SecurityEngineer II
Assignment Length: 6 month W2 Assignment (possible extension)
Pay Rate: $53- $59/ HR
About the Organization
This organization is a leading healthcare provider delivering patient-centered care through advanced clinical services, research, and education. The technology and security teams support critical healthcare systems that enable safe, compliant, and reliable patient care operations.
Position Summary
The SecurityEngineer II provides operational, administrative, and project support for the Information Security team. This role is responsible for protecting information systems and organizational data from unauthorized access, misuse, or destruction. The position supports network and system security, incident response, monitoring, reporting, policy development, and implementation of security solutions. The SecurityEngineer II serves as an escalation point for complex security issues and collaborates closely with senior engineers and cross-functional IT teams.
Key Responsibilities
Implement and monitor security measures to protect computer systems, networks, and organizational data
Perform technical analysis, installation, maintenance, and modification of security systems and software
Monitor, analyze, and report on system and security performance
Participate in security solution implementations and system hardening initiatives
Investigate, respond to, mitigate, and remediate security incidents using established incident response protocols
Support the full incident lifecycle including detection, response, mitigation, reporting, recovery, remediation, and lessons learned
Provide escalation support to senior engineers for complex security issues
Assist in the development and maintenance of security policies, standards, procedures, and documentation
Configure, manage, and troubleshoot security infrastructure devices
Identify and define system security requirements
Develop and recommend short- and long-term security strategies and enhancements
Create and maintain standard operating procedures and security documentation
Prepare reports documenting security incidents and impact assessments
Collaborate with other IT and Information Security teams on incidents, remediation, and security initiatives
Provide after-hours and weekend support as needed in a 24x7 incident response environment
Perform other duties as assigned
Required Education
Associate's degree in Computer Science or a related field
OR an equivalent combination of education and experience demonstrating the ability to perform the role successfully
Required Experience
Minimum of 5 years of experience in Information Security
Healthcare industry experience
Experience with PCI, HIPAA, and NIST frameworks
Proven experience as a system securityengineer or information securityengineer
Hands-on experience maintaining and supporting security systems
Knowledge of security control concepts including physical, logical, and administrative controls
Required Knowledge, Skills, and Abilities
Strong technical knowledge of operating system security
Hands-on experience with security tools and systems such as:
Intrusion detection and prevention systems
Anti-virus and endpoint protection solutions
Authentication and access control systems
Log management and monitoring tools
Content filtering solutions
Solid understanding of network security concepts and networking technologies
Ability to analyze security events and respond effectively to incidents
Please submit your resume in Word or PDF format to be considered.
$53-59 hourly 2d ago
Looking for a job?
Let Zippia find it for you.
Network Engineer (Trustsec)
Prosum 4.4
Security engineer job in Beverly Hills, CA
Senior Network Engineer (Cisco / Enterprise)
Pay Range: $75/hour to $81/hour
We are seeking a highly experienced Senior Network Engineer to support, design, and secure large-scale enterprise network environments. This role is hands-on and strategic, requiring deep expertise in Cisco networking, security architecture, and full lifecycle network implementations. Candidates must have extensive experience working in complex enterprise environments with 5,000-15,000+ network nodes.
Responsibilities
Design, architect, and provide engineering support for enterprise network and systems infrastructure
Develop and implement network standards, policies, and procedures
Serve as a technical mentor for Network Engineers and provide team leadership
Perform maintenance, upgrades, and lifecycle management of:
Routers, switches, firewalls
Remote access systems
Network management and monitoring systems
Monitor network connectivity and ensure high-quality, reliable data transmission
Provide technical support across LAN, WAN, MAN, wireless, security, and cloud-based networks
Manage day-to-day network operations and ensure adherence to enterprise SLAs
Evaluate new applications and technologies for impact on existing infrastructure and security posture
Coordinate and support network vulnerability assessments and penetration testing efforts
Implement remediation strategies and threat mitigation solutions
Collaborate with project managers, IT teams, vendors, contractors, and consultants
Participate in security policy creation, reviews, and compliance initiatives
Design, implement, and maintain perimeter and internal network security systems
Own and secure enterprise data networks, including:
Network perimeter
Remote access
WAN
Data centers
Wired and wireless environments
Identify, troubleshoot, and resolve complex network hardware and software issues
Promote governance, compliance, scalability, performance, and reliability across the network infrastructure
Required Qualifications
10+ years of experience as a Senior Network Engineer in large enterprise environments
Proven hands-on experience with Cisco SDA and TrustSec (full lifecycle implementation experience strongly preferred)
Extensive experience supporting enterprise networks with 5,000-15,000+ nodes
10+ years of hands-on configuration and support of Cisco routers, switches, and related infrastructure
Experience in complex, multi-platform, multi-protocol network environments
Strong background in planning, designing, and documenting Cisco-based enterprise networks
Expertise in:
LAN, WAN, MAN, Metro Ethernet
Routing, topology, QoS, multicast, and network protocols
MPLS, NAC, VPN, remote access solutions
Firewalls, IDS/IPS, security devices, NAT/PAT
ACS, Adaptive Authentication, SecurID
RADIUS / LDAP / TACACS
Wireless networking
Packet-level network traffic analysis expertise
Experience with network monitoring, analysis, and management tools
Strong project management, leadership, and interpersonal skills
Ability to work independently while mentoring and leading other engineers
Preferred:
Healthcare industry experience
$75 hourly 1d ago
Critical Systems Engineer
Sotalent
Security engineer job in Los Angeles, CA
📍
Los Angeles, CA (On-site)
About the Role
Seeking an experienced Critical Systems Engineer to support the design, development, and optimization of engineering projects and critical utilities in a regulated manufacturing environment. This position involves providing technical expertise, overseeing small-scale projects, and driving system reliability and energy efficiency improvements.
Key Responsibilities
Act independently to execute approved projects and recommend process or design improvements.
Serve as the Subject Matter Expert (SME) for critical utilities and related systems.
Review and evaluate process and equipment design drawings, ensuring compliance with industry and internal standards.
Apply engineering tools such as FMEA, process modeling, and statistical process control (SPC) to solve operational challenges.
Lead energy optimization initiatives and drive sustainable facility performance.
Manage contractors, coordinate project activities, and support maintenance and troubleshooting of systems.
Ensure compliance with safety regulations and environmental standards at the city, state, and federal levels.
Qualifications
Bachelor's degree in Chemical or Mechanical Engineering (required).
3+ years of experience in a pharmaceutical, biotechnology, or food processing facility.
Strong understanding of GMP principles and critical systems (RO, WFI).
Proven project management skills with experience coordinating contractors and technical teams.
Familiarity with automation, control systems, and compliance documentation.
Working Conditions
May involve working in controlled or cleanroom environments requiring protective gowning.
Exposure to chemicals, wet or cold conditions, and loud environments.
Occasional shift, weekend, or supplemental work as needed.
Ideal Candidate
You're a proactive engineer who thrives in a dynamic, regulated environment. You balance technical rigor with practical problem-solving, continuously seeking innovative ways to improve system reliability and efficiency.
$78k-106k yearly est. 15h ago
Principal/ Sr. Principal Industrial Security Analyst (level 3/4)
Northrop Grumman 4.7
Security engineer job in Los Angeles, CA
RELOCATION ASSISTANCE: No relocation assistance available CLEARANCE TYPE: SecretTRAVEL: Yes, 25% of the TimeDescriptionAt Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work - and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history.
Put your skills to the test by pushing the boundaries of what's possible. From global defense to sustainment and modernization to mission readiness, your experience and ability will make it a reality. Our programs are built on equal parts of curiosity and collaboration. Our combined effort means our customers can connect and defend millions of people around the world. With Northrop Grumman, you'll have the opportunity to be an essential part of projects that will define your career, now and in the future.
Northrop Grumman Defense Systems is seeking an Principal or Sr. Principal Industrial Security Analyst (3/4) for our Northridge, CA location.
