Cyber Security Engineer
Remote job
Our client Dscout is a flexible Experience Research Platform for capturing in-context insights from high-quality participants, bridging the gap between product teams and users. Leading brands like Sonos, Spotify, Duolingo and Best Buy use Dscout to test ideas, iterate quickly, collaborate, and build confidently. We are expanding our smart and driven team and would love for you to join us.
We are looking for a Cybersecurity Engineer to become a part of the Cybersecurity team reporting to the VP, Compliance and Information.
The Cybersecurity Engineer will contribute to reducing risk within the Dscout SaaS environment and internal IT systems. This includes planning and implementing cybersecurity controls, supporting cybersecurity operations, and monitoring the threat landscape. This role will ensure Dscout controls operate effectively over time.
What You Will Do
Lead the process to build security into the Dscout SaaS environment. This includes applying security throughout the software development lifecycle.
Collaborate with Engineering to plan and implement cybersecurity controls to protect the SaaS environment. This includes applying leading practices to secure AWS resources (e.g., VPCs, EC2 instances, and containers).
Continually enhance security monitoring of the SaaS environment and internal IT services by implementing SIEM and working with Engineering to continuously improve logging and auditability.
Assess evolving threats and develop recommendations to mitigate risk to Dscout. You will provide weekly threat intelligence reports highlighting potential risk to the organization.
Work side-by-side with Engineering to analyze, contain, and mitigate cyber attacks and other related incidents.
Perform vulnerability monitoring and, where appropriate, ensure remediation.
Participate in the development of security policies and processes.
Assist third party risk reviews.
Provide recommendations to continually improve security controls.
Assist in development of security programs and efforts to promote security awareness.
What you need to have (we can call them Desired Skills and Background):
Experience working with developers to conduct security reviews and provide strong recommendations to manage risk. This includes a strong understanding and practical use of OWASP Top 10 (web and AI).
Experience securing AWS cloud environments and infrastructure as code solutions such as Terraform.
Proven ability to implement security monitoring tools such as Datadog. This includes the ability to identify relevant scenarios and ensure proper logging.
Experience responding to cyber attacks such as bots and account compromise as well as threats like data leakage and infected computers.
Strong knowledge of cloud computing environments.
Working knowledge of security in software development and continuous integration/continuous delivery (CI/CD).
Experience documenting and implementing security policies and processes.
Knowledge of security frameworks and standards: ISO 27001, NIST, or SANS preferred.
Experience with HITRUST and/or SOC 2 certification is preferred.
Good communication, documentation and presentation skills.
Limitless curiosity and insatiable appetite to understand human behavior and relevant technologies.
Background
Bachelor's degree is preferred
CISSP, CCSP, or GIAC security certification preferred
A minimum of 3 years of security experience
Of course, what is outlined above is an ideal set of expectations, but things may shift based on business needs, and other projects and tasks could be added at the discretion of your manager.
About Dscout
Dscout is a team of passionate, empathetic, and curious professionals. As a recognized leader in the Forrester Wave, we're at the cutting edge of experience research technology. The power of research drives us-how in-context insights from real people can build more enjoyable products and services.
We prioritize learning, sharing, and building. We also deeply value being a diverse and inclusive team and company and look for team members who align with that belief. Join our dynamic team and help shape product roadmaps and business strategies for the world's most loved brands.
It doesn't stop there. When you join the Dscout team, you will get:
* A strong and competitive compensation package with a built-in bonus and equity program.
* An incredible and progressive benefits package (for both you and your dependents) to support work/life balance, including flexible PTO, 16 company holidays, 12 weeks of paid parental leave, 401k match, and much more.
* An education stipend to support your growth & development and a remote work stipend.
* A company that is open and transparent with our team. You will know what is happening and why it matters.
Dscout is an equal-opportunity employer that values diversity. We do not discriminate based on identity, including race, color, religion, national origin or ancestry, sex, gender identity and expression, age, physical or mental disability, pregnancy, veteran or military status, unfavorable discharge from military service, genetic information, sexual orientation, marital status, order of protection status, citizenship status, arrest record or expunged or sealed convictions, or any other legally recognized protected basis under federal, state, or local law.
If you need reasonable accommodations for any part of the employment process, please email us at accommodations@dscout.com with the nature of your request and your contact information. We'll do all we can to ensure you're set up for success during our interview process while upholding your privacy, including accommodation requests. Please note that only inquiries concerning a request for reasonable accommodation will be responded to from this email address.
When you apply at Dscout, we will process your job applicant data, including your employment and education history, transcript, writing samples, and references, as necessary to consider your job application for open positions. For more information about our privacy practices, please visit our Privacy Policy.
Dscout participates in the E-Verify program in certain locations, as required by law.
NOTE: DSCOUT NEVER CONTACTS JOB APPLICANTS VIA TEXT, MESSENGER, OR OTHER SIMILAR APPLICATIONS. BE AWARE OF PHISHING AND SPOOFING SCAMS, BOTH VIA TEXT AND EMAIL. ONLY RESPOND TO EMAILS FROM DSCOUT.COM
#BI-Remote
#LI-Remote
Nuclear Cyber Security Engineer - REMOTE
Remote job
IF YOU DO NOT HAVE THE REQUIRED BACKGROND IN THE U.S. COMMERCAL NUCLEAR INDUSTRY, PLEASE DO NOT APPLY. Immediate opening for a Cyber Security Engineer with commercial nuclear background, to perform design modifications (involving digital upgrades) as well as preparing cyber assessments on those digital components. Prefer direct/perm hire, will consider contract. This person will be the go-to individual for Cyber related projects.
Must be familiar with NEI-08-09, EPRI graded approach, have digital mod experience, and extensive understanding of plant SSC (Safety Classification of Structures, Systems, and Components). Site Cyber qualifications to perform CSAT (Cyber Security Assessment Team) would be a plus. Compensation based on experience, but likely in the 140K-$160K range.
JSG offers medical, dental, vision, life insurance options, short-term disability, 401(k), weekly pay, and more. Johnson Service Group (JSG) is an Equal Opportunity Employer. JSG provides equal employment opportunities to all applicants and employees without regard to race, color, religion, sex, age, sexual orientation, gender identity, national origin, disability, marital status, protected veteran status, or any other characteristic protected by law.
#D650
OT Security Architect
Remote job
We are seeking an OT Security Architect to work remotely. This position will be responsible for safeguarding our operational technology infrastructure. This role offers the flexibility to work remotely with periodic travel to our manufacturing sites. First Quality is a growing manufacturing organization that has defined security as one of its key business values. Joining our team will provide you with unique personal and professional growth opportunities where you'll be hands-on and securing cutting-edge industrial automation and technologies contributing to a growing field where cybersecurity directly protects critical processes, manufacturing, and safety.
Primary responsibilities include:
• Primarily responsible for OT security event monitoring, management, and response
• Create an IS reference architecture for our OT networks
• Work with OT engineering team, as well as with SOC team and verify that the reference architecture fits the business processes and requirements
• Work with OT engineering teams for defining security controls for their on-going projects
• Provide technical guidance to the GRC team with assessing OT 3rd party vendor and supply chain
• Integrate with OT engineering projects and verify that the required IS controls are properly implemented
• Revise and develop processes to strengthen the current OT Security Operations Framework, review policies and highlight the challenges in managing SLAs
• Perform threat management, threat modeling, identify threat vectors and develop use cases for OT security monitoring including red\blue penetrations tests
• Responsible for developing, configuring, and maintaining OT security automation and orchestration IR's and tools.
• Creation of reports, dashboards, metrics for OT security operations and presentation to Sr. Mgmt.
• Create required standards and procedures (i.e. IS purchasing standard, sanitization process) in coordination with all relevant stakeholders
The ideal candidate should possess the following:
• Minimum of five (5) years of professional experience in OT security and operations.
• Knowledge of controls and automation equipment and principles (i.e. PLCs, SCADA, DCS, HMIs, VFDs, etc.)
• Familiarity with security frameworks and standards such as NIST, ICS Mitre ATT&CK, and IEC 62443
• Experience in defining and implementing security controls for OT engineering projects.
• Experience managing projects with the abilities to prioritize tasks and manage time effectively.
• Experience in developing, configuring, and maintaining OT security automation and orchestration tools.
• Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field. In lieu of degree, related experience will be considered.
• Background in manufacturing controls is preferred
What We Offer You
We believe that by continuously improving the quality of our benefits, we can help to raise the quality of life for our team members and their families. At First Quality you will receive:
• Competitive base salary and bonus opportunities
• Paid time off (three-week minimum)
• Medical, dental and vision starting day one
• 401(k) with employer match
• Paid parental leave
• Child and family care assistance (dependent care FSA with employer match up to $2500)
• Bundle of joy benefit (years' worth of free diapers to all team members with a new baby)
• Tuition assistance
• Wellness program with savings of up to $4,000 per year on insurance premiums
• ...and more!
