careers. #ForgeYourPath with us! Find us on Facebook, Instagram, X, LinkedIn, Youtube, and Tik Tok. --- Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities. The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing or action, including an investigation conducted by the employer or (c) consistent with the contractor's legal duty to furnish information. 41 CFR 60-1.35(c).
    $84k-119k yearly est. 14d ago
  • Security Engineer II

    Trustmark 4.6company rating

    Security engineer job in Bismarck, ND

    Trustmark's mission is to improve wellbeing - for everyone. It is a mission grounded in a belief in equality and born from our caring culture. It is a culture we can only realize by building trust. Trust established by ensuring associates feel respected, valued and heard. At Trustmark, you'll work collaboratively to transform lives and help people, communities and businesses thrive. Flourish in a culture of diversity and inclusion where appreciation, mutual respect and trust are constants, not just for our customers but for ourselves. At Trustmark, we have a commitment to welcoming people, no matter their background, identity or experience, to a workplace where they feel safe being their whole, authentic selves. A workplace made up of diverse, empowered individuals that allows ideas to thrive and enables us to bring the best to our colleagues, clients and communities. We are seeking a highly skilled Cyber Security Engineer to join our team and play a pivotal role in safeguarding our organization's digital assets. The ideal candidate will possess a deep understanding of cybersecurity principles, a strong technical background, and a passion for protecting sensitive information. You will be responsible for engineering, implementing and monitoring security measures for the protection of Trustmark's computer systems, networks and information. The role helps identify and define system security requirements as well as develop detailed cyber security designs. **Responsibilities:** + Design, implement, and maintain security architectures, systems, and solutions to protect critical infrastructure and data. + Conduct vulnerability assessments and penetration testing to identify and mitigate risks. + Develop and implement security policies, standards, and procedures. + Monitor security systems and respond to incidents promptly and effectively. + Stay up-to-date with the latest cybersecurity threats and trends. + Collaborate with cross-functional teams to ensure security is integrated into all aspects of the business. + Provide technical guidance and support to internal stakeholders. **Qualifications:** + Bachelor's degree in Computer Science, Information Technology, or a related field or + 3-5 Years of network engineering or cyber engineering experience + Strong understanding of cybersecurity frameworks and standards (e.g., NIST, ISO 27001). + Proficiency in network security, systems security, application security, and data security. + Hands-on experience with security tools and technologies (e.g., firewalls, intrusion detection systems, encryption, SIEM). + Excellent problem-solving and analytical skills. + Strong communication and interpersonal skills. + Ability to work independently and as part of a team. **Preferred Qualifications:** + Certifications such as CISSP, CISA, or CEH. + Experience with cloud security (e.g., AWS, Azure, GCP). + Knowledge of scripting and programming languages (e.g., Python, PowerShell). Brand: Trustmark Come join a team at Trustmark that will not only utilize your current skills but will enhance them as well. Trustmark benefits include health/dental/vision, life insurance, FSA and HSA, 401(k) plan, Employee Assistant Program, Back-up Care for Children, Adults and Elders and many health and wellness initiatives. We also offer a Wellness program that enables employees to participate in health initiatives to reduce their insurance premiums. **For the fourth consecutive year we were selected as a Top Workplace by the Chicago Tribune.** The award is based exclusively on Trustmark associate responses to an anonymous survey. The survey measured 15 key drivers of engaged cultures that are critical to the success of an organization. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, sex, sexual orientation, sexual identity, age, veteran or disability. Join a passionate and purpose-driven team of colleagues who contribute to Trustmark's mission of helping people increase wellbeing through better health and greater financial security. At Trustmark, you'll work collaboratively to transform lives and help people, communities and businesses thrive. Flourish in a culture where appreciation, mutual respect and trust are constants, not just for our customers but for ourselves. Introduce yourself to our recruiters and we'll get in touch if there's a role that seems like a good match. When you join Trustmark, you become part of an organization that makes a positive difference in people's lives. You will play a vital role in delivering on our mission of helping people increase wellbeing through better health and greater financial security. Our customers tell us they simply appreciate the personal attention and knowledgeable service. Others tell us we've changed their lives. At Trustmark, you'll be part of a close-knit team. You'll enjoy abundant opportunities to grow your career. That's why so many of our associates stay at Trustmark and thrive. Trustmark benefits from more than 100 years of experience but pairs that rich history with a palpable sense of optimism, growth and excitement for what's ahead - and beyond. This is a place where associates bring their whole selves to work each day. A place where you can be yourself. Whatever your beyond is, you can achieve it at Trustmark.
    $79k-98k yearly est. 60d+ ago
  • Lottery Information Security Specialist

