Meta's Product Security team is seeking a experienced hacker who derives purpose in life by revealing potential weaknesses and then crafting creative solutions to eliminate those weaknesses. Your skills will be the foundation of security initiatives that protect the security and privacy of over two billion people. You will be relied upon to provide engineering and product teams with the web, mobile, or native code security expertise necessary to make informed product decisions. Come help us make life hard for the bad guys.
**Required Skills:**
Product SecurityEngineer, AI Responsibilities:
1. Security Reviews: perform manual design and implementation reviews of products and services that make up the Meta ecosystem, like Instagram, WhatsApp, Oculus, Portal, and more
2. Developer Guidance: provide guidance and education to developers that help prevent the authoring of vulnerabilities
3. Automated Analysis and Secure Frameworks: build automation (static and dynamic analysis) and frameworks with software engineers that enable Meta to scale consistently across all of our products
**Minimum Qualifications:**
Minimum Qualifications:
4. BS or MS in Computer Science or a related field, or equivalent experience
5. 8+ years of experience finding vulnerabilities in interpreted languages. Knowledge of best practice secure code development
6. Experience with exploiting common security vulnerabilities
7. Knowledge of common exploit mitigations and how they work
8. Coding and scripting experience in one or more general purpose languages
**Preferred Qualifications:**
Preferred Qualifications:
9. Experience creating software that enables security processes, especially those leveraging AI/ML for automation or augmentation
10. Experience integrating or building AI-powered tools to assist with vulnerability detection, code review, or threat modeling
11. Experience creating software that enables security processes
12. 8+ years of experience finding vulnerabilities in C/C++ code
13. Contributions to the security community (public research, blogging, presentations, bug bounty)
14. Demonstrated ability to collaborate with AI researchers or engineers to apply AI in security workflows
**Public Compensation:**
$184,000/year to $257,000/year + bonus + equity + benefits
**Industry:** Internet
**Equal Opportunity:**
Meta is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Meta participates in the E-Verify program in certain locations, as required by law. Please note that Meta may leverage artificial intelligence and machine learning technologies in connection with applications for employment.
Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at accommodations-ext@fb.com.
$184k-257k yearly 60d+ ago
Looking for a job?
Let Zippia find it for you.
Cyber Security Analyst
Thehivecareers.Co
Security engineer job in Oregon
The Cyber Security Analyst will be responsible for protecting all of the companys hardware, software, and networks from cybercriminals. The analyst's primary role will be to understand the company IT infrastructure in detail in order to detect, evaluate and respond to threats that could potentially breach the network. The Cyber Security Analyst provides specific guidance and coaching to key security areas, e.g. key and encryption, secure software development. In this capacity, a cyber security analyst is part of the proactive work to help shape the tech delivery of the organization.The successful incumbent must possess excellent analytical, communication skills and be solution oriented.
RESPONSIBILITIES AND DUTIES
Responsible for understanding the global threat landscape and acting on threat intelligence.
Conduct cyber security incident response, following industry standards of containment, eradication, recovery and lessons learned.
Manage containment and eradication of threats and remediation of environment during or after an incident, including identifying potential business impact and communication with stakeholders
Manage information security-related breaches
Document event analysis and write reports of incident investigations.
Perform forensic analysis on threat indicators and intelligence insight and identify impact of vulnerabilities
Support the tech delivery in product and services teams with expert security knowledge relevant to a specific technology area or domain (e.g. Key & encryption, secure software development)
Develop the required processes and tools to support the tech delivery teams
Define and develop security guardrails relevant to the tech area/domain
The above responsibilities are indicative of the work required and should not be seen as an exhaustive list.
KNOWLEDGE AND SKILLS
Security solutions (proxy, email gateway, IDS/IPS, FW, SIEM, SOAR, EDR etc.)
Cloud, key and encryption management, SDLC concepts
IT and security architecture
Excellent English skills, both written and spoken.
QUALIFICATIONS AND EXPERIENCE
BSc. in Computer Science, Computer Engineering, Mathematics, Information Security or any related field (or equivalent work experience).
Minimum of 3 years experience in the field
Penetration testing (OWASP, MITRE etc.) experience
Cyber Security certifications (e.g. Security+, GCIA, GCIH, GREM, CISSP, CEH, GCFA)
DESIRED ATTRIBUTES AND BEHAVIOURAL COMPETENCIES
Apply fundamental security concepts to cyber defense and understand business and risk to guide the cyber defense day to day operations.
Manage cases with enterprise SIEM or Incident Management systems
Support network investigations and network monitoring in a SOC environment.
Perform vulnerability assessment and penetration testing
SPECIAL CONDITIONS
N/A
FUNCTIONAL RELATIONSHIPS
External: N/A
Internal: Development team, Tech Lead, CTO
PERFORMANCE CRITERIA
Timely delivery of agreed daily, weekly and monthly KPIs
$86k-119k yearly est. 60d+ ago
Microsoft Cloud Security and Systems Administrator
Family Resource Home Care 4.4
Security engineer job in Boise, ID
The Microsoft Cloud Security and Systems Administrator is responsible for administering and securing the organization's Microsoft 365 environment, Azure cloud services, enterprise endpoints, and related cloud applications. This role blends traditional systems administration with strong security responsibilities, including vulnerability remediation, cloud app governance, risk tracking, and continual improvement of the organization's security posture.
The role is hands-on and operational-supporting configurations, monitoring, troubleshooting, and security workflows across Microsoft cloud services-while also contributing to policies, procedures, and documentation. The position works closely with IT operations, security, compliance, and leadership teams.
Duties and responsibilities
Microsoft 365 Administration & Security
Administer and support Microsoft 365 services with a focus on secure configuration and operations, including:
Intune (device compliance, security baselines, configuration profiles, application deployment)
Entra ID (identity and access management, conditional access, MFA, role administration)
Exchange Online (security settings, anti-spam/anti-malware policies)
Teams (security and compliance configuration)
Defender suite (Defender for Endpoint, Office 365, Identity, Cloud Apps)
Purview (DLP, information governance, sensitivity labels)
Azure Cloud Security & Administration
Support Azure resource access controls, RBAC, logging, and monitoring.
Review Azure Defender / Defender for Cloud alerts and assist with remediation.
Help implement secure configuration for Azure-hosted workloads.
Maintain identity, networking, and platform configurations as needed.
Systems Administration
Assist with endpoint management, including device onboarding, compliance issues, patching coordination, and security baselines.
Support troubleshooting of M365 and Azure-related system issues.
Work with IT operations to ensure systems follow security and configuration standards.
Vulnerability Management
Participate in vulnerability scanning, triage, remediation tracking, and validation.
Coordinate with system owners and IT staff to resolve identified risks.
Document findings and maintain remediation timelines.
Threat Intelligence & Monitoring
Monitor threat feeds and evaluate relevance to the organization's environment.
Review security alerts and logs for anomalous activity.
Recommend actions to improve detection and reduce risk exposure.
Risk Register Maintenance
Maintain and update the organization's security risk register.
Track risk mitigation progress and document status updates.
Cloud Application Security
Support Defender for Cloud Apps (CASB) configurations and monitoring.
Review risky behaviors, shadow IT findings, and suspicious cloud app usage.
Assist with policy development and enforcement for SaaS application governance.
Policies, Procedures & Documentation
Assist with the development, review, and maintenance of security policies and procedures.
Document technical processes and standard operating procedures.
Security Program Improvement
Assist in maturing the organization's cloud and endpoint security controls.
Participate in initiatives focused on identity security, endpoint protection, vulnerability reduction, and cloud governance.
Help implement best practices aligned with NIST, CIS, and Microsoft recommended baselines.
Qualifications
Required Qualifications
3-5 years of experience in systems administration, cloud administration, or IT security roles.
Hands-on experience with:
Microsoft 365 administration
Azure administration
Intune & Entra ID
Defender security tools
Understanding of:
Identity and access management
Endpoint compliance
Cloud security principles
Strong troubleshooting and analytical skills.
Ability to create and maintain documentation.
Strong communication skills with both technical and non-technical audiences.
Preferred Qualifications
Microsoft certifications such as:
SC-900, SC-200, SC-300
MD-102
AZ-900, AZ-104, AZ-500
CompTia certifications such as:
Security+
CySA+
Familiarity with security frameworks (NIST CSF, CIS Controls).
Experience with Defender for Cloud Apps (CASB).
Experience contributing to risk management or compliance initiatives.
Working conditions
This will require time both spent at a computer station for office work.
The usual business hours for this role will be Monday through Friday 8am-5pm, however this role may require some evening and weekends to meet job requirements.
This position will have intermittent supervision.
Physical requirements
Position will require the employee to talk and hear.
Direct reports
This position will not have any direct reports.
Pay Range: $80,000 - $100,000/yr
Benefits & Perks
Medical, Dental, Vision and Prescription Insurance options
3 weeks of Paid Time Off
401k
11 Paid Holidays
Health Savings Account
Employee Assistance Program
Leadership Development Program and career growth opportunities
FRHC is an equal opportunity employer
$80k-100k yearly Auto-Apply 14d ago
IT and Security Systems Administrator (Nuclear critical)
Aalo Atomics
Security engineer job in Idaho Falls, ID
About the role
We're hiring across IT and Security Systems Administration Levels 1-3 (final level determined by experience). You will provide hands‑on Windows, Linux, and MacOS administration across on‑prem and cloud environments, deliver reliable desktop support to a high‑speed engineering org, and partner with IT & SecurityEngineering on larger‑scale, critical projects and hardening efforts. Experience working in or supporting data centers is valued; No formal on‑call rotation exists today; a rotation may be introduced in the future.
What you'll do
Windows & identity administration (on‑prem + cloud)
Administer Active Directory/Group Policy, DNS/DHCP, and Microsoft 365/Entra ID; manage Intune/Endpoint Manager policies and device compliance for critical systems.
Own server/endpoint baseline configuration, access controls, and environment hygiene in a critical systems context.
Desktop support & reliability
Provide L2/L3 support, imaging, break/fix, VIP support, and escalations with clear comms and high customer satisfaction.
Maintain patch/update posture for OS and core applications; drive vulnerability remediation in coordination with Security.
Security collaboration
Apply least‑privilege/RBAC, hardening baselines (e.g., CIS), secure configuration, and change control appropriate to regulated environments with guidance from Engineering.
Operate endpoint protection/EDR and contribute data sources to SIEM in partnership with SecurityEngineering.
Automation & scale
Use PowerShell (and optionally Python) to automate builds, configuration, and repetitive workflows; emphasize configuration‑as‑code and documentation. This is a strong plus.
Data center & Infrastructure support
Periodic racking/stacking, cabling standards, and out‑of‑band management (IPMI/iDRAC/iLO) as needed; asset lifecycle and inventory accuracy.
Qualifications
Required
Hands‑on Windows administration across on‑prem (AD/GPO) and cloud (Entra ID, Intune, Microsoft 365).
Demonstrated desktop support experience (L2/L3), strong troubleshooting, and clear documentation.
Security‑minded approach: least‑privilege, patch discipline, vulnerability remediation, and incident handling fundamentals.
Automation with PowerShell or Python or similar (modules, remoting, error handling) to turn manual tasks into reliable scripts.
Experience in or exposure to data center environments.
Preferred
Background in nuclear, aerospace, or other highly regulated/critical systems environments.