First Quality is committed to protecting information under the care of First Quality Enterprises commensurate with leading industry standards and applicable regulations. As such, First Quality provides at least annual training regarding data privacy and security to employees who, as a result of their role specifications, may come in to contact with sensitive data.
First Quality is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, sexual orientation, gender identification, or protected Veteran status.
For immediate consideration, please go to the Careers section at ********************
to complete our online application.
Application Security Architect - Hybrid
Remote job
Crown Equipment Corporation is a leading innovator in world-class forklift and material handling equipment and technology. As one of the world's largest lift truck manufacturers, we are committed to providing the customer with the safest, most efficient and ergonomic lift truck possible to lower their total cost of ownership.
Remote Work: Crown offers hybrid remote work for this position. A reasonable commute is necessary as some onsite work is required. Relocation assistance is available.
Primary Responsibilities
Define security architecture standards and blueprints for web, mobile, cloud, and Application Programming Interface (API)-based applications.
Review design documents and perform architecture risk assessments for new and existing applications.
Collaborate with DevOps, Engineering, and Infrastructure teams to ensure architectures align with secure design principles.
Integrate automated security testing/scanning tools (Static Application Security Testing (SAST), Software Composition Analysis (SCA)) into Continuous Integration (CI) or Continuous Delivery (CD) pipelines.
Define and enforce secure coding standards and practices across development teams.
Provide training and guidance to developers on secure development principles and vulnerability prevention.
Conduct threat modeling and attack surface reviews for high-risk or critical applications.
Identify potential security flaws and recommend mitigations early in development process.
Track and communicate technical risk to product managers, developers, and leadership teams.
Develop and maintain application security policies, baselines, and architecture frameworks.
Ensure application security practices align with regulations including General Data Protection Regulation (GDPR) and Payment Card Industry Data Security Standard (PCI-DSS).
Support audit and compliance initiatives by providing documentation and evidence of secure development practices.
Minimum Qualifications
Bachelor's degree in Information Technology, Cyber Security, Computer Science, or related field is required, along with 2-4 years related experience.
Non-degree considered if 12+ years of related experience along with a high school diploma or GED
Preferred Qualifications
5+ years in cybersecurity with at least 3 years in application security or secure software development experience.
Secure Software Development Life Cycle (SDLC) in development. Deep knowledge of Open Web Application Security Project (OWASP) Top 10, National Institute of Standards and Technology (NIST), and secure coding frameworks.
Experience with Securing Secrets and Service Accounts desired.
Experience with Web Application Firewall (WAF) implementation/support preferred.
Familiarity with Identity and Access Management and cloud security practices (AWS, Azure).
Certified Information Systems Security Professional (CISSP), or similar certification (Certified Secure Software Lifecycle Professional, Certified Ethical Hacker (CEH) certified).
Familiarity with container security (Docker, Kubernetes).
Understanding of authentication protocols (Open Authorization (OAuth) and Security Assertion Markup Language (SAML)).
Experience with DevSecOps tools and container security tools desired.
Work Authorization:
Crown will only employ those who are legally authorized to work in the United States. This is not a position for which sponsorship will be provided. Individuals with temporary visas or who need sponsorship for work authorization now or in the future, are not eligible for hire.
No agency calls please.
Compensation and Benefits:
Crown offers an excellent wage and benefits package for full-time employees including Health/Dental/Vision/Prescription Drug Plan, Flexible Benefits Plan, 401K Retirement Savings Plan, Life and Disability Benefits, Paid Parental Leave, Paid Holidays, Paid Vacation, Tuition Reimbursement, and much more.
EOE Veterans/Disabilities
Network Security Engineer II
Remote job
Sr. Network Engineer II Employment Type: Full-Time Sponsorship: Not Provided
We're seeking an experienced Sr. Network Engineer to join a growing IT team and play a key role in designing, implementing, and maintaining enterprise-level network infrastructure. This is a remote position available exclusively to candidates residing in Idaho or Utah.
What You'll Do
Plan, implement, and support network projects, including risk assessment and migration strategies.
Configure and maintain Cisco routers, switches, wireless, remote access, and WAN devices.
Recommend and implement new technologies to improve network performance and scalability.
Monitor global network performance, troubleshoot issues, and perform preventative maintenance.
Collaborate with carriers for circuit procurement and migrations.
Maintain accurate technical documentation and configurations.
Participate in on-call rotation and occasional travel as needed.
What You'll Bring
6+ years of hands-on networking and troubleshooting experience in multiprotocol environments.
5+ years with router/switch technology and routing protocols (BGP, MPLS, EIGRP).
4+ years supporting LANs, VLANs, WLANs, VPNs, NAT, and DHCP services.
3+ years with network security products and protocols (IPS/IDS, IPSEC VPN).
CCNP preferred.
Experience with Cisco Nexus (9k, 7k, 5k), ISR, ASR, Next Gen Firewalls, Meraki wireless.
Familiarity with monitoring tools (SolarWinds, Splunk, ThousandEyes, AppDynamics).
Strong leadership, problem-solving, and communication skills.
Remote Pre-Sales Security Systems Engineer - Access Control & CCTV
Remote job
Together, We Enhance Innovation and Growth i2G specializes in advanced physical electronic security and life safety solutions. I2G has proven experience in surveillance, access control, and intrusion detection systems, biometrics, fence sensors, radars, ground sensors, anti-drone technologies, and more. We excel in design, project management, commissioning, and enterprise technology integrations.
i2G's mission is to provide the products and services that meet our customers' needs to give them a vital advantage in today's market, helping to protect what matters most.
This position will provide engineering design and support for security solutions for new and existing clients while working alongside internal teams, external teams, clients, and subcontractors to ensure project success.
Responsibilities
* Possess a thorough understanding of standard Electronic Security technology (ACS, IDS, FDS, CCTV) and supporting equipment such as computer software/hardware, databases, and networking infrastructure.
* Ability to review architectural, electrical, telecommunication, security engineering floor plans, riser drawings, device schedules, and detail drawings.
* Design, develop, and implement solutions for system installations, upgrades, repairs, and conversions.
* Review of Field Site Survey documentation and provide technical assistance with RFI/RFP responses.
* Create solution design documentation (drawings, BOMs, solution design summaries).
* Provide technical support for in-office and on-site team members.
* Support management in the process of creating documentation for implementing new technology with new and existing customers.
* Maintain familiarity with current and emerging electronic security technologies such as access control, video surveillance, intrusion detection, biometrics, etc. and industry leading vendors.
Qualifications
* A minimum of 3-7 years previous experience in the industry.
* Associate or bachelor's degree in relevant field preferred or applicable amount of experience in the appropriate field may be substituted for the educational background.
* Experience in the design and planning of access control and video systems.
* Professional Electronic Security Certifications or training (Lenel, Genetec, C-Cure. Avigilon, Axis, Bosch, Milestone, etc.) preferred.
Company Overview
This is a Security Systems Engineer career opportunity with i2G Systems. Learn more about i2G: ***************************************
"Kastle Systems Makes Strategic Investment in i2G Systems, Strengthening Leadership in Serving High-Security Industries and High-Value, Large Scale Facilities" Read More About the Partnership Here:
***********************************************************************************************************************************************************************************
Equal Opportunity Statement
We are an Equal Opportunity / Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, age, protected veteran status, marital status, pregnancy or any other basis protected by applicable federal or state laws.
Auto-ApplySecurity Systems Engineer (Remote)
Remote job
The application window is expected to close on 12/08/2025. Job posting may be removed earlier if the position is filled or if a sufficient number of applications are received. **AI at Cisco** With Cisco, you're not just embracing the future - you're helping create it! We are focused on integrating AI into our solutions to transform collaboration, security, networking, observability, and more. We are innovating ethical AI products and infrastructure that enable our customers to stay ahead of cyberattacks, predict and prevent network outages, and make team meetings more productive. Our extensive data sets and broad customer reach means limitless possibilities for you to build impactful AI solutions that solve a wide array of real-world problems. Join us at Cisco where you will innovate with top AI experts and be a part of our mission to power an inclusive future for all.
**AI in the Business Unit**
The Cisco Security group includes such industry leading security suites and products as Hypershield, Cisco Secure Access, Identity Intelligence, Duo, XDR, Cisco Security AI, Talos, and more. We are using machine learning and GenAI across our products to simplify security, prevent sophisticated attacks, and ensure the secure use of large language models (LLMs).
In Security, we are building AI-enhanced cybersecurity for better outcomes, combining AI with the breadth of Cisco telemetry across the network, private and public cloud infrastructure, applications, internet, email, and endpoints. With Security AI, we make it simple to use natural language instruction and interact with GenAI - from deploying and managing firewall policies to streamlining incident response. With Duo, we are creating extensive machine learning and analytics to detect and block suspicious users. We are harnessing our rich security expertise in conjunction with AIML to transform the way we assist, augment, and automate security efforts for our customers! We need your help to tip the scale in favor of defenders and enable enterprises everywhere to cancel bad actors.