    State of North Dakota 4.2company rating

    Security engineer job in Bismarck, ND

    125-23653 Salary Range: $4,882 - $6,380 per month. For full benefits package, click here: Total Rewards Calculator. Status: Full-Time with State Benefit Package Recruitment: Internal/External Selecting Supervisor: Thomas Lawler, Director, Lottery Division Summary of Work The purpose of this position is to assist the Lottery Security Officer in ensuring the integrity and operability of all lottery systems and its assets. These systems include the Central Gaming System (CGS), Internal Control System (ICS), and the Sci-Core subscription service, and all related network access and security. This position is responsible for assisting in ensuring that all systems meet or exceed the Multi-State Lottery (MUSL) rules and security requirements. Additionally, this position assists in the investigation of any thefts, ticket disputes, and breaches of confidentiality or rule requirements by users. Typical duties for this position include the following tasks: * Assisting the Lottery Security Officer in user acceptance testing for system implementations, changes, upgrades, and enhancements meeting or exceeding all lottery regulatory requirements while delivering quality results within budget and on schedule. * Assisting in the management and review of informational and physical security to ensure the integrity of the lottery and its assets. * Adherence to and compliance with MUSL Rules. * Assisting in investigations of player and retailer disputes. * Participating in nightly draws on an as needed/rotational basis. * Conduct draws balancing procedures. This includes certain on call rotations, which may include evenings, weekends and holidays. * Availability to troubleshoot any system issues. * Ensure firewall configurations and exceptions align with organizational security policies, compliance requirements, and operational needs. In addition to the monthly salary, this position includes fully paid health insurance for employee and family, the option to participate in employee-paid dental and vision for employee and family, participation in the state NDPERS defined contribution retirement plan as well as the option to participate in the 457 deferred compensation plan, the option to contribute to a medical spending account, and earning annual and sick leave. Location of Work: The Division office is located in Bismarck, North Dakota. Minimum Qualifications * Bachelor's degree and at least one year of information technology experience or the combined equivalent of relevant years of experience and education * High ethical standards; clean discipline record. * Ability to maintain a high degree of confidentiality. * Excellent written and verbal communication skills. * Interpersonal skills needed to work well with colleagues, vendors, and the public. * The judgment, reliability, and willingness to devote time and energy necessary to provide excellent work to the Lottery Division and the State of North Dakota. * Ability, demonstrated in previous employment experience or otherwise shown, to establish and maintain effective, harmonious working relationships with colleagues, vendors, and supervisors. * Excellent time management and organizational skills. * Successful completion of the interview process, reference checks, and standard background and criminal record checks to determine knowledge, skills, and abilities to perform assistant attorney general tasks. About Team ND "Far and away the best prize life offers is the chance to work hard at work worth doing." - Theodore Roosevelt More than 7,500 talented, hard-working people across sixty-three agencies have come together as Team North Dakota. At Team ND, we are driven to succeed through gratitude, humility, curiosity and courage. Our purpose is to empower people, improve lives, and inspire success. Join us in being legendary. Total Rewards: The State of North Dakota is committed to providing team members with a strong and competitive rewards package that support you, your health and your family. Considering a new position on Team ND? How does your current position stack up? Use our Total Rewards Calculator to estimate. Application Procedures Applicants are screened based on qualifications, successful completion of the interview process and a background and criminal investigation. Applicants must be currently authorized to work in the United States on a full-time basis. The Office of Attorney General does not provide sponsorships. Application package must be received by 11:59 PM Central Standard Time (CST) on the closing date listed on the opening. TO BE CONSIDERED FOR THIS POSITION APPLICATIONS MUST BE SUBMITTED ONLINE AT: ****************** Documents to be submitted: * Resume * Cover letter with a summary that clearly explains how the applicant's work experience is related to the summary of work and minimum/preferred qualifications * 3 Professional References * College Transcripts (copies or unofficial versions are acceptable for the initial application process but when the top candidate is given a conditional employment offer, they are required to present official transcripts) The North Dakota Office of Attorney General prohibits candidates from plagiarizing any portion of their employment application and interview process to include responses to questions in which you must provide a narrative and/or verbal response. You must create your own responses originally and not copy or adapt them from other sources. While the North Dakota Office of Attorney General encourages you to create your narratives and interview responses with great care, including correct use of grammar and style, you are prohibited from using any artificial intelligence (AI) or AI-assisted tool, to include but not limited to ChatGPT during the interview process. Any information you provide during the application and interview process is subject to verification. The North Dakota Office of Attorney General will discontinue your candidacy if we find you have violated this prohibition on use of AI tools in the application and interview process. All hiring decisions are subject to approval by the Attorney General. No offer of employment is final or binding until approved by the Attorney General. Anyone needing assistance or accommodations during any part of the application or interview process please contact Ashley, Office of Attorney General: E-mail: *****************; phone: ************** or TTY: **************. * Learn more about Office of Attorney General at: ******************************* * Learn more about Employment Benefits at: ****************************************************** * Visit North Dakota State government: ***************** To learn more about living in North Dakota, visit *************************** Equal Employment Opportunity The State of North Dakota and this hiring agency do not discriminate on the basis of race, color, national origin, sex (including sexual orientation and gender identity), genetics, religion, age or disability in employment or the provisions of services and complies with the provisions of the North Dakota Human Rights Act. As an employer, the State of North Dakota prohibits smoking in all places of state employment in accordance with N.D.C.C. § 23-12-10.
    $4.9k-6.4k monthly 13d ago
  • Information Security Officer (m/f/d)

    Nemetschek

    Security engineer job in Munich, ND

    Nemetschek are one of Germany's largest software companies and a true pioneer in digital transformation for the architecture, engineering, construction, operations and media industries. With a remarkable growth trajectory - delivering double-digit revenue growth year after year and recently reaching close to €1 billion in annual revenues - Nemetschek stands at the forefront of innovation and business transformation. Our dynamic, global team of over 4,000 experts is driving the shift to SaaS and subscription models, harnessing cutting-edge technologies like AI and digital twins to shape the future of the built environment. If you're looking to be part of a company that is not only aiming at leading its industry but also transforming how the world designs, builds, and manages the spaces we live and work in, Nemetschek is the place to accelerate your career. We are looking for an experienced Information Security Officer to lead security implementation at the brand level, with a focus on an organisational entity within the global ISO organisation. This role oversees the ISMS, ensures ISO 27001 compliance, and drives security initiatives across multiple brands. Responsibilities: * Information Security Management for one or more Nemetschek Brands (depending on Brand size) * Operations of the Nemetschek Information Security Management System (ISMS, based on ISO 27001) for the Brand(s) * Maintenance of the ISO 27001 certification on brand level (Sub-certificates) * Participation in and collaboration with the Information Security Core Community * Collaboration with and contribution to shared security services * Implementation or collaboration in projects to improve group-wide or brand-specific Information Security * Close collaboration with other ISOs and CISOs, as well as internal and external experts * Permanent learning on the job * Contribution to the group-wide Information Security Management System (ISMS) * Management and execution of Security Audits (Security Peer Review) * Management of security inquiries from 3rd partes like customers or external auditors Requirements: * Completed studies with content in information security, business informatics or comparable training * At least 3 years of professional experience in the field of Information Security * Good communication skills in English * The ability to think outside the box of Information Security * Knowledge of relevant security standards and frameworks * Subject-specific certifications are an advantage * Very high integrity and trustworthiness * Motivation to improve our company every day * Willingness to travel about 1x a month Key Relationships: * Reports to: Head of Security Management EU Brands Why Nemetschek? * Impact: We offer you a diverse position in a motivating work environment where you can realise your ideas. * Sustainable Growth: In our sustainably growing and innovative company, you have the chance to develop yourself further. * Culture: With us, you work in an international team with flat hierarchies and short decision-making processes, in which you can make a difference. * Work-Life-Balance: We offer you various benefits in the areas of sports, nutrition, childcare and much more. * Health: The health of all employees is important to us, which is why we offer a wide range of health and preventive care services. * Hybrid Way Forward: Through mobile working and variable working hours without core working hours, we enable you to be flexible, both professionally and privately. #Nemetschek We, the Nemetschek Group, are a global organisation with employees from 60 nations. For us, diversity, equity, inclusion, and belonging are the keys to unleashing our full potential and driving true innovation. We can best support our customers in shaping the world through a diverse culture. We aim to treat EVERYONE with respect and appreciation, regardless of differences. Valuing diverse opinions and creating equal opportunities for all is of the utmost importance for us as an organisation and as individuals.
    $95k-140k yearly est. 28d ago
  • Chief Information & Product Security Officer (f/m/d)