Familiarity with endpoint protection/EDR, SIEM, and enterprise patch/orchestration tools (e.g., Autopilot/Autopatch, WSUS, MECM/SCCM or equivalents).
Virtualization (VMware or Hyper‑V or ProxMox), basic networking (VLANs, firewalls, VPNs), and PKI/certificates.
Infrastructure‑as‑code or config management (PowerShell DSC, Git; Terraform optional) and DR/backup practices.
Physical
If/when datacenter work is required: ability to maneuver equipment safely and follow DC procedures and protocols.
Candidates only, no recruiters or agencies please.
$64k-88k yearly est. 47d ago
Security Systems Administrator
Peraton 3.2
Security engineer job in Portland, OR
Responsibilities is Contingent Upon Award Peraton seeks innovative professionals who thrive in mission-critical environments and are passionate about protecting our national critical infrastructure. This is your chance to make an impact on one of the nation's vital organizations, working alongside leaders in cybersecurity engineering, operations, forensics, threat analysis, data science, and systems integration.
Join Peraton in supporting a large critical infrastructure operator to defend its corporate and operations networks from nation-state attacks, ensure the confidentiality, integrity, and availability of its systems and operations infrastructure, and comply with federal and industry cybersecurity regulation. As a security systems administrator in a state-of-the-art 24-hour Cybersecurity Operations Center (CSOC), you will be part of a dynamic team responsible for securing and maintaining enterprise systems in accordance with established security standards and compliance requirements. This role ensures system availability while enforcing security controls, hardening standards, and compliance requirements. The systems administrator will maintain smooth operation of multi-user CSOC computer systems, including coordination with network engineers. You will monitor and manage system resources, including CPU usage, disk usage, and response times to maintain operating efficiency and perform systems security administration functions, including creating user profiles and accounts. Other duties may include setting up administrator accounts, maintaining system documentation, tuning system performance, installing system wide software and allocating mass storage space and performing installation and providing backup recovery.
Primary Responsibilities:
The Security Systems Administrator will be responsible for:
* In accordance with security baselines, administer, configure, harden, and backup Windows and Linux security applications systems used in the CSOC such as Splunk, Axonius, Palo Alto XSOAR
* Implement and maintain security controls, access controls, and system configurations
* Monitor system logs, alerts, and security events; investigate and escalate issues as needed
* Apply system updates, patches, and configuration changes in a timely and secure manner
* Manage user accounts, permissions, and authentication mechanisms
* Maintain system documentation, security configurations, operational procedures, and backups
* Collaborate with CSOC, infrastructure, and compliance teams
* Prepare shift reports and brief CSOC Manager, infrastructure stakeholders and corporate management on systems' status
* Stay abreast of the latest cyber threats and relevant system updates
Additional Responsibilities:
* Security hardening and configuration
* Support incident response by collecting logs, artifacts, and system data
* Perform vulnerability scanning, assess findings, and support remediation efforts
* Support audits and compliance activities by providing evidence and system details
Qualifications
2 years with BS/BA; 0 years with MS/MA; 6 years with no degree
Required:
* U.S. Citizenship Required
* Must have the ability to obtain / maintain a DOE L Level or DOE Secret clearance
* Degree in computer science, engineering, information technology, or related field
* 2 years of experience with BS/BA; 0 years with MS/MA
* Experience in IT infrastructure and cybersecurity
* Understanding of industry cybersecurity standards such as FISMA, NIST 800 series, and regulatory compliance requirements
* Strong analytical and problem-solving skills to troubleshoot and provide reactive maintenance for system-level issues
* Understanding of TCP/UDP packet capture and analysis
* Excellent verbal and written communications skills
* Ability to communicate technical issues to CSOC team members and management
* Must be available for occasional on-call or after-hours flexibility
Desired:
* Hold technical and/or cybersecurity certification such as GIAC GSEC, GIAC GCIH, CISA SSCP, CompTIA Security+
* A master's degree in computer science, engineering, cybersecurity, information technology, or related field
* Basic understanding of computer networking and routing principles
Peraton Overview
Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can't be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we're keeping people around the world safe and secure.
Target Salary Range
$66,000 - $106,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.
EEO
EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.
$66k-106k yearly Auto-Apply 6d ago
Sr. Security Analyst
Maximus 4.3
Security engineer job in Boise, ID
Description & Requirements Maximus is seeking a qualified Sr. Technical/Security Analyst for multiple projects, current and upcoming. The qualified candidate will be involved in technical/security planning and assessment projects with potentially multiple state agencies. The position requires the candidate to produce/review security relevant documentation, such as system security plans, POA&Ms, assessment plans, etc., produce technical/security analyses, develop estimates, review and contribute to requirements for large systems-planning efforts in the Child Support, Child Welfare and/or Integrated Eligibility public-sector domains. The individual will report directly to a Senior Manager. Maximus is a matrix-managed organization, which means the individual will have secondary reporting relationships to one or more Project Managers, depending on which projects they are assigned.
*This role is remote but requires working standard business hours in the US time zone of the client. This position is contingent upon award. *
Essential Duties and Responsibilities:
- Collaborate with project managers on various initiatives and projects to track progress and provide support as necessary.
- Support leadership in ensuring that the project is delivered to specifications, is on time, and within budget.
- Work closely with management and work groups to create and maintain work plan documents.
- Track the status and due dates of projects.
- Manage relationships with project staff responsible for projects.
- Produce regular weekly and monthly status reports that could include; work plan status, target dates, budget, resource capacity, and other reports as needed.
- Facilitate regular meetings and reviews.
- Adhere to contract requirements and comply with all corporate policies and procedures.
Job Specific Duties and Responsibilities:
-Perform duties independently under the direction of their direct manager and/or Project Managers on specific projects.
-Review project documentation and client materials and provide analysis of technical and security related topics.
-Participate in client meetings and offer observations and insight on technical and security related topics.
-Identify risk areas and potential problems that require proactive attention.
-Review and author artifacts and other project documents and identify potential gaps, inconsistencies, or other issues that may put the project at risk. Such artifacts and documents may include but are not limited to:
*System Security Plan
*Plan of Action and Milestones (POA&M)
*Security Assessment Plan
*Risk Assessment reports
*CMS ARC-AMPE forms and documentation
*Data Conversion and Migration Management Plan
*Deployment and/or roll-out plans
-Perform security assessments, lead security audit and assessment activities, and provide direct security oversight support to assigned clients and projects.
-Identify and escalate to the Senior Manager / Project Manager risks, alternatives, and potential quality issues.
-Attend interviews, focus groups, or other meetings necessary to gather information for project deliverables in accordance with the project scope of work.
-Attend project meetings with the client, subcontractors, project stakeholders, or other Maximus Team members, as requested by the Senior Manager / Project Manager.
-Complete project work in compliance with Maximus standards and procedures.
-Support team to complete assigned responsibilities as outlined in the Project schedule.
-Support all other tasks assigned by Senior Manager / Project Manager.
Minimum Requirements
- Bachelor's degree in related field.
- 7-10 years of relevant professional experience required.
- Equivalent combination of education and experience considered in lieu of degree.
Job Specific Requirements:
-Be available to work during standard client business hours. Projects may involve clients from any US time zone, so it is possible that work outside of the individual's local business hours will be required.
-Bachelor's degree from an accredited college or university, or equivalent work experience.
-7+ years of experience in information security, with at least 3 years of security-compliance work in a regulated industry.
-5+ years of experience working with HIPAA, NIST 800-53 and/or CMS MARS-E or ARC-AMPE security frameworks.
-Familiar with operating systems: Windows, Linux/UNIX, OS/X.
-Familiar with AI tools, capabilities.
-Strong command of cloud computing topics.
-Strong command of agile software development practices as well as waterfall development practices.
-Strong desktop software skills: proficient in MS Office, Excel, Word, Project.
-Ability to explain and communicate technical subjects to non-technical audiences.
-Ability to develop advanced concepts, techniques, and standards requiring a high level of interpersonal and technical skills.
-Ability to work independently.
-Good organizational skills and the ability to manage multiple tasks and deadlines simultaneously.
-Strong interpersonal and team building skills, as well as an understanding of client relationship building are essential.
-Excellent verbal and writing skills and be comfortable working with customers.
-Ability to multi-task with supervision.
-Self-motivated fast learner.
Preferred Skills:
-Prefer a candidate with experience in the Health & Human Services industry, which may include working with programs such as Child Support, Child Welfare, or Integrated Eligibility (SNAP, TANF, and Medicaid).
-Preference for security related certifications, such as the CISSP (Certified Information Systems Security Professional).
EEO Statement
Maximus is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, age, national origin, disability, veteran status, genetic information and other legally protected characteristics.
Pay Transparency
Maximus compensation is based on various factors including but not limited to job location, a candidate's education, training, experience, expected quality and quantity of work, required travel (if any), external market and internal value analysis including seniority and merit systems, as well as internal pay alignment. Annual salary is just one component of Maximus's total compensation package. Other rewards may include short- and long-term incentives as well as program-specific awards. Additionally, Maximus provides a variety of benefits to employees, including health insurance coverage, life and disability insurance, a retirement savings plan, paid holidays and paid time off. Compensation ranges may differ based on contract value but will be commensurate with job duties and relevant work experience. An applicant's salary history will not be used in determining compensation. Maximus will comply with regulatory minimum wage rates and exempt salary thresholds in all instances.
Accommodations
Maximus provides reasonable accommodations to individuals requiring assistance during any phase of the employment process due to a disability, medical condition, or physical or mental impairment. If you require assistance at any stage of the employment process-including accessing job postings, completing assessments, or participating in interviews,-please contact People Operations at **************************.
Minimum Salary
$
120,000.00
Maximum Salary
$
140,000.00
$92k-126k yearly est. Easy Apply 6d ago
Network Security Consultant
Rapinno Tech
Security engineer job in Oregon
McAfee, Microsoft, Cisco AMP, Cylance, DLP, SIEM, WAF, Palo Alto, Tufin , F5, Cisco ISE, Jump Servers, Segmentation
Job Description:-
• 7 to 8 Years' Experience in End Point Protection, Data Protection, Network Security, Network Segmentation, Application Security
• Experience in in Architecture, Design, and Configuration of Network Security Tools - Firewall, Intrusion Prevention, Proxy
• Experience in Architecture, Design, and Configuration of Network Security Tools - Firewall, Intrusion Prevention, Proxy
• Experience in Security Transformation Projects - Design, Document, Build, Transition. SDLC Documentation
• Strong Security credentials with certifications like Security +, CISSP, SANS certification
• Good understanding on the Infra security architecture, Experience in engineering infra security solutions
• Strong oral and written English communications skill ITM Lead and responsible for managing customer expectations and implementation of security solution
$84k-122k yearly est. 60d+ ago
Information Security Analyst I
Beneficial State Bank 3.2
Security engineer job in Portland, OR
TITLE: N/A JOB CODE: FLSA: Exempt SALARY GRADE: 7 CATEGORY: Full-time UNION REPRESENTATION: NA SCHEDULE: Hybrid SUPERVISORY ROLE Y/N: 11.2025 The Information Security Analyst I plays a critical role in safeguarding the organization's systems and information assets. This position supports the development and implementation of security strategies, tools, and guidelines to protect against unauthorized access, data breaches, and system disruptions.
Responsibilities include monitoring and responding to Information Security-related alerts, supporting audit and risk assessment activities, evaluating internal controls, and recommending improvements to enhance security posture.