**Meet the Team**
You will be a part of our Cisco Security Innovation team within the Security Business Group. This team incubates ideas that turn into the future of Cisco's innovative security solutions. You will play a pivotal role in driving scalable performance AI models to improve the efficacy of threat detections. You will bring your expertise in deep learning and large transformer models conduct research, design and development of state-of-the-art ML/AI techniques applicable to threat detection, including anomaly detection, behavioral analysis, signature generation, and predictive modeling. The techniques are focused toward realtime efficacy and evaluating scalable architectures.
**Your Impact**
+ Leverage modern AI/ML techniques to improve the accuracy of threat detection solutions and automate/accelerate manual analysis processes.
+ Develop and implement advanced machine learning models across different hardware environments (including cloud and network edge); models may include adapting neural network architectures or creating novel ones to address challenges.
+ Develop methods to identify performance metrics and efficacy of the models especially of the hardware accelerated models.
+ Analyze and extract significant patterns in high-dimensional data spaces using advanced techniques.
+ Implement robust software systems for integrating and maintaining machine learning models.
+ Collaborate with software engineering teams to design primary deployment strategies for machine learning models into security systems.
+ Establish and maintain best practices for machine learning and security operations, including clear documentation of models and procedures.
**Minimum Qualifications:**
+ Bachelor's degree or higher in Computer Science or related field
+ 5+ years of related security experience, specifically in the areas of network security environments
+ Experience with multi-threaded environments
+ Experience with Linux operating systems and embedded Linux environments
**Preferred Qualifications:**
+ Master's or PhD degree in Computer Science, Computer Engineering, or a related field
+ Experience with state-of-the art machine learning techniques and libraries
+ Debugging skills in complex hardware/software
+ Coding experience with Python, C/C++, etc.
+ Experience with software development environments and version control systems (e.g. Git)
+ A strategic problem solver in the areas of threat detection and analysis
+ Experience optimizing machine learning or deep learning models for specific hardware
+ Familiarity with hardware acceleration libraries (e.g., Morpheus, cu DNN, TensorRT, OpenVINO).
+ Experience with containerization technologies (e.g., Docker, Kubernetes) in the context of hardware-specific deployments
+ Knowledge of cybersecurity concepts and threat detection methodologies
+ Low-level Kernel coding experience
\#LI-RN1
**Why Cisco?**
At Cisco, we're revolutionizing how data and infrastructure connect and protect organizations in the AI era - and beyond. We've been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds. These solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint.
Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions. Add to that our worldwide network of doers and experts, and you'll see that the opportunities to grow and build are limitless. We work as a team, collaborating with empathy to make really big things happen on a global scale. Because our solutions are everywhere, our impact is everywhere.
We are Cisco, and our power starts with you.
**Message to applicants applying to work in the U.S. and/or Canada:**
The starting salary range posted for this position is $165,000.00 to $241,400.00 and reflects the projected salary range for new hires in this position in U.S. and/or Canada locations, not including incentive compensation*, equity, or benefits.
Individual pay is determined by the candidate's hiring location, market conditions, job-related skillset, experience, qualifications, education, certifications, and/or training. The full salary range for certain locations is listed below. For locations not listed below, the recruiter can share more details about compensation for the role in your location during the hiring process.
U.S. employees are offered benefits, subject to Cisco's plan eligibility rules, which include medical, dental and vision insurance, a 401(k) plan with a Cisco matching contribution, paid parental leave, short and long-term disability coverage, and basic life insurance. Please see the Cisco careers site to discover more benefits and perks. Employees may be eligible to receive grants of Cisco restricted stock units, which vest following continued employment with Cisco for defined periods of time.
U.S. employees are eligible for paid time away as described below, subject to Cisco's policies:
+ 10 paid holidays per full calendar year, plus 1 floating holiday for non-exempt employees
+ 1 paid day off for employee's birthday, paid year-end holiday shutdown, and 4 paid days off for personal wellness determined by Cisco
+ Non-exempt employees** receive 16 days of paid vacation time per full calendar year, accrued at rate of 4.92 hours per pay period for full-time employees
+ Exempt employees participate in Cisco's flexible vacation time off program, which has no defined limit on how much vacation time eligible employees may use (subject to availability and some business limitations)
+ 80 hours of sick time off provided on hire date and each January 1st thereafter, and up to 80 hours of unused sick time carried forward from one calendar year to the next
+ Additional paid time away may be requested to deal with critical or emergency issues for family members
+ Optional 10 paid days per full calendar year to volunteer
For non-sales roles, employees are also eligible to earn annual bonuses subject to Cisco's policies.
Employees on sales plans earn performance-based incentive pay on top of their base salary, which is split between quota and non-quota components, subject to the applicable Cisco plan. For quota-based incentive pay, Cisco typically pays as follows:
+ .75% of incentive target for each 1% of revenue attainment up to 50% of quota;
+ 1.5% of incentive target for each 1% of attainment between 50% and 75%;
+ 1% of incentive target for each 1% of attainment between 75% and 100%; and
+ Once performance exceeds 100% attainment, incentive rates are at or above 1% for each 1% of attainment with no cap on incentive compensation.
For non-quota-based sales performance elements such as strategic sales objectives, Cisco may pay 0% up to 125% of target. Cisco sales plans do not have a minimum threshold of performance for sales incentive compensation to be paid.
The applicable full salary ranges for this position, by specific state, are listed below:
New York City Metro Area:
$165,000.00 - $277,600.00
Non-Metro New York state & Washington state:
$146,700.00 - $247,000.00
* For quota-based sales roles on Cisco's sales plan, the ranges provided in this posting include base pay and sales target incentive compensation combined.
** Employees in Illinois, whether exempt or non-exempt, will participate in a unique time off program to meet local requirements.
Cisco is an Affirmative Action and Equal Opportunity Employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, gender, sexual orientation, national origin, genetic information, age, disability, veteran status, or any other legally protected basis.
Cisco will consider for employment, on a case by case basis, qualified applicants with arrest and conviction records.
Senior Systems Engineer, SAP Security
Remote job
The Role: As the Senior Systems Engineer you will own and drive Moderna's SAP Security and GRC roadmap-driving access-management procedures, periodic access reviews, and audit readiness across our global SAP landscape. You will architect secure, compliant solutions for S/4HANA and adjacent platforms (Ariba, MDG, BTP etc.), support Upgrades, Implementation and Enhancement initiatives for the Security and GRC scope.
Here's What You'll Do:
Security Governance & Compliance
* Define and maintain SAP security guidelines, operating procedures, and SoD framework
* Own SOX, GxP, and ITGC controls; coordinate testing and remediation
* Drive periodic user-access reviews and license optimization initiatives
Access Management & GRC
* Experience with full-cycle implementation and support of SAP GRC 12.x modules (ARM, ARA, BRM, EAM, access certifications)
* Design, build, and transport security roles across SAP landscapes; leverage CHARM workflows
* Translate business requirements into technical role designs and custom GRC rules
Architecture & Project Support
* Set security and GRC architecture standards for ongoing SAP projects and upgrades
* Evaluate risk and control impacts of role changes; provide guidance to project teams
* Coordinate SIT/UAT for security objects and drive cut-over activities
Audit, Monitoring & Reporting
* Serve as primary contact for internal/external audit inquiries; deliver evidence and action plans
* Track KPIs and SLAs, prepare regular metrics for management reporting
* Lead Continuous Improvement of monitoring and alerting capabilities
Innovation & AI Enablement
* Research and recommend AI/ML solutions for predictive access analytics, risk scoring, and anomaly detection
* Pilot and operationalize AI features that enhance security intelligence and compliance automation
Here's what you'll bring to the table:
* Education: Bachelor's degree or Equivalent
* Overall Experience: 7-8 years of SAP Security & GRC (v10.0 +) experience, including S/4HANA and Fiori-role design. Deep knowledge of access-management principles, SOD analysis, SOX/GxP compliance, and ITGCs. Hands-on expertise with SAP GRC 12.0 modules (ARM, EAM, ARA) and CHARM processes in Solution Manager
* Implementation Experience: Experience implementing GRC, supporting security design for Greenfield implementations, upgrades and similar projects
* Applications/Solution experience: Security and GRC implementation experience for SAP Ariba, MDG, GTS, BTP, ATTP
* Strong troubleshooting skills, attention to detail, and commitment to service-level excellence
* Outstanding communication skills and aptitude for collaborating with technical and business stakeholders
Preferred Qualifications
* SAP certifications in Security and/or GRC Access Control
* Global implementation or multi-landscape experience
* Exposure to AI/ML tools for security analytics and compliance monitoring
* Familiarity with SAP licensing models and optimization tactics
Pay & Benefits
At Moderna, we believe that when you feel your best, you can do your best work. That's why our US benefits and global well-being resources are designed to support you-at work, at home, and everywhere in between.