Roles and Responsibilities:
Develops and administers physical security programs and procedures for classified or proprietary materials, documents, and equipment. Studies and implements federal security regulations that apply to company operations
Obtains rulings, interpretations, and acceptable deviations for compliance with regulations from government agencies
Prepares manuals outlining regulations, and establishes procedures for handling, storing, and keeping records, and for granting personnel and visitors access to restricted records and materials
Conducts security education classes and security audits
Ensures security compliance as a CSSO in accordance with DoDM 5205.07
Responsible for offsite and subcontractor security standups and posture
ISA duties will include:
CSSO for offsite and subcontractor sites associated with the program
Support a fast-paced, high-profile program; creating, maintaining, and leveraging working relationships with internal and external customers
Study and implement company and federal security policies, regulations, and procedures that apply to company operations
Obtain rulings, interpretations, and acceptable deviations for compliance with regulations from government agencies
Manage program security compliance and operations across multiple functions, including security SCIF and/or SAPF administration, PHYSEC, COMSEC, PERSEC, OPSEC, Contract Security, Security Education, Investigations, Visitor Control, and Document Control Management
Develop and implement a security education and awareness program
Conduct internal security audits. Investigate security violations and prepare reports specifying preventive action to be taken
Ensure adherence to contractual guidance for classified programs and cleared facilities in accordance with the Security Statements of Work, DD Form 254, DoD Contract Security Classification Specifications guidance
Assist program managers and professional staff in interpreting, applying, and complying with program Security Classification Guides (SCG)
Provide personnel security (PERSEC) support to include but not limited to reviewing and processing required documentation in support of SCI and SAP nomination processes; maintain PERSEC databases; prepare and administer program indoctrination and debriefings; access, review, and submit clearance and access information using the appropriate government database and other information systems
Provide facility security administration, documentation, and support: implement Standard Operating Procedures (SOP); conduct SCI and SAP security program self-inspections
Provide security support for Sensitive Compartmented Information Facility (SCIF) and Special Access Program Facility (SAPF) build construction projects to include obtaining customer accreditation in accordance with SCI and SAP DoD Manuals, ICD, ICS Tech Spec, and other government requirements
Manage and maintain UL-2050 Compliant Intrusion Detection Systems (IDS) and automated Access Control Systems (ACS)
Other duties as assigned
Basic Qualifications:
Principal Industrial Security Analyst (level 3)
Must have a high school diploma or GED with at least 9 years of related experience; OR 5 year of experience with a bachelor's degree
Experience with any of the following: Government manuals (32 CFR Part 117, NISPOM, DODM 5205.07, etc.)
Strong working knowledge of basic office automation tool suites such as MS Office (Word, Excel, PowerPoint)
Excellent customer service and communication skills
Must have an active Secret clearance
Ability to maintain flexibility to deal with changing priorities and deadlines.
Ability to work extended hours, in a fast paced, deadline driven environment, excellent communication skills speaking, writing skills and organized skills enabling effective communications
CSSO Experience
Ability to travel
Basic Qualifications:
Sr. Principal Industrial Security Analyst (level 4)
Must have a high school diploma or GED with at least 12 years of related experience; OR 8 year of experience with a bachelor's degree
Experience with any of the following: Government manuals (32 CFR Part 117, NISPOM, DODM 5205.07, etc.)
Strong working knowledge of basic office automation tool suites such as MS Office (Word, Excel, PowerPoint)
Excellent customer service and communication skills
Must have an active Secret clearance
Ability to maintain flexibility to deal with changing priorities and deadlines.
Ability to work extended hours, in a fast paced, deadline driven environment, excellent communication skills speaking, writing skills and organized skills enabling effective communications
CSSO Experience
Ability to travel
Preferred Qualifications:
Experience Leading Security Teams from Subcontractors and Offsite
Ability to work independently and follow projects through to completion.
Current Top-Secret clearance
Self-starter with minimal supervision
Security experience in a manufacturing environment
Supply Chain Security Experience
Primary Level Salary Range: $94,200.00 - $141,200.00Secondary Level Salary Range: $117,500.00 - $176,300.00The above salary range represents a general guideline; however, Northrop Grumman considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills and current market conditions.Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. Annual bonuses are designed to reward individual contributions as well as allow employees to share in company results. Employees in Vice President or Director positions may be eligible for Long Term Incentives. In addition, Northrop Grumman provides a variety of benefits including health insurance coverage, life and disability insurance, savings plan, Company paid holidays and paid time off (PTO) for vacation and/or personal business.The application period for the job is estimated to be 20 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates.Northrop Grumman is an Equal Opportunity Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. For our complete EEO and pay transparency statement, please visit *********************************** U.S. Citizenship is required for all positions with a government clearance and certain other restricted positions.
$117.5k-176.3k yearly Auto-Apply 2d ago
Cyber Defense Forensics Analyst
About EY-Parthenon
Security engineer job in Los Angeles, CA
At EY, you'll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we're counting on your unique voice and perspective to help EY become even better. Join us and build an exceptional experience for yourself, and a better working world for all. The exceptional EY experience. It's yours to build. EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
Today's world is fuelled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team helps protect the EY brand and build client trust.
Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.
The opportunity
Cyber Triage and Forensics (CTF) Incident Analyst will work as a senior member of the technical team responsible for security incident response for EY. The candidate will work as an escalation point for suspect or confirmed security incidents. Responsibilities include performing digital forensic analysis, following security incident response standard methodologies, malware analysis, identify indicators of compromise, support remediation or coordinate remediation efforts of a security incident, and develop documentation to support the security incident response process.
Your key responsibilities
Investigate, coordinate, bring to resolution, and report on security incidents as they are brought up or identified
Forensically analyze end user systems and servers found to have possible indicators of compromise
Analysis of artifacts collected during a security incident/forensic analysis
Identify security incidents through ‘Hunting' operations within a SIEM and other relevant tools
Interface and connect with server owners, system custodians, and IT contacts to pursue security incident response activities, including: obtaining access to systems, digital artifact collection, and containment and/or remediation actions
Provide consultation and assessment on perceived security threats
Maintain, manage, improve and update security incident process and protocol documentation
Regularly provide reporting and metrics on case work
Resolution of security incidents by identifying root cause and solutions
Analyze findings in investigative matters, and develop fact based reports
Be on-call to deliver global incident response
Skills and attributes for success
Resolution of security incidents by identifying root cause and solutions
Analyze findings in investigative matters, and develop fact-based reports
Proven integrity and judgment within a professional environment
Ability to appropriately balance work/personal priorities
To qualify for the role you must have
Bachelors or Masters Degree in Computer Science, Information Systems, Engineering or a related field
5+ years experience in incident response, computer forensics analysis and/or malware reverse engineering;
Understanding of security threats, vulnerabilities, and incident response;
Understanding of electronic investigation, forensic tools, and methodologies, including: log correlation and analysis, forensically handling electronic data, knowledge of the computer security investigative processes, malware identification and analysis;
Be familiar with legalities surrounding electronic discovery and analysis;
Experience with SIEM technologies (i.e. Splunk);
Deep understanding of both Windows and Unix/Linux based operating systems;
Ideally, you'll also have
Hold or be willing to pursue related professional certifications such as GCFE, GCFA or GCIH
Background in security incident response in Cloud-based environments, such as Azure
Programming skills in PowerShell, Python and/or C/C++
Understanding of the best security practices for network architecture and server configuration
What we look for
Demonstrated integrity in a professional environment
Ability to work independently
Have a global mind-set for working with different cultures and backgrounds
Knowledgeable in business industry standard security incident response process, procedures, and life cycle
Excellent teaming skills
Excellent social, communication, and writing skills
What we offer you The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary range/s. At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more.
We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $87,700 to $164,000. The salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $105,200 to $186,400. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options. Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year. Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances. You'll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
Are you ready to shape your future with confidence? Apply today.
EY accepts applications for this position on an on-going basis.
For those living in California, please click here for additional information.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
EY | Building a better working world
EY is building a better working world by creating new value for clients, people, society, and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy, and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY's Talent Shared Services Team (TSS) or email the TSS at **************************.
$105.2k-186.4k yearly 60d+ ago
Security Engineer II
JBA International 4.1
Security engineer job in Los Angeles, CA
Duties and Responsibilities
Assist in implementing Security Information and Event Management (SIEM), which includes but is not limited to; identifying deployment solutions, maintaining logs, assisting in developing company best practices for security alert correlations, perform root case analysis after incidents
Assist with Endpoint Detection and Response (EDR) vendor analysis and deployment, which includes, but is not limited to; partnering with IT to develop a decision matrix for EDR vendor selection, assist with deployment, develop patterns for automatic response to identified threats
Conduct structured and unstructured data scans, testing, and debugging of applications by using a variety of technical privacy tools to increase compliance and documentation of procedures and information assets
Write and deploy SQL to archive and or purge data from databases and to locate, review, explain and document data for privacy requirements
Perform regular privacy assessments and impact analysis on databases and operational processes by developing effective tools, training, and guidance to help identify and mitigate risk. This includes data anonymization, pseudonymization and encryption
Perform detection, analysis, and containment of an incident
Identify key performance metrics for security IR and implement instrumentation for those metrics
Maintain, manage and prioritize hardware, software, systems and/or product backlog, while actively identifying risks, constraints, and dependencies that would impact roadmap
Demonstrate, integrate, and collaborate on enhancing existing security solutions and services to address any gaps or deficiencies
Perform security incident response drill scenarios and lead table top exercises
Ensure proper training for stakeholders regarding their incident response roles and responsibilities in the event of a breach
Collaborate with internal teams to ensure the data retention or system requirements, user-facing privacy controls, new or existing software, and big data solutions enable the business to be data driven while protecting the data assets
Work with the legal department to produce data both internally and externally and ensure any legal request or litigation hold requirements are met
Assist with projects and enhancements, including gathering requirements, conducting research, task management and updating key partners and stakeholders with the goal of developing solutions to help mitigate privacy vulnerabilities and future privacy risks
Studies and interprets past privacy events and current privacy threats to improve privacy compliance using advanced technologies and design principles to develop and implement new tools and processes
Assist both internal and external teams on data governance strategy, updates to legal regulations, and direction on future roadmaps
Collaborate with vendors on data and privacy standards
Qualifications & Requirements
Bachelor's Degree in computer science, IT, systems engineering, or related qualification
2+ years of experience in the security industry working in any combination of the following areas: Risk management, cloud operations and engineering, network security monitoring, log analysis, static and dynamic malware analysis, NIST Kill Chain, MITRE ATT&CK framework, threat hunting, SIEM, EDR
Experience responding to security events
Writing and reviewing code (Java, Python, Node or similar)
Excellent written and verbal communication, facilitation, and presentation skills to collaborate effectively with software engineering teams
Implementing security detection capabilities
Proven ability to make decisions and perform complex problem-solving activities under pressure
Some knowledge of AWS cloud infrastructure and their threat landscape
$114k-155k yearly est. 60d+ ago
Security Engineer
Classic Collision 4.2
Security engineer job in Los Angeles, CA
Responsibilities:
Monitor security systems, logs, and alerts to detect and respond to potential security incidents promptly.