The analyst assists in migrating non-compliant environments to meet regulatory standards and ensures adherence to data protection laws and banking industry compliance requirements. This role is foundational to maintaining the confidentiality, integrity, and availability of sensitive financial data and supporting the organization's overall cybersecurity framework.
ESSENTIAL DUTIES
Identity and Access Management
Support access provisioning, modification, and termination processes to ensure timely and secure access control.
Conduct administrator activity and user access reviews across IT systems, including privileged access audits and firewall/cloud app usage monitoring.
Maintain asset and access inventories, perform recurring audits of critical systems, and reconcile against endpoint and network tools.
Security Monitoring and Incident Response
Monitor and respond to alerts from SIEM, IDS, firewalls, and endpoint protection systems.
Conduct vulnerability scans, track remediation efforts, and facilitate related meetings.
Maintain readiness for incident response activation, including participation in tabletop exercises.
System Administration and Tool Management
Administration of cloud computing environments, conditional access, and guest provisioning following established best practices.
Manage software controls, browser extensions, and patching processes.
Administer security camera system and ensure system uptime.
Administer Mobile Device Management system.
Threat Intelligence and Continuous Improvement
Stay informed on emerging threats in the banking sector and contribute to threat intelligence reporting.
Research and test new security tools, controls, and AI applications to enhance the Bank's security posture.
Correctly identify true and false positives in alerting systems and tune these systems for continuous improvement.
Security Awareness and Training
Support phishing simulations and training campaigns, track completion, and report metrics to management.
Documentation and Reporting
Log findings, remediation efforts, and audit results in a structured ticketing system.
Assist with vendor management program administration and reporting.
Data Protection and Compliance
Ensure compliance with GLBA, FFIEC, and other applicable regulations through log retention, configuration management oversight, and DLP monitoring.
Administer data classification tools and respond to violations involving PII or sensitive data.
Audit VPN usage and test controls across email, endpoint, and network security platforms.
Completes mandatory compliance training in accordance with established deadlines.
The position performs duties specific to the position and other functions as assigned.
ROLE COMPETENCIES/SKILLS
Attention to Detail
Collaboration & Communication
Diversity & Inclusion
Execution & Ownership
Time Management
Compliance
Innovation
Systems Thinking
Data Analysis & Management
Information Security
Network Operations
Critical Thinking
Consulting
Analytical Thinking
ENVIRONMENT, PHYSICAL & MENTAL ACTIVITIES
The incumbent is in a non-confined office-type setting in which they are free to move about at will. It may include some minor annoyances such as noise, odors, drafts, etc. For Hybrid and Remote roles, work may also be performed away from BSB worksites depending on the position and requirements. For Hybrid/Remote work, employees are required to have an environment when working at home that has a dependable, high-speed internet connection and environment conducive to frequent phone or internet calls where private, confidential or other information is not visible, able to be overheard, or physically or electronically accessible to anyone else.
The incumbent in the course of performing this position spends time writing, typing, speaking, listening, lifting (up to 10 pounds), driving, carrying, seeing (such as close, color and peripheral vision, depth perception and adjusted focus), sitting, pulling, walking, standing, squatting, kneeling and reaching.
The incumbent for this position may operate any or all of the following: personal computer, cellular telephone, printer, fax, and other standard office equipment.
The incumbent in this position must be able to accommodate reading documents or instruments, detailed work, problem solving, customer contact, reasoning, math, language, presentations, verbal and written communication, analytical reasoning, stress, multiple concurrent tasks and constant interruptions.
The work environment characteristics, physical and mental demands described here are representative of those an employee encounters while performing the essential functions of this job.
Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
POSITION REQUIREMENTS
Minimum Qualifications
Bachelor's degree in Information Technology, Cybersecurity, or a related field, or equivalent combination of education and experience.
5 years of professional experience in IT support or related technical roles.
Foundational understanding of cybersecurity principles, including access control, endpoint protection, and network monitoring.
Familiarity with Microsoft 365, Active Directory, and basic system administration tasks.
Ability to conduct audits, manage tickets, and document findings accurately.
Strong analytical and troubleshooting skills.
Effective communication skills and ability to collaborate across departments.
Preferred Qualifications
Bachelor's degree in Information Technology, Cybersecurity, or a related field.
Experience with banking industry compliance standards (e.g., GLBA, FFIEC).
Hands-on experience with security tools such as SIEM, DLP, IDS/IPS, EDR, Email Filtering, and Firewalls.
Exposure to vulnerability management platforms and identity/access management processes.
Familiarity with Microsoft cloud services and Mobile Device Management.
Experience supporting or administering phishing simulations, security awareness programs, or similar efforts.
Knowledge of vendor management platforms and data classification tools.
Management reserves the right to change this position description at any time according to business needs. #LI_Hybrid
$111k-144k yearly est. 12d ago
Engineer, Information Security and Risk
Cardinal Health 4.4
Security engineer job in Boise, ID
Cardinal Health, Inc. (NYSE: CAH) is a global healthcare services and products company. We provide customized solutions for hospitals, healthcare systems, pharmacies, ambulatory surgery centers, clinical laboratories, physician offices and patients in the home. We are a distributor of pharmaceuticals and specialty products; a global manufacturer and distributor of medical and laboratory products; an operator of nuclear pharmacies and manufacturing facilities; and a provider of performance and data solutions. Working to be healthcare's most trusted partner, our customer-centric focus drives continuous improvement and leads to innovative solutions that improve the lives of people every day. With approximately 50,000 employees worldwide, Cardinal Health ranks among the top fifteen in the Fortune 500.
**_Department Overview:_**
**Information Technology** oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value.
**Information Security and Risk** develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure, or destruction. This job family develops system back-up and disaster recovery plans, conducts incident responses, threat management, vulnerability scanning, virus management and intrusion detection as well as completes risk assessments.
**Responsibilities:**
+ **M&A Integration Execution:** Collaborate and engage with IAM Lead and other business partners on planning, design, and execution of IAM integration strategies for M&A activities, ensuring alignment with overall business and security objectives. This includes assessing the IAM landscapes of merging entities to identify challenges and solutions.
+ **Design and Implement Sailpoint IIQ Solutions:** Configure and customize Sailpoint IIQ components (Lifecycel Manager, Compliance Manager etc). Also develop workflows, rules, and connectors for identity governance.
+ **Application integration with Sailpoint IIQ:** Integrate Sailpoint IIQ with enterprise applications, directories and cloud platforms in addition to developing and maintaining connectros for provisioning and de-provisioning.
+ **Sailpoint IIQ Development and Scripting:** Write and maintain BeanShell scripts, Java code and XML configurations, develop customer Sailpoint tasks and workflows.
+ **Identity System Merging & Consolidation:** Manage the complex process of merging disparate identity providers, user directories (e.g., Active Directory, Azure AD, LDAP), and access management systems from acquired companies into the existing infrastructure.
+ **User Lifecycle Management:** Streamline and automate user provisioning, de-provisioning, and periodic access reviews for employees, contractors, and partners across all integrated systems, ensuring smooth onboarding and offboarding during M&A transitions.
+ **Security & Compliance:** Ensure IAM systems and processes comply with regulatory requirements (e.g., GDPR, HIPAA, SOX) and internal security policies, providing auditable records of access activities. Protect against data breaches by ensuring only authorized personnel can access sensitive information.
+ **Technical Troubleshooting & Support:** Troubleshoot, identify, and resolve technical identity and access management-related issues, providing expert support to internal teams and end-users during and after integration.
+ **Collaboration & Communication:** Coordinate cross-functional teams, including Information Security, IT Operations, HR, and Application Development, to ensure effective IAM implementation and seamless integration with business processes. Communicate complex security concepts to technical and non-technical stakeholders.
+ **Documentation & Best Practices:** Develop, review, and maintain comprehensive technical documentation, including architecture diagrams, configuration guides, and operational procedures. Stay up-to-date with IAM best practices, regulatory requirements, and security trends.
**Qualifications**
+ Experience with SailPoint IdentityIQ (IIQ) is a must
+ Experience with SailPoint IIQ Integrations (Workday, Active Directory/LDAP, Webservices, SCIM, JDBC, SAP)
+ Experience implementing Life Cycle Manager (LCM) Configuration workflow tasks that model business functions, including Lifecycle Requests (Role or Entitlement), Lifecycle Events (Joiner, Mover, or Leaver), and LCM Workflow Details (Workflows and Subprocesses)
+ Solid understanding of the SailPoint object model, rules, and policies
+ Experience with both lifecycle manager (LCM) and compliance manager (CM) modules
+ Knowledge of Active Directory, LDAP, Workday, and cloud platforms (GCP, MS Entra ID) is required
+ Proven track record of successful IAM implementations including large scale enterprise deployments.
+ Experience working within regulatory standards and requirements such as, SOX, HIPAA, GDPR etc. is desired.
**Anticipated salary range:** $94,900 - $135,600
**Bonus eligible:** No
**Benefits:** Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
+ Medical, dental and vision coverage
+ Paid time off plan
+ Health savings account (HSA)
+ 401k savings plan
+ Access to wages before pay day with my FlexPay
+ Flexible spending accounts (FSAs)
+ Short- and long-term disability coverage
+ Work-Life resources
+ Paid parental leave
+ Healthy lifestyle programs
**Application window anticipated to close:** 12/20/2025 *if interested in opportunity, please submit application as soon as possible.
The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.
_Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply._
_Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal_ _Opportunity/Affirmative_ _Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law._
_To read and review this privacy notice click_ here (***************************************************************************************************************************
$94.9k-135.6k yearly 60d ago
Information System Security Manager
Booz Allen Hamilton 4.9
Security engineer job in Mountain Home Air Force Base, ID
Key Role:
Supports day-to-day technical aspects of product operational data to identify diagnostic issues in enough detail to determine if the root cause is hardware or software related. Applies specific functional, working, and general industry knowledge. Develops or contributes to solutions to a variety of problems of moderate scope and complexity. Works independently with some guidance. May review or guide the activities of more junior employees.
Basic Qualifications:
5+ years of experience with cybersecurity projects and integrated systems
5+ years of experience with STIGs, NESSUS, and Vulnerability or application scanners for IA use
5+ years of experience with NIST 800-53 and RMF practices, including computer networking and operating systems administration
Knowledge of NISPOM, JSIG, ICD, or eMASS
Ability to generate RMF security documentation to support Interim Authorities to Test (IATTs), Authorizations to Operate (ATOs), Interconnection Security Agreements (ISAs), and Authorities to Connect (ATCs)
Top Secret clearance
Associate's degree
Additional Qualifications:
Experience with managing the authorization status of DoD RMF from step 1 through step 6
Knowledge of continuous monitoring, cyber security risk management, disaster recovery, FISMA compliance, information security architecture, information security auditing, security control assessment, threat modeling, threat management, vulnerability analysis, and vulnerability assessments
DoD 8570 Security+ Certification
Clearance:
Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; Top Secret clearance is required.
Compensation
At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen's benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.
Salary at Booz Allen is determined by various factors, including but not limited to location, the individual's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $77,500.00 to $176,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen's total compensation package for employees. This posting will close within 90 days from the Posting Date.
Identity Statement
As part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.
Work Model
Our people-first culture prioritizes the benefits of flexibility and collaboration, whether that happens in person or remotely.
If this position is listed as remote or hybrid, you'll periodically work from a Booz Allen or client site facility.