* Best-in-class healthcare coverage, plus voluntary benefit programs to support your unique needs
* A holistic approach to well-being, with access to fitness, mindfulness, and mental health support
* Family planning benefits, including fertility, adoption, and surrogacy support
* Generous paid time off, including vacation, volunteer days, sabbatical, global recharge days, and a discretionary year-end shutdown
* Savings and investment opportunities to help you plan for the future
* Location-specific perks and extras
The salary range for this role is $130,800.00 - $209,400.00. This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. An individual's position within the salary range will be based on several factors including, but not limited to, specific competencies, relevant education, qualifications, certifications, experience, skills, performance, and business or organizational needs.
The successful candidate may be eligible for an annual discretionary bonus, other incentive compensation, or equity award, subject to company plan eligibility criteria and individual performance.
About Moderna
Since our founding in 2010, we have aspired to build the leading mRNA technology platform, the infrastructure to reimagine how medicines are created and delivered, and a world-class team. We believe in giving our people a platform to change medicine and an opportunity to change the world.
By living our mission, values, and mindsets every day, our people are the driving force behind our scientific progress and our culture. Together, we are creating a culture of belonging and building an organization that cares deeply for our patients, our employees, the environment, and our communities.
We are proud to have been recognized as a Science Magazine Top Biopharma Employer, a Fast Company Best Workplace for Innovators, and a Great Place to Work in the U.S.
If you want to make a difference and join a team that is changing the future of medicine, we invite you to visit modernatx.com/careers to learn more about our current opportunities.
Our Working Model
As we build our company, we have always believed an in-person culture is critical to our success. Moderna champions the significant benefits of in-office collaboration by embracing a 70/30 work model. This 70% in-office structure helps to foster a culture rich in innovation, teamwork, and direct mentorship. Join us in shaping a world where every interaction is an opportunity to learn, contribute, and make a meaningful impact.
Moderna is a smoke-free, alcohol-free, and drug-free work environment.
Equal Opportunities
Moderna is committed to equal employment opportunity and non-discrimination for all employees and qualified applicants without regard to a person's race, color, sex, gender identity or expression, age, religion, national origin, ancestry or citizenship, ethnicity, disability, military or protected veteran status, genetic information, sexual orientation, marital or familial status, or any other personal characteristic protected under applicable law. Moderna is a place where everyone can grow. If you meet the Basic Qualifications for the role and you would be excited to contribute to our mission every day, please apply!
Moderna is an E-Verify Employer in the United States. We consider qualified applicants regardless of criminal histories, consistent with legal requirements.
Accommodations
We're focused on attracting, retaining, developing, and advancing our employees. By cultivating a workplace that values diverse experiences, backgrounds, and ideas, we create an environment where every employee can contribute their best.
Moderna is committed to offering reasonable accommodations to qualified job applicants with disabilities. Any applicant requiring an accommodation in connection with the hiring process and/or to perform the essential functions of the position for which the applicant has applied should contact the Accommodations team at leavesandaccommodations@modernatx.com.
Export Control Notice
This position may involve access to technology or data that is subject to U.S. export control laws, including the Export Administration Regulations (EAR). As such, employment is contingent upon the applicant's ability to access export-controlled information in accordance with U.S. law. Due to the nature of the work and regulatory requirements, only individuals who qualify as U.S. persons (citizens, permanent residents, asylees, or refugees) are eligible for this position. For this role Moderna is unable to sponsor non-U.S. persons to apply for an export control license.
#LI-CK1
*
Auto-ApplySenior Backend Engineer - Identity Security & Agentic Systems
Remote job
At Veza, we're building the next generation of Access Identity Security - and we're bringing GenAI into the core of that mission. We're seeking a Senior Backend Engineer who is excited to work on multi-agent systems, LLM-based automation, and Model Context Protocols (MCP) to transform how access control intelligence is built and delivered.
This is a rare opportunity to operate at the frontier of LLM research and backend systems engineering, contributing to both the design of scalable architectures and the implementation of intelligent agents that reason, decide, and act.
You will:
Building APIs and backend services, test and evaluation frameworks in Python/Golang to support agentic workflows.
Prototyping and productizing LLM-based capabilities into the identity access pipeline.
Developing agent orchestration layers and working with frameworks like LangGraph or AutoGen.
Designing systems around context-awareness, memory, and autonomous decision-making.
You Have:
Education:
Bachelor's or Master's degree in Computer Science, Engineering, or a related field.
Experience:
5+ years of backend development experience.
Strong proficiency in one or more programming languages, such as Python, Golang, or Java.
Experience designing and implementing RESTful APIs and Microservices Architectures.
Experience with cloud platforms, such as AWS, Azure, or Google Cloud Platform, and familiarity with IAM services and features.
Curiosity and/or experience with GenAI technologies, multi-agent systems, or prompt orchestration.
Strong communication and interpersonal skills, with the ability to effectively communicate technical concepts to both technical and non-technical stakeholders.
Strong sense of Product feature Ownership - from Ideation to Deployment
The compensation for this role depends on several factors such as the candidate's skills, qualifications, experience, and work location. For candidates offered a position at the posted job level, the provided range is the expected base salary. This does not include any additional variable compensation, such as commission.
Compensation Disclosure $154,000-$210,000 USD
Our Culture
We're driven to build a strong company culture and are looking for individuals with solid alignment with the following:
Ownership Mindset
Act with Integrity
Guardians of our Customers
Opinionated Humility
Build Trust, Earn Trust
At Veza, your base pay is one part of your total compensation package. For this position, the reasonably expected pay range can be discussed with your recruiter for the level at which this job has been scoped. Your base pay will depend on several factors, including your experience, qualifications, education, location, and skills. In the event that you are considered for a different level, a higher or lower pay range would apply. This position is also eligible for equity and a competitive benefits package.
Veza is proud to be an equal opportunity employer. We are committed to equal employment opportunities regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, veteran status, or other applicable legally protected characteristics. We also consider qualified applicants according to applicable federal, state, and local laws. If a candidate with a disability requires an accommodation during the recruitment process, please email *******************
About Veza
Veza is the identity security company. Identity and security teams use Veza to secure identity access across SaaS apps, on-prem apps, data systems, and cloud infrastructure. Veza solves the blind spots of traditional identity tools with its unique ability to ingest and organize permissions metadata in the Veza Authorization Graph. Global enterprises like Blackstone, Wynn Resorts, and Expedia trust Veza to visualize access permissions, monitor permissions activity, automate access reviews, and remediate privilege violations. Founded in 2020, Veza is headquartered in Redwood City, California, and is funded by Accel, Bain Capital, Ballistic Ventures, GV, Norwest Venture Partners, and True Ventures. Visit us at veza.com and follow us on LinkedIn, Twitter, and YouTube.
Auto-ApplyCyber Insider Threat Analyst (Remote)
Remote job
Country:
United States of America Remote
U.S. Citizen, U.S. Person, or Immigration Status Requirements:
U.S. citizenship is required, as only U.S. citizens are authorized to access information under this program/contract.
Security Clearance:
None/Not Required
RTX Corporation is an Aerospace and Defense company that provides advanced systems and services for commercial, military and government customers worldwide. It comprises three industry-leading businesses - Collins Aerospace Systems, Pratt & Whitney, and Raytheon. Its 185,000 employees enable the company to operate at the edge of known science as they imagine and deliver solutions that push the boundaries in quantum physics, electric propulsion, directed energy, hypersonics, avionics and cybersecurity. The company, formed in 2020 through the combination of Raytheon Company and the United Technologies Corporation aerospace businesses, is headquartered in Arlington, VA.
The following position is to join our RTX Enterprise Services team:
Role Overview:
Enterprise Services (ES) Cybersecurity has an immediate opening for a qualified insider threat analyst to join RTX Cyber Defense reporting to the Associate Director of Cyber Insider Threat Operations. As an insider threat analyst, you will be responsible for supporting the analysis, monitoring and triage of alerts stemming from potential insider threats.
What You Will Do:
Perform log analysis to detect anomalies, leveraging expertise in security operations tools to monitor and safeguard sensitive data. Utilize behavioral analytics and endpoint security solutions to identify and investigate unusual patterns.
Monitor potential data exfiltration points using data loss prevention tools and other security solutions to detect and prevent unauthorized transfers.
Apply Open-Source Intelligence (OSINT) techniques to gather and analyze publicly available information related to insider threats.
Identify insider threat trends and patterns to assist content teams in the development of new detection rules and models.
