Security System Engineer jobs at Ukpeagvik IOoOupiat Corporation - 145 jobs
ISSO/Systems Security Engineer
UIC Alaska 4.7
Security system engineer job at Ukpeagvik IOoOupiat Corporation
ISSO/SYSTEMSSECURITYENGINEER (RDTE)
Bowhead is seeking a skilled full-time ISSO/SystemsSecurityEngineer to join our team in Dahlgren, VA. The ideal candidate will assure all Information Systems (IS), Government desktops, and corporate network components, unclassified and classified, adhere to and are certified in accordance with the latest versions of guidance such as NAVSEA, DoN, DoD, US CYBERCOM, and other relevant guidance, such as DoD 8500 series, NAVSEAINST 5239.1, and DOD Inst. 5200.40.
Responsibilities
Key Responsibilities:
Provide technical assistance to the Government in assuring compliance with all policies, guidance, and recommendations stipulated and promulgated by the NSWCDD ISSM.
Recommend and develop draft IA and systemsecurity procedures and practices, in accordance with the NSWCDD Information Assurance and Compliance Office standards and administer approved procedures and practices.
Identify security vulnerabilities and recommend corrective security measures for network access points.
Working knowledge in Risk Assessment (RA), Risk Management Framework (RMF) which outlines the 6 Steps to Risk Management Process for Federal Information Systems in order to assist the business areas in completion of the Business Impact Analysis, and subsequent creation of Security Documentations like SystemSecurity Plan (SSP), Security Assessment Report (SAR) and Plans of Action and Milestones (POA&M).
RMF Review, validate, and maintain Assessment & Authorization (A&A) documentation, accreditation records for NSWCDD RDT&E classified and unclassified IT and network systems for the NSWCDD IAM.
Ensure RMF packages are updated and accredited during the regular three-year Authority to Operate (ATO) cycles.
Experience with NIST 800 SPs to include but not limited to NIST SPs 800-37, 800-53 & 53A, 800-60, FIPS (199 & 200).
Develop PDS Approval Request packages for new PDSs and update PDS Daily Inspection Procedures.
Developing a variety of IA related documentation, to include but not be limited to, Platform Information Technology (PIT) designation requests, PIT Risk Assessment requests,
SystemsSecurityEngineer will create Plan of Actions and Milestones (POA&M) and Standard Operating Procedures (SOPs)
Ability to analyze Security Technical Implementation Guides (STIGs), Security Content Automation Protocol (SCAP) and Assured Compliance Assessment Solution (ACAS) scanning results.
Ability to assess technical and non-technical security controls to determine compliance.
Qualifications
Required:
High School Diploma required. Bachelors Degree preferred.
A minimum of to five (5) years of experience in systems design, development and integration preferred.
Must meet DoDD 8140 IAM Level II Certification
Knowledgeable with DoD security and IA requirements as outlined in DoDI 8500.2 and the Defense Information Systems Agency (DISA) Security Technical Implementation Guidelines (STIG).
Must have knowledge of basic to advanced UNIX and Windows system administration as well as current knowledge of DoD Ports, Protocols, and Services (PPS), Public Key Infrastructure (PKI), and DoD Information Assurance Vulnerability Management (IAVM) policies and standards.
Strong oral and written communication skills.
Preferred:
Experience with the Enterprise Mission Assurance Support Service (eMASS), or managing DoD and DoN IA Portfolios is desired.
Prefer a working knowledge of STIG Viewer, ACAS, eMASSter, and Excel.
Knowledge of RDT&E and/or tactical systems
Ability to communicate effectively with all levels of employees and outside contacts
Strong interpersonal skills and good judgment with the ability to work alone or as part of a team
Physical Demands:
Must be able to lift up to 10 pounds
Must be able to stand and walk for prolonged amounts of time
Must be able to twist, bend and squat periodically
SECURITY CLEARANCE REQUIREMENTS: Must be able to obtain a Top Secret clearance may start with a Secret clearance. US Citizenship is a requirement for Top Secret clearance at this location.
#LI-JR1
$92k-121k yearly est. Auto-Apply 19d ago
Looking for a job?
Let Zippia find it for you.
Information Assurance Engineer - Majestic - 26731
Huntington Ingalls Industries 4.3
Washington, DC jobs
Search by Keyword (use Keyword for Remote Positions)
Select how often (in days) to receive an alert:
Information Assurance Engineer - Majestic - 26731
Required Travel: 0 - 10%
Employment Type:Full Time/Salaried/Exempt
Anticipated Salary Range:$75,791.00-$140,000.00
Security Clearance:TS/SCI
Level of Experience:Mid
This opportunity resides with Warfare Systems (WS), a business group within HII's Mission Technologies division. Warfare Systems comprises cyber and mission IT; electronic warfare; and C5ISR systems.
HII works within our nation's intelligence and cyber operations communities to defend our interests in cyberspace and anticipate emerging threats. Our capabilities in cybersecurity, network architecture, reverse engineering, software and hardware development uniquely enable us to support sensitive missions for the U.S. military and federal agency partners.
Meet HII's Mission Technologies Division
Our team of more than 7,000 professionals worldwide delivers all-domain expertise and advanced technologies in service of mission partners across the globe. Mission Technologies is leading the next evolution of national defense - the data evolution - by accelerating a breadth of national security solutions for government and commercial customers. Our capabilities range from C5ISR, AI and Big Data, cyber operations and synthetic training environments to fleet sustainment, environmental remediation and the largest family of unmanned underwater vehicles in every class. Find the role that's right for you. Apply today. We look forward to meeting you.
HII's Mission Technologies division is dedicated to delivering cutting‑edge solutions that advance national security and defense objectives. This position is part of our Cyber and Intelligence division, which plays a critical role in supporting Enterprise‑Level Security and Modernization efforts across IT infrastructure, cybersecurity, physical facilities, and personnel operations.
The selected candidate will contribute to a high‑impact government program focused on enhancing and securing mission‑critical systems and environments. The program is scheduled to launch in early 2026 and due to the classified nature of the mission and the sensitivity of the operational environment, an active TS/SCI security clearance will be required.
Information Assurance Engineer 1: $71,735 - $101,106
Information Assurance Engineer 2: $85,371 - $118,529
Information Assurance Engineer 3: $104,519 - $140,599
Information Assurance Engineer 4: $120,472 - $172,103
Designs and implements information assurance and securityengineeringsystems with requirements of business continuity, operations security, cryptography, forensics, regulatory compliance, internal counter‑espionage (insider threat detection and mitigation), physical security analysis (including facilities analysis, and security management).
Assesses and mitigates systemsecurity threats and risks throughout the program life cycle.
Validates systemsecurity requirements definition and analysis.
Implements security designs in hardware, software, data, and procedures.
Verifies security requirements; performs system certification and accreditation planning and testing and liaison activities.
Supports securesystems operations and maintenance.
Minimum Qualifications
Information Assurance Engineer 1: 0 years experience with Bachelors in related field; or High School Diploma or equivalent and 4 years relevant experience.
Information Assurance Engineer 2: 2 years relevant experience with Bachelors in related field; 0 years experience with Masters in related field; or High School Diploma or equivalent and 6 years relevant experience.
Information Assurance Engineer 3: 5 years relevant experience with Bachelors in related field; 3 years relevant experience with Masters in related field; or High School Diploma or equivalent and 9 years relevant experience.