    Yunex Traffic

    Security engineer job in Munich, ND

    We're the Yunex Traffic team, a global leader in intelligent traffic systems. We have been working on revolutionary technologies for the mobility of the future. We develop solutions for traffic management leading to greater traffic flow, safety, efficiency and environmental friendliness. The results of our work are perceived by the citizens in cities around the world. Who are we looking for? We are seeking a highly skilled and experienced Chief Information and Product Security Officer to lead the cybersecurity department, covering both enterprise and product cybersecurity practices. The cybersecurity organization employs 10 direct reports operating from Germany, Czech Republic, United Kingdom, and the US. Experience in Product Security is essential, as this area is a key focus of the position alongside enterprise-level cybersecurity. What will be your responsibilities? Shape the future of cybersecurity in intelligent traffic systems, leading a global team protecting both our enterprise and our products. * Direct a team of 10 professionals across Germany, Czech Republic, United Kingdom, and the US. * Define and deliver a cybersecurity strategy aligned with business and shareholder goals. * Strengthen IT security frameworks, governance, KPIs, and compliance. * Oversee risk assessments, incident response, and vulnerability management. * Ensure adherence to international standards (e.g., NIST CSF, ISO 27001, IEC 62443). * Drive cloud security governance and secure product hosting. * Embed security in the SDLC and DevSecOps practices. * Lead product security testing, threat modeling, and hardening initiatives. * Manage RFP security responses and customer security requirements. * Coordinate with SOC, cloud, and security advisory service providers. * Partner with risk management and shareholders on strategic initiatives. * Report regularly to the Supervisory Board on security posture and regulations. * Foster a high-performance culture through coaching, reviews, and development planning. What do you need to qualify for the role? * University degree in computer science, cybersecurity, or a related STEM field. * Minimum 8 years of experience in leadership and people management roles. * Experience with regulations for operators of critical infrastructure and providers of digital products and services in the European Union, United States, and United Kingdom (e.g. NIS2 and Cyber Resilience Act). * Clear understanding of main cybersecurity standards and frameworks such as the NIST CSF, ISO 27001, ISO 27005, IEC 26443, and IEC 62264. * Experience with cloud and OT security. * Knowledge and experience with DevSecOps and security testing methodologies such as Software Composition Analysis, Static Application Security Testing, Dynamic Application Security Testing, and Hardening. * Excellent communication skills. Fluent in English (C1+). * Proven ability to coordinate and communicate on director level in a multinational group. Additional skills we value: * German language is a plus. * Understanding and experience in national implementations of NIS and NIS2 are a plus, e.g. in Germany and Austria. * CISM, CISSP, or CCISO certifications. * Knowledge and experience with agile and waterfall project management methodologies. We offer: * Competitive payment in line with the market * 30 days of vacation * Flexible working time models * Company pension scheme * Childcare allowance * Monthly shopping vouchers * An open and diverse corporate culture where you can develop your strengths * Extensive training opportunities in our Yunex Traffic Academy and on our online learning platform How do I apply? We can only accept online applications. Click the "Apply Now" button below to submit your application. About Us: We are a global leader in intelligent transport systems with more than 3,500 passionate employees who pioneer, develop, create, install and maintain innovative road traffic and mobility solutions all over the world. We make our roads smarter, safer and greener. The work we do enables cities, highways authorities and infrastructure operators to create a new world of mobility and makes cities more livable for everyone. Our solutions range from traffic lights, tolling solutions and tunnel management to software, AI applications and the intelligent networking of all road users. Become a Traffic Transformer and help us to continue transforming towns and cities all over the world. Our Commitment: At Yunex Traffic, the uniqueness of our people is our strength. Our people are at the heart of what we do and every voice, perspective and contribution is valued. The future of mobility needs people who think down different tracks and we empower our people to transform cities all over the world. Join us and make a difference too.
    $95k-140k yearly est. 9d ago
  • Security Engineer - Nashville or Austin Location