If this position is listed as onsite, you'll work with colleagues and clients in person, as needed for the specific role.
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.
$77.5k-176k yearly Auto-Apply 53d ago
Information Security Analyst
Idaho Health Insurance Exchange
Security engineer job in Boise, ID
Description:
Information Security Analyst Reports to: Privacy and Security Officer FLSA status: Exempt
This role is 100% in-office. No hybrid or remote work arrangements are available.
Position Summary
The Information Security Analyst (ISA) will work alongside the Privacy and Security Officer to implement and administer IT security and privacy functions across the organization
Responsibilities (Position may include additional functions not listed)
Primarily responsible for monitoring the IT security infrastructure, assisting with articulating technical security requirements, monitoring the effectiveness of existing IT security framework, making recommendations for enhancements, and raising the level of security awareness.
Manage security information and event management (SIEM) platforms.
Establish controls to support security and privacy policies/procedures and oversee their implementation.
Ensure access to all information systems is controlled, both internally and externally, commensurate with the level of potential risk.
Responsible for responding to information security incidents, to include coordination, root cause analysis, and other security investigation activities.
Facilitate development, design, and implementation of proposed updates, enhancements and new functionality so that enterprise privacy and security is maintained.
Participate in execution of IT security projects, such as risk assessments, security audits, vulnerability scans, and related.
Participate in development of techniques, procedures, and utilities for improving the overall security posture of Your Health Idaho.
Participate as a member of a team providing pertinent security information and input to strategic and tactical planning, initiatives and project planning.
Identify emerging privacy and security practices and technologies to be assimilated, integrated, and introduced within the organization.
Participate in ongoing improvements of system enhancements from an Information Security perspective.
Assess new security threats and vulnerabilities and make recommendations on appropriate avoidance and mitigation strategies.
Stay informed of evolving regulations, statues, threats, risks, technology, and recognized best practices and to regularly coordinate with counterparts at CMS, NIST, SANS and other privacy and security authorities.
Participate in ensuring Idaho's Authority to Operate by administering Your Health Idaho's Authority to Connect (ATC) compliance package.
Perform other duties as assigned.
Qualifications (Required knowledge, skills, abilities, education, experience, etc.)
BA/BS in computer science or business-related field or equivalent
Certified Information Systems Security Professional (CISSP) certification preferred
Minimum three years' related experience to include enterprise IT operations and/or privacy/security responsibilities preferred
Thorough understanding of the CIA Triad (Confidentiality, Integrity, Availability)
Skilled across all areas of Information Security including Operations, Physical, Network, OS, Application Security
Demonstrated project management skills, vendor management, and analytical skills
Ability to balance strict regulations with the ambiguity seen in fast paced operations and a start-up organization
A committed team player with exceptional interpersonal, problem-solving, and communication skills with ability to develop and maintain cooperative and productive work relationships.
Ability to assume responsibility and maintain confidentiality consistent with the values and integrity of YHI.
Physical & Other Requirements
Ability to work in an office environment. Frequent facilitation of meetings or group discussions.
Ability to listen to and understand others as well as ability to give and receive instructions via telephone, electronically, face-to-face, and in writing. Must possess the ability to write and compose correspondence, memorandums, and reports manually and via computer or email.
Occasional lifting or movement of materials up to 25 pounds.
Availability to work additional hours or weekends as projects demand. Some travel may be required.
*The functions described herein are not the only responsibilities and tasks to be performed by the individual occupying this position. The individual will be required to follow any other instructions and to perform any other job-related duties as required by his/her supervisor or manager. Requirements stated herein are minimum levels of knowledge, skills, and/or abilities to qualify for this position. To perform the responsibilities of this position successfully, the individual will possess the abilities and aptitudes to perform each task proficiently. “Ability” means to possess and apply both knowledge and skill.
This includes the essential functions of the job that an incumbent must be able to perform with or without reasonable accommodation.
This document does not create an employment contract, implied or otherwise. The organization maintains “at will” employment. This job description is subject to review and may be revised or updated at management's discretion.
Requirements:
$69k-102k yearly est. 2d ago
Information Security Operations Analyst
Moda Health 4.5
Security engineer job in Portland, OR
Let's do great things, together!
About Moda Founded in Oregon in 1955, Moda is proud to be a company of real people committed to quality. Today, like then, we're focused on building a better future for healthcare. That starts by offering outstanding coverage to our members, compassionate support to our community and comprehensive benefits to our employees. It keeps going by connecting with neighbors to create healthy spaces and places, together. Moda values diversity and inclusion in our workplace. We aim to demonstrate our commitment to diversity through all our business practices and invite applications from candidates that share our commitment to this diversity. Our diverse experiences and perspectives help us become a stronger organization. Let's be better together.
Position Summary
The Operations Analyst is a technical role within Moda's Information Security team and will play a vital role in keeping the organization's proprietary and sensitive information secure. This position works interdepartmentally to investigate issues, identify and correct flaws in security systems, solutions, and programs, and recommend measures to improve the company's overall security posture. Acting as a liaison between Security and IT management, the analyst assists IT strategy and architecture design from a security perspective and identifies issues, concerns, or recommendations as the organization grows its technology infrastructure and processes. This is a FT WFH position.
Pay Range
$70,496.52 - $91,647.55 annually (depending on experience)
*This role may be classified as hourly (non-exempt) depending on the applicant's location. Actual pay is based on qualifications. Applicants who do not exceed the minimum qualifications will only be eligible for the low end of the pay range.
Please fill out an application on our company page, linked below, to be considered for this position.
************************** GK=27768922&refresh=true
Benefits:
Medical, Dental, Vision, Pharmacy, Life, & Disability
401K- Matching
FSA
Employee Assistance Program
PTO and Company Paid Holidays
Required Skills, Experience & Education:
Bachelor's or master's in Computer Science, Information Security, Cybersecurity, or a related field.
5+ years of experience as a security operations analyst or in related fields such as IT audit, enterprise risk management, penetration testing, or red team/incident response.
Experience with common security tools such as SIEM platforms, EDR solutions, and cloud platforms (e.g., Microsoft Azure, Amazon AWS).
Knowledge of Microsoft Azure configuration and management is highly desirable.
3+ years of experience with regulatory compliance and information security management frameworks (e.g., HIPAA, NIST, IS0 27000, or COBIT).
Strong documentation and reporting skills, including the ability to record security events, investigations, and recommendations for technical and non-technical audiences.
Excellent collaboration and communication skills with the ability to influence and work effectively across cross-functional teams.
Industry recognized cybersecurity certification (e.g., CISSP, CISM, CompTIA Security+) preferred.
Primary Functions:
Defend against cybersecurity incidents and identify, analyze, communicate, and contain incidents as they occur.
Monitor systems and networks for security alerts, notifications, and issues including patching and update process issues and investigate and document any security issues or events that may occur.
Own and drive the investigation of security events and other cybersecurity incidents including review, triage, and response to alerts and notifications.
Take a lead role in the documentation of security events and incidents and the assessment of the damage they cause.
Review threat intelligence and analyze the current threat landscape and apply threat analysis to Moda's infrastructure systems and networks to identify and address vulnerabilities or exploitable attack paths.
Build and drive proactive threat hunting programs including detailed threat analysis of exploitable vulnerabilities leading to actionable remediation plans.
Work with IT resources and architects to develop and implement cloud security strategies to facilitate migration of key assets into a public cloud hosted environment.
Advise on installation and configuration of security controls, systems, and software to protect systems and information infrastructure and recommend enhancements based on compliance requirements and industry best practices.
Work with IT and Security leadership to perform tests or support external testing such as network penetration tests, vulnerability testing, and disaster response failover tests to uncover network vulnerabilities.
Advise on installation and configuration of security controls, systems, and software to protect systems and information infrastructure and recommend enhancements based on compliance requirements and industry best practices.
Take a proactive and operational role in creating the best practices for IT security companywide.
Support cybersecurity risk assessment activities.
Work with both Security and IT management to ensure security policies and goals are met in infrastructure and development contexts.
Stay current on IT security trends and news including evolving standards.
Collaborate and communicate effectively with cross functional colleagues at all levels.
Other duties as assigned.
Working Conditions:
Remote office environment with extensive close PC and keyboard use, constant sitting, and frequent phone communication. Must be able to navigate multiple computer screens. A reliable, high-speed, hard-wired internet connection required to support remote or hybrid work. Must be comfortable being on camera for virtual training and meetings. Work in excess of standard workweek, including evenings and occasional weekends, to meet business need.
Internally with all departments. Externally with auditors, clients, technology partners, and other various entities.
Together, we can be more. We can be better.
Moda Health seeks to allow equal employment opportunities for all qualified persons without regard to race, religion, color, age, sex, sexual orientation, national origin, marital status, disability, veteran status or any other status protected by law. This is applicable to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absences, compensation, and training.
For more information regarding accommodations, please direct your questions to Kristy Nehler & Danielle Baker via our ***************************** email.
$70.5k-91.6k yearly Easy Apply 12d ago
Information Security Manager - INTL - UK
Insight Global
Security engineer job in Medford, OR
The Information Security Manager is responsible for designing, implementing, and enhancing a comprehensive technology compliance and risk management program to bolster the organization's security posture. This role involves continuous assessment, reporting, and improvement of technology risks and compliance activities across global operations. You will serve as a pillar of the Information Security Program by driving and managing program activities, ensuring success through collaboration with internal and external partners. In the future you will establish a team and reports, but on the forefront there will be a focus on managing third party and vendor risk with an emphasis on front end offensive security activities and conducting service provider security assessments.
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to ********************.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: ****************************************************
Skills and Requirements
-5+ years of experience managing an enterprise risk register
-5+ years of experience managing InfoSec gathering and reporting metrics
-5+ years of experience spearheading offensive security activities
-5+ years of experience managing policy document and improvement
-5+ years of experience implementing data retention policies
-5+ years of experience managing third party risk management and cyber risk rating tools
-CISSP Certification -Automotive industry experience
$109k-157k yearly est. 60d+ ago
Export Control and Research Security Analyst
Oregon State University 4.4
Security engineer job in Corvallis, OR
Details Information Department VP for Research (RIP) Position Title Officer-Compliance Job Title Export Control and Research Security Analyst Appointment Type Professional Faculty Job Location Corvallis Benefits Eligible Full-Time, benefits eligible Remote or Hybrid option? Yes Job Summary
The Division of Research and Innovation is seeking an Export Control and Research Security Analyst. This is a full-time (1.00 FTE), 12-month, professional faculty position.
The Oregon State University (OSU) Division of Research and Innovation is seeking an Export Control and Research Security Analyst (Analyst) to work under the direction of the Director of Export Controls and Research Security (Director) to ensure OSU's compliance with United States regulations and laws protecting national security, foreign policy, and economic interests. The Analyst will have an exciting opportunity to work within an important, evolving regulatory landscape, supporting the Export Control and Research Security operations, as well as others across the University, to support OSU's mission. The Analyst will assist with communication and dispensation of OSU's Export Control and Research Security programs, requiring the application of OSU policies and procedures while reviewing University activities such as international travel requests, foreign collaborations and visitors, Unmanned System research activities, contract reviews, Technology Control Plan (TCP) drafting and management, and required documentation in congruence with all applicable U.S. export control laws and regulations and research security policies and requirements. The Analyst will work cooperatively with colleagues in the Division of Research and Innovation, partnering with university administrative units, academic departments, and external stakeholders, including Federal partners, to promote compliance while being mindful of the impact on university activities. This is a full-time (1.00 FTE), 12-month professional faculty position.