Information Assurance Engineer 4: 9 years relevant experience with Bachelors in related field; 7 years relevant experience with Masters in related field; or High School Diploma or equivalent and 13 years relevant experience.
Relevant industry certifications (as applicable)
Prior experience in defense, aerospace, or government contracting
Proficiency with specialized tools or software aligned to the role
Demonstrated ability to work collaboratively in multidisciplinary teams
Active TS/SCI government security clearance required to start, candidate must willing to obtain and maintain a CI poly
Physical Requirements
Job performance will normally require only minor lifting and carrying of boxes of records or equipment.
The listed salary range for this role is intended as a good faith estimate based on the role's location, expectations, and responsibilities. When extending an offer, HII's Mission Technologies division takes a variety of factors into consideration which include, but are not limited to, the role's function and a candidate's education or training, work experience, and key skills.
Together we are working to ensure a future where everyone can be free and thrive.
All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, physical or mental disability, age, or veteran status or any other basis protected by federal, state, or local law.
Do You Need Assistance?
If you need a reasonable accommodation for any part of the employment process, please send an e‑mail to ************************** and let us know the nature of your request and your contact information. Reasonable accommodations are considered on a case-by-case basis. Please note that only those inquiries concerning a request for reasonable accommodation will be responded to from this email address. Additionally, you may also call ************** for assistance. Press #3 for HII Mission Technologies.
#J-18808-Ljbffr
$120.5k-172.1k yearly 1d ago
Senior Information Systems Security Officer
Aerovironment 4.6
Jessup, MD jobs
The Senior Information SystemsSecurity Officer will provide aid to the program, organization, system, or enclave's information assurance program. In this position the individual will lend assistance for proposing, coordinating, implementing, and enforcing information systemssecurity policies, standards, and methodologies.
Position Responsibilities:
Assist security authorization activities in compliance with Information System Certification and Accreditation Process (NISCAP) and DoD Risk Management Framework (RMF).
Assists with the management of security aspects of the information system and performs day-to-day security operations of the system.
Evaluate security solutions to ensure they meet security requirements for processing classified information.
Maintain operational security posture for an information system or program to ensure information systemssecurity policies, standards, and procedures are established and followed.
Manage changes to system and assesses the security impact of those changes.
Perform vulnerability/risk assessment analysis to support certification and accreditation.
Provide configuration management (CM) for information systemsecurity software, hardware, and firmware.
Prepare and reviews documentation to include SystemSecurity Plans (SSPs), Risk Assessment Reports, Certification and Accreditation (C&A) packages, and System Requirements Traceability Matrices (SRTMs).
Basic Qualifications (Required Skills & Experience):
Bachelor's degree in an IT-related or similar relevant field is required or equivalent combination of education, training, and experience
Twelve (12) years of related work experience - at least 7 years of experience as an ISSO supporting IC or DoD programs and contracts of similar scope, type, and complexity
DoD 8570 compliance with IAM Level II or IAT Level III (i.e., CASP, CISSP, or Associate)
An active TS/SCI with polygraph
Salary Range: $120,000 - $175,000
The AV pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Determination of official compensation or salary relies on several factors including, but not limited to, level of position, job responsibilities, geographic location, scope of relevant work experience, educational background, certifications, contract-specific affordability, organizational requirements, alignment with local internal equity as well as alignment with market data.
Clearance Level
Top Secret with Poly
ITAR Requirement:
T
his position requires access to information that is subject to compliance with the International Traffic Arms Regulations (“ITAR”) and/or the Export Administration Regulations (“EAR”). In order to comply with the requirements of the ITAR and/or the EAR, applicants must qualify as a U.S. person under the ITAR and the EAR, or a person to be approved for an export license by the governing agency whose technology comes under its jurisdiction. Please understand that any job offer that requires approval of an export license will be conditional on AeroVironment's determination that it will be able to obtain an export license in a time frame consistent with AeroVironment's business requirements. A “U.S. person” according to the ITAR definition is a U.S. citizen, U.S. lawful permanent resident (green card holder), or protected individual such as a refugee or asylee. See 22 CFR § 120.15. Some positions will require current U.S. Citizenship due to contract requirements.
Benefits: AV offers an excellent benefits package including medical, dental vision, 401K with company matching, a 9/80 work schedule and a paid holiday shutdown. For more information about our company benefit offerings please visit: **********************************
We also encourage you to review our company website at ******************** to learn more about us.
Principals only need apply. NO agencies please.
Who We Are
Based in California, AeroVironment (AVAV) is a global leader in unmanned aircraft systems (UAS) and tactical missile systems. Founded in 1971 by celebrated physicist and engineer, Dr. Paul MacCready, we've been at the leading edge of technical innovation for more than 45 years. Be a part of the team that developed the world's most widely used military drones and created the first submarine-launched reconnaissance drone, and has seven innovative vehicles that are part of the Smithsonian Institution's permanent collection in Washington, DC.
Join us today in developing the next generation of small UAS and tactical missile systems that will deliver more actionable intelligence to our customers so they can proceed with certainty - and succeed.
What We Do
Building on a history of technological innovation, AeroVironment designs, develops, produces, and supports an advanced portfolio of unmanned aircraft systems (UAS) and tactical missile systems. Agencies of the U.S. Department of Defense and allied military services use the company's hand-launched UAS to provide situational awareness to tactical operating units through real-time, airborne reconnaissance, surveillance, and target acquisition.
We are proud to be an EEO/AA Equal Opportunity Employer, including disability/veterans. AeroVironment, Inc. is an Equal Employment Opportunity (EEO) employer and welcomes all qualified applicants. Qualified applicants will receive fair and impartial consideration without regard to race, sex, color, religion, national origin, age, disability, protected veteran status, genetic data, sexual orientation, gender identity or other legally protected status.
ITAR
U.S. Citizenship required
$120k-175k yearly Auto-Apply 40d ago
Security Engineer, Identity Management
Interstate Gas Supply 4.8
Remote
For this role, we are looking for a curious and innovative SecurityEngineer with a passion for information security, customer service, and compliance. You will be responsible for guiding security best practices while following security frameworks such as NIST, and SOC2. You will be leading the security programs to ensure minimal risk exposure. At IGS, we take a risk-based approach to our decisions and utilize industry best practices and security frameworks to guide us along the way. We are looking for someone that is good at understanding and solving complex and ambiguous problems and constantly seek improvement.
Primary Responsibilities
Architect and manage Azure Entra infrastructure, including tenant design, hybrid identity configurations, and conditional access policies.
Maintain and optimize Active Directory environments, including domain controllers, group policies, organizational units, and security hardening.
Design and implement Active Directory Federation Services (ADFS) and manage complex federation trusts between internal and external identity providers.
Plan and execute domain trust relationships, including forest trusts, external trusts, and realm trusts across complex enterprise environments.
Lead identity platform through organizational transitions, including tenant-to-tenant migrations, directory consolidations, and identity lifecycle transitions.
Manage multi-tenant Microsoft 365 migrations, ensuring secure data transfer and seamless user transitions during organizational changes.
Develop and maintain disaster recovery and business continuity plans for identity infrastructure.
Implement identity security best practices, including privileged access management, MFA enforcement, and identity protection policies.
Monitor identity infrastructure health, performance, and security posture, responding to incidents and anomalies.
Collaborate with business stakeholders during organizational transitions to ensure smooth identity transitions with minimal business impact.