Assist in investigating and analyzing security breaches, unauthorized access attempts, and suspicious activities to mitigate risks and prevent future incidents.
Collaborate with the IT Security team to coordinate incident response efforts and implement appropriate measures to contain and remediate security incidents.
Educate employees on best security practices, including data protection, password management, and phishing awareness.
Assist in managing KnowBe4 training platform.
Assist in the implementation and configuration of security technologies such as firewalls, antivirus software, and intrusion detection/prevention systems.
Aid in conducting regular vulnerability assessments and scans on network devices, applications, and systems.
Assist in ensuring compliance with internal security policies and industry regulations by helping to conduct periodic audits and reviews.
Requirements:
Bachelor's degree in computer science, Information Security, or a related field is preferred, but relevant work experience or certifications will also be considered.
Familiarity with security tools and technologies such as firewalls, antivirus software, and SIEM (Security Information and Event Management) systems is advantageous.
Strong attention to detail and the ability to follow established security protocols.
Any relevant security certifications (Sec+) is a plus
Basic understanding of cybersecurity principles, concepts, and technologies.
Experience with the following is preferred:
Office 365, Entra, M365 Defender, Exchange
Active Directory, GPO
Azure Sentinel or other SIEM
Fortinet/FortiOS
SOC Experience
Behaviors/Competencies:
Integrity-Respect and accountability at every level and every interaction
Customer Service-Provide the highest level of customer service while building customer satisfaction and retention
Innovation-Develops and displays innovative approaches and ideas to our business
Teamwork-Contributes to building a positive team spirit and supports everyone's efforts to succeed
Physical & Environmental
While performing the duties of this job, the employee is regularly required to use hands, and is required to talk and hear. The employee is frequently required to stand, sit, and walk occasionally for long periods at a time. The employee may occasionally be required to reach with hands, arms and move objects up to 20 pounds. Specific vision abilities required by this job include close vision, peripheral vision, and ability to adjust focus. In addition, abilities for assessing the accuracy, neatness and thoroughness of the work assigned is required. The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individual with disabilities to perform the essential function.
Classic Collision is an Equal Opportunity Employer:
As an equal opportunity employer, Classic Collision does not discriminate against any employee or candidate based on age, race, gender identity, gender expression, genetic information, national origin, physical or mental disability, protected veteran status, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by all applicable federal, state, and local laws.
Reasonable Accommodations:
Classic Collision is an equal opportunity employer that is committed to working with and providing reasonable accommodations to individual with disabilities. If you have a disability and you believe you need a reasonable accommodation to search for a job opening or submit an online application, please.
e-mail *******************************. This email is listed exclusively to assist disabled job seekers whose disability prevents them from being able to apply online.
This job description is not a complete statement of all duties and responsibilities comprising the position.
$96k-134k yearly est. Auto-Apply 60d+ ago
Staff Product Security Engineer
Crunchyroll 3.8
Security engineer job in Los Angeles, CA
Founded by fans, Crunchyroll delivers the art and culture of anime to a passionate community. We super-serve over 100 million anime and manga fans across 200+ countries and territories, and help them connect with the stories and characters they crave. Whether that experience is online or in-person, streaming video, theatrical, games, merchandise, events and more, it's powered by the anime content we all love.
Join our team, and help us shape the future of anime!
About the role
Crunchyroll is growing and changing, presenting unique challenges and opportunities to support millions of anime fans around the world. The Fan Experiences Services & Tools team provides seamless help to our partners and internal stakeholders, ensuring an exceptional experience for all Crunchyroll fans.
Our charter is focused on helping our internal and external teams around the world integrate, test, and deploy the Crunchyroll applications quickly and with the highest levels of quality. We do this with tools and infrastructure that optimize the developer experience. We tie it all together with sophisticated automated testing and productivity solutions designed to support our culture of experimentation, autonomy and ownership. Our goal is to focus on delivering the best possible anime fan experience.
You will:
Security Strategy & Leadership: Lead, mentor, and grow the Application Security team. Define the long-term roadmap for Mobile, Desktop, and Game security to proactively mitigate reverse engineering, piracy, and cheating.
Binary Defense Architecture: Oversee the design and implementation of binary protection strategies. Direct the evaluation and integration of anti-tamper, obfuscation, and RASP solutions (e.g., Promon, Guardsquare) ensuring minimal impact on game FPS, app performance and user experience.
Game Integrity & Anti-Cheat: Collaborate with game studios to design "server-authoritative" economies and implement client-side detections for memory manipulation, touch macros, and modded APKs.
Trust & Identity Management: Architect robust chains of trust for the ecosystem. Manage code signing certificates, secure boot processes, and the integration of hardware-backed storage (TEE) for sensitive keys.
Vulnerability Research & Validation: Lead internal or external "red team" initiatives using reverse engineering tools (IDA Pro, Frida) to simulate attacks against our apps and games. Validate the effectiveness of binary defenses and attestation checks before release.
Content Protection Engineering: Collaborate with media engineering to harden DRM implementations (Widevine, FairPlay). Ensure secure handling of media keys and enforce output protection (HDCP).
In the role of Staff Product SecurityEngineer, you will report to the Senior Director of Fan Experience Engineering Service & Tools. We are considering applicants for the location of Dallas, Los Angeles, or San Francisco.
About You
We get excited about candidates, like you, because you have...
Binary Application Construction: Solid understanding of how applications are constructed, including compilers, linkers, dynamic loaders, ABI interaction, and executable formats (ELF, Mach-O, PE).
Game Engine & Anti-Cheat Security: Solid understanding of Unity (IL2CPP) and Unreal Enginesecurity architectures. Experience designing defenses against game-specific attacks: memory editors (GameGuardian), speed hacks, wallhacks, and protecting asset integrity (AssetBundles).
Cryptography & Chain of Trust: Comprehensive experience with cryptographic primitives (hashing, digests) and Public Key Infrastructure (PKI), including managing digital certificates and establishing chains of trust for code signing and secure boot.
Anti-Tamper & Ecosystem: Proven track record evaluating and implementing commercial shielding (Promon, Guardsquare, Verimatrix) and platform attestation (Google Play Integrity, Apple App Attest) for both apps and games.
Content Protection & DRM: Experience with Google Widevine, Apple FairPlay, and Microsoft PlayReady, including HDCP enforcement and screen recording prevention.
Reverse Engineering & Analysis: Hands-on experience with tools (IDA Pro, Ghidra, Frida, Il2CppDumper) to simulate attacks, analyze game logic, and validate the resilience of binary protections.
TBD: Mobile Security Standards: Relevant certifications OWASP MASVS and the OWASP Mobile Top 10, with the ability to map these standards to engineering roadmaps.
Web & Network Security: Experience securing web standards within application contexts, including HTTPS/TLS, cookie security (Secure, HttpOnly, SameSite), local storage, and Content Security Policy (CSP).
Hybrid App & WebView Security: Expert handling of WebView bridges (WKWebView), ensuring secure data exchange between native and web contexts.
Hardware-Backed Security: Experience utilizing TEEs (Secure Enclave, TrustZone, TPM) for secure key storage, cryptographic operations, and offline license management.
DevSecOps & Supply Chain: Experience automating security (SAST/DAST) within CI/CD pipelines and managing third-party SDK risks (supply chain attacks).
About the Team
The Fan Experiences Engineering team at Crunchyroll plays a pivotal role in enhancing and expanding our users' experiences. We collaborate extensively with a diverse network of device, payment, and gaming partners to broaden the reach of Crunchyroll's offerings. Our primary objective is to drive growth, open up new acquisition channels, and optimize both the scope and quality of our services. Situated at the crossroads of technology and business, we are dedicated to continually enabling experiences that delights our fans.