The Office of Research Integrity, within the Division of Research and Innovation, supports OSU's commitment to exceptional research by collaborating with faculty, staff, and students to help ensure that research is conducted ethically, to high professional standards, and in compliance with regulatory requirements. The Analyst will work alongside a team of compliance and regulatory experts in the Office of Research Integrity and will join our Export Control and Research Security programs.
As one of only three land, sea, space, and sun grant universities in the nation, OSU serves Oregon and the world through our campuses in Corvallis and Bend, our marine research center in Newport, and our award-winning E-campus. With over $470 million in competitive research awards per year, OSU continues to lead the way with practical, impact-driven research that improves lives, protects natural resources, and generates economic growth to transform our future.
The Export Control and Research Security Analyst reports to the Director, Export Controls and Research Security.
Why OSU?
Working for Oregon State University is so much more than a job!
Oregon State University is a dynamic community of dreamers, doers, problem-solvers and change-makers. We don't wait for challenges to present themselves - we seek them out and take them on. We welcome students, faculty and staff from every background and perspective into a community where everyone feels seen and heard. We have deep-rooted mindfulness for the natural world and all who depend on it, and together, we apply knowledge, tools and skills to build a better future for all.
FACTS:
* Top 1.4% university in the world
* More research funding than all public universities in Oregon combined
* 1 of 3 land, sea, space and sun grant universities in the U.S.
* 2 campuses, 11 colleges, 12 experiment stations, and Extension programs in all 36 counties
* 7 cultural resource centers that offer education, celebration and belonging for everyone
* 100+ undergraduate degree programs, 80+ graduate degrees plus hundreds of minor options and certificates
* 35k+ students including more than 2.3k international students and 10k students of color
* 217k+ alumni worldwide
* For more interesting facts about OSU visit: *****************************
Locations:
Oregon State has a statewide presence with campuses in Corvallis and Bend, the OSU Portland Center and the Hatfield Marine Science Center on the Pacific Coast in Newport.
Oregon State's beautiful, historic and state-of-the-art main campus is located in one of America's best college towns. Corvallis is located close to the Pacific Ocean, the Cascade mountains and Oregon wine country. Nestled in the heart of the Willamette Valley, this beautiful city offers miles of mountain biking and hiking trails, a river perfect for boating or kayaking and an eclectic downtown featuring local cuisine, popular events and performances.
Total Rewards Package:
Oregon State University offers a comprehensive benefits package with benefits eligible positions that is designed to meet the needs of employees and their families including:
* Medical, Dental, Vision and Basic Life. OSU pays 95% of premiums for you and your eligible dependents.
* Free confidential mental health and emotional support services, and counseling resources.
* Retirement savings paid by the university.
* A generous paid leave package, including holidays, vacation and sick leave.
* Tuition reduction benefits for you or your qualifying dependents at OSU or the additional six Oregon Public Universities.
* Robust Work Life programs including Dual Career assistance resources, flexible work arrangements, a Family Resource Center, Affinity Groups and an Employee Assistance Program.
* Optional lifestyle benefits such as pet, accident, and critical illness insurance, giving you peace of mind and the support you need to thrive in all aspects of your life.
Oregon State University is deeply committed to the principles of a Health Promoting University. This commitment drives a collaborative approach across OSU's safety and well-being programs, reducing silos and coordinating efforts to enhance employee safety and well-being. By prioritizing resources that support the health of both employees and students, OSU fosters a culture of care and a healthier campus environment where everyone can thrive.
2025 Best Place for Working Parents Designation!
Future and current OSU employees can use the Benefits Calculator to learn more about the full value of the benefits provided at OSU.
Key Responsibilities
45% - Export Compliance
* Primary duties include conducting reviews of university activities for deemed exports, end-use and end-user restrictions, embargoes and sanctions, restricted party screenings, and anti-boycott restrictions in order to determine recommendations for the best course of action to minimize risk to the University, including requests for specific authorization or determinations from the U.S. Government, according to the regulatory requirements and best practices, included within but not limited to the International Traffic in Arms Regulations (ITAR), the Export Administration Regulations (EAR), the Foreign Assets Controls Regulations (FACR), and those administered by the Nuclear Regulatory Commission and Department of Energy.
* Assist in implementing methods to ensure physical as well as deemed export controls are in place. In doing so, the Analyst must understand or be willing to learn a range of commodities controlled by the Commerce Control List and U.S. Munitions List, and how export control regulations and laws apply, etc.
* Work with the Director and researchers to make accurate commodity classification determinations and requests for classification to external parties, including the Department of Commerce and the Department of State.
* Work with the Director and OSU's international programs to ensure compliance with Federal requirements for the issuance and maintenance of visas for visiting scholars and international employees.
* Review foreign travel requests involving OSU-owned equipment or business in order to make recommendations to ensure the safety and security of the faculty, staff, or students and the materials with which they are traveling.
* Review proposals, awards, and agreements for concerns related to export compliance and identify potential risks or compliance issues, and prepare recommendations for the Director.
* Maintain detailed records and the export control record-keeping systems.
25% Research Security Compliance
* Support the Research Security program's outreach and training, including preparing materials, management, liaison with other departments, reviews, and tracking, as well as website maintenance.
* Assist researchers in understanding and navigating reporting requirements, and mitigating risks and assisting in the development and monitoring of any necessary mitigation plans.
* Conduct comprehensive reviews to ensure compliance with institutional and federal requirements, as outlined in National Security Presidential Memorandum No. 33 (NSPM-33) and the CHIPS + Science Act and make recommendations to the Director.
15% - Coordination, Analysis and Communication
* Work closely and collaborate with partners in the Division of Research and Innovation, Procurement, Contract Services, Office of General Counsel, University Information Technology, Office of International Services, and other units, including with researchers and faculty, to identify, understand, apply, and comply with export control and research security obligations to a wide variety of university activities that have implications for operations in international travel and collaborations, physical exports, research agreements, awards, and grants, fieldwork, and international visiting scholar or employee appointments.
* Serve as an effective partner with all OSU units. Build rapport and relationships with key stakeholders as export control and research security compliance involves extensive and ongoing collaboration with internal and external partnerships and working collaboratively in a cross-functional approach on sensitive and complex issues.
* Performs regular assessments of export compliance and research security. Identifies and researches potential compliance risks, gaps, and violations. Makes recommendations to the Director.
10% - Outreach and Training
* Support export control and research security education and outreach for the OSU community, including preparation of materials, record keeping, and assisting with facilitation of the educational programs.
* Assist with the maintenance of a comprehensive website, including up-to-date web-based materials.
* Participate in regional and national organizations that include export controls or research security as a distinct component. Including continuing education and remaining current on issues, policies, regulations, and best practices.
* Serves as the communications manager for the export and drone email accounts.
5% - Other Duties as Assigned by the Director, Export Control and Research Security
* The percentage of time spent on each of the above duties is expected to vary over time and with the demands of the position.
What You Will Need
* Bachelor's degree from an accredited university in International Relations or Business, English, Law, or related field.
* Ability to maintain confidentiality on sensitive subjects.
* To ensure compliance with U.S. export control regulations, the applicant should be eligible for any required authorization from the U.S. Government.
* Interpersonal skills and a collaborative problem solver who can navigate complex issues to completion.
* Demonstrated commitment and ability to promote, enhance, and work with diverse, multi-national, multi-ethnic groups in respectful, productive, and collaborative ways.
* Ability to conduct a comprehensive, detailed analysis of complex Federal regulations and policies.
* Effective communicator; able to convey complex information to varied audiences, both verbally and in writing.
This position is designated as a critical or security-sensitive position; therefore, the incumbent must successfully complete a criminal history check and be determined to be position qualified as per University Standard: 05-010 et seq. Incumbents are required to self-report convictions and those in youth programs may have additional criminal history checks every 24 months.
What We Would Like You to Have
* Self-motivated, life-long learner.
* An advanced professional degree such as an M.S. in a field of Science, Engineering, Business, Law, International Relations, English, or an area of specialization or closely related field.
* Relevant experience in a regulatory or compliance field, or a combination of education, training, and relevant experience, including working within higher education.
* Knowledge of the EAR, ITAR, or OFAC regulations, with the NISP-OM or NIST, or NSPM-33 and the CHIPS + Science Act.
* Experience with export controls, Federal agencies, Federal contractors, labs, universities, or a related area in industry.
* Demonstrated ability to perform under time constraints and manage competing priorities.
Working Conditions / Work Schedule
Primarily based on the Corvallis campus, however, a remote or hybrid work arrangement may be considered for candidates with the appropriate background and experience, as agreed upon with the supervisor.
Domestic and/or international travel may be required on occasion.
Pay Method Salary Pay Period 1st through the last day of the month Pay Date Last working day of the month Recommended Full-Time Salary Range $66,032 - $85,740 Link to Position Description
*********************************************************
Posting Detail Information
Posting Number P09647UF Number of Vacancies 1 Anticipated Appointment Begin Date 03/01/2026 Anticipated Appointment End Date Posting Date 12/29/2025 Full Consideration Date Closing Date 01/25/2026 Indicate how you intend to recruit for this search Competitive / External - open to ALL qualified applicants Special Instructions to Applicants
When applying you will be required to attach the following electronic documents:
1) A resume/CV; and
2) A cover letter indicating how your qualifications and experience have prepared you for this position.
You will also be required to submit the names of at least three professional references, their e-mail addresses and telephone numbers as part of the application process.
For additional information please contact: Gretchen Cuevas at *******************************
We are an Equal Opportunity Employer, including disability, protected veteran, and other protected status.
OSU will conduct a review of the National Sex Offender Public website prior to hire.
Starting salary within the salary range will be commensurate with skills, education, and experience.
OSU is a fair chance employer committed to inclusive hiring. We encourage applications from candidates who bring a wide range of lived experience including involvement with the justice system. This job has "critical or security-sensitive" responsibilities. If you are selected as a finalist, your initial job offer will be contingent upon the results of a job-related pre-employment check (such as a background check, motor vehicle history check, sexual misconduct reference check, etc.). Background check results do not automatically disqualify a candidate. Take a look at our Background Checks website including the for candidates section for more details. If you have questions or concerns about the pre-employment check, please contact OSU's Employee and Labor Relations team at **********************************.
Supplemental Questions
$66k-85.7k yearly Easy Apply 20d ago
CAF - F-15 Mission Planning Support (MPS) Information System Security Manager (ISSM) Support
Blue Force 3.9
Security engineer job in Mountain Home Air Force Base, ID
BlueForce Inc is seeking Mission Planning Support (MPS) F-15 Information System Security Manager (ISSM) Support Specialists in support of the Combat Air Forces (CAF) Fighter Squadron (FS), United States Air Force Warfare Center (USAFWC) flying units, and Air Support Operations Squadrons (ASOS) in Air Combat Command (ACC).
The MPS F-15 ISSM Support position will manage the security aspects of F-15 Training Systems and coordinate with designated stakeholders to ensure cybersecurity protocols of the F-15 Training Systems. Locations are Eglin AFB, FL, Mountain Home AFB, ID, Nellis AFB, NV and Seymour-Johnson AFB, NC.