Other Responsibilities
Work closely with IT and other departments to ensure security measures are integrated into all aspects of the organization's technology and operations.
Apply knowledge of information security principles and practices.
Ability to think strategically but willingness to handle, first-hand, the mechanics of technology services required by the business.
Other duties and responsibilities as assigned.
Required Skills
Proven experience managing complex Microsoft 365 environments, particularly multi-tenant migrations and consolidations.
Strong understanding of Active Directory Federation Services, domain trusts, and forest architectures.
Hands-on experience with Azure Entra, including conditional access, privileged identity management, and hybrid identity configurations.
Solid understanding of authentication protocols (SAML, OAuth 2.0, OpenID Connect, Kerberos, LDAP).
Exceptional organizational skills, follow through, and multitasking abilities.
Decisiveness, good judgment, analytical aptitude, and problem-solving skills to act with authority and take risks in an environment with little direction from others.
Excellent communicator with strong organizational savvy and leadership skills necessary to interface with and influence all levels of organization.
Ability to work in a fast-paced and dynamic environment.
Minimum Education and Experience
Minimum of 5 years of technical experience, with at least 3 years of security focus.
Demonstrated knowledge of, and experience in implementing security technologies and processes.
Professional certifications within security-related areas, while not a minimum requirement, would be highly desirable.
#LI-AM1
Work Authorization: Applicants must be authorized to work in the US on a full-time basis. Unfortunately, a current or future need for sponsorship is not supported or available for this position.
Salary Range:
$87,630.00 - $140,210.00
*This range reflects base pay only. Incentive earnings, like commissions or bonuses, are not included.
This role is also eligible for an annual incentive plan based on company performance. How We Support Your Wellbeing:
Our employees are our most valuable asset. That's why at IGS, we are committed to offering a holistic benefit program that allows employees to stay healthy, feel secure, and maintain flexibility in their wellbeing journey.
Healthcare Essentials: Comprehensive coverage including medical (plus free telehealth), dental, vision, and employer health savings account contributions.
Mental Wellbeing: Robust support through Headspace and free mental healthcare visits for you and your dependents.
Family Planning Support: Extensive assistance with Maven, paid family and caregiver leave, and fertility, adoption, and surrogacy services.
Financial Readiness: Strong financial foundation with a 401(k) plan, company match, and access to financial wellbeing tools.
Work-Life Balance: paid time off, tuition reimbursement, paid leaves, employee hardship fund, and a wide range of additional perks.
Equal Opportunity Employment:
It is the policy of IGS Energy to ensure equal employment opportunity in accordance with all applicable federal and state regulations and guidelines. Employment discrimination against employees and applicants due to race, color, religion, sex (including sexual harassment), national origin, disability, age, sexual orientation, gender identity, military status, and veteran status or other legally protected class under applicable law is prohibited.
$87.6k-140.2k yearly Auto-Apply 27d ago
Cyber Security Operations Analyst
Explorer Pipeline 4.1
Tulsa, OK jobs
The Cyber Security Operations Analyst is primarily responsible for monitoring the front lines of the company's cyber defense program, helping to protect critical systems and data from potential threats, responding to reported security violations, analyzing internet access, connectivity and threats (virus protection, spam, etc.)
DUTIES AND RESPONSIBILITIES
The following represents the majority of the duties performed by the position but is not meant to be all-inclusive nor prevent other duties from being assigned when necessary.
1. Complies with DOT and OSHA health, safety and environmental requirements and follows safety philosophy and procedures developed by the Company including: applicable environmental, health and safety rules, procedures, and accepted safe work practices, the use of appropriate personal protective equipment and safety systems, and the reporting of workplace hazards and injury or illness arising from workplace activities; observes the workplace to identify conditions or behaviors that should be corrected and takes appropriate action.
2. Monitors Security Information and Event Management (SIEM) alerts, firewall logs, intrusion detection systems, and network activity for suspicious behavior including public and private threat intelligence sources for emerging risks; analyzes internet access, connectivity logs, and alerts related to virus protection, spam, and suspicious behavior including user account activity providing reports on potential anomalies.
3. Conducts daily security log reviews and assists in identifying potential threats; summarizes and shares relevant alerts with the cybersecurity team.
4. Monitors incoming security tickets and alerts; documents and triages security incidents, escalating to senior analysts as needed; assists with evidence collection and incident tracking.
5. Performs scheduled vulnerability scans, analyzes findings, and maintains remediation tracking logs; assists with patch management processes including deployment, tracking, and reporting.
6. Assists with internal and external audits by collecting necessary documentation and evidence.
7. Maintains regulatory compliance documentation as required by TSA, DOT, O SHA, etc.; creates and updates procedural documents, runbooks, security playbooks, and knowledge base articles.
8. Documents all incidents, assessments, and routine checks to support audit readiness and knowledge transfer; manages project tracking logs.
9. Assists with the configuration and maintenance of endpoint protection, firewall settings, and other cybersecurity tools under guidance.
10. Reviews vendor solutions and compiles initial summaries for team consideration; maintains security-related inventories, software licenses, and access lists.
11. Assists with development and dissemination of basic cybersecurity awareness content for end users; tracks completion of required security training and assists with scheduling refresher sessions.
12. Participates in a scheduled on-call rotation for after-hours and weekend security support.
REQUIREMENTS
· Associate's degree or the equivalent in experience in Cyber Security, Information Technology or related field and a minimum of two (2) years of prior experience in cybersecurity, IT support, or SOC environment. Internship or hands-on training in networking, firewalls, or securitysystems preferred. Certification such as CompTIA Security+, CASP+, or CEH (preferred or in progress).
Knowledge, Skills and Abilities
· Ability to actively engage in safe behavior and understand and follow the principles and methods related to pipeline and workplace safety as established by the Company.
· Knowledge of emergency and safety procedures, policies procedures, equipment operating parameters, and all applicable DOT, EPA, FERC, DHS, and OSHA requirements.
· Knowledge of Active Directory, Exchange, SharePoint, CISCO routing and switching configuration.
· Knowledge of firewall and network security and IDS (intrusion detection systems), and network management tools.
· Knowledge of TSA security requirements and regulations.
· Knowledge of identity management processes and procedures.
· Skill in project management.
· Ability to manage, track and analyze information.
· Ability to effectively work and cooperate with supervisors, co-workers, and vendors.
· Ability to follow corporate policies and the directions of supervisors.
· Ability to refrain from causing or contributing to the disruption of the workplace.
$87k-113k yearly est. 55d ago
Cyber Security Operations Analyst
Explorer Pipeline Corporation 4.1
Tulsa, OK jobs
The Cyber Security Operations Analyst is primarily responsible for monitoring the front lines of the company's cyber defense program, helping to protect critical systems and data from potential threats, responding to reported security violations, analyzing internet access, connectivity and threats (virus protection, spam, etc.)
DUTIES AND RESPONSIBILITIES
The following represents the majority of the duties performed by the position but is not meant to be all-inclusive nor prevent other duties from being assigned when necessary.
1. Complies with DOT and OSHA health, safety and environmental requirements and follows safety philosophy and procedures developed by the Company including: applicable environmental, health and safety rules, procedures, and accepted safe work practices, the use of appropriate personal protective equipment and safety systems, and the reporting of workplace hazards and injury or illness arising from workplace activities; observes the workplace to identify conditions or behaviors that should be corrected and takes appropriate action.