    Oracle 4.6company rating

    Security engineer job in Bismarck, ND

    Responsible for the planning, design and build of security architectures; oversees the implementation of network and computer security and ensures compliance with corporate security policies and procedures. **Responsibilities** Responsible for advanced planning, design and build of security systems, applications, environments and architectures; oversees the implementation of security systems, applications, environments and architectures and ensures compliance with information security standards and corporate security policies and procedures. Provides technical advice and direction to support the design and development of secure architectures. May participate in an incident management team, bringing advanced-level skills to respond to security events in line with Oracle incident response playbooks. Investigates purported intrusions and breaches, and oversees root cause analysis. Coordinates incidents with other business units and may act as Incident Commander of serious incidents. Develops new methods, and playbooks, as well as sophisticated scripts, applications, and tools, and trains others in their use. May participate in an incident management team, responding to security events in line with Oracle incident response playbooks. Investigates purported intrusions and breaches, and oversees root cause analysis. Coordinates incidents with other business units and may act as incident commander of serious incidents. Participates in developing new methods, playbooks throughout Oracle. Evaluates existing and proposed technical architectures for security risk, provides technical advice to support the design and development of secure architectures and recommends security controls to mitigate those risks. Evaluations of internal security architecture may include design assessment, risk assessment, and threat modeling. Brings advanced-level skills to research, evaluate, track, and manage information security threats and vulnerabilities in situations where in-depth analysis of ambiguous information is required, and where computer programming/scripting knowledge is required. Work with Senior management to develop and implement a multi-year security roadmap Focus on operational and strategic level tasks, and provide counsel and guidance to the junior level security operations engineers in the department. Disclaimer: **Certain US customer or client-facing roles may be required to comply with applicable requirements, such as immunization and occupational health mandates.** **Range and benefit information provided in this posting are specific to the stated locations only** US: Hiring Range in USD from: $109,200 to $223,400 per annum. May be eligible for bonus and equity. Oracle maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect Oracle's differing products, industries and lines of business. Candidates are typically placed into the range based on the preceding factors as well as internal peer equity. Oracle US offers a comprehensive benefits package which includes the following: 1. Medical, dental, and vision insurance, including expert medical opinion 2. Short term disability and long term disability 3. Life insurance and AD&D 4. Supplemental life insurance (Employee/Spouse/Child) 5. Health care and dependent care Flexible Spending Accounts 6. Pre-tax commuter and parking benefits 7. 401(k) Savings and Investment Plan with company match 8. Paid time off: Flexible Vacation is provided to all eligible employees assigned to a salaried (non-overtime eligible) position. Accrued Vacation is provided to all other employees eligible for vacation benefits. For employees working at least 35 hours per week, the vacation accrual rate is 13 days annually for the first three years of employment and 18 days annually for subsequent years of employment. Vacation accrual is prorated for employees working between 20 and 34 hours per week. Employees working fewer than 20 hours per week are not eligible for vacation. 9. 11 paid holidays 10. Paid sick leave: 72 hours of paid sick leave upon date of hire. Refreshes each calendar year. Unused balance will carry over each year up to a maximum cap of 112 hours. 11. Paid parental leave 12. Adoption assistance 13. Employee Stock Purchase Plan 14. Financial planning and group legal 15. Voluntary benefits including auto, homeowner and pet insurance The role will generally accept applications for at least three calendar days from the posting date or as long as the job remains posted. Career Level - IC4 **About Us** As a world leader in cloud solutions, Oracle uses tomorrow's technology to tackle today's challenges. We've partnered with industry-leaders in almost every sector-and continue to thrive after 40+ years of change by operating with integrity. We know that true innovation starts when everyone is empowered to contribute. That's why we're committed to growing an inclusive workforce that promotes opportunities for all. Oracle careers open the door to global opportunities where work-life balance flourishes. We offer competitive benefits based on parity and consistency and support our people with flexible medical, life insurance, and retirement options. We also encourage employees to give back to their communities through our volunteer programs. We're committed to including people with disabilities at all stages of the employment process. If you require accessibility assistance or accommodation for a disability at any point, let us know by emailing accommodation-request_************* or by calling *************** in the United States. Oracle is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans' status, or any other characteristic protected by law. Oracle will consider for employment qualified applicants with arrest and conviction records pursuant to applicable law.
    $109.2k-223.4k yearly 60d+ ago
  • Product Security Engineer, AI

    Meta 4.8company rating

    Security engineer job in Bismarck, ND

    Meta's Product Security team is seeking a experienced hacker who derives purpose in life by revealing potential weaknesses and then crafting creative solutions to eliminate those weaknesses. Your skills will be the foundation of security initiatives that protect the security and privacy of over two billion people. You will be relied upon to provide engineering and product teams with the web, mobile, or native code security expertise necessary to make informed product decisions. Come help us make life hard for the bad guys. **Required Skills:** Product Security Engineer, AI Responsibilities: 1. Security Reviews: perform manual design and implementation reviews of products and services that make up the Meta ecosystem, like Instagram, WhatsApp, Oculus, Portal, and more 2. Developer Guidance: provide guidance and education to developers that help prevent the authoring of vulnerabilities 3. Automated Analysis and Secure Frameworks: build automation (static and dynamic analysis) and frameworks with software engineers that enable Meta to scale consistently across all of our products **Minimum Qualifications:** Minimum Qualifications: 4. BS or MS in Computer Science or a related field, or equivalent experience 5. 8+ years of experience finding vulnerabilities in interpreted languages. Knowledge of best practice secure code development 6. Experience with exploiting common security vulnerabilities 7. Knowledge of common exploit mitigations and how they work 8. Coding and scripting experience in one or more general purpose languages **Preferred Qualifications:** Preferred Qualifications: 9. Experience creating software that enables security processes, especially those leveraging AI/ML for automation or augmentation 10. Experience integrating or building AI-powered tools to assist with vulnerability detection, code review, or threat modeling 11. Experience creating software that enables security processes 12. 8+ years of experience finding vulnerabilities in C/C++ code 13. Contributions to the security community (public research, blogging, presentations, bug bounty) 14. Demonstrated ability to collaborate with AI researchers or engineers to apply AI in security workflows **Public Compensation:** $177,000/year to $251,000/year + bonus + equity + benefits **Industry:** Internet **Equal Opportunity:** Meta is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Meta participates in the E-Verify program in certain locations, as required by law. Please note that Meta may leverage artificial intelligence and machine learning technologies in connection with applications for employment. Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at accommodations-ext@fb.com.
    $177k-251k yearly 60d+ ago
  • Engineer, Information Security and Risk