* Subject to Contract Award*
Tasks the Contractor shall perform include, but are not limited to:
* Manage the security aspects of F-15 Training Systems and support the Government with obtaining and maintaining Interim Authorities to Test (IATTs), Authorizations to Operate (ATOs), Interconnection Security Agreements (ISAs), Authorities to Connect (ATCs), and similar.
* Coordinate with the F-15 Training Systems Program Office (TSPO), Air Force Life Cycle Management Center (AFLCMC) SPO Simulators Division (WNS) at Wright-Patterson Air Force Base (AFB), local Government personnel using the F-15 Training Systems, and the F-15 Training Systems prime contractor to ensure the cybersecurity of the F-15 Training Systems.
* Ensure F-15 Training Systems are operated and maintained IAW security policies and procedures as required by the Joint Special Access Program (SAP) Implementation Guide (JSIG), National Industrial Security Program Operating Manual (NISPOM), and F-15 Training Systems security policy. Support the Government in ensuring F-15 Training Systems and related equipment is disposed of IAW the JSIG, NISPOM, and F-15 Training Systems security policy.
* Ensure all users of F-15 Training Systems have the requisite security clearances, authorization, and need-to-know, and are aware of their security responsibilities before creating accounts and granting them access to the F-15 Training Systems. Perform validation transfers and user account terminations.
* Monitor and report all security-related incidents to the local F-15 Training Devices lead, Security team, and the F-15 TSPO within 24 hours of identifying or being made aware of the incident(s). Perform necessary activities, including media control and proper storage, to prevent spillage/loss of F-15 Training Systems program information. Assist the Government in investigating the root cause incident(s) and developing Corrective Action Plan to prevent recurrence of the incident(s).
* Monitor various systems in the vault to ensure connections with external systems are properly maintained, recovery processes properly restore security features, and all restored features function correctly.
* Collect and review F-15 Training Systems audit, tools, and maintenance logs on a quarterly basis. Document and report any deficiencies in the logs to the F-15 TSPO.
* Conduct quarterly reviews of user and equipment lists for accuracy and currency. Coordinate with the F-15 Training Systems prime contractor to rectify any discrepancies and ensure the lists accurately reflect authorized users and equipment.
* Perform quarterly compliance and vulnerability scans and reviews of the F-15 Training Systems. Document all identified deficiencies and their associated system risks. Submit a report of these findings to the F-15 TSPO and the local government lead for F-15 Training Devices within five business days of completing the scan.
* Perform an annual risk assessment for the F-15 Training Systems. This risk assessment shall be provided to the F-15 TSPO at least 60 calendar days prior to the end of each calendar year.
* Perform an annual inventory of the F-15 Training Systems and associated sub-assemblies. Results of the inventory shall be submitted to the F-15 TSPO at least 30 calendar days prior to the end of the calendar year.
* Conduct quarterly self-assessments/inspections and inform the F-15 TSPO when any authorizations/approvals are projected to expire within six months. Assist with the necessary activities to obtain new authorizations/approvals. If an expiration date is within six months of the F-15E MPS ISSM's start date, the F- 15 MPS ISSM shall inform the F-15 TSPO at least 90 calendar days prior to expiration and assist the Government in obtaining any necessary extensions and/or new authorizations/approvals.
* Coordinate with the Government and the F-15 Training Systems prime contractor to support the creation, updating, and maintenance of authorization/approval packages required per the JSIG/Risk Management Framework (RMF) or the F-15 Training Systems. Ensure all information is accurate, current, complete, and submitted on time to avoid program disruptions. Conduct security surveys at subordinate facilities and gather pertinent security documentation for inclusion into system authorization/approval packages. These packages include, but are not limited to:
* System Security Plan (SSP)
* Plans of Actions and Milestones (POA&Ms)
* Security Control Traceability Matrix (SCTM)
* Continuous Monitoring Plan (CONMON)
* Information Assurance Standard Operating Procedures (IASOP)
* Hardware Lists
* Software Lists
* Support assessments of F-15 Training Systems and their locations by ensuring all necessary documentation, reports, and data are readily available to assessing officials. Assist in addressing any assessing official questions or comments. Report any identified deficiencies to the F-15 TSPO within 14 calendar days of the assessment. Work with the government to address these deficiencies and implement any required mitigation processes or procedures as directed by the assessing officials.
* Review, prepare, track, and update AIS authorization packages and AIS inspections, reports, and responses. Notify the local Government F-15 Training Devices program and the F-15 TSPO (AFLCMC/WNS) when changes occur that might affect AIS authorization. Perform AIS self-inspections and provide security coordination and review of all system test plans. Identify any AIS vulnerabilities, recommend countermeasures, and support their implementation.
* Review, track, and conduct AIS training.
* Maintain AIS security records and prepare Co-Utilization Agreements for network nodes operating in government facilities. Ensure AIS and network nodes are operated, maintained, and disposed of IAW security policies and practices.
* Prepare reports on the status of security safeguards applied to computer systems.
* Support various technical review and inspection teams.
* Assist Government and Contractor organizations with assessment and authorization (A&A) efforts.
* Conduct vault opening or closing procedures as required.
$91k-116k yearly est. 40d ago
Network Engineer
Leidos Holdings Inc. 4.7
Security engineer job in Meridian, ID
Looking for an opportunity to make an impact? Join the Leidos Digital Modernization (DigiMod) team in accelerating information technology in a changing world where we make a difference by modernizing critical networks for our government and commercial customers.
At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success. We empower our teams, contribute to our communities, and operate sustainably. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community. Our Mission, Vision, and Values guide the way we do business.
Are you ready to challenge yourself with an organization that encourages & supports career growth on an enterprise-wide scale? Your greatest work is ahead!
We are in search of a Network Engineer to join our Agile Network Operations Cell supporting Department of the Air Force Air Combat Command's (ACC) base readiness initiative. As a Network Engineer, you will be the primary Base Area Network (BAN) technical expert for a regional grouping of ACC bases representing Leidos with our government customer as well as providing support to other ACC locations. This position is responsible for providing expertise, guidance, and execution support for LAN architecture design, sustainment and system modernizations. Qualified candidates will have in depth technical knowledge and extensive hands-on networking skills as well as strong communication and ability to work as part of an integrated government and contractor team.
The effort supports the ACC Headquarters, but support may be required at any of the following locations: Mountain Home AFB, Beale AFB, Nellis AFB, and Creech AFB; The candidate must be able to travel.
TRAVEL: 50%
Clearance Requirements:
Must be a US Citizen and have at a minimum an Active Secret clearance.
Primary Responsibilities
* Provide overall network engineering support for a broad range of programs including planning, designing, and evaluating various components of the network.
* Provide specifications for network architecture, identify technical capability gaps, evaluate and recommend new technologies to enhance current capabilities, and perform needs assessments.
* Develop, recommend, and implement approved network configurations according to local change management processes
* Duties may include monitoring, installation, cabling/wiring, modification, troubleshooting, repairs and maintenance, testing and servicing of network equipment
* Draft and review technical documentation and communicate requirements.
* Participate in testing to ensure requirements are adequately met
* Develop and facilitate training of the operations team on newly deployed equipment
* Support the project lifecycle for infrastructure and technology changes
* Foster an environment of collaboration with the government customer
3. Basic Qualifications.
* BS degree and 8 - 12 years of prior relevant experience or Masters with 6 - 10 years of prior relevant experience
* Additional years of experience may be accepted in lieu of degree
* Experience with designing, configuring, and troubleshooting Transmission Control Protocol/Internet Protocol (TCP/IP) networks to include hardware (switches, routers), software (operating system), network management systems, network access control (NAC), quality of service (QoS), network services (timing, logging, etc.), and distribution systems (fiber and copper cables and infrastructure).
* Experience with Network Administration, Network Security, Networking Standards, Network Protocols, NIST/FISMA standards and controls.
* Ability to write and verbally communicate complex networking, security and risk-related concepts effectively to both technical and non-technical audiences.
* Must have strong problem-solving, analytical, communication and people skills
* Experience in IPv4 and IPv6 implementation
* Experience with CCC/DNAC and ISE
* Understanding of Zero Trust principles to include network segmentation best practices and experience implementing C2C
Must possess one of the following certifications:
* SecurityX / CASP+
* CCNA
* CCNP Security
* CEH
* GCED
* GCIA
* GCLD
* GDSA
* GFACT
* GICSP
* GSEC
* Security +
* SSCP
Clearance Required:
* Must be a US Citizen and have at a minimum an Active Secret clearance.
Preferred Qualifications.
* Demonstrated experience with an Air Force or Department of War Customer, and/or prior military experience
* Experience designing, implementing, and managing SDN, virtualization, and SDA solutions
* Experience implementing and/or using SIEM/SOAR platforms and other networking tools to include Splunk, Solarwinds, and automation tools
* Experience in network planning, design, and management strategies for an enterprise Wireless LAN including advanced wireless site surveying, security design, and troubleshooting of Wireless LAN design and familiarity with wireless networking components and management tools for Cisco and HPE wireless solutions.
* Familiarity with the Risk Management Framework and the government Authority to Operate process.
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.
Original Posting:
December 5, 2025
For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:
Pay Range $92,300.00 - $166,850.00
The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
$92.3k-166.9k yearly 29d ago
Network Engineer II (T & E)
City of Yonkers, Ny 3.6
Security engineer job in Eagle, ID
THIS IS NOT AN OFFER OF EMPLOYMENT Please download Civil Service Exam Application here. MUNICIPAL CIVIL SERVICE COMMISSION 1 Larkin Center - 2nd Floor - Yonkers, N.Y. 10701 A NON-REFUNDABLE $40.00 APPLICATION FEE IS REQUIRED FOR EACH SEPARATELY NUMBERED EXAMINATION FOR WHICH YOU APPLY
CONTINUOUS EXAMINATION PROGRAM FOR:
NETWORK ENGINEER II
APPOINTING AUTHORITY VACANCIES SALARY RANGE (per annum)
City of Yonkers As they occur $72,495 - 125,849
RESIDENCY REQUIREMENT WAIVED
DISTINGUISHING FEATURES OF THE CLASS:
This position is responsible for the support of the City's computer network. The work includes providing technical assistance, troubleshooting, and equipment repair for users on the network. An incumbent in this position is also responsible for researching and recommending improved hardware and software options and following the latest technological advances in the industry. This position differs from a Network Engineer I in that the incumbent performs duties with greater complexity and with a higher degree of independent judgement. General supervision is received from administrative personnel. Does related work as required.
TYPICAL WORK ACTIVITIES: (Illustrative only)
* Develops and implements configuration management plans to ensure optimization of network connectivity;
* Designs, implements, and configures complex switching environments and wireless networking servers with the ability to support voice and video applications at various levels of security;
* Troubleshoots issues with Voice Over Internet Protocol (VoIP);
* Maintains system performance by anticipating issues and proposing solutions;
* Implements and maintains virtualization at multiple levels across the network;
* Performs regular network monitoring in order to detect possible security breaches;
* Assists with the development of user guides, system standards, and training;
* Installs and configures server operating systems at multiple locations;
* Assists in the development of procedures for the installation, use, and troubleshooting of hardware and software
MINIMUM QUALIFICATIONS: EITHER
A. Possession of a regionally accredited or New York State registered four year college or university with a Bachelor's Degree which includes at least (15) credit hours in computer science courses and two (2) years of experience in the design, implementation, maintenance, and troubleshooting of computer networks; or
B. Possession of a regionally accredited or New York State registered two year college or university with an Associate's Degree which includes at least (15) credit hours in computer science courses and four (4) years of experience as described in (A); or
C. Graduation from high school or possession of a High School Equivalency Diploma and six (6) years of experience as described in (A) and (B); or
D. An equivalent combination of education/training and experience as defined by the limits of (A) through (C).
NOTE:
Your degree must have been awarded by a college or university accredited by a regional, national, or specialized agency recognized as an accrediting agency by the U.S. Department of Education/U.S. Secretary of Education. If your degree was awarded by an educational institution outside the United States and its territories, you must provide independent verification of equivalency. A list of acceptable companies who provide this service can be found on the Internet at ******************************************* You must pay the required evaluation fee."