Why you will love working at Crunchyroll
In addition to getting to work with fun, passionate and inspired colleagues, you will also enjoy the following benefits and perks:
Receive a great compensation package including salary plus performance bonus earning potential, paid annually.
Flexible time off policies allowing you to take the time you need to be your whole self.
Generous medical, dental, vision, STD, LTD, and life insurance
Health Saving Account HSA program
Health care and dependent care FSA
401(k) plan, with employer match
Employer paid commuter benefit
Support program for new parents
Pet insurance and some of our offices are pet friendly!
#LifeAtCrunchyroll #LI-Hybrid
The Pay Range for this position is listed. Actual pay will vary based on factors including, but not limited to location, experience, and performance. The range listed is just one component of Crunchyroll's Total Rewards offerings for employees. Other rewards may include performance bonuses, employer matched retirement savings, time-off programs, and progressive health benefits and perks.Pay Transparency - Los Angeles, CA$200,000-$249,000 USDAbout our Values
We want to be everything for someone rather than something for everyone and we do this by living and modeling our values in all that we do. We value
Courage. We believe that when we overcome fear, we enable our best selves.
Curiosity. We are curious, which is the gateway to empathy, inclusion, and understanding.
Kaizen. We have a growth mindset committed to constant forward progress.
Service. We serve our community with humility, enabling joy and belonging for others.
Our commitment to diversity and inclusion
Our mission of helping people belong reflects our commitment to diversity & inclusion. It's just the way we do business.
We are an equal opportunity employer and value diversity at Crunchyroll. Pursuant to applicable law, we do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
Crunchyroll, LLC is an independently operated joint venture between US-based Sony Pictures Entertainment, and Japan's Aniplex, a subsidiary of Sony Music Entertainment (Japan) Inc., both subsidiaries of Tokyo-based Sony Group Corporation.
Questions about Crunchyroll's hiring process? Please check out our Hiring FAQs:
https://help.crunchyroll.com/hc/en-us/articles/3**********2-Crunchyroll-Hiring-FAQs
Please refer to our Candidate Privacy Policy for more information about how we process your personal information, and your data protection rights: **********************************************************************************************************
Please beware of recent scams to online job seekers. Those applying to our job openings will only be contacted directly ********************* email account.
$116k-164k yearly est. Auto-Apply 8d ago
Cyber Security
Forhyre
Security engineer job in Los Angeles, CA
Job Description
Forhyre is seeking a talented individual that will be able to provide security architecture support and interface across the program as needed. This support includes, but is not limited to, cybersecurity solutions, providing technical strategy for solutions, guidance, policy, and implementations. The successful candidate for this position is a highly motivated individual, with a strong IT security background who excels integrating, operating, and deploying security technology and solutions and interacts well with both internal teams and clients.
Note: U.S. citizens and those authorized to work in the U.S. are encouraged to apply. We are unable to sponsor at this time.
Responsibilities:
Engineer, implement and monitor security measures for the protection of computer systems, networks and information
Develop and implement security policies and controls to support the Cyber Security framework
Manage the existing cyber security training program across global, multilingual business
Assists in ensuring global Information security program meets all industry regulations, standards, and compliance requirements
Drive adoption of infrastructure security best practices and work with Information Technology teams to ensure security standards are maintained
Implement technology to proactively scan Information Technology environment for security breaches and suspicious activity
Continuous improvement in the areas of Information Security technologies, techniques and processes
Develops and maintains an effective system for the distribution of regular key performance indicator reports and dashboard
Ability to interpret penetration test results and describe issues and fixes to non-security expert
Responsible for leading an accurate & comprehensive status reporting to the executive steering committee
Create and implement SOP/ process improvement initiatives to achieve outcomes that align or exceed the expectations of strategic roadmap
Skills & Experience
Bachelor's degree and 12+ years of experience; additional years of directly applicable experience may be accepted in lieu of a degree.
Certified Information Systems Security Professional (CISSP)
8+ years hands-on experience designing or implementing security solutions, including all related documentation and artifacts
Analytical ability, problem-solving skills, and ability to break down complex problems into actionable steps
Extensive experience in design and development of enterprise security architectures. Experience must include a wide range of work in creating diagrams and documentation with all components that comprise IT systems including network topology.
Strong knowledge and experience in secure enterprise architecture design, especially with regard to IAM, NDR, EDR, SIEM, AI/ML, and other cybersecurity tools and resultant applications
Experience selecting effective methods, techniques, and evaluation criteria to achieve desired outcomes
Previous experience developing architectures, strategies, strategic plans, roadmaps, and technical standards for the federal IT enterprise environment.
Vulnerability Assessment testing and/or Penetration Testing (preferred)
Robotic Process Automation/Intelligent Automation (preferred)
Business case development supporting security technology solutions (preferred)
Additional certifications demonstrating cybersecurity/technical mastery (preferred)
$82k-116k yearly est. 28d ago
Information Security Analyst
Mount Indie
Security engineer job in Camarillo, CA
Job Description
Mount Indie is seeking a highly skilled and experienced Cyber Accreditation Specialist with 5+ years of experience for Department of Defense (DoD) programs at the Naval Base Point Mugu located near Camarillo, CA. The Cyber Accreditation Specialist will be responsible for the development, coordination, and maintenance of cyber accreditation packages, primarily focusing on Risk Management Framework (RMF) artifacts, inheritance mapping, and Plan of Action & Milestones (POA&M) management supporting the Navy's Authority To Operate initiatives. This role ensures compliance with relevant DoD and federal cybersecurity guidelines and contributes to our organization's mission support objectives by securing critical Navy information systems.
Responsibilities
Cyber Accreditation Package Development: Develop and maintain RMF artifacts, including System Security Plans (SSP), generate & control implementation evidence, inheritance maps, and POA&Ms
Coordination and Compliance: Coordinate with Authorizing Officials (AO) and Information System Security Managers (ISSM) to define an Authority to Operate (ATO) plan, develop an interim risk acceptance strategy, and manage control inheritance from enterprise services and range systems
Reference Compliance: Ensure that all activities and documentation are compliant with the latest DoD and federal cybersecurity standards, such as:
DoDI 8510.01 Risk Management Framework (RMF)
NIST SP 800-53 Rev. 5
NIST SP 800-171 (CUI)
DoD Zero Trust Reference Architecture
DoD Cloud Security Requirements Guide (SRG) / FedRAMP baselines (aligned to IL5 unless otherwise directed)
Qualifications
5+ years of experience in cybersecurity, specifically in the development and coordination of cyber accreditation packages
BS or BA degree in Cybersecurity, Information Technology, or a related field. An additional 6 years of relevant work experience may be substituted for a bachelor's degree, or 4 additional years of work experience with a relevant associate degree.
Active Secret Clearance
Demonstrated experience with RMF, SSP development, and POA&M management
Familiarity with DoD and federal cybersecurity guidelines, including DoDI 8510.01, NIST SP 800-53 Rev. 5, NIST SP 800-171, DoD Zero Trust Reference Architecture, and DoD Cloud SRG/FedRAMP baselines
Strong analytical and problem-solving skills
Ability to effectively coordinate and communicate with various stakeholders, including AO, ISSM, and other cybersecurity professionals
Current Security+ Certificate
IAM Level 2 as per DoD Directive 8570.01; and experience working with the DIACAP/Risk Management Framework processes
Excellent communication and interpersonal skills-verbal, non-verbal, written, and listening-for staff, customer and organizational level communications, both formal and informal
Ability to work independently, self-starter
Working knowledge and use of Microsoft Office suite programs, MS Word, Excel, Access, and PowerPoint
Preferred Qualifications:
Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or equivalent certification
Experience with cloud security and FedRAMP compliance
$91k-134k yearly est. 17d ago
Sr Anlyst, Security - Goleta, CA
RTX Corporation
Security engineer job in Goleta, CA
**Country:** United States of America ** Onsite **U.S. Citizen, U.S. Person, or Immigration Status Requirements:** Active and transferable U.S. government issued security clearance is required prior to start date.
U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance
**Security Clearance:**
DoD Clearance: Secret
At Raytheon, the foundation of everything we do is rooted in our values and a higher calling - to help our nation and allies defend freedoms and deter aggression. We bring the strength of more than 100 years of experience and renowned engineering expertise to meet the needs of today's mission and stay ahead of tomorrow's threat. Our team solves tough, meaningful problems that create a safer, more secure world.
Our Senior Security Analyst provides industrial security support within the following areas: clearance processing, visit certifications, document control, and physical security, including alarm response for Open Storage Areas. You will make critical security decisions concerning high value contracts and implement security procedures that will prevent unauthorized access to company and government facilities or information.