2. Monitors Security Information and Event Management (SIEM) alerts, firewall logs, intrusion detection systems, and network activity for suspicious behavior including public and private threat intelligence sources for emerging risks; analyzes internet access, connectivity logs, and alerts related to virus protection, spam, and suspicious behavior including user account activity providing reports on potential anomalies.
3. Conducts daily security log reviews and assists in identifying potential threats; summarizes and shares relevant alerts with the cybersecurity team.
4. Monitors incoming security tickets and alerts; documents and triages security incidents, escalating to senior analysts as needed; assists with evidence collection and incident tracking.
5. Performs scheduled vulnerability scans, analyzes findings, and maintains remediation tracking logs; assists with patch management processes including deployment, tracking, and reporting.
6. Assists with internal and external audits by collecting necessary documentation and evidence.
7. Maintains regulatory compliance documentation as required by TSA, DOT, O SHA, etc.; creates and updates procedural documents, runbooks, security playbooks, and knowledge base articles.
8. Documents all incidents, assessments, and routine checks to support audit readiness and knowledge transfer; manages project tracking logs.
9. Assists with the configuration and maintenance of endpoint protection, firewall settings, and other cybersecurity tools under guidance.
10. Reviews vendor solutions and compiles initial summaries for team consideration; maintains security-related inventories, software licenses, and access lists.
11. Assists with development and dissemination of basic cybersecurity awareness content for end users; tracks completion of required security training and assists with scheduling refresher sessions.
12. Participates in a scheduled on-call rotation for after-hours and weekend security support.
REQUIREMENTS
* Associate's degree or the equivalent in experience in Cyber Security, Information Technology or related field and a minimum of two (2) years of prior experience in cybersecurity, IT support, or SOC environment. Internship or hands-on training in networking, firewalls, or securitysystems preferred. Certification such as CompTIA Security+, CASP+, or CEH (preferred or in progress).
Knowledge, Skills and Abilities
* Ability to actively engage in safe behavior and understand and follow the principles and methods related to pipeline and workplace safety as established by the Company.
* Knowledge of emergency and safety procedures, policies procedures, equipment operating parameters, and all applicable DOT, EPA, FERC, DHS, and OSHA requirements.
* Knowledge of Active Directory, Exchange, SharePoint, CISCO routing and switching configuration.
* Knowledge of firewall and network security and IDS (intrusion detection systems), and network management tools.
* Knowledge of TSA security requirements and regulations.
* Knowledge of identity management processes and procedures.
* Skill in project management.
* Ability to manage, track and analyze information.
* Ability to effectively work and cooperate with supervisors, co-workers, and vendors.
* Ability to follow corporate policies and the directions of supervisors.
* Ability to refrain from causing or contributing to the disruption of the workplace.
$87k-113k yearly est. 11d ago
Cyber Security Engineer/Information Systems Security Officer (ISSO)
Aerovironment 4.6
Huntsville, AL jobs
AV is looking for a highly talented Cyber SecurityEngineer/Information SystemsSecurity Officer (ISSO) to join our team! In this role you will be part of our team providing SystemsEngineering Technical Assistance to the Ground-based Midcourse Dense (GMD) Product Office under the Teams-Next Missile Defense SystemsEngineering (TN-MDSE) contract managed by the Missile Defense Agency (MDA).
Job Description:
+ Serve as a member of the cybersecurity team, developing SystemSecurity Plans (SSPs), Interim Authority to Test (IATT), Authority to Connect (ATC) and, Authority to Operate (ATO) packages.
+ Perform technical work utilizing the Risk Management Framework (RMF) process including analyzing and solving Information Assurance (IA)-related technical problems.
+ Ensure that systemsecurity artifacts are developed, reviewed, and updated as needed.
+ Confirm all RMF requirements are properly addressed and required artifacts are loaded and managed within Enterprise Mission Assurance Support Service (eMASS).
+ Ability to analyze complex problems, identify root causes, and develop actionable recommendations with effective solutions.
+ Interface with other cyber teams to review RMF Contract Data Requirements List (CDRL) submissions and ensure timely delivery of CDRL artifacts, while providing feedback to ensure the sufficiency and quality of cyber artifacts.
+ Periodically conduct a review of each system's audits and monitors corrective actions until all actions are closed.
+ Perform vulnerability/risk analysis of systems using expertise in relevant information systemssecurity.
+ Track and monitor Plan of Action and Milestones (POA&M).
+ Conduct reviews of cybersecurity artifacts and technical briefings and work with customer to resolve any findings.
+ Ensure that identified security controls are implemented and operating as intended through all phases of the lifecycle.
+ Track deliverables (i.e., artifacts, schedules, metrics).
Required:
+ Bachelor's degree and 7+ years of related professional experience.
+ Active Secret clearance.
+ DoD 8570 compliant IAM Level II certification is required (Security +)
+ Experience with DoD's RMF and SSP processes
Desired:
+ Experience with MDA specific RMF and SSP processes
+ Self-Motivated
+ Customer-oriented
**Clearance Level**
Secret
**ITAR Requirement:**
_T_ _his position requires access to information that is subject to compliance with the International Traffic Arms Regulations ("ITAR") and/or the Export Administration Regulations ("EAR"). In order to comply with the requirements of the ITAR and/or the EAR, applicants must qualify as a U.S. person under the ITAR and the EAR, or a person to be approved for an export license by the governing agency whose technology comes under its jurisdiction. Please understand that any job offer that requires approval of an export license will be conditional on AeroVironment's determination that it will be able to obtain an export license in a time frame consistent with AeroVironment's business requirements. A "U.S. person" according to the ITAR definition is a U.S. citizen, U.S. lawful permanent resident (green card holder), or protected individual such as a refugee or asylee. See 22 CFR § 120.15. Some positions will require current U.S. Citizenship due to contract requirements._
**Benefits** : AV offers an excellent benefits package including medical, dental vision, 401K with company matching, a 9/80 work schedule and a paid holiday shutdown. For more information about our company benefit offerings please visit: ********************************* .
We also encourage you to review our company website at ******************** to learn more about us.
Principals only need apply. NO agencies please.
**Who We Are**
Based in California, AeroVironment (AVAV) is a global leader in unmanned aircraft systems (UAS) and tactical missile systems. Founded in 1971 by celebrated physicist and engineer, Dr. Paul MacCready, we've been at the leading edge of technical innovation for more than 45 years. Be a part of the team that developed the world's most widely used military drones and created the first submarine-launched reconnaissance drone, and has seven innovative vehicles that are part of the Smithsonian Institution's permanent collection in Washington, DC.
Join us today in developing the next generation of small UAS and tactical missile systems that will deliver more actionable intelligence to our customers so they can proceed with certainty - and succeed.
**What We Do**
Building on a history of technological innovation, AeroVironment designs, develops, produces, and supports an advanced portfolio of unmanned aircraft systems (UAS) and tactical missile systems. Agencies of the U.S. Department of Defense and allied military services use the company's hand-launched UAS to provide situational awareness to tactical operating units through real-time, airborne reconnaissance, surveillance, and target acquisition.