Articulate the implications of the risks relative to insider threats and educate team members, peers and stakeholders on the potential impacts.
Review data, alerts and behaviors to identify potential concerns from multiple angles, gather information and understand and articulate information gaps needed to inform decisions.
Work independently and with teams to define and complete analysis activities.
Document findings in a manner that technical and non-technical stakeholders understand and can articulate findings to leadership and peers.
Perform initial analysis on data from systems to identify unexpected or malicious activity across channels while understanding how activity fits into the threat landscape.
Assist in building processes, procedures and training for the insider threat team.
Collaborate with stakeholders to provide suggestions and feedback for validation and improvement of various tools, models, and processes.
Stay updated on the latest developments and trends in insider threats, emerging and/or advanced persistent attack vectors, and industry best practices, incorporating this knowledge into RTX's defense strategies.
Perform other duties as assigned and as required to continuously drive process excellence.
Qualifications You Must Have:
Typically requires a University Degree or equivalent experience and a minimum 5 years of experience, or an Advanced Degree and a minimum 3 year's experience.
Minimum 5 years supporting a cyber insider threat program and/or a cyber incident response team, including at least 3 years with cybersecurity tools and technologies used to detect and mitigate insider threats, including, but not limited to security information and event monitoring (SIEM), user entity and behavior analytics (UEBA), user activity monitoring (UAM), data loss prevention (DLP) technologies and endpoint security solutions.
Must be able to effectively communicate (verbal and written) technical and strategic details to peers, leadership, and stakeholders with varying levels of operational expertise.
The ability to obtain and maintain a U.S. government issued security clearance is required. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance.
Qualifications We Prefer:
Insider Threat specific training/certifications such as CERT Insider Threat course work or Center for Development of Security Excellence (CDSE).
Industry certifications in information security or technology such as, CISSP, CISM, CGEIT.
Experience collaborating with teams inside and outside of Digital Technology (ex. Privacy, Legal, HR).
Preferred candidate will have experience with Operating System, cloud access, and web proxy event logs, endpoint/extended detection & response, and security incident & event management (SIEM) platforms.
Demonstrate critical thinking and problem-solving skills.
What We Offer: Whether you're just starting out on your career journey or are an experienced professional, we offer a robust total rewards package with compensation; healthcare, wellness, retirement and work/life benefits; career development and recognition programs. Some of the benefits we offer include parental (including paternal) leave, flexible work schedules, achievement awards, educational assistance and child/adult backup care.
Learn More & Apply Now!
Work Location: Remote
Please consider the following role type definition as you apply for this role:
Remote: This position is currently designated as remote. However, the successful candidate will be required to work from one of the 50 U.S. states (excluding U.S. Territories). Employees who are working in Remote roles will work primarily offsite (from home). An employee may be expected to travel to the site location as needed.
As part of our commitment to maintaining a secure hiring process, candidates may be asked to attend select steps of the interview process in-person at one of our office locations, regardless of whether the role is designated as on-site, hybrid or remote.
The salary range for this role is 82,000 USD - 164,000 USD. The salary range provided is a good faith estimate representative of all experience levels. RTX considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate's work experience, location, education/training, and key skills.Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement.Hired applicants may be eligible for annual short-term and/or long-term incentive compensation programs depending on the level of the position and whether or not it is covered by a collective-bargaining agreement. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company's performance.This role is a U.S.-based role. If the successful candidate resides in a U.S. territory, the appropriate pay structure and benefits will apply.RTX anticipates the application window closing approximately 40 days from the date the notice was posted. However, factors such as candidate flow and business necessity may require RTX to shorten or extend the application window.
RTX is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or veteran status, or any other applicable state or federal protected class. RTX provides affirmative action in employment for qualified Individuals with a Disability and Protected Veterans in compliance with Section 503 of the Rehabilitation Act and the Vietnam Era Veterans' Readjustment Assistance Act.
Privacy Policy and Terms:
Click on this link to read the Policy and Terms
Auto-ApplyCyber Security Analyst
Remote job
Responsibilities:
Investigate security incidents and escalate when necessary
Work Incident Response and Administrative tickets
Perform and develop data mining queries using Splunk/Splunk ES
Communicate in a clear and concise manner with Leadership, Customers and Peers
Monitor and respond to multiple shared Mailbox inquiries
Provide vulnerability, threat, and risk mitigation support
Monitor Security Operations Dashboards for alerts
Support daily Operations briefings
Monitor and answer the SOC phone hotline
Support customer defined metrics reports
Support government data calls
This opportunity offers remote work!
Candidates must be willing to work in a SOC environment and demonstrate strong problem-solving skills
Must be able to work well both on their own (in an individual setting) as well as with others (in a team setting)
Must possess strong self-initiative, curiosity, and diligence - must be willing to engage with the team, in the capacity of both learning and sharing information
Computer Associates' Top Secret Security product Systems Administrator (Remote)
Remote job
Type of Requisition:
Regular
Clearance Level Must Currently Possess:
None
Clearance Level Must Be Able to Obtain:
None
Public Trust/Other Required:
Other
Job Family:
IT Infrastructure and Operations
Job Qualifications:
Skills:
CA Top Secret, IBM z/OS, Security Tools
Certifications:
None
Experience:
7 + years of related experience
US Citizenship Required:
Yes
Job Description:
We are GDIT. The people supporting and securing some of the most complex government, defense, and intelligence projects across the country. We are currently seeking a Computer Associates' Top Secret Security product Systems Administrator .
Responsibilities:
• Provide mentor level support experience.
• Provide customer support by preparing ad hoc reports and giving presentations.
• Monitors the environment for adherence to security standards.
• Customer focus and act as a SPOC dealing with customer. Liaison with business areas and other technical support areas
• Review and monitor mainframe security reports for any possible policy violations.
• Execute mainframe vulnerability scans utilizing zSecure and other security tools.
• Review and report on Universal Access, revoked users, Super UNIX User authority, and CICS/IMS/DB2 Access violation reports.
• Provide off hour on call support for security related incidents.
Candidates should have 7+ years of experience with expertise in the skills/duties listed below:
• In-depth knowledge of CA Top Secret for z/OS and provide the ability to externalize security.
• Hands on experience and knowledge CA Top Secret, z/OS
• Hands-on administration of z/OS, CICS, and Top Secret login ID's, dataset and resource rules.
• Key knowledge areas are to find and remove obsolete, unused, redundant, and excessive access right in CA Top Secret
• Understand group structures in CA Top Secret, and UID string setup gives access to Mainframe resources.
WHAT GDIT CAN OFFER YOU
Full-flex work week
401K with company match
Customizable health benefits packages
Collaborative teams of highly motivated critical thinkers and innovators
Internal mobility team dedicated to helping you own your career
Rewards program for high-performing employees
GDIT CAREERS
Opportunity Owned
Discover more at ********************
The likely salary range for this position is $114,750 - $155,250. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
Scheduled Weekly Hours:
40
Travel Required:
None
Telecommuting Options:
Remote
Work Location:
Any Location / Remote
Additional Work Locations:
Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. GDIT typically provides new employees with 15 days of paid leave per calendar year to be used for vacations, personal business, and illness and an additional 10 paid holidays per year. Paid leave and paid holidays are prorated based on the employee's date of hire. The GDIT Paid Family Leave program provides a total of up to 160 hours of paid leave in a rolling 12 month period for eligible employees. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.Join our Talent Community to stay up to date on our career opportunities and events at
gdit.com/tc.
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
Auto-ApplyCyber Analyst, Digital Forensics Incident Response
Remote job
Why you should join our At-Bay Security team:
At-Bay is a fast-growth InsurSec company (Insurance x Cybersecurity) on a mission to bring innovative products to the market that help protect small businesses from digital risks. As an InsurSec provider, we uniquely combine insurance with mission-critical security technologies, threat intelligence, and human expertise, to bridge the critical security capability gap that exists among SMBs in the community. We believe InsurSec is an $80B market opportunity and we are excited to expand our DFIR team in order to help expand our reach and influence in the business and security community, of which we serve 35,000 customers.
The Role:
Cybersecurity Analysts focused on Digital Forensics and Incident Response (DFIR) deliver incident investigation and response services to At-Bay insureds via:
Forensically sound collection, transmission, and storage of digital evidence
Analysis of digital evidence to identify indicators of compromise and adversary activity
Development of incident timelines and theories of compromise
Identification of incident root causes
Participation in threat actor negotiations as necessary (e.g., ransom negotiations, etc.)