**What You Will Do**
+ Administrative duties of administering security clearance briefings to employees who are granted a security clearance
+ Debriefing Personal upon notification of Retirement/Termination
+ Continuously evaluates compliance of personnel security activities with security requirements
+ Conduct security self-inspections, program security reviews, apply risk mitigation methodologies, support customer assessments, and implement security measures to meet requirements
+ Administer day-to-day security programs, personnel processing, program reviews, document control system, audits & self-inspections, violation investigations & reports, receipt/dispatch/destruction/mail logs, visit certs, etc.
+ Analyze security issues/problems and provide focused solutions
+ Solve routine problems of limited scope and complexity
+ Willing to work extended hours, in a fast paced, driven environment
+ Must possess a valid driver's license
**Qualifications You Must Have**
+ Typically requires a Bachelor's degree and 2 years relevant experience OR in absence of a degree, 6 years relevant experience.
+ Active and transferable U.S. government issued SECRET security clearance is required prior to start date. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance.
+ Experience with any of the following: NISPOM, ICD 705, or experience working in a classified environment.
**Qualifications We Prefer**
+ Ability to solve routine problems of limited scope and complexity
+ Self-starter with minimal supervision
+ Willing to work extended hours, in a fast paced, driven environment
+ Able to perform well in fast-paced, multi-task environment
+ Great attention to detail
+ Strong organizational and interpersonal skills
+ Customer service oriented
+ Team player
**What We Offer**
+ Our values drive our actions, behaviors, and performance with a vision for a safer, more connected world. At RTX we value: Trust, Respect, Accountability, Collaboration, and Innovation.
+ Relocation Non-Eligible - Relocation assistance not available
.
**Learn More & Apply Now!**
+ Please consider the following role type definition as you apply for this role. ‒ Onsite: Employees who are working in Onsite roles will work primarily onsite. This includes all production and maintenance employees, as they are essential to the development of our products.
**_As part of our commitment to maintaining a secure hiring process, candidates may be asked to attend select steps of the interview process in-person at one of our office locations, regardless of whether the role is designated as on-site, hybrid or remote._**
The salary range for this role is 72,000 USD - 144,000 USD. The salary range provided is a good faith estimate representative of all experience levels.
RTX considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate's work experience, location, education/training, and key skills.
Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement.
Hired applicants may be eligible for annual short-term and/or long-term incentive compensation programs depending on the level of the position and whether or not it is covered by a collective-bargaining agreement. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company's performance.
This role is a U.S.-based role. If the successful candidate resides in a U.S. territory, the appropriate pay structure and benefits will apply.
RTX anticipates the application window closing approximately 40 days from the date the notice was posted. However, factors such as candidate flow and business necessity may require RTX to shorten or extend the application window.
_RTX is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or veteran status, or any other applicable state or federal protected class. RTX provides affirmative action in employment for qualified Individuals with a Disability and Protected Veterans in compliance with Section 503 of the Rehabilitation Act and the Vietnam Era Veterans' Readjustment Assistance Act._
**Privacy Policy and Terms:**
Click on this link (******************************************************** to read the Policy and Terms
Raytheon Technologies is An Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age or any other federally protected class.
$111k-151k yearly est. 60d+ ago
Sr Anlyst, Security - Goleta, CA
RTX
Security engineer job in Goleta, CA
Country:
United States of America Onsite
U.S. Citizen, U.S. Person, or Immigration Status Requirements:
Active and transferable U.S. government issued security clearance is required prior to start date. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance
Security Clearance:
DoD Clearance: Secret
At Raytheon, the foundation of everything we do is rooted in our values and a higher calling - to help our nation and allies defend freedoms and deter aggression. We bring the strength of more than 100 years of experience and renowned engineering expertise to meet the needs of today's mission and stay ahead of tomorrow's threat. Our team solves tough, meaningful problems that create a safer, more secure world.
Our Senior Security Analyst provides industrial security support within the following areas: clearance processing, visit certifications, document control, and physical security, including alarm response for Open Storage Areas. You will make critical security decisions concerning high value contracts and implement security procedures that will prevent unauthorized access to company and government facilities or information.
What You Will Do
Administrative duties of administering security clearance briefings to employees who are granted a security clearance
Debriefing Personal upon notification of Retirement/Termination
Continuously evaluates compliance of personnel security activities with security requirements
Conduct security self-inspections, program security reviews, apply risk mitigation methodologies, support customer assessments, and implement security measures to meet requirements
Administer day-to-day security programs, personnel processing, program reviews, document control system, audits & self-inspections, violation investigations & reports, receipt/dispatch/destruction/mail logs, visit certs, etc.
Analyze security issues/problems and provide focused solutions
Solve routine problems of limited scope and complexity
Willing to work extended hours, in a fast paced, driven environment
Must possess a valid driver's license
Qualifications You Must Have
Typically requires a Bachelor's degree and 2 years relevant experience OR in absence of a degree, 6 years relevant experience.
Active and transferable U.S. government issued SECRET security clearance is required prior to start date. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance.
Experience with any of the following: NISPOM, ICD 705, or experience working in a classified environment.
Qualifications We Prefer
Ability to solve routine problems of limited scope and complexity
Self-starter with minimal supervision
Willing to work extended hours, in a fast paced, driven environment
Able to perform well in fast-paced, multi-task environment
Great attention to detail
Strong organizational and interpersonal skills
Customer service oriented
Team player
What We Offer
Our values drive our actions, behaviors, and performance with a vision for a safer, more connected world. At RTX we value: Trust, Respect, Accountability, Collaboration, and Innovation.
Relocation Non-Eligible - Relocation assistance not available
.
Learn More & Apply Now!
Please consider the following role type definition as you apply for this role. ‒ Onsite: Employees who are working in Onsite roles will work primarily onsite. This includes all production and maintenance employees, as they are essential to the development of our products.
As part of our commitment to maintaining a secure hiring process, candidates may be asked to attend select steps of the interview process in-person at one of our office locations, regardless of whether the role is designated as on-site, hybrid or remote.
The salary range for this role is 72,000 USD - 144,000 USD. The salary range provided is a good faith estimate representative of all experience levels. RTX considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate's work experience, location, education/training, and key skills.Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement.Hired applicants may be eligible for annual short-term and/or long-term incentive compensation programs depending on the level of the position and whether or not it is covered by a collective-bargaining agreement. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company's performance.This role is a U.S.-based role. If the successful candidate resides in a U.S. territory, the appropriate pay structure and benefits will apply.RTX anticipates the application window closing approximately 40 days from the date the notice was posted. However, factors such as candidate flow and business necessity may require RTX to shorten or extend the application window.
RTX is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or veteran status, or any other applicable state or federal protected class. RTX provides affirmative action in employment for qualified Individuals with a Disability and Protected Veterans in compliance with Section 503 of the Rehabilitation Act and the Vietnam Era Veterans' Readjustment Assistance Act.
Privacy Policy and Terms:
Click on this link to read the Policy and Terms
$111k-151k yearly est. Auto-Apply 60d+ ago
Information Security Risk Specialist
American Riviera Bank
Security engineer job in Santa Barbara, CA
About
the
Role:
$93k-137k yearly est. Auto-Apply 13d ago
Manager, Information Security, Productions
Sony Pictures Entertainment 4.8
Security engineer job in Culver City, CA
The Information Security organization at Sony Pictures Entertainment is responsible for protecting our content, systems, and data from being stolen, damaged, or destroyed. To do so, we are continuously improving our tools, capabilities, and processes to stay ahead of evolving threats.
The Manager, Information Security Productions is accountable for operationalizing the Information Security Productions program across all SPE U.S. productions. This includes driving consistent implementation of approved security standards, tools, and controls; ensuring data-driven visibility into production security risk; and supporting compliance and readiness reporting to leadership. Success in this role requires strong cross-functional collaboration across Information Security, IT, S3, and production teams to embed security into creative workflows without friction, while ensuring protection of SPE's most valuable assets-our stories and intellectual property.
This role will also ensure program consistency with regional and global counterparts, contribute to automation and standardization of key controls, and support ongoing improvement of information security for productions practices across the production lifecycle.
Key indicators of success in this role will be:
+ Business leaders have near real-time visibility into production information security risk using meaningful, actionable metrics that drive timely and effective decision-making.
+ Consistent application of approved tools, workflows, and controls across productions, ensuring compliance and readiness reporting aligns with studio KPIs.
+ Production teams trust SPE to provide a secure, highly available, and easy-to-use digital production environment that safeguards our content and data.
+ Information Security, Physical Security, and IT operate as unified partners to protect SPE productions from concept to archive.
Within this organization, we value learning, agility, and collaboration. The Manager, Information Security Productions (CC, US) will be a key contributor to Sony Pictures Entertainment's goal of being the most trusted studio in the industry.
Responsibilities
Provide visibility and actionable insight into Information Security risk across active U.S. productions.
+ Monitor, analyze, and report on production security posture and key control performance metrics for each production.
+ Partner with global InfoSec, Risk, Threat Intelligence, Incident Response, Training, and Governance teams to align production needs with enterprise programs.