SPECIAL REQUIREMENTS:
Possession of a Class D Driver's License valid in the State of New York.
PROMOTIONAL:
One (1) year permanent competitive status currently holding position of Network Engineer I.
RATED EVALUATION OF TRAINING AND EXPERIENCE:
You will complete a questionnaire that asks for specific information on your information technology education (formal degrees, IT-related training courses, certifications) and experience. You will also be asked to briefly describe a significant achievement in each of the job's areas and to provide the name and contact information for someone who can verify your information. The information you provide about your experience will be rated against the following areas:
* Network Administration
* Data communications
$72.5k-125.8k yearly 60d+ ago
Information Security Analyst
Idaho Health Insurance Exchange
Security engineer job in Boise, ID
Full-time Description
Information Security Analyst Reports to: Privacy and Security Officer FLSA status: Exempt
This role is 100% in-office. No hybrid or remote work arrangements are available.
Position Summary
The Information Security Analyst (ISA) will work alongside the Privacy and Security Officer to implement and administer IT security and privacy functions across the organization
Responsibilities (Position may include additional functions not listed)
Primarily responsible for monitoring the IT security infrastructure, assisting with articulating technical security requirements, monitoring the effectiveness of existing IT security framework, making recommendations for enhancements, and raising the level of security awareness.
Manage security information and event management (SIEM) platforms.
Establish controls to support security and privacy policies/procedures and oversee their implementation.
Ensure access to all information systems is controlled, both internally and externally, commensurate with the level of potential risk.
Responsible for responding to information security incidents, to include coordination, root cause analysis, and other security investigation activities.
Facilitate development, design, and implementation of proposed updates, enhancements and new functionality so that enterprise privacy and security is maintained.
Participate in execution of IT security projects, such as risk assessments, security audits, vulnerability scans, and related.
Participate in development of techniques, procedures, and utilities for improving the overall security posture of Your Health Idaho.
Participate as a member of a team providing pertinent security information and input to strategic and tactical planning, initiatives and project planning.
Identify emerging privacy and security practices and technologies to be assimilated, integrated, and introduced within the organization.
Participate in ongoing improvements of system enhancements from an Information Security perspective.
Assess new security threats and vulnerabilities and make recommendations on appropriate avoidance and mitigation strategies.
Stay informed of evolving regulations, statues, threats, risks, technology, and recognized best practices and to regularly coordinate with counterparts at CMS, NIST, SANS and other privacy and security authorities.
Participate in ensuring Idaho's Authority to Operate by administering Your Health Idaho's Authority to Connect (ATC) compliance package.
Perform other duties as assigned.
Qualifications (Required knowledge, skills, abilities, education, experience, etc.)
BA/BS in computer science or business-related field or equivalent
Certified Information Systems Security Professional (CISSP) certification preferred
Minimum three years' related experience to include enterprise IT operations and/or privacy/security responsibilities preferred
Thorough understanding of the CIA Triad (Confidentiality, Integrity, Availability)
Skilled across all areas of Information Security including Operations, Physical, Network, OS, Application Security
Demonstrated project management skills, vendor management, and analytical skills
Ability to balance strict regulations with the ambiguity seen in fast paced operations and a start-up organization
A committed team player with exceptional interpersonal, problem-solving, and communication skills with ability to develop and maintain cooperative and productive work relationships.
Ability to assume responsibility and maintain confidentiality consistent with the values and integrity of YHI.
Physical & Other Requirements
Ability to work in an office environment. Frequent facilitation of meetings or group discussions.
Ability to listen to and understand others as well as ability to give and receive instructions via telephone, electronically, face-to-face, and in writing. Must possess the ability to write and compose correspondence, memorandums, and reports manually and via computer or email.
Occasional lifting or movement of materials up to 25 pounds.
Availability to work additional hours or weekends as projects demand. Some travel may be required.
*The functions described herein are not the only responsibilities and tasks to be performed by the individual occupying this position. The individual will be required to follow any other instructions and to perform any other job-related duties as required by his/her supervisor or manager. Requirements stated herein are minimum levels of knowledge, skills, and/or abilities to qualify for this position. To perform the responsibilities of this position successfully, the individual will possess the abilities and aptitudes to perform each task proficiently. “Ability” means to possess and apply both knowledge and skill.
This includes the essential functions of the job that an incumbent must be able to perform with or without reasonable accommodation.
This document does not create an employment contract, implied or otherwise. The organization maintains “at will” employment. This job description is subject to review and may be revised or updated at management's discretion.
Salary Description $86,400 - 94,900
$86.4k-94.9k yearly 5d ago
Information Security Operations Analyst
Moda Health 4.5
Security engineer job in Portland, OR
Job Description
Let's do great things, together!
About Moda Founded in Oregon in 1955, Moda is proud to be a company of real people committed to quality. Today, like then, we're focused on building a better future for healthcare. That starts by offering outstanding coverage to our members, compassionate support to our community and comprehensive benefits to our employees. It keeps going by connecting with neighbors to create healthy spaces and places, together. Moda values diversity and inclusion in our workplace. We aim to demonstrate our commitment to diversity through all our business practices and invite applications from candidates that share our commitment to this diversity. Our diverse experiences and perspectives help us become a stronger organization. Let's be better together.
Position Summary
The Operations Analyst is a technical role within Moda's Information Security team and will play a vital role in keeping the organization's proprietary and sensitive information secure. This position works interdepartmentally to investigate issues, identify and correct flaws in security systems, solutions, and programs, and recommend measures to improve the company's overall security posture. Acting as a liaison between Security and IT management, the analyst assists IT strategy and architecture design from a security perspective and identifies issues, concerns, or recommendations as the organization grows its technology infrastructure and processes. This is a FT WFH position.
Pay Range
$70,496.52 - $91,647.55 annually (depending on experience)
*This role may be classified as hourly (non-exempt) depending on the applicant's location. Actual pay is based on qualifications. Applicants who do not exceed the minimum qualifications will only be eligible for the low end of the pay range.
Please fill out an application on our company page, linked below, to be considered for this position.
************************** GK=27768922&refresh=true
Benefits:
Medical, Dental, Vision, Pharmacy, Life, & Disability
401K- Matching
FSA
Employee Assistance Program
PTO and Company Paid Holidays
Required Skills, Experience & Education:
Bachelor's or master's in Computer Science, Information Security, Cybersecurity, or a related field.
5+ years of experience as a security operations analyst or in related fields such as IT audit, enterprise risk management, penetration testing, or red team/incident response.
Experience with common security tools such as SIEM platforms, EDR solutions, and cloud platforms (e.g., Microsoft Azure, Amazon AWS).
Knowledge of Microsoft Azure configuration and management is highly desirable.
3+ years of experience with regulatory compliance and information security management frameworks (e.g., HIPAA, NIST, IS0 27000, or COBIT).
Strong documentation and reporting skills, including the ability to record security events, investigations, and recommendations for technical and non-technical audiences.
Excellent collaboration and communication skills with the ability to influence and work effectively across cross-functional teams.
Industry recognized cybersecurity certification (e.g., CISSP, CISM, CompTIA Security+) preferred.
Primary Functions:
Defend against cybersecurity incidents and identify, analyze, communicate, and contain incidents as they occur.
Monitor systems and networks for security alerts, notifications, and issues including patching and update process issues and investigate and document any security issues or events that may occur.
Own and drive the investigation of security events and other cybersecurity incidents including review, triage, and response to alerts and notifications.
Take a lead role in the documentation of security events and incidents and the assessment of the damage they cause.
Review threat intelligence and analyze the current threat landscape and apply threat analysis to Moda's infrastructure systems and networks to identify and address vulnerabilities or exploitable attack paths.
Build and drive proactive threat hunting programs including detailed threat analysis of exploitable vulnerabilities leading to actionable remediation plans.
Work with IT resources and architects to develop and implement cloud security strategies to facilitate migration of key assets into a public cloud hosted environment.
Advise on installation and configuration of security controls, systems, and software to protect systems and information infrastructure and recommend enhancements based on compliance requirements and industry best practices.
Work with IT and Security leadership to perform tests or support external testing such as network penetration tests, vulnerability testing, and disaster response failover tests to uncover network vulnerabilities.
Advise on installation and configuration of security controls, systems, and software to protect systems and information infrastructure and recommend enhancements based on compliance requirements and industry best practices.
Take a proactive and operational role in creating the best practices for IT security companywide.
Support cybersecurity risk assessment activities.
Work with both Security and IT management to ensure security policies and goals are met in infrastructure and development contexts.
Stay current on IT security trends and news including evolving standards.
Collaborate and communicate effectively with cross functional colleagues at all levels.
Other duties as assigned.
Working Conditions:
Remote office environment with extensive close PC and keyboard use, constant sitting, and frequent phone communication. Must be able to navigate multiple computer screens. A reliable, high-speed, hard-wired internet connection required to support remote or hybrid work. Must be comfortable being on camera for virtual training and meetings. Work in excess of standard workweek, including evenings and occasional weekends, to meet business need.
Internally with all departments. Externally with auditors, clients, technology partners, and other various entities.
Together, we can be more. We can be better.
Moda Health seeks to allow equal employment opportunities for all qualified persons without regard to race, religion, color, age, sex, sexual orientation, national origin, marital status, disability, veteran status or any other status protected by law. This is applicable to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absences, compensation, and training.
For more information regarding accommodations, please direct your questions to Kristy Nehler & Danielle Baker via our ***************************** email.
$70.5k-91.6k yearly Easy Apply 13d ago
Export Control and Research Security Analyst
Oregon State University 4.4
Security engineer job in Corvallis, OR
Details Information Department VP for Research (RIP) Title Officer-Compliance Job Title Export Control and Research Security Analyst Appointment Type Professional Faculty Benefits Eligible Full-Time, benefits eligible
Remote or Hybrid option? Yes
Job Summary
The Division of Research and Innovation is seeking an Export Control and Research Security Analyst. This is a full-time (1.00 FTE ), 12-month, professional faculty position.
The Oregon State University ( OSU ) Division of Research and Innovation is seeking an Export Control and Research Security Analyst (Analyst) to work under the direction of the Director of Export Controls and Research Security (Director) to ensure OSU's compliance with United States regulations and laws protecting national security, foreign policy, and economic interests. The Analyst will have an exciting opportunity to work within an important, evolving regulatory landscape, supporting the Export Control and Research Security operations, as well as others across the University, to support OSU's mission. The Analyst will assist with communication and dispensation of OSU's Export Control and Research Security programs, requiring the application of OSU policies and procedures while reviewing University activities such as international travel requests, foreign collaborations and visitors, Unmanned System research activities, contract reviews, Technology Control Plan ( TCP ) drafting and management, and required documentation in congruence with all applicable U.S. export control laws and regulations and research security policies and requirements. The Analyst will work cooperatively with colleagues in the Division of Research and Innovation, partnering with university administrative units, academic departments, and external stakeholders, including Federal partners, to promote compliance while being mindful of the impact on university activities. This is a full-time (1.00 FTE ), 12-month professional faculty position.