    Cardinal Health 4.4company rating

    Security engineer job in Bismarck, ND

    Cardinal Health, Inc. (NYSE: CAH) is a global healthcare services and products company. We provide customized solutions for hospitals, healthcare systems, pharmacies, ambulatory surgery centers, clinical laboratories, physician offices and patients in the home. We are a distributor of pharmaceuticals and specialty products; a global manufacturer and distributor of medical and laboratory products; an operator of nuclear pharmacies and manufacturing facilities; and a provider of performance and data solutions. Working to be healthcare's most trusted partner, our customer-centric focus drives continuous improvement and leads to innovative solutions that improve the lives of people every day. With approximately 50,000 employees worldwide, Cardinal Health ranks among the top fifteen in the Fortune 500. **_Department Overview:_** **Information Technology** oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value. **Information Security and Risk** develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure, or destruction. This job family develops system back-up and disaster recovery plans, conducts incident responses, threat management, vulnerability scanning, virus management and intrusion detection as well as completes risk assessments. Lead IAM work for new customer onboardings and migrations. Collaborate with CAH Account Management, Application Teams, and Customers to design, implement, and test federated SSO solution based on customer login requirements. Provide technical guidance and act as primary point of contact for business partners and customer related to IAM work for onboarding. Additional responsibilities include supporting application integrations and enhancing SSO self service application onboarding. **Responsibilities:** + **Customer Onboarding IAM Efforts - Strategy & Execution :** Lead the planning, design, and execution for Customer Onboarding via federated SSO, ensuring alignment with overall business and security objectives. This includes assessing multiple Cardinal Health e-commerce applications, understanding login requirements for new/existing customers, designing, testing and implementing solutions etc to ensure top notch user login experience and enhancing Cardinal Health's security posture. + **Collaboration & Communication:** Coordinate cross-functional teams, including Customer Business and IT teams, Cardinal Health's Account Management/Sales and Application teams, Information Security and others to ensure effective IAM implementation and seamless integration with business processes. Communicate complex security concepts to technical and non-technical internal and external stakeholders. + **Application Integration Leadership:** Lead the integration of various enterprise applications (SaaS, on-premise, custom-built) with our core IAM infrastructure, ensuring secure authentication, authorization, and user provisioning/de-provisioning. + **User Lifecycle Management:** Streamline and automate user provisioning, de-provisioning, and periodic access reviews for employees, contractors, and partners across all integrated systems, ensuring smooth onboarding and offboarding during M&A transitions. + **Solution Design & Implementation:** Design, implement, and maintain IAM solutions including Single Sign-On (SSO), Multi-Factor Authentication (MFA), and Role-Based Access Control (RBAC) frameworks. + **Technical Troubleshooting & Support:** Troubleshoot, identify, and resolve technical identity and access management-related issues, providing expert support to internal teams and end-users during and after integration. + **Documentation & Best Practices:** Develop, review, and maintain comprehensive technical documentation, including architecture diagrams, configuration guides, and operational procedures. Stay up-to-date with IAM best practices, regulatory requirements, and security trends. **Qualifications:** + **Education:** Bachelor's degree in Computer Science, Information Technology, Information Security, or a related field, or equivalent practical experience. + **Experience:** 5+ years of progressive experience as an IAM Engineer, designing and implementing enterprise scale solutions with significant experience in supporting M&A integration projects preferred. + **Technical Expertise:** + Extensive knowledge and experience with authentication standards and technologies such as SSO (SAML, OAuth, OpenID Connect), MFA + Proficiency in directory services (e.g., Active Directory, Azure AD, LDAP). + Hands-on experience with leading IAM platforms (e.g., Okta, Microsoft Azure AD, CyberArk, ForgeRock, Ping Identity, SailPoint). + Strong understanding of security principles, risk management, and access control models (e.g., RBAC). + Familiarity with Zero Trust architecture principles. + Familiarity with AI/ML concepts and their practical application in security and risk management, especially in IAM context. + Strong communication and interpersonal skills to collaborate effectively with various teams and stakeholders. + Detail-oriented mindset to ensure precise access control configurations and compliance. + Excellent problem-solving and analytical abilities to troubleshoot access issues and design solutions for unique business requirements + Must be a self-starter who takes full ownership of projects from inception to completion , holding oneself accountable for the security and operation integrity of IAM platform. + Ability to manage multiple priorities and meet tight deadlines in a fast-paced M&A environment. **Anticipated salary range:** $94,900 - $135,600 **Bonus eligible:** No **Benefits:** Cardinal Health offers a wide variety of benefits and programs to support health and well-being. + Medical, dental and vision coverage + Paid time off plan + Health savings account (HSA) + 401k savings plan + Access to wages before pay day with my FlexPay + Flexible spending accounts (FSAs) + Short- and long-term disability coverage + Work-Life resources + Paid parental leave + Healthy lifestyle programs **Application window anticipated to close:** 12/20/2025 *if interested in opportunity, please submit application as soon as possible. The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity. _Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply._ _Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal_ _Opportunity/Affirmative_ _Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law._ _To read and review this privacy notice click_ here (***************************************************************************************************************************
    $94.9k-135.6k yearly 28d ago
  • Senior Analyst, Security Compliance (SOX IT)