+ Prepare and present dashboards and reports on security trends, compliance status, and improvement opportunities.
+ Support the development of production-specific metrics and KPIs to measure control effectiveness.
+ With IT and Physical Security, maintain security controls in place for productions to most effectively meet our business goals.
Operationalize the Production Information Security Program across U.S. productions.
+ Ensure consistent implementation of approved security tools, policies, and workflows within productions.
+ Coordinate adoption of automated controls with productions, such as provisioning, watermarking, and access telemetry.
+ Support the standardization and scalability of production security practices across production titles and business units.
Ensure and track production security culture, awareness, and response readiness.
+ Amplify the reach of security training and awareness initiatives by coordinating rollout to productions, ensuring consistent messaging and participation tracking.
+ Gather feedback from productions to help refine information security for productions training and awareness efforts.
+ Partner with Incident Response to ensure clear communications, timely follow-up, and closure of corrective actions.
+ Track cultural and operational readiness indicators (e.g., onboarding rates, reporting engagement, post-incident improvements) to measure program maturity and continuous improvement.
Qualifications
+ 5+ Years of experience in Information Security, Information Technology or a related field
+ 5+ Years of experience in an organization directly involved in movie, television and/or other entertainment production, or equivalent educational experience.
+ Bachelor's degree preferred
+ Strong understanding of the technologies, tools and processes used in production of movies and/or television.
+ Knowledge of Information Security frameworks, standards and best practices and their relevance to business success
+ Specific knowledge of processes, tools and practices used to maintain confidentiality in the context of movie and television productions.
+ Ability to develop and maintain meaningful metrics to track program and process effectiveness.
+ Strong planning and analytical skills
+ Strong communications skills
Sony Pictures Entertainment is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, national origin, disability, veteran status, age, sexual orientation, gender identity, or other protected characteristics. To request an accommodation for purposes of participating in the hiring process, you may contact us at SPE_Accommodation_Assistance@spe.sony.com.
$139k-180k yearly est. 56d ago
Information Security Analyst
The Azoff Music Company
Security engineer job in Los Angeles, CA
at The Azoff Music Company LLC
Information Security Analyst About the RoleWe are looking for an Information Security Ånalyst to operate and maintain our information security systems. As a mid-size entertainment company with global reach, we manage sensitive intellectual property and digital assets that demand the highest level of security. This role will be responsible for helping to design, implement, and maintain a robust information security program that aligns with business objectives and compliance requirements. Key Responsibilities
Governance, Risk Management, and Compliance
Establish and maintain security policies, standards, and procedures that comply with applicable regulations (e.g., GDPR, CCPA, SOC 2, ISO 27001, PCI-DSS).
Oversee risk assessments and audits, ensuring remediation plans are executed effectively.
Manage vendor security evaluations and third-party risk management programs.
Operational Security
Oversee incident detection, response, and recovery processes to ensure rapid containment and resolution of security events.
Implement and monitor security controls across endpoints, networks, and cloud infrastructure. This may include selecting, implementing, and monitoring security software, reviewing network settings like firewall rules and access policies, inspecting hardware and software for vulnerabilities.
Lead vulnerability management, penetration testing, and threat intelligence initiatives.
Awareness and Culture
Develop and deliver ongoing security training and awareness programs for all employees.
Champion a culture of security across departments, ensuring staff understand their role in protecting company assets.
Mentor junior technical staff on information security best practices, operations, and technology.
Technology and Innovation
Partner with IT and digital teams to integrate security into technology architecture and workflows.
Evaluate and implement advanced security tools, automation, and analytics for proactive threat management.
Stay current with emerging threats, trends, and technologies in cybersecurity and the entertainment industry.
Qualifications
Bachelor's degree in Computer Science, Information Security, or a related field.
5+ years of progressive experience in information security.
Proven experience supporting enterprise security programs, preferably in media, entertainment, or technology environments.
Strong knowledge of cloud security, identity and access management, and data loss prevention.
Strong knowledge of Conditional Access Policies and Device Compliance in Microsoft Entra ID.
Experience implementing and managing SSO and SCIM configurations.
Familiarity managing PAM solutions like Microsoft Privileged Identity Management.
Strong programming (Python) and/or scripting skills (PowerShell/Bash)
Familiarity with common device management tools like Intune, Jamf, Mosyle, Addigy, etc.
Professional certifications such as Security +, Network +, CISSP, CCSP or CASP, or similar highly desired.
Excellent communication and stakeholder management skills - able to translate complex technical risks into clear business implications.
We will not be able to support sponsorship or visas for this position at this time.
The base salary range for this role is $120,000 - $150,000 depending upon experience.Our offices are located in Westwood Village, Los Angeles, CA. Employees work in the office Monday through Thursday and from home on Fridays. We offer a very competitive benefits package, annual bonus, and a creative and dynamic working environment. This position is based in California and is subject to California employment laws and workplace safety requirements, including the Company's Covid vaccination policy. Reasonable accommodations will be considered in accordance with applicable law. Successful candidates will be required to show proof of being vaccinated against COVID-19. This requires having a two-dose series and a booster, or a single dose series and a booster. Reasonable accommodations will be considered on a case-by-case basis for exemptions to this requirement in accordance with applicable law. Disclaimer: This job description only provides an overview of job responsibilities that are subject to change. We are an Equal Opportunity Employer
$120k-150k yearly Auto-Apply 46d ago
Manager, Information Security Compliance
Walt Disney Co 4.6
Security engineer job in Santa Monica, CA
Department Description At Disney, we're storytellers. We make the impossible, possible. The Walt Disney Company (TWDC) is a world-class entertainment and technological leader. Walt's passion was to continuously envision new ways to move audiences around the world-a passion that remains our touchstone in an enterprise that stretches from theme parks, resorts and a cruise line to sports, news, movies and a variety of other businesses. Uniting each endeavor is a commitment to creating and delivering unforgettable experiences - and we're constantly looking for new ways to enhance these exciting experiences.
The Enterprise Technology mission is to deliver technological solutions that align to business strategies while enabling enterprise efficiency and promoting cross-company collaborative innovation. Our group drives competitive advantage by enhancing our consumer experiences, enabling business growth, and advancing operational excellence.
The Global Information Security (GIS) organization strives to secure the magic by employing best-in-class services to assess, prevent, detect, and respond to cyber threats that present risk to The Walt Disney Company. We enable the business by integrating enterprise and business segment-specific supported services to create a robust, efficient, and adaptable cybersecurity program. Our key objectives are to:
* Secure the Magic by protecting information systems and platforms.
* Reduce Risk by proactively assessing, preventing, and detecting to prevent harm to the Company and our Guests.
* Strengthen the business through optimizing execution, application, and technology used to protect the Company.
* Innovate by investing in core capabilities to enhance operational efficiency.
Team Description:
Global Information Security (GIS) supports all of Disney's business segments, including Disney Entertainment & ESPN (DE&E). DE&E encompasses the operations of Disney's streaming services-Disney+, Hulu, ESPN+, Disney+ Hotstar, Star, and the upcoming Venu Sports streaming service-as well as Disney's broadcast and cable networks, including ABC, ESPN, FX, Disney Channels, and National Geographic. DE&E sits at the intersection of entertainment, sports, and technology, striving to connect viewers with beloved stories while advancing the streaming industry with consumer-first innovations. Security professionals supporting DE&E work with industry-leading technologies to deliver world-class, highly secure services to customers.
What You'll Do:
* Independent audit support for:
* SOX 404 ITGCs
* PII
* PCI
* ISPS
* Collaborate with Enterprise Controls and Compliance (ECC) to scope systems and respective ITGCs.
* Perform control health checks and remediation testing procedures to address issues identified via audit assessments, access control reviews, internal or external audits and/or other assessments.
* Develop and lead the Control Assurance Programs (ISPS and SOX).
* Lead Audit Readiness efforts to ensure proper system scoping and respective ITGCs, control validations and timely program onboarding.
* Participate in audit walkthrough meetings to help establish internal testing procedures to gain operational comfort in the design of the Company's automated controls.
* This includes control self-evaluations of new controls or processes that impact the effectiveness of an existing control.
* Perform impact analysis and risk assessment on deficiency findings and documentation associated with the assessment.
* Work with management and internal audit on maintaining the master Risk and Control Matrix over the systems material to Disney Entertainment and ESPN (Broadcast TV and Streaming - Hulu, Disney+, ESPN+, STAR+ products)
* Ensure for timely management response of audit findings into our corporate SOCD/SAD.
* Oversee ISPS Management Audit coordination and open action plans.
* Provide consultancy to Development leads to identify and implement automation and efficiency opportunities to meet governance and compliance demands.
* Management of GRC workflows around coordination of certifications and attestations.
* Partner with leadership to support the PCI-DSS compliance program.
* Develop training materials, coordinate training sessions, and monitor compliance with training requirements.
* Oversee and manage a team of compliance analysts, ensuring day-to-day operations run smoothly and efficiently.