Participation in incident recovery (e.g., restoration of data from backups, reimaging workstations and servers, rebuilding network infrastructure, etc.) activities as necessary
Development and delivery of incident reports to document key incident details for engagement stakeholders including executive leaders for insureds, breach coach attorneys, and At-Bay claims management staff as necessary
Development and delivery of recommendations to mitigate the risk of future incidents for impacted insureds
Development and delivery of incident response training and simulations for targeted insureds
Key skills:
Previous digital forensics and incident response experience
Strong oral and written communication skills
Previous hands-on experience performing digital forensics and incident response, including several of the following:
Business Email Compromise
Ransomware
Digital evidence collection and analysis
Development and analysis of cyber threat intelligence
Leadership of or participation in investigations involving digital evidence
Intrusion detection / cyber threat hunting
Malware analysis
Incident recovery activities such as restoration of data from backups, operation of decryptor tools, etc.
Previous hands-on experience working in information technology operations (e.g., Network Operations Center, Security Operations Center, Incident Response Team, etc.)
Minimum requirements:
Bachelor's degree or equivalent
Minimum of 2 years of experience in cybersecurity operations, incident response, incident recovery, or another security discipline
Willingness to travel as needed to perform job functions
Preferred requirements:
Significant undergraduate or graduate coursework in computer science, computer engineering, information systems, or cybersecurity
Previous background in law enforcement or government/military with experience leading complex technical investigations
Knowledge of cloud environments, including knowledge of cloud security products and services offered by major cloud service providers (e.g., AWS, Azure, Google)
Experience in a top-10 cyber consulting firm or leading DFIR provider preferred
One or more industry cybersecurity certifications (e.g., GCIH, Security+, CISSP, etc.)
Work location:
USA, Nationwide
Fully Remote
Our estimated base pay range for this role is $80,000-$115,000 per year. Base salary is determined by a variety of factors including but not limited to market data, location, internal equitability, domain knowledge, experiences and skills. In general, if the position sparks your interest we encourage you to apply - our team prioritizes talent.
#LI-CK1
Auto-ApplyAssociate Cyber Security Operations Analyst
Remote job
As an S&C Electric team member, you'll work on projects that have real-world impact. You'll help transform the grid for resilient and reliable power worldwide. S&C has more than a 100-year history of innovation and has been 100% employee-owned since 2012. We continue this legacy as a trusted, forward-thinking leader in the electrical industry. You will advance a safer, more reliable, and more resilient electrical grid. Our products help the grid adapt to severe weather and transition to clean energy. We're big enough to be a respected industry leader but small enough for you to impact our company directly. Our commitment gives you opportunities to impact on and off the job positively.
Join S&C to make an impact on tomorrow's energy challenges and become an employee-owner!
Hours
8:00 am - 5:00 pm (Mon-Fri) Remote
Compensation
At S&C, we are dedicated to providing competitive and equitable compensation for all our team members, and we are committed to transparency in our pay practices. The estimated annual base salary range for this position in the United States is $67,200 - $86,814 and can be found in the JOB INFO section below. Individual pay within this salary range is determined by several compensable factors, including performance, knowledge, job-related skills and experience, and relevant education or training. This role is also eligible for S&C's annual incentive plan (AIP), subject to eligibility criteria.
Join Our Team as an Associate Cyber Security Operations Analyst!
The Grid Enablement Cyber Security and Communications Team is responsible for designing, implementing, and maintaining secure system configurations in accordance with Federal and industry cyber security standards, stakeholder requirements, & operational needs. Leveraging deep expertise in both Information Technology (IT) and Operational Technology (OT), the team applies cyber security principles in a way that not only protects systems but also ensures they operate at their full potential. This approach balances robust security with optimal system performance, supporting the mission-critical functions of our customers.
The Associate Cyber Security Operations Analyst is tasked with supporting the Grid Enablement - Cyber Security teams project requirements by assisting in the implementation of cyber security frameworks used by the Department of Defense (DoD) and private sector utilities. This role works closely with technical leads and team members to develop strategies, timelines, and high quality deliverables for cybersecurity and complex engineering projects. Responsibilities include contributing to network design and security architecture, participating in hardware/software specifications, and ensuring device configurations meet compliance and risk management standards while maintaining functionality of mixed IT and OT systems.
Key Responsibilities:
Work with the technical lead on cybersecurity project scopes
Work with Team to develop strategy and timeline to meet project's milestones and deliverables
Participate in network design, security architecture, and diagrams
Participate in hardware, software, and communications media specification
Participate in device configurations and hardening for security compliance and Risk Management
Work with Team to ensure timely delivery of high-quality cybersecurity documentation including security policies and procedures, RMF artifacts, configuration guides, testing reports, and training materials
Participate in cybersecurity assessments including vulnerability and compliance scanning and reporting
Participate in S&C's Information Security program as it applies to customer facing services
Must be able to work independently in a fully remote environment
Ability to relay technical information to non-technical audiences
Function effectively within a global teams environment and under minimal supervision
Ability to travel internationally and out of state on average 4-5 times per year for 1-3 weeks per trip
Maintains regular and punctual attendance.
Attends in-person or virtual meetings as requested or required.
Communicates effectively and respectfully with others.
Other responsibilities as assigned.
Must be a United States Citizen.
What you'll Need To Succeed:
Degree program in Information Systems, Cybersecurity, Computer Science, Computer Engineering, or a related field in progress to be complete within 2 years (associate's degree) or 3 years (bachelor's degree) from date of hire.
It may be permissible to substitute current technical certification to meet requirements at the discretion of the hiring manager.
Familiarity with Microsoft security technology
Foundational knowledge of cyber security and risk management concepts.
Strong interpersonal skills with the ability to interview, facilitate, and collaborate with diverse subject matter experts and stakeholders.
Strong written and verbal communication skills with the ability to communicate effectively with all levels of leaders and team members, adjusting communication approaches based on the audience.
Strong organizational skills with the ability to manage multiple projects simultaneously to deadlines.
Ability to work independently and as part of a team.
Strong attention to detail and ability to follow activities through on time and with accuracy.
Critical thinking and problem-solving skills and an ability to identify potential issues and seek support for resolution.
Proficient in Microsoft Office products including Outlook, Excel, and PowerPoint.
Preferred:
At least 1 year experience in cyber security or technical field.
S&C Electric is committed to equal-opportunity employment. All employees and applicants will be considered without regard to age, color, disability, gender, national origin, race, religion, sexual orientation, gender identity, protected veteran status, or any other classification protected by federal, state, or local law. If you are an individual with a disability and need an accommodation to complete the application, please email us at *******************.
No fixed deadline
#LI-BB1
Auto-ApplyGlobal Cyber Wordings Analyst
Remote job
Join our global Cyber team as a Wordings Analyst supporting the Global Cyber Wordings Manager in the strategic development and governance of our Cyber and Tech policy suite, including Liberty Cyber Resolution and Liberty Tech Resolution. This role is a hands-on business enabler: you will help translate complex legal and regulatory requirements into clear, market-ready wordings, maintain our global clause library, support manuscript negotiations, and produce practical tools that empower underwriters and strengthen broker confidence. It's an excellent opportunity for an early-career insurance wordings or legal professional to build expertise in a fast-moving, global specialty line and make a visible impact on growth, innovation, and client experience.
Key responsibilities:
Wording library and drafting support
Maintain and expand the global wording library centered on Liberty Cyber Resolution and Liberty Tech Resolution, including endorsements, exclusions, and guidance notes.
Redline and prepare first drafts of standard clauses and endorsements; ensure consistency with definitions, coverage intent, and plain-language standards.
Track version control, change logs, approvals, and archiving;
Assist with localization for different jurisdictions, coordinating translations and filing documentation with Legal/Compliance.
Commercial enablement
Build practical tools (playbooks, FAQs, objection-handling guides, coverage summaries) to help regional teams position our products and close deals efficiently.
Prepare broker/client comparison decks and battlecards; support pitches, RFP/RFI responses, and manuscript negotiations with clause comparisons and recommended alternatives.
Triage wording queries from regions; track SLAs and referral approvals per the global governance framework.
Partner closely with Underwriting, Product, Global Cyber Engagement, Claims, Legal/Compliance, and regional leaders to deliver accurate, timely support and uphold governance standards.
Regulatory and legal stewardship
Monitor and synthesize global regulatory and market developments (e.g., Lloyd's cyber war/systemic guidance, GDPR, DORA, NIS2, sanctions) into succinct briefs and recommended wording actions.
Maintain audit-ready documentation; assist with regulatory filings or attestations where required.
Claims partnership and feedback loop
Collaborate with Claims to capture lessons from disputes and litigation trends; draft guidance notes and propose clarifications to improve coverage certainty.
Support coverage position letters and documentation packs with research, citations, and clause histories.
Innovation and product development support
Help draft prototype wordings for new propositions
Check alignment between underlying policy wordings and reinsurance treaty/facultative clauses.
Administer wording management tools, ensuring robust version control, approval workflows, and usage analytics.
Build dashboards and trackers for adoption of standard forms, deviation rates, SLA performance, disputes, and audit findings; provide monthly reporting to stakeholders.