_We are proud to be an EEO/AA Equal Opportunity Employer, including disability/veterans. AeroVironment, Inc. is an Equal Employment Opportunity (EEO) employer and welcomes all qualified applicants. Qualified applicants will receive fair and impartial consideration without regard to race, sex, color, religion, national origin, age, disability, protected veteran status, genetic data, sexual orientation, gender identity or other legally protected status._
**ITAR**
**About AV:**
**AV isn't for everyone. We hire the curious, the relentless, the mission-obsessed. The best of the best.**
We don't just build defense technology-we redefine what's possible. As the premier autonomous systems company in the U.S., AV delivers breakthrough capabilities across air, land, sea, space, and cyber. From AI-powered drones and loitering munitions to integrated autonomy and space resilience, our technologies shape the future of warfare and protect those who serve.
Founded by legendary innovator Dr. Paul MacCready, AV has spent over 50 years pushing the boundaries of what unmanned systems can do. Our heritage includes seven platforms in the Smithsonian-but we're not building history, we're building what's next.
**If you're ready to build technology that matters-with speed, scale, and purpose-there's no better place to do it than AV.**
**Careers at AeroVironment (*****************************************
$61k-79k yearly est. 13d ago
Cyber Security Engineer/Information Systems Security Officer (ISSO)
Aerovironment 4.6
Redstone Arsenal, AL jobs
AV is looking for a highly talented Cyber SecurityEngineer/Information SystemsSecurity Officer (ISSO) to join our team! In this role you will be part of our team providing SystemsEngineering Technical Assistance to the Ground-based Midcourse Dense (GMD) Product Office under the Teams-Next Missile Defense SystemsEngineering (TN-MDSE) contract managed by the Missile Defense Agency (MDA).
Job Description:
Serve as a member of the cybersecurity team, developing SystemSecurity Plans (SSPs), Interim Authority to Test (IATT), Authority to Connect (ATC) and, Authority to Operate (ATO) packages.
Perform technical work utilizing the Risk Management Framework (RMF) process including analyzing and solving Information Assurance (IA)-related technical problems.
Ensure that systemsecurity artifacts are developed, reviewed, and updated as needed.
Confirm all RMF requirements are properly addressed and required artifacts are loaded and managed within Enterprise Mission Assurance Support Service (eMASS).
Ability to analyze complex problems, identify root causes, and develop actionable recommendations with effective solutions.
Interface with other cyber teams to review RMF Contract Data Requirements List (CDRL) submissions and ensure timely delivery of CDRL artifacts, while providing feedback to ensure the sufficiency and quality of cyber artifacts.
Periodically conduct a review of each system's audits and monitors corrective actions until all actions are closed.
Perform vulnerability/risk analysis of systems using expertise in relevant information systemssecurity.
Track and monitor Plan of Action and Milestones (POA&M).
Conduct reviews of cybersecurity artifacts and technical briefings and work with customer to resolve any findings.
Ensure that identified security controls are implemented and operating as intended through all phases of the lifecycle.
Track deliverables (i.e., artifacts, schedules, metrics).
Required:
Bachelor's degree and 7+ years of related professional experience.
Active Secret clearance.
DoD 8570 compliant IAM Level II certification is required (Security +)
Experience with DoD's RMF and SSP processes
Desired:
Experience with MDA specific RMF and SSP processes
Self-Motivated
Customer-oriented
Clearance Level
Secret
ITAR Requirement:
T
his position requires access to information that is subject to compliance with the International Traffic Arms Regulations (“ITAR”) and/or the Export Administration Regulations (“EAR”). In order to comply with the requirements of the ITAR and/or the EAR, applicants must qualify as a U.S. person under the ITAR and the EAR, or a person to be approved for an export license by the governing agency whose technology comes under its jurisdiction. Please understand that any job offer that requires approval of an export license will be conditional on AeroVironment's determination that it will be able to obtain an export license in a time frame consistent with AeroVironment's business requirements. A “U.S. person” according to the ITAR definition is a U.S. citizen, U.S. lawful permanent resident (green card holder), or protected individual such as a refugee or asylee. See 22 CFR § 120.15. Some positions will require current U.S. Citizenship due to contract requirements.
Benefits: AV offers an excellent benefits package including medical, dental vision, 401K with company matching, a 9/80 work schedule and a paid holiday shutdown. For more information about our company benefit offerings please visit: **********************************
We also encourage you to review our company website at ******************** to learn more about us.
Principals only need apply. NO agencies please.
Who We Are
Based in California, AeroVironment (AVAV) is a global leader in unmanned aircraft systems (UAS) and tactical missile systems. Founded in 1971 by celebrated physicist and engineer, Dr. Paul MacCready, we've been at the leading edge of technical innovation for more than 45 years. Be a part of the team that developed the world's most widely used military drones and created the first submarine-launched reconnaissance drone, and has seven innovative vehicles that are part of the Smithsonian Institution's permanent collection in Washington, DC.
Join us today in developing the next generation of small UAS and tactical missile systems that will deliver more actionable intelligence to our customers so they can proceed with certainty - and succeed.
What We Do
Building on a history of technological innovation, AeroVironment designs, develops, produces, and supports an advanced portfolio of unmanned aircraft systems (UAS) and tactical missile systems. Agencies of the U.S. Department of Defense and allied military services use the company's hand-launched UAS to provide situational awareness to tactical operating units through real-time, airborne reconnaissance, surveillance, and target acquisition.
We are proud to be an EEO/AA Equal Opportunity Employer, including disability/veterans. AeroVironment, Inc. is an Equal Employment Opportunity (EEO) employer and welcomes all qualified applicants. Qualified applicants will receive fair and impartial consideration without regard to race, sex, color, religion, national origin, age, disability, protected veteran status, genetic data, sexual orientation, gender identity or other legally protected status.
ITAR
$61k-79k yearly est. Auto-Apply 14d ago
System Administrator Advisor - SAP Security
Diamondback Energy 4.3
Oklahoma City, OK jobs
CURRENT EMPLOYEES - Please apply using "Jobs Hub" in Workday. This career site is for external applicants only. The SAP Security/GRC Admin is responsible for the management and support of SAP Roles and Security with the Diamondback SAP environment. This position will provide technical and thought leadership in the design, development, implementation, and support of the SAP Role Administration functions across the entire landscape. This role will also provide key contributions in a cross functional approach in the overall and ongoing management, testing and support of the SAP landscape for patches, upgrades and day to day operational issues.
Job Duties and Responsibilities:
* Design, deploy and maintain security solutions that enables the business community to achieve
their goals while providing proper identity and access management controls
* Analyze processes and system user needs to deliver quality solutions that meet both business and functional end-to-end requirements
* Drive overall security strategy including role design and provisioning for S4Hana ecosystem including SAP S/4 HANA, FIORI, GTS, Solution manager, HANA & other Databases, BTP, etc.
* Identify security risks, determines the root causes of security violations, suggest the risk mitigation and control measures and build required procedures and controls
* Ensures SAP security development and deployment execution align with standards, methodologies, and processes
* Identify the root cause of the issues and providing a permanent solution. Work with the Functional team in proposing solutions for the overall stability of the applications
* Daily monitoring of jobs that are necessary for the GRC application(s) to run effectively and efficiently, for example nightly management risk analysis reporting
* Responsible for day-to-day technical support and resolution of security issues, troubleshooting sap security problems including approval procedures and all the necessary compliance
* Develop and maintain processes with applicable documentation related to security by coordinating with IT management and governance teams
* Work with IT management as well as governance groups to facilitate appropriate controls around user/system access
* Proactively Interact with senior management to discuss and explain issues affecting users or systems
* Generate SOX/ad hoc reports on monthly/quarterly/semi-annual basis
* Provide production support and enhancement testing for existing security roles and positions/functions
* Work closely with SAP functional teams to create roles, profiles and authorizations that meet audit requirements as well as functional requirements for end users
* Maintain Segregation of Duties for the SAP environment (e.g. HR/Payroll, BASIS, Security Administration, and BI)
* Work collaboratively with a team to design, build and deploy security frameworks, devices
and applications
* Vulnerability Assessment and Penetration Testing: Conduct regular security assessments, vulnerability scans, and penetration tests to identify and address potential security weaknesses in SAP S/4 environments.