    Coinbase 4.2company rating

    Security engineer job in Bismarck, ND

    Ready to be pushed beyond what you think you're capable of? At Coinbase, our mission is to increase economic freedom in the world. It's a massive, ambitious opportunity that demands the best of us, every day, as we build the emerging onchain platform - and with it, the future global financial system. To achieve our mission, we're seeking a very specific candidate. We want someone who is passionate about our mission and who believes in the power of crypto and blockchain technology to update the financial system. We want someone who is eager to leave their mark on the world, who relishes the pressure and privilege of working with high caliber colleagues, and who actively seeks feedback to keep leveling up. We want someone who will run towards, not away from, solving the company's hardest problems. Our ******************************** is intense and isn't for everyone. But if you want to build the future alongside others who excel in their disciplines and expect the same from you, there's no better place to be. While many roles at Coinbase are remote-first, we are not remote-only. In-person participation is required throughout the year. Team and company-wide offsites are held multiple times annually to foster collaboration, connection, and alignment. Attendance is expected and fully supported. Coinbase stores more digital currency than any company in the world, making us a top tier target on the internet. Security is core to our mission and has been a key competitive differentiator for us as we scale worldwide. Essential to scaling is building and running a security compliance program that reflects how we protect the data and assets in our care, to open the doors with customers, regulators, auditors, and other external stakeholders. If you love working with fast moving companies to grow and scale security compliance engines and create positive change across the business, we'd like to speak with you about joining our team. Coinbase is looking for a Security Compliance Senior Analyst to drive the second line of defense IT SOX initiatives and help mature the IT SOX program. *What you'll be doing (ie. job duties):* * Lead Security and IT initiatives to support the SOX roadmap and advance program maturity * Assist with SOX planning activities, including scoping of IT systems and creating training material to owners in preparation for SOX audit * Lead security control gap assessments over SOX control environment, recommend remediation plans and track through completion * Assess SOX implications of new products, update relevant controls, and communicate requirements to product organization and other stakeholders * Provide ongoing reporting to stakeholders and leadership on above responsibilities and communicate progress and escalations management * Perform SOX audit and control impact analysis as a result of security and technology incidents and partner with owning teams on control uplift activities * Build close relationships with stakeholder teams including Security, IT, Infrastructure, Engineering, Data, and Finance to advise on SOX requirements and ensure excellence in control ownership * Create and improve SOX procedural documentation, including process documentation, data flow diagrams, and uplifting templates * Work closely with internal and external auditors to educate them about a complex technology control environment * Oversee quality of audit initiatives, identify and analyze process gaps, provide guidance and expertise to team members * Develop creative solutions to prove risk mitigation and solve for complex audit problems faced by the crypto industry * Identify opportunities to address systemic program challenges, recommend solutions and drive efficiency through AI and automation *What we look for in you (ie. job requirements):* * Minimum of 5+ years of security/IT compliance or equivalent experience * Strong knowledge and hands-on experience in Internal Controls over Financial Reporting, SOX 404 frameworks, and testing to support compliance * Prior experience at a big 4 accounting firm * Experience leading compliance initiatives from start to finish * Proven understanding and audit experience of cloud technologies, AWS preferred * Ability to effectively and autonomously accomplish outcomes across cross-functional teams in ambiguous situations with minimal supervision * Strong oral and written communication skills * Ability to multitask, direct cross functional work, and hold others accountable to committed deadlines in a fast paced environment * Ability to communicate with technical / non-technical stakeholders to align on shared outcomes * Experience in Financial services, Big Tech, or FinTech *Nice to haves:* * BA or BS in a technical field or equivalent experience * Security certifications e.g. CISA, CISSP, CISM or other relevant certifications * Experience auditing in Crypto space Position ID: P73675 \#LI-Remote *Pay Transparency Notice:* Depending on your work location, the target annual salary for this position can range as detailed below. Full time offers from Coinbase also include bonus eligibility + equity eligibility**+ benefits (including medical, dental, vision and 401(k)). Pay Range: $167,280-$196,800 USD Please be advised that each candidate may submit a maximum of four applications within any 30-day period. We encourage you to carefully evaluate how your skills and interests align with Coinbase's roles before applying. Commitment to Equal Opportunity Coinbase is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, sex, gender expression or identity, sexual orientation or any other basis protected by applicable law. Coinbase will also consider for employment qualified applicants with criminal histories in a manner consistent with applicable federal, state and local law. For US applicants, you may view the *********************************************** in certain locations, as required by law. Coinbase is also committed to providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please contact us at accommodations*********************************** *Global Data Privacy Notice for Job Candidates and Applicants* Depending on your location, the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) may regulate the way we manage the data of job applicants. Our full notice outlining how data will be processed as part of the application procedure for applicable locations is available ********************************************************** By submitting your application, you are agreeing to our use and processing of your data as required. *AI Disclosure* For select roles, Coinbase is piloting an AI tool based on machine learning technologies to conduct initial screening interviews to qualified applicants. The tool simulates realistic interview scenarios and engages in dynamic conversation. A human recruiter will review your interview responses, provided in the form of a voice recording and/or transcript, to assess them against the qualifications and characteristics outlined in the job description. For select roles, Coinbase is also piloting an AI interview intelligence platform to transcribe and summarize interview notes, allowing our interviewers to fully focus on you as the candidate. *The above pilots are for testing purposes and Coinbase will not use AI to make decisions impacting employment*. To request a reasonable accommodation due to disability, please contact accommodations[at]coinbase.com
    $167.3k-196.8k yearly 58d ago
  • Senior Information Security Operations Engineer

    Sanford Health 4.2company rating

    Security engineer job in Bismarck, ND

    **Careers With Purpose** **Sanford Health is one of the largest and fastest-growing not-for-profit health systems in the United States. We're proud to offer many development and advancement opportunities to our nearly 50,000 members of the Sanford Family who are dedicated to the work of health and healing across our broad footprint.** **Facility:** Bismarck Business Center **Location:** Bismarck, ND **Address:** 3451 N 14th St, Bismarck, ND 58503, USA **Shift:** 8 Hours - Day Shifts **Job Schedule:** Full time **Weekly Hours:** 40.00 **Salary Range:** $43.00 - $71.00 **Pay Info:** Pay starts at $43 and increases according to years of applicable experience. **Department Details** Lead day-to-day vulnerability operations (scan scheduling, authenticated coverage, agent health) and engineer improvements across tooling workflows. Develop and mature the Vulnerability Management program: define SLAs, priorities, exception guardrails, and reporting; design playbooks for zero-day/KEV response. Drive remediation campaigns with asset owners; convert findings into work items with clear scope, owners, and due dates; track to closure. Partner with Technology Solutions teams to reduce exposure footprint (consult on configuration baselines, conditional access, system hardening). Produce executive metrics and service reporting (exposure trends, SLA compliance, coverage, time-to-remediate). Project management exposure preferred (owning cross-team initiatives, roadmaps, and deliverables). **Job Summary** Responsible for the technical and operational delivery of enterprise cybersecurity; focusing on the development and implementation of processes and tools that support Vulnerability Management threat prevention, threat hunting, vulnerability assessments, and incident response. Also responsible for minimizing identified threats and risks to the organization through collaboration with other Information Security and Sanford technological groups. Perform and coordinate, with other team members, real-time and forensic log and EDR monitoring and analysis to provide network, data, and asset security for Sanford Health. Complete, configure, and tune vulnerability assessments and report results to application and asset owners. Provide consulting services to owners relating to response activities. Perform, lead, and coordinate on Incident Response activities including the collection, preservation, and interpretation of digital evidence. Build, administer, and support the IS Vulnerability Management tools, processes, and services. Identify and complete improvements and metrics to Vulnerability Management processes and services. Manage the IS Vulnerability Management ticket queue. Prioritize and complete tickets according to impact to Sanford Health business functions. Provide security consulting services to other Sanford Health groups. Mentor other Vulnerability Management team members on tools, processes, and Sanford Health areas. Coordinate and participate in activities with other IT Security groups by providing aid and consulting when needed. Works under limited guidance due to previous experience/breadth of knowledge of processes and organizational knowledge. Acts independently to determine methods and procedures on new assignments. Regularly presented with new assignments and projects that require the application of independent judgement/interpretation of policies/practices. Checks own work and the work of other team members. **Qualifications** Bachelor's degree required, in lieu of education, leadership may consider an Associates degree plus 3 years of applicable experience in computer science, cyber security or an information technology related field. Minimum of 4 years' experience working in Cyber Security required. Advanced security training is desired. Strong working knowledge of the information security standards and procedures including HIPAA and PCI. Security Certifications are desired. **Benefits** Sanford Health offers an attractive benefits package for qualifying full-time and part-time employees. Depending on eligibility, a variety of benefits include health insurance, dental insurance, vision insurance, life insurance, a 401(k) retirement plan, work/life balance benefits, and a generous time off package to maintain a healthy home-work balance. For more information about Total Rewards, visit *********************************** . Sanford is an EEO/AA Employer M/F/Disability/Vet. If you are an individual with a disability and would like to request an accommodation for help with your online application, please call ************** or send an email to ************************ . Sanford Health has a Drug Free Workplace Policy. An accepted offer will require a drug screen and pre-employment background screening as a condition of employment. **Req Number:** R-0232476 **Job Function:** Information Technology **Featured:** No
    $43-71 hourly 60d+ ago
  • Security Engineer Investigator, Insider Trust