* Assign tasks and projects to team members based on priorities, deadlines, and individual strengths.
* Provide executive level updates on Compliance programs
Must Haves (Years of Experience, languages, programs, tools, etc.):
* Minimum of 8 years of related work experience, with 3 in management roles
* IT SOX experience and proven experience in supporting IT audit/compliance functions
* Experience in managing people
* Thorough understanding of SOX ITGC and ICFR 404 standards and audit objectives
* Interpersonal skills with the ability to work with teams cross-functionally
* Strong verbal and written communication skills and ability to effectively communicate to technical and non-technical audiences, including developers and tech operators
* Detail-oriented but able to understand the big picture. Highly organized and efficient
* Ability to navigate through ambiguity, manage and coordinate multiple project assignments simultaneously in a fast-paced, deadline-driven environment, accepting ownership and accountability of the process and deliver on commitments
* Experience with cloud-based services, specifically AWS
Nice To Haves (see above):
* Experience and knowledge of NIST framework, ISO 27001, K-ISMS, GDPR
* Experience working with companies that have a heavy microservice architecture
Education:
Bachelor's degree in Computer Science, CPA license, Information Systems, Software, Electrical or Electronics Engineering, or comparable field of study, and/or equivalent work experience
The hiring range for this position in Glendale, CA and Santa Monica, CA is $141,900 to $190,300 per year and in New York, NY is $148,700 to $199,400 per year. The base pay actually offered will take into account internal equity and also may vary depending on the candidate's geographic region, job-related knowledge, skills, and experience among other factors. A bonus and/or long-term incentive units may be provided as part of the compensation package, in addition to the full range of medical, financial, and/or other benefits, dependent on the level and position offered.
About The Walt Disney Company (Corporate):
At Disney Corporate you can see how the businesses behind the Company's powerful brands come together to create the most innovative, far-reaching and admired entertainment company in the world. As a member of a corporate team, you'll work with world-class leaders driving the strategies that keep The Walt Disney Company at the leading edge of entertainment. See and be seen by other innovative thinkers as you enable the greatest storytellers in the world to create memories for millions of families around the globe.
About The Walt Disney Company:
The Walt Disney Company, together with its subsidiaries and affiliates, is a leading diversified international family entertainment and media enterprise that includes three core business segments: Disney Entertainment, ESPN, and Disney Experiences. From humble beginnings as a cartoon studio in the 1920s to its preeminent name in the entertainment industry today, Disney proudly continues its legacy of creating world-class stories and experiences for every member of the family. Disney's stories, characters and experiences reach consumers and guests from every corner of the globe. With operations in more than 40 countries, our employees and cast members work together to create entertainment experiences that are both universally and locally cherished.
This position is with Disney Worldwide Services, Inc., which is part of a business we call The Walt Disney Company (Corporate).
Disney Worldwide Services, Inc. is an equal opportunity employer. Applicants will receive consideration for employment without regard to race, religion, color, sex, sexual orientation, gender, gender identity, gender expression, national origin, ancestry, age, marital status, military or veteran status, medical condition, genetic information or disability, or any other basis prohibited by federal, state or local law. Disney champions a business environment where ideas and decisions from all people help us grow, innovate, create the best stories and be relevant in a constantly evolving world.
Apply Now Apply Later
Current Employees Apply via My Disney Career
Explore Location
$148.7k-199.4k yearly 60d ago
Analyst, Information Security (Compliance)
Melco Resorts & Entertainment
Security engineer job in Los Angeles, CA
As an Analyst, Information Security (Compliance) you will be part of Team focusing adherence to Macau Cyber Security Law (MCSL), ISO27001 (latest) standard, regulatory requirements, and in-house policies.
PRIMARY RESPONSIBILITIES:
* Ensure Melco Information Security Policy is compliant with Macau Cyber Security Law (MCSL) and to carried out required activities accordingly.
* Enforce Melco Information Security Policy based on industrial standards (e.g. ISO27001 latest) and best practices across all Melco properties and locations
* Oversee security control systems to prevent or deal with violation of Information Security Policies and Standards
* Review and revise Information Security policies, procedures, standards and checklists periodically to ensure compliance to the latest standards and best practices
* Coordinate/support an information security awareness program to deliver risk communication, awareness and training for audiences, which may range from senior leaders to field staff
* Coordinate/support internal/external audit activities; perform annual internal audit in conjunction with internal policy, regulation and governance. Ensure audit findings and corrective actions are closed out accordingly
* Review change/service request tickets in ticketing system within agreed SLA
* Remain informed on current standards, trends and issues in the information security industry
* Ensure cloud product (e.g. AWS, Azure, Alibaba) compliance to an array of cyber-security industry frameworks
* Support Information Security Operation Calendar activities
* Produce required dashboard for management reviews (e. Compliance, Vulnerability reports)
QUALIFICATIONS:
Experience
* 2+ years' working of experience in a related field.
* Requires in depth experience and knowledge of enterprise IT concerns and technologies
* Experience with managing a compliance and/or security organization, including planning and executing security policies and standards development
* Experience in ISO 27001 latest standard
* Experience in Macau Cyber Security Law is a plus
* 1+ years in information security preferred to include management or administration in least 6 of the following disciplines:
* Network Security and firewalls (CCSP/CCIE - Security, CCNA)
* Relational Database Security
* Remote Access/VPN solutions
* Information Security Auditing
* Intrusion Detection and Response
* Anti-virus systems
* Messaging Security
* Security policy and procedure development
* Windows and Active Directory security
* Access management processes
* Security benchmarking requirements (CIS)
* Security compliance for Regulatory requirements (NERC/SOX/HIPPA/FISMA)
* Security Strategic Planning and Risk Management
* Web and application based security
* Encryption (PKI/Kerberos/SSL)
* Cloud Technologies
Education
* Bachelor's degree in Management Information System, Computer Science, or related disciplines
* An information security or other similar technical certification such as Certified Information Systems Auditor (CISA) and Certified Information Systems Security Professional (CISSP) is highly desirable
Skills / Competencies
* Knowledge of security policies, standards, regulatory requirements such as ISO 27001, PCI-DSS, GDPR, MCSL
* Fluent in of written and spoken English. Fluency in Cantonese and Mandarin will also be an advantage
* Good knowledge of cloud platforms (e.g. AWS, Azure, Alibaba) a plus
* Proven excellence in researching, organizing, writing, and presenting technical information via report writing and presentation (PowerPoint, Excel)
* Capacity to work independently and in a team environment, with leadership ability and project management skills
* Ability to multi-task and have solid project management skills.
* Ability to understand the relationship between business processes, priorities, risk and their underlying
* technologies and security risks
* Ability to keep pace with a fast pace and growing company
* Strong analytical and inter-personal skills to communicate technical information to non-technical background
* users
PERSONAL COMPETENCIES:
* Displays a high commitment to delivering results
* Leads others to achieve business objectives
* Communicates effectively
* Displays the highest level of integrity
* Ability to maintain discretion
* Self-motivated
* Approachable
$90k-132k yearly est. 1d ago
Health Hacker - Los Angeles
Next Health 4.2
Security engineer job in Los Angeles, CA
About UsAt Next Health, we are redefining health optimization by integrating cutting-edge medical innovation with preventative, data-driven wellness. Through our technology-forward platform and luxury clinical environments, we empower our members to take control of their well-being with personalized longevity solutions. We are rapidly expanding across the U.S., and we are seeking visionary leaders to help scale our digital infrastructure and member experience.
Your ImpactAs the Front Desk Receptionist at Next Health, you will be the first point of contact for our patients, visitors, and vendors. You will play a critical role in creating a positive patient experience and ensuring that our operations run smoothly.
Job DescriptionAs the Front Desk Receptionist, you will be responsible for:
Greeting patients and visitors with a welcoming and professional demeanor Checking in patients and verifying their demographic and payment information Scheduling appointments and managing the clinic schedule Assisting patients with questions and concerns Maintaining patient records and updating them as needed.Coordinating with other departments and healthcare providers to ensure seamless patient care.
What to Expect In this role, you can expect to:
Interact with a diverse group of patients and visitors Manage multiple tasks and responsibilities simultaneously Use electronic medical records and scheduling software Work closely with other departments and healthcare providers Provide excellent customer service and patient care
What You'll BringWe're looking for someone who has:
1+ years of experience in a medical office or healthcare setting Excellent communication and interpersonal skills Strong attention to detail and organizational skills Ability to manage multiple tasks and ************************************** Super AdminExperience with electronic medical records and scheduling software Knowledge of medical terminology and insurance billing practicesA passion for providing exceptional customer service and patient care Aptitude for sales Passion for and knowledge of health & wellness services.Exceptional at customer service.Display a genuine interest in helping other people.Excited to learn new things and be on the cutting edge of health & wellness.