* Be able to provision and de-provision users and roles with appropriate SAP security levels
* Able to effectively prioritize tasks in a high-speed environment
* Candidate must have strong problem-solving skills, be self-directed and capable of working with minimal supervision
* Must have a strong, demonstrated commitment to customer service and be committed to pro-active review of processes and procedures to continually enhance service quality, service delivery and support
* Cross Training Support for other SAP S/4 HANA Cross-functional team
* Occasional work in off-hours to minimize disruption to business
Required Qualifications:
* Bachelor's Degree in Business Management, Information Systems or related field or
equivalent in years of experience
* Four (4+) years in-depth experience in SAP GRC, Role Administration & Security implementation, and production support in ECC 6.0/S4-HANA
* Experience with SAP S/4 HANA security and authorizations
* Experience in SAP S/4 HANA version 1909 or later
* Experience in creating and assigning FF ID's and extracting Fire Fighter logs
* In-Depth understanding of SAP Security Role design & GRC Architecture
* Very good understanding of role remediation, setting up of SAP Security processes
* Expertise in SAP Security automation and scripts creation for mass maintenance
* Expertise in Running and publishing various SOX reports like, UAR, Critical Actions, SOD,
Critical Permissions, Firefighter Log Review
* Experience in maintaining and troubleshooting Structural Authorizations
Preferred Qualifications:
* Experience in SAP security engagements with cloud applications, Azure, etc
* Experience in supporting end-to-end SAP Security projects, Security and GRC workshops,
testing support, Cutover prep, and Hyper care activities
* Experience in Role design in S/4 with Catalog and Group for Fiori Apps and good analytical skills in issue resolution
* SAP GRC Certification
* In-Depth understanding on FIORI requirement specifications, design, development, and testing
* In-Depth understanding of core BASIS functions and activities
* Minimum of three (3+) years of SAP experience within a large organization including implementing and supporting
* Experience in creating/maintaining GRC solutions
* Experience creating user and security roles for Fiori applications
* Experience with SOD development and ongoing controls
* Role administration across multiple landscape
* Oil and Gas experience preferred
* Experience with system monitoring, background job administration, spool administration
* Experience working with SAP GRC 10.0/10.1, SAP HCM and SAP Solution Manager
* Experience with SAP GRC Access Control configuration that includes MSMP and BRFPlus
* Experience in designing, configuring, and implementing SAP GRC Access Request Analysis (ARA), Access Request Management (ARM), Emergency Access Management (EAM), and Business Role Management (BRM)
* Strong knowledge in provisioning to SAP LDAP and SAP Enterprise Portal platforms for ABAP Roles, UME Roles, and Portal Roles/Groups.
Work Authorization:
Diamondback Energy is not currently sponsoring employment visas for this position.
Diamondback is an Equal Employment Opportunity Employer. Diamondback provides equal employment opportunities to all qualified applicants without regard to race, sex, sexual orientation, gender identity, national origin, color, age, religion, veteran or disability status, genetic information, pregnancy, or any other status protected by law. Diamondback participates in E-Verify. Learn more about E-Verify.
$65k-78k yearly est. Auto-Apply 60d+ ago
Physical Security Systems Administrator
Atmos Energy Corp 4.7
Dallas, TX jobs
The selected candidate will: * Oversee the full badge lifecycle for employees, contractors, and visitors * Administer access control and video management systems * Monitor securitysystems for unauthorized activity and respond to incidents * Conduct audits, maintain accurate databases, and generate compliance reports
The ideal candidate will have:
* Experience with physical securitysystems and access control platforms
* Strong attention to detail and ability to work in a multi-site environment
* Proficiency with Microsoft Office and familiarity with security workflows
* TSA PreCheck status required
THIS JOB DESCRIPTION DOES NOT ATTEMPT TO LIST ALL OF THE DUTIES THAT ARE OR MAY BE PERFORMED IN THIS POSITION
Primary Duties
1. Ensure the integrity and security of building access through the operation and administration of company badging/physical access control and video management systems for all Atmos Energy facilities.
2. Lead proactive reviews and assessments of securitysystems, including LenelS2 and Verkada, to optimize functionality, identify potential vulnerabilities, and direct the resolution of identified system deficiencies.
3. Monitor, evaluate, and maintain systems and procedures to safeguard company facilities.
4. Establish and maintain a comprehensive framework for compliance documentation, ensuring alignment with applicable regulations and best practices.
5. Partner closely with security vendors/third parties to provide expert guidance and strategic oversight to ensure prompt and effective resolution of securitysystem and equipment outages.
6. Analyze security incident data to prepare reports and presentations, offering strategic recommendations to leadership on breach mitigation and prevention.
7. Work with the Security Leadership Team to create, implement, and enforce policies and procedures to prevent unauthorized access.
8. Analyze and troubleshoot denied access reports to recommend improvements and ensure facility security is compliant with company and regulatory requirements.
9. Conduct securitysystem audits (badge, access control and camera) to assess effectiveness and identify areas for strategic improvement.
10. Oversee and support new security installation augments remotely as requested.
MINIMUM REQUIREMENTS
Educational/Experience Level:
Bachelor's degree in business administration, information systems, security management, or related field, and two years of relevant professional experience; or
A general educational knowledge normally acquired through a high school diploma or a General Equivalency Diploma (GED) and a minimum of four years of experience in security, law enforcement or related field.
Experience working in a corporate, campus, or multi-site environment with controlled access requirements.
Experience with video surveillance and physical security preferred.
This role requires the employee to have and maintain active TSA PreCheck status.
Computer Skills:
Requires basic computer skills in order to utilize various software applications for developing documents, reports and graphics. Experience with physical securitysystems, including access control and CCTV platforms, as well as badging, preferred. Proficiency in Microsoft Office applications required.
Communication Skills:
Requires the ability to communicate, persuade and/or influence internal and/or external customers at a high level such as senior management on matters of a technical and/or complex nature.
Work Conditions:
Works in an indoor environment. Requires occasionally performing activities including, but not limited to, bending, stooping, grasping, reaching, twisting, turning and/or lifting.
Atmos Energy Corporation is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, or veteran status.
Job Family:
Risk Management
$93k-112k yearly est. Auto-Apply 13d ago
Physical Security Systems Administrator
Atmos Energy 4.7
Dallas, TX jobs
The selected candidate will:
Oversee the full badge lifecycle for employees, contractors, and visitors
Administer access control and video management systems
Monitor securitysystems for unauthorized activity and respond to incidents
Conduct audits, maintain accurate databases, and generate compliance reports
The ideal candidate will have:
Experience with physical securitysystems and access control platforms
Strong attention to detail and ability to work in a multi-site environment
Proficiency with Microsoft Office and familiarity with security workflows
TSA PreCheck status required
THIS JOB DESCRIPTION DOES NOT ATTEMPT TO LIST ALL OF THE DUTIES THAT ARE OR MAY BE PERFORMED IN THIS POSITION
Primary Duties
1. Ensure the integrity and security of building access through the operation and administration of company badging/physical access control and video management systems for all Atmos Energy facilities.