    Meta 4.8company rating

    Security engineer job in Bismarck, ND

    As part of Meta Security, our Insider Trust team is dedicated to identifying and responding to insider threats that target our data. Our mission is to detect, investigate, and mitigate damage caused by insider threats. We handle a wide range of abuse cases, including misuse of user data, intellectual property theft, and leaks of sensitive information.We are seeking an experienced Security Engineer to join the team. This role involves investigating, hunting, and automating internal signals to detect malicious activities related to insider threats. **Required Skills:** Security Engineer Investigator, Insider Trust Responsibilities: 1. Perform analysis, and threat hunting from a variety of log sources (e.g., individual host logs, network traffic logs) to identify potential insider threats 2. Create workflows and automations to streamline signal detection, threat hunts, and investigative processes 3. Collaborate with software and production engineering teams to build scalable and adaptable solutions for insider threat investigations 4. Identify gaps in our infrastructure and work with cross-functional partners to improve visibility through logging and automation 5. Build operational workflows and actions to auto-resolve false positives and provide context, scaling investigation capabilities 6. Prioritize efforts to maximize impact by enhancing visibility, automating processes, and scaling investigative capabilities 7. Coach, mentor, and support team members to foster long-term career growth, job satisfaction, and success **Minimum Qualifications:** Minimum Qualifications: 8. Bachelor's degree in Computer Science, Engineering, or equivalent experience 9. 5+ years of experience in Detection & Response Engineering, Insider Threat, or a similar Security Engineering role 10. Technical and procedural expertise in conducting security investigations, including response, forensics, and large-scale log analysis 11. Experience with attacker tactics, techniques, and procedures 12. Proficiency in coding or scripting in one or more general-purpose programming languages **Public Compensation:** $147,000/year to $208,000/year + bonus + equity + benefits **Industry:** Internet **Equal Opportunity:** Meta is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Meta participates in the E-Verify program in certain locations, as required by law. Please note that Meta may leverage artificial intelligence and machine learning technologies in connection with applications for employment. Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at accommodations-ext@fb.com.
    $147k-208k yearly 60d+ ago
  • Engineer, Information Security and Risk

    Cardinal Health 4.4company rating

    Security engineer job in Bismarck, ND

    Cardinal Health, Inc. (NYSE: CAH) is a global healthcare services and products company. We provide customized solutions for hospitals, healthcare systems, pharmacies, ambulatory surgery centers, clinical laboratories, physician offices and patients in the home. We are a distributor of pharmaceuticals and specialty products; a global manufacturer and distributor of medical and laboratory products; an operator of nuclear pharmacies and manufacturing facilities; and a provider of performance and data solutions. Working to be healthcare's most trusted partner, our customer-centric focus drives continuous improvement and leads to innovative solutions that improve the lives of people every day. With approximately 50,000 employees worldwide, Cardinal Health ranks among the top fifteen in the Fortune 500. **_Department Overview:_** **Information Technology** oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value. **Information Security and Risk** develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure, or destruction. This job family develops system back-up and disaster recovery plans, conducts incident responses, threat management, vulnerability scanning, virus management and intrusion detection as well as completes risk assessments. **Responsibilities:** + **M&A Integration Execution:** Collaborate and engage with IAM Lead and other business partners on planning, design, and execution of IAM integration strategies for M&A activities, ensuring alignment with overall business and security objectives. This includes assessing the IAM landscapes of merging entities to identify challenges and solutions. + **Design and Implement Sailpoint IIQ Solutions:** Configure and customize Sailpoint IIQ components (Lifecycel Manager, Compliance Manager etc). Also develop workflows, rules, and connectors for identity governance. + **Application integration with Sailpoint IIQ:** Integrate Sailpoint IIQ with enterprise applications, directories and cloud platforms in addition to developing and maintaining connectros for provisioning and de-provisioning. + **Sailpoint IIQ Development and Scripting:** Write and maintain BeanShell scripts, Java code and XML configurations, develop customer Sailpoint tasks and workflows. + **Identity System Merging & Consolidation:** Manage the complex process of merging disparate identity providers, user directories (e.g., Active Directory, Azure AD, LDAP), and access management systems from acquired companies into the existing infrastructure. + **User Lifecycle Management:** Streamline and automate user provisioning, de-provisioning, and periodic access reviews for employees, contractors, and partners across all integrated systems, ensuring smooth onboarding and offboarding during M&A transitions. + **Security & Compliance:** Ensure IAM systems and processes comply with regulatory requirements (e.g., GDPR, HIPAA, SOX) and internal security policies, providing auditable records of access activities. Protect against data breaches by ensuring only authorized personnel can access sensitive information. + **Technical Troubleshooting & Support:** Troubleshoot, identify, and resolve technical identity and access management-related issues, providing expert support to internal teams and end-users during and after integration. + **Collaboration & Communication:** Coordinate cross-functional teams, including Information Security, IT Operations, HR, and Application Development, to ensure effective IAM implementation and seamless integration with business processes. Communicate complex security concepts to technical and non-technical stakeholders. + **Documentation & Best Practices:** Develop, review, and maintain comprehensive technical documentation, including architecture diagrams, configuration guides, and operational procedures. Stay up-to-date with IAM best practices, regulatory requirements, and security trends. **Qualifications** + Experience with SailPoint IdentityIQ (IIQ) is a must + Experience with SailPoint IIQ Integrations (Workday, Active Directory/LDAP, Webservices, SCIM, JDBC, SAP) + Experience implementing Life Cycle Manager (LCM) Configuration workflow tasks that model business functions, including Lifecycle Requests (Role or Entitlement), Lifecycle Events (Joiner, Mover, or Leaver), and LCM Workflow Details (Workflows and Subprocesses) + Solid understanding of the SailPoint object model, rules, and policies + Experience with both lifecycle manager (LCM) and compliance manager (CM) modules + Knowledge of Active Directory, LDAP, Workday, and cloud platforms (GCP, MS Entra ID) is required + Proven track record of successful IAM implementations including large scale enterprise deployments. + Experience working within regulatory standards and requirements such as, SOX, HIPAA, GDPR etc. is desired. **Anticipated salary range:** $94,900 - $135,600 **Bonus eligible:** No **Benefits:** Cardinal Health offers a wide variety of benefits and programs to support health and well-being. + Medical, dental and vision coverage + Paid time off plan + Health savings account (HSA) + 401k savings plan + Access to wages before pay day with my FlexPay + Flexible spending accounts (FSAs) + Short- and long-term disability coverage + Work-Life resources + Paid parental leave + Healthy lifestyle programs **Application window anticipated to close:** 12/20/2025 *if interested in opportunity, please submit application as soon as possible. The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity. _Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply._ _Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal_ _Opportunity/Affirmative_ _Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law._ _To read and review this privacy notice click_ here (***************************************************************************************************************************
    $94.9k-135.6k yearly 28d ago
  • Manager, IT Security - Network Security