Our Culture & PerksWe're a patient-centered healthcare clinic with a culture that values empathy, respect, and teamwork. We offer:
Competitive salary and benefits package Opportunities for professional growth and developmentA supportive and inclusive work environment Meaningful work that makes a difference in patient's lives
Expected CompensationThe expected compensation for this position is $21 per hour, plus benefits.
Pay offered may vary depending on multiple individualized factors, job-related knowledge, skills, and experience. The total compensation package for this position may also include other elements dependent on the position offered. Details of participation in these benefit plans will be provided if an employee receives an offer of employment.
Additional Information: As part of our selection process, all candidates may be required to participate in an in-person interview with a Next Health representative at one of our locations, whenever possible, prior to a final hiring decision.Next Health is an Equal Opportunity employer, committed to promoting a diverse and inclusive workplace. All qualified applicants will be considered for employment without regard to race, color, religion, sex, sexual orientation, age, national origin, disability, protected veteran status, gender identity or expression, or any other characteristic protected by applicable federal, state, or local laws.
We are dedicated to ensuring equal employment opportunities for all applicants and employees, including those with criminal histories, arrest records, or conviction records, in accordance with relevant laws. This includes compliance with the City of Los Angeles' Fair Chance Initiative for Hiring Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, where applicable.
Qualified individuals with a disability who require assistance during the application or recruitment process, have the right to request a reasonable accommodation. Please submit your request to ********************.
We kindly ask that applicants refrain from calling our office regarding job inquiries. All application-related questions should be directed to ********************. Thank you for your understanding.
$21 hourly Auto-Apply 60d+ ago
Systems Security Engineer
Teledyne 4.0
Security engineer job in El Segundo, CA
**Be visionary** Teledyne Technologies Incorporated provides enabling technologies for industrial growth markets that require advanced technology and high reliability. These markets include aerospace and defense, factory automation, air and water quality environmental monitoring, electronics design and development, oceanographic research, deepwater oil and gas exploration and production, medical imaging and pharmaceutical research.
We are looking for individuals who thrive on making an impact and want the excitement of being on a team that wins.
**Job Description**
Teledyne Controls is a global leader in delivering innovative avionics systems and data management solutions for both civil and military aircraft operators. Our cutting-edge technologies enable real-time access, analysis, and utilization of critical flight data, enhancing safety, efficiency, and operational performance across the aviation industry. Become part of a team that thrives on innovation and excellence in a dynamic, mission-driven environment.
**Join Our Team as a Systems SecurityEngineer!**
As an Entry-Level Avionics SecurityEngineer, you will play a key role in safeguarding next-generation avionics systems. This position combines hands-on testing, vulnerability analysis, and collaborative design support to ensure robust security across connected products. You'll work closely with engineering teams and customers to implement secure architectures, monitor emerging threats, and contribute to innovative solutions that meet stringent aerospace security standards.
If you're ready to take on the challenge of securing cutting-edge avionics products and thrive in a dynamic environment, we want to hear from you!
**Essential Duties and Responsibilities** include the following. Other duties may be assigned.
+ Collaborate with engineering teams, program management, and customers to define and communicate security requirements and updates.
+ Perform testing and validation of security features and controls to ensure compliance and effectiveness.
+ Contribute to security assessments, including risk analysis, threat modeling, and penetration testing activities.
+ Monitor and evaluate Common Vulnerabilities and Exposures (CVEs) for relevance to Teledyne products.
+ Execute test scenarios to assess product security resilience under various conditions.
+ Participate in trade studies and evaluations of security processes, tools, and technologies.
+ Support design teams in strengthening security architecture and implementing secure solutions for new and existing products.
+ Assist in customer-facing technical reviews, including preliminary and critical design presentations.
+ Stay informed on emerging security threats and trends to proactively enhance product security.
+ Contribute to the development and integration of security features for connected avionics systems.
+ Promote security awareness through education, communication, and best-practice initiatives.
**Qualifications**
+ Bachelor degree in engineering or other technical field and 0-2 years of experience (can include coursework, projects and internships).
+ Basic understanding of Security Architecture principles, including cryptography, authentication, network security, and public key infrastructure mechanisms to secure product, network, and system boundaries, as well as inter-system communications.
+ Familiarity with networking concepts, including design and troubleshooting.
+ Basic knowledge of system design concepts and application development.
+ Awareness of security implementations in cloud environments, such as AWS.
+ Understanding of the design, auditing, analysis, support, and troubleshooting of security systems.
+ Basic knowledge of embedded system security and Linux.
+ Experience with scripting using Python, Bash, or PowerShell is a plus.
+ Must be a U.S. Person (includes U.S. citizens, lawful permanent residents, refugees, and asylees)
**Salary Range:**
$58,100.00-$77,400.000
**Pay Transparency**
The anticipated salary range listed for this role is only an estimate. Actual compensation for successful candidates is carefully determined based on several factors including, but not limited to, location, education/training, work experience, key skills, and type of position.
Teledyne conducts background checks on qualified applicants who receive a conditional offer of employment in accordance with applicable laws, regulations and ordinances. Background checks may include, but are not limited to, education verification, employment history and verification, criminal convictions, Motor Vehicle Report (MVR & driving history), reference check, credit checks/credit history and drug testing. All qualified applicants with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.
Teledyne and all of our employees are committed to conducting business with the highest ethical standards. We require all employees to comply with all applicable laws, regulations, rules and regulatory orders. Our reputation for honesty, integrity and high ethics is as important to us as our reputation for making innovative sensing solutions.
Teledyne is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age, or any other characteristic or non-merit based factor made unlawful by federal, state, or local laws.
You may not realize it, but Teledyne enables many of the products and services you use every day **.**
Teledyne provides enabling technologies to sense, transmit and analyze information for industrial growth markets, including aerospace and defense, factory automation, air and water quality environmental monitoring, electronics design and development, oceanographic research, energy, medical imaging and pharmaceutical research.
$58.1k-77.4k yearly 41d ago
Information Security Risk Specialist
American Riviera Bank
Security engineer job in Santa Barbara, CA
Job Description
About the Role:
The Information Security Risk Specialist plays a critical role in safeguarding an organization's information assets by identifying, assessing, and mitigating security risks. This position involves developing and implementing risk management strategies that align with business objectives and regulatory requirements. The specialist will collaborate with cross-functional teams to ensure security controls are effective and that risk exposure is minimized.The ideal candidate must have an understanding of current and emerging technological trends and be able to implement appropriate security controls. Also requires an awareness of IT standards, regulations, and laws affecting financial institutions. They are responsible for examining applications from new customers, requesting supportive and missing data and information, and working with other departments to classify data.
Understanding the way the Bank operates and the various internal and external factors that may affect its performance and information security is vital to this role. Strong communication skills are also necessary to communicate technological concepts and techniques in daily work. Analytical thinking skills are also crucial, as they must apply a high level of technical knowledge and skill while working in a fast-paced environment. This role also requires strong problem-solving skills and the ability to work independently to successfully perform the assigned tasks. Must learn effective methods to manage risk and have the ability to analyze complex data, interpret laws, and represent management views. Good understanding of all risk-related issues and procedures relating to bank products and services.
Minimum Qualifications:
Bachelor's degree in Information Security, Computer Science, or a related field.
At least 3 years of experience in information security risk management or a similar role.
Strong understanding of risk assessment methodologies and information security frameworks such as NIST, ISO 27001, or CIS Controls.
Familiarity with regulatory requirements such as GDPR, HIPAA, or SOX.
Excellent analytical, communication, and problem-solving skills.
Preferred Qualifications:
Professional certifications such as CISSP, CISM, CRISC, or equivalent.
Experience with security governance, risk, and compliance (GRC) tools.
Knowledge of cloud security risk management and emerging technologies.
Experience working in a large enterprise or highly regulated industry.
Advanced degree in cybersecurity, risk management, or business administration.
Responsibilities:
Conduct comprehensive risk assessments to identify potential threats to information systems and data.
Develop, implement, and maintain risk management frameworks and policies in accordance with industry standards and regulations.
Collaborate with IT, compliance, and business teams to design and enforce security controls that mitigate identified risks.
Monitor and report on risk metrics, security incidents, and compliance status to senior management and stakeholders.
Stay current with evolving cybersecurity threats, vulnerabilities, and regulatory changes to update risk strategies accordingly.
Skills:
The Information Security Risk Specialist uses analytical skills daily to evaluate complex security risks and develop effective mitigation strategies. Communication skills are essential for collaborating with diverse teams and conveying risk findings to both technical and non-technical stakeholders. Proficiency with risk management frameworks and tools enables the specialist to implement structured and repeatable processes for assessing and managing risks. Knowledge of regulatory environments ensures that risk strategies comply with legal and industry standards. Additionally, staying informed about emerging threats and technologies allows the specialist to adapt risk management approaches proactively, maintaining a strong security posture.
How much does a security engineer earn in Oxnard, CA?
The average security engineer in Oxnard, CA earns between $92,000 and $181,000 annually. This compares to the national average security engineer range of $77,000 to $141,000.