2. Lead proactive reviews and assessments of securitysystems, including LenelS2 and Verkada, to optimize functionality, identify potential vulnerabilities, and direct the resolution of identified system deficiencies.
3. Monitor, evaluate, and maintain systems and procedures to safeguard company facilities.
4. Establish and maintain a comprehensive framework for compliance documentation, ensuring alignment with applicable regulations and best practices.
5. Partner closely with security vendors/third parties to provide expert guidance and strategic oversight to ensure prompt and effective resolution of securitysystem and equipment outages.
6. Analyze security incident data to prepare reports and presentations, offering strategic recommendations to leadership on breach mitigation and prevention.
7. Work with the Security Leadership Team to create, implement, and enforce policies and procedures to prevent unauthorized access.
8. Analyze and troubleshoot denied access reports to recommend improvements and ensure facility security is compliant with company and regulatory requirements.
9. Conduct securitysystem audits (badge, access control and camera) to assess effectiveness and identify areas for strategic improvement.
10. Oversee and support new security installation augments remotely as requested.
MINIMUM REQUIREMENTS
Educational/Experience Level:
Bachelor's degree in business administration, information systems, security management, or related field, and two years of relevant professional experience; or
A general educational knowledge normally acquired through a high school diploma or a General Equivalency Diploma (GED) and a minimum of four years of experience in security, law enforcement or related field.
Experience working in a corporate, campus, or multi-site environment with controlled access requirements.
Experience with video surveillance and physical security preferred.
This role requires the employee to have and maintain active TSA PreCheck status.
Computer Skills:
Requires basic computer skills in order to utilize various software applications for developing documents, reports and graphics. Experience with physical securitysystems, including access control and CCTV platforms, as well as badging, preferred. Proficiency in Microsoft Office applications required.
Communication Skills:
Requires the ability to communicate, persuade and/or influence internal and/or external customers at a high level such as senior management on matters of a technical and/or complex nature.
Work Conditions:
Works in an indoor environment. Requires occasionally performing activities including, but not limited to, bending, stooping, grasping, reaching, twisting, turning and/or lifting.
Atmos Energy Corporation is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, or veteran status.
Job Family:
Risk Management
$93k-112k yearly est. Auto-Apply 19d ago
Security Engineer
Practice Xpert Inc. 3.7
Eagan, MN jobs
TekWissen provides a unique portfolio of innovative capabilities that seamlessly combines clients insights, strategy, design, software engineering and systems integration. Our tightly integrated offerings are tailored to each clients requirements and span the services spectrum from Application Development/Maintenance testing, IT Consulting & staffing for IT Infrastructure Management through strategic consulting and industry-oriented business process.
Job Description
Bachelor's preferably in computer science or technical discipline (i.e. engineering) or equivalent experience.
3-5 years experience in mainframe production support/operations environment
Thorough understanding of data center hardware and software technologies including network, storage, security, servers, mainframes, and load balancers
Expert level experience in Information Technology Security practices, CISSP certification preferred • Knowledge of maintaining and enhancing data security infrastructure, applications and processes
1-3 years experience in working with 3rd party mainframe software suppliers.
Basic knowledge of mainframe operational tools (Tivoli, CA-Sysview, Omegamon)
Experience with distributed, multi-platform architecture
Experience with high volume production systems
1-5 years experience with TSO, MVS, JCL, JES III, FTP, and other operations related to mainframe
1-3 years experience in RACF, and CA-Top Secret security processes and procedures
3 or more years experience developing, deploying or supporting systems software and hardware technologies. Airline or Travel industry experience preferred.
Able to successfully handle multiple assignments concurrently.
Able to effectively communicate with internal and external customers.
Able to follow technical methods and standards
Analytic Approach to problem solving Please see attachment.
Additional Information
Thanks & Regards
Raj
****************************
************
$81k-110k yearly est. Easy Apply 2h ago
ISSO/Systems Security Engineer
Ukpeagvik Inupiat Corporation 4.7
Security system engineer job at Ukpeagvik IOoOupiat Corporation
ISSO/SYSTEMSSECURITYENGINEER (RDTE) Bowhead is seeking a skilled full-time ISSO/SystemsSecurityEngineer to join our team in Dahlgren, VA. The ideal candidate will assure all Information Systems (IS), Government desktops, and corporate network components, unclassified and classified, adhere to and are certified in accordance with the latest versions of guidance such as NAVSEA, DoN, DoD, US CYBERCOM, and other relevant guidance, such as DoD 8500 series, NAVSEAINST 5239.1, and DOD Inst. 5200.40.
Responsibilities
Key Responsibilities:
* Provide technical assistance to the Government in assuring compliance with all policies, guidance, and recommendations stipulated and promulgated by the NSWCDD ISSM.
* Recommend and develop draft IA and systemsecurity procedures and practices, in accordance with the NSWCDD Information Assurance and Compliance Office standards and administer approved procedures and practices.
* Identify security vulnerabilities and recommend corrective security measures for network access points.
* Working knowledge in Risk Assessment (RA), Risk Management Framework (RMF) which outlines the 6 Steps to Risk Management Process for Federal Information Systems in order to assist the business areas in completion of the Business Impact Analysis, and subsequent creation of Security Documentations like SystemSecurity Plan (SSP), Security Assessment Report (SAR) and Plans of Action and Milestones (POA&M).
* RMF Review, validate, and maintain Assessment & Authorization (A&A) documentation, accreditation records for NSWCDD RDT&E classified and unclassified IT and network systems for the NSWCDD IAM.
* Ensure RMF packages are updated and accredited during the regular three-year Authority to Operate (ATO) cycles.
* Experience with NIST 800 SPs to include but not limited to NIST SPs 800-37, 800-53 & 53A, 800-60, FIPS (199 & 200).
* Develop PDS Approval Request packages for new PDSs and update PDS Daily Inspection Procedures.
* Developing a variety of IA related documentation, to include but not be limited to, Platform Information Technology (PIT) designation requests, PIT Risk Assessment requests,
* SystemsSecurityEngineer will create Plan of Actions and Milestones (POA&M) and Standard Operating Procedures (SOPs)
* Ability to analyze Security Technical Implementation Guides (STIGs), Security Content Automation Protocol (SCAP) and Assured Compliance Assessment Solution (ACAS) scanning results.
* Ability to assess technical and non-technical security controls to determine compliance.
Qualifications
Required:
* High School Diploma required. Bachelors Degree preferred.
* A minimum of to five (5) years of experience in systems design, development and integration preferred.
* Must meet DoDD 8140 IAM Level II Certification
* Knowledgeable with DoD security and IA requirements as outlined in DoDI 8500.2 and the Defense Information Systems Agency (DISA) Security Technical Implementation Guidelines (STIG).
* Must have knowledge of basic to advanced UNIX and Windows system administration as well as current knowledge of DoD Ports, Protocols, and Services (PPS), Public Key Infrastructure (PKI), and DoD Information Assurance Vulnerability Management (IAVM) policies and standards.
* Strong oral and written communication skills.
Preferred:
* Experience with the Enterprise Mission Assurance Support Service (eMASS), or managing DoD and DoN IA Portfolios is desired.