Qualifications
Bachelor's degree in business, economics, or other quantitative field. Minimum 3 years, typically 4 years or more of relevant work experience.
2 - 5 years of experience in insurance wordings, legal/paralegal support, underwriting support, or product documentation; cyber specialty experience preferred.
Strong drafting, redlining, and proofreading skills with a plain-language mindset and exceptional attention to detail.
Working knowledge of insurance policy structures, endorsements, exclusions, and coverage interpretation; familiarity with cyber war/systemic language, sanctions, and privacy regulations is advantageous.
Research and synthesis skills to translate complex regulatory/legal topics into practical guidance and actionable updates.
Proficiency with MS Word (advanced track changes/redlining), Excel (trackers and dashboards), PowerPoint (training/pitch materials), and document/enablement tools.
Collaborative, service-oriented approach; comfortable operating in a global matrix and meeting defined SLAs.
Curiosity about cybersecurity risks and the incident response ecosystem; willingness to learn common threat scenarios to inform practical drafting.
About Us
Pay Philosophy: The typical starting salary range for this role is determined by a number of factors including skills, experience, education, certifications and location. The full salary range for this role reflects the competitive labor market value for all employees in these positions across the national market and provides an opportunity to progress as employees grow and develop within the role. Some roles at Liberty Mutual have a corresponding compensation plan which may include commission and/or bonus earnings at rates that vary based on multiple factors set forth in the compensation plan for the role.
At Liberty Mutual, our goal is to create a workplace where everyone feels valued, supported, and can thrive. We build an environment that welcomes a wide range of perspectives and experiences, with inclusion embedded in every aspect of our culture and reflected in everyday interactions. This comes to life through comprehensive benefits, workplace flexibility, professional development opportunities, and a host of opportunities provided through our Employee Resource Groups. Each employee plays a role in creating our inclusive culture, which supports every individual to do their best work. Together, we cultivate a community where everyone can make a meaningful impact for our business, our customers, and the communities we serve.
We value your hard work, integrity and commitment to make things better, and we put people first by offering you benefits that support your life and well-being. To learn more about our benefit offerings please visit: ***********************
Liberty Mutual is an equal opportunity employer. We will not tolerate discrimination on the basis of race, color, national origin, sex, sexual orientation, gender identity, religion, age, disability, veteran's status, pregnancy, genetic information or on any basis prohibited by federal, state or local law.
Fair Chance Notices
California
Los Angeles Incorporated
Los Angeles Unincorporated
Philadelphia
San Francisco
We can recommend jobs specifically for you! Click here to get started.
Auto-ApplySenior Information Security Risk Specialist (GRC)
Remote job
About Us
At SentinelOne, we're redefining cybersecurity by pushing the limits of what's possible-leveraging AI-powered, data-driven innovation to stay ahead of tomorrow's threats.
From building industry-leading products to cultivating an exceptional company culture, our core values guide everything we do. We're looking for passionate individuals who thrive in collaborative environments and are eager to drive impact. If you're excited about solving complex challenges in bold, innovative ways, we'd love to connect with you.
What are we looking for?
We are looking for a highly motivated, collaborative and experienced Senior InfoSec Risk Specialist with a security-focused mindset who can balance risk, business drivers and timelines. This position will be responsible for understanding and supporting the design of SentinelOne's organizational, procedural and technological security controls within the context of the security frameworks applicable to SentinelOne. In addition, you will be responsible for identifying and testing appropriate controls to ensure they are designed, implemented, and operating effectively to mitigate risk. The selected employee will help implement, automate, document and maintain controls while supporting and responding to inquiries from internal and external stakeholders. This individual must be self-directed and be able to work independently and collaboratively.
What will you do?
Support the planning and performance of IT risk-based security audits and projects, risk assessments, execution of fieldwork and communication to stakeholders.
Help in evaluating relevant global standards, compliance frameworks and regulations to analyze existing controls; identify areas for improvement; and design control growth.
Collaborate with process and control owners through the audit lifecycle for process documentation updates, testing coordination, remediation of identified deficiencies and advising on internal control enhancements or process changes, as appropriate.
Proactively manage audit findings, tracking and documentation of status updates obtained via action owners, and timely execution of remediation activities.
Participate in internal security and compliance programs and track recurring controls, such as SSAE 18 SOC 2, ISO 27001/27002.
Provide control consultative support to the business to assist in redesign efforts to improve the control environment and identify opportunities for control improvements with the objective of mitigating risk and improving compliance and operational performance.
Help support internal/external audits and evidence collection via a GRC tool.
Document new and update existing policies, procedures, standards and resources
Participate in Security awareness program, train personnel on data security and privacy-related processes and responsibilities.
Help support customer security reviews, RFPs and external security and privacy inquiries.
Participate in defining, collecting and tracking various Security Metrics.
What skills and experience should you bring?
5+ years of experience working in information security, risk or compliance.
Experience working with Security Controls across at least some of the following domains: Access Management, Encryption, Risk Management, Network Security, Configuration Management, Patch Management, Change Management, Awareness and Training, BC/DRP, etc.
Ability to perform internal audits with minimal direct supervision, exhibit professional audit judgment and have experience in a broad range of audit projects such as SSAE 16/18 SOC 2, ISO 27001/2, NIST.
Strong risk management experience, performing assessments and audits, designing controls, managing enterprise control frameworks, and prioritizing risk.
Strong project management skills and ability to manage a variety of projects simultaneously to completion within the agreed timelines.
Excellent collaboration and interpersonal skills. Must be able to communicate with all levels in the organization.
Ability to communicate effectively, in writing and verbally, to target audiences, including customers, partners, auditors, executive management, vendors, and peers.
Experience working with both technical and non-technical teams.
Ability and desire to understand the intent of requirements and provide effective recommendations.
Ability to prioritize in a highly dynamic work environment.
Our Preferred Qualifications:
Advanced degree in computer science, Information Technology, Information Security or related field.
Experience with, and strong understanding of common Security Compliance frameworks, controls, and best practices such as COSO, SOC 2, SOX ITGC, ISO 27001/27002, GDPR, PCI, NIST and other applicable regulatory compliance frameworks.
Relevant certifications (ISO 27001 LA/LI, CISA, CISM, CISSP, CRISC, etc.)
Ability to assess and pragmatically define scope and relevant controls.
Strong desire to learn and continuously develop and deepen technical skills.
Why us?
You will be joining a cutting-edge company where you will tackle extraordinary challenges and work with the very best in the industry.
Medical, Vision, Dental, 401(k), Commuter, Health and Dependent FSA
Unlimited PTO
Industry-leading gender-neutral parental leave
Paid Company Holidays
Paid Sick Time
Employee stock purchase program
Disability and life insurance
Employee assistance program
Gym membership reimbursement
Cell phone reimbursement
Numerous company-sponsored events, including regular happy hours and team-building events
This U.S. role has a base pay range that will vary based on the location of the candidate. For some locations, a different pay range may apply. If so, this range will be provided to you during the recruiting process. You can also reach out to the recruiter with any questions.
Base Salary Range$104,000-$138,000 USD
SentinelOne is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.
SentinelOne participates in the E-Verify Program for all U.S. based roles.
Auto-ApplySenior Information Security Specialist-SECRET CLEARANCE REQUIRED
Remote job
Primary Responsibilities:
Execute and support the Risk Management Framework (RMF) lifecycle including system categorization, control selection, implementation, assessment, and authorization.
Develop, maintain, and validate System Security Plans (SSPs), Security Assessment Reports (SARs), POA&Ms, Contingency Plans (CPs), and related compliance documentation.
Conduct and lead vulnerability assessments, leveraging tools such as Nessus, ACAS, and Fortify to identify and prioritize remediation efforts.
Perform continuous monitoring of security controls and produce metrics, dashboards, and evidence in support of ATO renewals and sustainment.
Analyze and respond to security incidents, working with SOC personnel and SIEM tools to evaluate logs, investigate events, and contain potential threats.
Conduct internal audits and risk assessments to validate the effectiveness of implemented controls and identify compliance gaps.
Provide security guidance to engineering and development teams, ensuring adherence to cybersecurity standards in a DevSecOps environment.
Stay informed of evolving threats, vulnerabilities, and regulatory changes to proactively enhance security postures.
Coordinate with Security Control Assessors (SCAs), ISSOs, system owners, and federal stakeholders on audit readiness and policy compliance.
Draft and enforce cybersecurity policies, SOPs, and standards that support mission-critical systems across hybrid environments.
All other duties as assigned by management.
Qualifications
Bachelor's or Associate's degree in Computer Science, Math, Information Technology, Engineering, or related field. Five (5) years of directly relevant experience may substitute for two (2) years of formal education.
Minimum of five (5) years of experience in experience with vulnerability scanning tools and security assessment methodologies.