    Sanford Health 4.2company rating

    Security engineer job in Bismarck, ND

    Careers With Purpose Sanford Health is one of the largest and fastest-growing not-for-profit health systems in the United States. We're proud to offer many development and advancement opportunities to our nearly 50,000 members of the Sanford Family who are dedicated to the work of health and healing across our broad footprint. Facility: Bismarck Business Center Location: Bismarck, ND Address: 3451 N 14th St, Bismarck, ND 58503, USA Shift: 8 Hours - Day Shifts Job Schedule: Full time Weekly Hours: 40.00 Department Details This position is managing our network security services team focused on ensuring our network meets all security requirements including network segmentation, network firewalls, and network observability. The ideal candidate will have a background leading networking and security operational functions. Job Summary The Manager of Information Security is responsible for developing and leading an Information Security team in the delivery of enterprise class security services in partnership with the Information Security and IT Operations leadership team. The IS manager oversees operations for Information Security services including but not limited to workflow analysis, design, implementation, continuous process improvement and operational support with a focus on network security. In addition to the day-to-day management of the team, the Manager is responsible for the development of the team and the individual team members. The Manager works closely with Sanford Privacy, Compliance, and other Technology Solutions' leaders along with their teams to ensure Information Security services meet the needs of the business and are compliant with federal guidelines. Expected to promote quality in support services to drive business value in compliance with internal and external IT policies and procedures. Responsible for identifying and managing potential risks of delivering the support services required to support and enable Sanford Health's current and future business needs, as well as identifying, assessing, and prioritizing meaningful strategic opportunities within both clinical or non-clinical settings, and to develop the people, processes, and underlying technologies to deliver on those opportunities. Provide subject matter expertise for governing bodies to ensure high quality service delivery, ongoing strategic partnership and support. Works with business partners to support and inform the financial and strategic management used to enable the enhanced performance of Sanford Health. Employs performance development programs that result in both individual and team growth. Creates opportunities for individuals to exercise and grow new skills. Accountable as a resource to team members in department as well as other departments in the organization. Approves time off requests, and signs off on employee timecards. Maintains schedule to ensure proper staffing at all times. Responsible for the interviewing, hiring, discipline of employees and any other personnel issues that arise. Completes performance appraisals. Develops and maintains all budgetary items. Responsible for oversight of vendor management, contracts, and support agreements. Responsible for statement of work review related to project leadership. Excellent interpersonal and communication skills required. Must have experience providing excellent customers service in a prompt and professional manner and have the ability to work independently, balancing multiple tasks within deadlines. Must be comfortable managing change with excellent problem solving skills. Experience in training and presentation techniques. Ability to manage a project across teams and meet goals required. Knowledge of current clinical practice, regulatory healthcare requirements, and healthcare information systems. Qualifications Bachelor's degree in computer science, management information systems, business or a related field required. Minimum of four years' relevant work experience required. Must have extensive knowledge of information security principles and techniques. Strong working knowledge of information security standards including but not limited to National Institute of Standards and Technology (NIST), Payment Card Industry (PCI) and Health Insurance Portability and Accountability (HIPAA). Information Technology Infrastructure Library (ITIL) Foundation certification preferred. Benefits Sanford Health offers an attractive benefits package for qualifying full-time and part-time employees. Depending on eligibility, a variety of benefits include health insurance, dental insurance, vision insurance, life insurance, a 401(k) retirement plan, work/life balance benefits, and a generous time off package to maintain a healthy home-work balance. For more information about Total Rewards, visit *********************************** . Sanford is an EEO/AA Employer M/F/Disability/Vet. If you are an individual with a disability and would like to request an accommodation for help with your online application, please call ************** or send an email to ************************ . Sanford Health has a Drug Free Workplace Policy. An accepted offer will require a drug screen and pre-employment background screening as a condition of employment. Req Number: R-0242462 Job Function: Information Technology Featured: No
    $61k-73k yearly est. 17d ago

Learn more about security engineer jobs

How much does a security engineer earn in Minot, ND?

The average security engineer in Minot, ND earns between $69,000 and $115,000 annually. This compares to the national average security engineer range of $77,000 to $141,000.

Average security engineer salary in Minot, ND

$89,000
Job type you want
Full Time
Part Time
Internship
Temporary