The Office of Research Integrity, within the Division of Research and Innovation, supports OSU's commitment to exceptional research by collaborating with faculty, staff, and students to help ensure that research is conducted ethically, to high professional standards, and in compliance with regulatory requirements. The Analyst will work alongside a team of compliance and regulatory experts in the Office of Research Integrity and will join our Export Control and Research Security programs.
As one of only three land, sea, space, and sun grant universities in the nation, OSU serves Oregon and the world through our campuses in Corvallis and Bend, our marine research center in Newport, and our award-winning E-campus. With over $470 million in competitive research awards per year, OSU continues to lead the way with practical, impact-driven research that improves lives, protects natural resources, and generates economic growth to transform our future.
The Export Control and Research Security Analyst reports to the Director, Export Controls and Research Security.
Why OSU?
Working for Oregon State University is so much more than a job!
Oregon State University is a dynamic community of dreamers, doers, problem-solvers and change-makers. We don't wait for challenges to present themselves - we seek them out and take them on. We welcome students, faculty and staff from every background and perspective into a community where everyone feels seen and heard. We have deep-rooted mindfulness for the natural world and all who depend on it, and together, we apply knowledge, tools and skills to build a better future for all.
FACTS :
-Top 1.4% university in the world
-More research funding than all public universities in Oregon combined
-1 of 3 land, sea, space and sun grant universities in the U.S.
-2 campuses, 11 colleges, 12 experiment stations, and Extension programs in all 36 counties
-7cultural resource centers (********************************************************************** that offer education, celebration and belonging for everyone
-100+ undergraduate degree programs, 80+ graduate degrees plus hundreds of minor options and certificates
-35k+ students including more than 2.3k international students and 10k students of color
-217k+ alumni worldwide
-For more interesting facts about OSU visit:*****************************
Locations:
Oregon State has a statewide presence with campuses in Corvallis and Bend, the OSU Portland Center and the Hatfield Marine Science Center on the Pacific Coast in Newport.
Oregon State's beautiful, historic and state-of-the-art main campus is located in one of America's best college towns. Corvallis is located close to the Pacific Ocean, the Cascade mountains and Oregon wine country. Nestled in the heart of the Willamette Valley, this beautiful city offers miles of mountain biking and hiking trails, a river perfect for boating or kayaking and an eclectic downtown featuring local cuisine, popular events and performances.
Total Rewards Package:
Oregon State University offers acomprehensive benefits package (********************************************************* with benefits eligible positions that is designed to meet the needs of employees and their families including:
-Medical, Dental, Vision and Basic Life. OSU pays 95% of premiums for you and your eligible dependents.
-Free confidential mental health and emotional support services, and counseling resources.
-Retirement savings paid by the university.
-A generous paid leave package, including holidays, vacation and sick leave.
-Tuition reduction benefits for you or your qualifying dependents at OSU or the additional six Oregon Public Universities.
-Robust Work Life programs including Dual Career assistance resources, flexible work arrangements, a Family Resource Center, Affinity Groups and an Employee Assistance Program.
-Optional lifestyle benefits such as pet, accident, and critical illness insurance, giving you peace of mind and the support you need to thrive in all aspects of your life.
Oregon State University is deeply committed to the principles of a Health Promoting University. This commitment drives a collaborative approach across OSU's safety and well-being programs, reducing silos and coordinating efforts to enhance employee safety and well-being. By prioritizing resources that support the health of both employees and students, OSU fosters a culture of care and a healthier campus environment where everyone can thrive.
2025 Best Place for Working Parents Designation! (***********************************************
Future and current OSU employees can use the Benefits Calculator (********************************************************************** to learn more about the full value of the benefits provided at OSU .
Key Responsibilities
45% - Export Compliance
+ Primary duties include conducting reviews of university activities for deemed exports, end-use and end-user restrictions, embargoes and sanctions, restricted party screenings, and anti-boycott restrictions in order to determine recommendations for the best course of action to minimize risk to the University, including requests for specific authorization or determinations from the U.S. Government, according to the regulatory requirements and best practices, included within but not limited to the International Traffic in Arms Regulations ( ITAR ), the Export Administration Regulations ( EAR ), the Foreign Assets Controls Regulations ( FACR ), and those administered by the Nuclear Regulatory Commission and Department of Energy.
+ Assist in implementing methods to ensure physical as well as deemed export controls are in place. In doing so, the Analyst must understand or be willing to learn a range of commodities controlled by the Commerce Control List and U.S. Munitions List, and how export control regulations and laws apply, etc.
+ Work with the Director and researchers to make accurate commodity classification determinations and requests for classification to external parties, including the Department of Commerce and the Department of State.
+ Work with the Director and OSU's international programs to ensure compliance with Federal requirements for the issuance and maintenance of visas for visiting scholars and international employees.
+ Review foreign travel requests involving OSU -owned equipment or business in order to make recommendations to ensure the safety and security of the faculty, staff, or students and the materials with which they are traveling.
+ Review proposals, awards, and agreements for concerns related to export compliance and identify potential risks or compliance issues, and prepare recommendations for the Director.
+ Maintain detailed records and the export control record-keeping systems.
25% Research Security Compliance
+ Support the Research Security program's outreach and training, including preparing materials, management, liaison with other departments, reviews, and tracking, as well as website maintenance.
+ Assist researchers in understanding and navigating reporting requirements, and mitigating risks and assisting in the development and monitoring of any necessary mitigation plans.
+ Conduct comprehensive reviews to ensure compliance with institutional and federal requirements, as outlined in National Security Presidential Memorandum No. 33 ( NSPM -33) and the CHIPS + Science Act and make recommendations to the Director.
15% - Coordination, Analysis and Communication
+ Work closely and collaborate with partners in the Division of Research and Innovation, Procurement, Contract Services, Office of General Counsel, University Information Technology, Office of International Services, and other units, including with researchers and faculty, to identify, understand, apply, and comply with export control and research security obligations to a wide variety of university activities that have implications for operations in international travel and collaborations, physical exports, research agreements, awards, and grants, fieldwork, and international visiting scholar or employee appointments.
+ Serve as an effective partner with all OSU units. Build rapport and relationships with key stakeholders as export control and research security compliance involves extensive and ongoing collaboration with internal and external partnerships and working collaboratively in a cross-functional approach on sensitive and complex issues.
+ Performs regular assessments of export compliance and research security. Identifies and researches potential compliance risks, gaps, and violations. Makes recommendations to the Director.
10% - Outreach and Training
+ Support export control and research security education and outreach for the OSU community, including preparation of materials, record keeping, and assisting with facilitation of the educational programs.
+ Assist with the maintenance of a comprehensive website, including up-to-date web-based materials.
+ Participate in regional and national organizations that include export controls or research security as a distinct component. Including continuing education and remaining current on issues, policies, regulations, and best practices.
+ Serves as the communications manager for the export and drone email accounts.
5% - Other Duties as Assigned by the Director, Export Control and Research Security
+ The percentage of time spent on each of the above duties is expected to vary over time and with the demands of the position.
What You Will Need
+ Bachelor's degree from an accredited university in International Relations or Business, English, Law, or related field.
+ Ability to maintain confidentiality on sensitive subjects.
+ To ensure compliance with U.S. export control regulations, the applicant should be eligible for any required authorization from the U.S. Government.
+ Interpersonal skills and a collaborative problem solver who can navigate complex issues to completion.
+ Demonstrated commitment and ability to promote, enhance, and work with diverse, multi-national, multi-ethnic groups in respectful, productive, and collaborative ways.
+ Ability to conduct a comprehensive, detailed analysis of complex Federal regulations and policies.
+ Effective communicator; able to convey complex information to varied audiences, both verbally and in writing.
This position is designated as a critical or security-sensitive position; therefore, the incumbent must successfully complete a criminal history check and be determined to be position qualified as per University Standard: 05-010 et seq. Incumbents are required to self-report convictions and those in youth programs may have additional criminal history checks every 24 months.
What We Would Like You to Have
+ Self-motivated, life-long learner.
+ An advanced professional degree such as an M.S. in a field of Science, Engineering, Business, Law, International Relations, English, or an area of specialization or closely related field.
+ Relevant experience in a regulatory or compliance field, or a combination of education, training, and relevant experience, including working within higher education.
+ Knowledge of the EAR , ITAR , or OFAC regulations, with the NISP -OM or NIST , or NSPM -33 and the CHIPS + Science Act.
+ Experience with export controls, Federal agencies, Federal contractors, labs, universities, or a related area in industry.
+ Demonstrated ability to perform under time constraints and manage competing priorities.
Working Conditions / Work Schedule
Primarily based on the Corvallis campus, however, a remote or hybrid work arrangement may be considered for candidates with the appropriate background and experience, as agreed upon with the supervisor.
Domestic and/or international travel may be required on occasion.
Pay Method Salary
Pay Period 1st through the last day of the month
Pay Date Last working day of the month
Recommended Full-Time Salary Range $66,032 - $85,740
Link to Position Description
**********************************************************
Posting Detail Information
Posting Number P09647UF
Number of Vacancies 1
Anticipated Appointment Begin Date 03/01/2026
Anticipated Appointment End Date
Posting Date 12/29/2025
Full Consideration Date
Closing Date 01/25/2026
Indicate how you intend to recruit for this search Competitive / External - open to ALL qualified applicants
Special Instructions to Applicants
When applying you will be required to attach the following electronic documents:
1) A resume/CV; and
2) A cover letter indicating how your qualifications and experience have prepared you for this position.
You will also be required to submit the names of at least three professional references, their e-mail addresses and telephone numbers as part of the application process.
For additional information please contact: Gretchen Cuevas at *******************************
We are an Equal Opportunity Employer, including disability, protected veteran, and other protected status.
OSU will conduct a review of the National Sex Offender Public website prior to hire.
Starting salary within the salary range will be commensurate with skills, education, and experience.
OSU is a fair chance employer committed to inclusive hiring. We encourage applications from candidates who bring a wide range of lived experience including involvement with the justice system. This job has "critical or security-sensitive" responsibilities. If you are selected as a finalist, your initial job offer will be contingent upon the results of a job-related pre-employment check (such as a background check, motor vehicle history check, sexual misconduct reference check, etc.). Background check results do not automatically disqualify a candidate. Take a look at our Background Checks (***************************************************** website including thefor candidates (********************************************** section for more details. If you have questions or concerns about the pre-employment check, please contact OSU's Employee and Labor Relations team ************************************.
Supplemental Questions
Read More at: ********************************************
OSU commits to inclusive excellence by advancing equity and diversity in all that we do. We are an Affirmative Action/Equal Opportunity employer, and particularly encourage applications from members of historically underrepresented racial/ethnic groups, women, individuals with disabilities, veterans, LGBTQ community members, and others who demonstrate the ability to help us achieve our vision of a diverse and inclusive community.
How much does a security engineer earn in Nampa, ID?
The average security engineer in Nampa, ID earns between $71,000 and $132,000 annually. This compares to the national average security engineer range of $77,000 to $141,000.