Minimum of five (5) years of experience with network security, firewall management, intrusion detection/prevention systems (IDS/IPS).
Minimum of (5) years of experience with Security Information and Event Management (SIEM).
Minimum of five (5) years of experience in the risk management framework.
Basic knowledge of the following: Active Directory, UNIX, RHEL, Windows, Relational Databases.
Previous support of federal government enterprise systems or DHS/DOD programs is strongly preferred.
Must have an active DoD Secret Clearance.
Auto-ApplyInformation Security Support Analyst, Contract
Remote job
Overview of 66degrees
66degrees is a leading consulting and professional services company specializing in developing AI-focused, data-led solutions leveraging the latest advancements in cloud technology. With our unmatched engineering capabilities and vast industry experience, we help the world's leading brands transform their business challenges into opportunities and shape the future of work.
At 66degrees, we believe in embracing the challenge and winning together. These values not only guide us in achieving our goals as a company but also for our people. We are dedicated to creating a significant impact for our employees by fostering a culture that sparks innovation and supports professional and personal growth along the way.
Overview of Role
A client of 66degrees' is seeking a junior contractor to engage on a 8+-month remote contract with the potential to extend/convert into a permanent role with the client. Interested candidates should have the following required skills and the ability to work independently as well as within a team environment.
The Information Security Support Contractor will function as a member of the Security Support team and help support day-to-day operations. This role will focus on frontline duties and interact with technical and business units. This role requires strong teamwork and initiative, along with the ability to build and maintain relationships across technical and business units. Excellent communication skills are essential.
Responsibilities
Provide level 1 support for incident and request tickets escalated from other technical teams.
Contribute to protecting the integrity and confidentiality of client data and infrastructure while enabling business functionality in all systems and environments by learning to support applicable security solutions.
Learn about the security tools and solutions implemented within the organization.
Assist in improving processes, identify efficiencies, and recommend solution enhancements to improve service-level delivery.
Support the client Information Security Governance & Compliance team as needed during risk assessments, internal and external Information Security Audits, and Vendor reviews.
Assist in supporting the Identity Access Management team.
Gather and report on key organizational information security metrics.
Qualifications
1-3 years of experience as an Information Security Analyst or experience in an IT support capacity.
Required experience working with:
Active Directory/Azure
File Share Permissions
Email security understanding
Mimecast or a similar solution
Keeper - Nice to have
zScaler - Nice to have
Strong communication, good customer service experience and flexibility with change are all required.
Eagerness to work in a collaborative environment.
66degrees is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to actual or perceived race, color, religion, sex, gender, gender identity, national origin, age, weight, height, marital status, sexual orientation, veteran status, disability status or other legally protected class.
Auto-ApplyInformation Security Controls Analyst
Remote job
United Community is seeking an experienced Information Security Controls Analyst to serve as a subject matter expert in evaluating and strengthening our cybersecurity and technology controls. This role plays a critical part in assessing risk exposure, recommending control improvements, and ensuring alignment with regulatory standards and business risk tolerance. You'll collaborate with enterprise risk, compliance, and legal teams to provide visibility into our risk posture and drive meaningful change across the organization.
What You'll Do
* Review and document the adequacy of security and technology controls across business and IT environments.
* Evaluate control posture through interviews, documentation reviews, and workflow analysis.
* Recommend and support implementation of risk reduction strategies via policies, procedures, and technical controls.
* Partner with risk management and security leadership to align controls with organizational risk tolerance.
* Identify control strengths and weaknesses related to privacy, security, resiliency, and compliance.
* Document and advocate for control improvements that balance risk with operational efficiency.
* Support control development across testing, QA, and production environments.
* Present control effectiveness reports to senior risk leadership.
* Stay current on regulatory requirements, internal policies, and industry best practices.
Requirements For Success
Experience:
* 3+ years in cybersecurity or IT practitioner roles.
* 2+ years in IT risk or controls analysis.
* Practical experience with risk management and IT control frameworks.
Education: Bachelor's degree preferred in Information Assurance, Computer Science, Engineering, or a related technical field.
Required Skills:
* Strong understanding of risk frameworks (CRI, COSO, RMF, COBIT, NIST).
* Familiarity with regulatory standards (PCI, FFIEC, SOX, HIPAA, GDPR, CCPA, GLBA).
* Experience with CIS CSC, ISO 2700, or NIST CSF.
* Excellent written and verbal communication across all organizational levels.
* Strong organizational skills and ability to meet SLAs.
* Sound judgment and decision-making in complex scenarios.
* High integrity, trustworthiness, and adaptability.
Preferred Skills:
* Certifications such as CISSP, CISA, CRISC, or CISM.
* Technical experience with enterprise networks, applications, and directory services.
* Familiarity with enterprise GRC platforms.
Conditions of Employment
* Must be able to pass a criminal background & credit check
* This is a full-time, non-remote position
FLSA Status:
* Exempt
We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, national origin, religion, sexual orientation, gender identity and/or expression, status as a veteran, and basis of disability or any other federal, state, or local protected class.
Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Pay Range
USD $49,972.00 - USD $76,958.00 /Yr.
Consultant - Cyber Security Analyst (Fractional/Contract Role)
Remote job
Join our experienced roster of consultants that support Hedge Funds and Family Offices. Arootah is a personal and professional development leader in the Investment and Financial Services industry. Our mission is to provide top business advisory services to our hedge fund client base. We focus our Business Consulting on the multi-faceted needs of Hedge Funds and Family Offices.
Arootah was founded by Rich Bello, the Co-Founder and COO of the industry-leading $10 billion hedge fund, Blue Ridge Capital. Rich brings more than 30 years of experience, including leadership positions at Morgan Stanley, Tiger Management, and Ernst & Young.
Visit us at **************************************** for more information. WHO WE NEED: Arootah is searching for experienced Cybersecurity Analysts to consult to our highly prestigious client base. As a consultant, you will work with our Hedge Fund and Family Office clients to provide expert advice. Having previously served in this role, you have specific, hands-on experience implementing, maintaining, and operating a cybersecurity program for a leading Hedge Fund or Family Office.
What You'll Do
Best practice reviews.
Developing realistic and effective action plans.
Breaking apart goals into actionable steps.
Advising on vendor selection and oversight.
Creating and implementing policies, procedures, and control measures.
Evaluating each client's advancement toward goal actualization through key performance indicators (KPIs) and scoring matrices.
Special projects or other areas of need.
Implement and assist with the day-to-day operations of securing the firm's various information systems by providing technical expertise in all areas of network, system, and application security.
Protect sensitive information by installing and configuring security software like firewalls and encryption programs.
Monitor network traffic and analyze records like authentication logs to identify and investigate anomalies to prevent and detect security incidents.
Lead the firm's vulnerability management program, conduct the annual cybersecurity assessments and penetration tests, and research and report on emerging threats, to help the firm take pre-emptive risk mitigation steps.
Implement organization-wide security best practices to protect the business against existing, new, and emerging security threats.
Test and analyze the organization's business continuity and disaster recovery plan to ensure operations will continue in the event of a cyberattack or natural disaster.
Assesses new security technologies to determine potential value for the firm.
Execute and carry out firm incident response program to identify and prevent all potential breaches (internal or external), or misuse of data, that may occur.
Review, investigate, and respond to real-time alerts within the environment.
Generate real-time and historical reports for internal and external stakeholders regarding security and/or compliance violations.
Qualifications
A Bachelor's degree in Computer Science, Computer Engineering, Information Systems, Information Sciences, or a related field, with a strong academic record.
One or more of the following certifications: CEH, CISM, CompTIA Security+, CISSP, GSEC, GCIH, GNFA, GREM or other related SANS certifications.
5+ years of specific experience as a Cybersecurity Analyst at a hedge fund or family office.
Working experience with one or more of the following technology vendors and products: Splunk Cloud, Rapid7 Nexpose Vulnerability Scanner, Sophos Antivirus, Varonis DatAlert, ForeScout CounterACT, or similar.
Thorough understanding of Microsoft's enterprise technology platform, including Azure, Active Directory, SQL, Office365, and the Windows server and desktop operating systems.
In-depth knowledge of security event management, network security monitoring, investigating common types of attacks, network packet analysis, log collection and analysis, and reviewing security events.
Demonstrated experience implementing and/or enforcing security and compliance frameworks such as NIST, Cobit, and ISO.
Strong writing and presentation skills are requiredin order to communicate findings and recommendations, as well as the ability to articulate security-related concepts to a broad range of technical and non-technical staff.
Job Status
Contractor
Hours are based on the needs of the assigned client (0-40 hours per week).
Join a well-funded disruptor in finance and technology. Enjoy the flexibility of remote work and choosing your assignments. Be part of a dynamic, high-energy company in its expansion stage. Now is the time to join!
For more information, visit us at Arootah.com.
Auto-Apply