* Prefer a working knowledge of STIG Viewer, ACAS, eMASSter, and Excel.
* Knowledge of RDT&E and/or tactical systems
* Ability to communicate effectively with all levels of employees and outside contacts
* Strong interpersonal skills and good judgment with the ability to work alone or as part of a team
Physical Demands:
* Must be able to lift up to 10 pounds
* Must be able to stand and walk for prolonged amounts of time
* Must be able to twist, bend and squat periodically
SECURITY CLEARANCE REQUIREMENTS: Must be able to obtain a Top Secret clearance may start with a Secret clearance. US Citizenship is a requirement for Top Secret clearance at this location.
#LI-JR1
$92k-121k yearly est. 19d ago
Staff Infrastructure Security Engineer
Crusoe 4.1
San Francisco, CA jobs
Job Description
Crusoe's mission is to accelerate the abundance of energy and intelligence. We're crafting the engine that powers a world where people can create ambitiously with AI - without sacrificing scale, speed, or sustainability.
Be a part of the AI revolution with sustainable technology at Crusoe. Here, you'll drive meaningful innovation, make a tangible impact, and join a team that's setting the pace for responsible, transformative cloud infrastructure.
We are seeking a highly skilled Staff Infrastructure SecurityEngineer to architect, deploy, and operationalize the foundational security services that will underpin our shift to a Zero Trust model.
In this strategic role, you will define and establish the "roots of trust" for our organization, serving as a technical leader in Secrets Management and Identity architecture. While your immediate focus is to serve as the Subject Matter Expert (SME) driving our enterprise HashiCorp Vault platform from Proof-of-Concept (PoC) to global production readiness, your long-term scope is far broader. You will be responsible for evolving our credentials management strategy, onboarding engineering teams to secure self-service workflows, and designing scalable trust patterns across our hybrid multi-cloud environment.
Key Responsibilities
1. Strategic Architecture & Governance
Zero Trust Architecture: Architect a highly available, disaster-resilient, and scalable multi-cluster secrets management platform that serves as the foundation for the organization's Zero Trust strategy.
Technical Leadership: Drive consensus across Cloud Engineering, DevOps, and SRE teams to define standardized secret management workflows and integrate security patterns into the SDLC.
Compliance & Governance: Ensure the platform design meets rigorous internal policies and external compliance frameworks (e.g., SOX, ISO 27001).
Policy as Code: Design and implement advanced governance controls, including Sentinel Policy as Code, to automate security guardrails and access decisions.
2. Platform Engineering & Implementation
Infrastructure as Code (IaC): Lead the engineering of the Vault infrastructure using Terraform, ensuring all deployments are reproducible, version-controlled, and automated.
Identity Integration: Architect the integration between the secrets platform, Identity Providers (Okta), and workload identities (Kubernetes Service Accounts) to establish robust machine-to-machine authentication.
Advanced Secrets Capabilities: Configure and tune essential secrets engines (KV, Transit, KMIP) and Enterprise features (Performance Replication, Seal automation) to support diverse engineering use cases.
3. Operational Excellence & Developer Enablement
Vault as a Service (VaaS): Operationalize the platform by building self-service mechanisms, distinct "paved road" onboarding procedures, and documentation that allows engineering teams to easily consume security services.
Observability: Implement comprehensive monitoring, alerting, and audit logging to ensure platform health, provide visibility into usage patterns, and satisfy audit requirements.
Lifecycle Management: Own the full operational lifecycle of the production environment, including patching, version upgrades, backup/restore procedures, and incident response runbooks.
Required Qualifications
6+ years (or equivalent) hands-on experience in cloud security, DevOps, or infrastructure engineering.
Deep expertise and proven track record deploying and managing HashiCorp Vault in an enterprise environment (experience with the Enterprise edition is highly preferred).
Expert-level knowledge of Secrets Management, X.509 PKI (Public Key Infrastructure), Certificate Authority Operations, and Cryptography concepts.
Strong experience with Google Cloud Platform (GCP) and cloud native identity and access management (IAM).
Proficiency with Infrastructure as Code (IaC) tools, especially Terraform, for automating the deployment and configuration of Vault and its dependent infrastructure.
Technical Skills
Fluent in at least one programming language (ideally Go or Python).
Demonstrable experience with Kubernetes and container security principles, especially integrating secrets into microservices architectures.
Strong understanding of network security concepts (IP addressing, IP routing, firewalls, segmentation, Zero Trust).
Benefits:
Industry competitive pay
Restricted Stock Units in a fast growing, well-funded technology company
Health insurance package options that include HDHP and PPO, vision, and dental for you and your dependents
Employer contributions to HSA accounts
Paid Parental Leave
Paid life insurance, short-term and long-term disability
Teladoc
401(k) with a 100% match up to 4% of salary
Generous paid time off and holiday schedule
Cell phone reimbursement
Tuition reimbursement
Subscription to the Calm app
MetLife Legal
Company paid commuter benefit; $300 per month
Crusoe is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, disability, genetic information, pregnancy, citizenship, marital status, sex/gender, sexual preference/ orientation, gender identity, age, veteran status, national origin, or any other status protected by law or regulation.
$126k-179k yearly est. 19d ago
Staff Infrastructure Security Engineer
Crusoe 4.1
San Francisco, CA jobs
Crusoe's mission is to accelerate the abundance of energy and intelligence. We're crafting the engine that powers a world where people can create ambitiously with AI - without sacrificing scale, speed, or sustainability.
Be a part of the AI revolution with sustainable technology at Crusoe. Here, you'll drive meaningful innovation, make a tangible impact, and join a team that's setting the pace for responsible, transformative cloud infrastructure.
We are seeking a highly skilled Staff Infrastructure SecurityEngineer to architect, deploy, and operationalize the foundational security services that will underpin our shift to a Zero Trust model.
In this strategic role, you will define and establish the "roots of trust" for our organization, serving as a technical leader in Secrets Management and Identity architecture. While your immediate focus is to serve as the Subject Matter Expert (SME) driving our enterprise HashiCorp Vault platform from Proof-of-Concept (PoC) to global production readiness, your long-term scope is far broader. You will be responsible for evolving our credentials management strategy, onboarding engineering teams to secure self-service workflows, and designing scalable trust patterns across our hybrid multi-cloud environment.
Key Responsibilities
1. Strategic Architecture & Governance
Zero Trust Architecture: Architect a highly available, disaster-resilient, and scalable multi-cluster secrets management platform that serves as the foundation for the organization's Zero Trust strategy.
Technical Leadership: Drive consensus across Cloud Engineering, DevOps, and SRE teams to define standardized secret management workflows and integrate security patterns into the SDLC.
Compliance & Governance: Ensure the platform design meets rigorous internal policies and external compliance frameworks (e.g., SOX, ISO 27001).
Policy as Code: Design and implement advanced governance controls, including Sentinel Policy as Code, to automate security guardrails and access decisions.
2. Platform Engineering & Implementation
Infrastructure as Code (IaC): Lead the engineering of the Vault infrastructure using Terraform, ensuring all deployments are reproducible, version-controlled, and automated.
Identity Integration: Architect the integration between the secrets platform, Identity Providers (Okta), and workload identities (Kubernetes Service Accounts) to establish robust machine-to-machine authentication.
Advanced Secrets Capabilities: Configure and tune essential secrets engines (KV, Transit, KMIP) and Enterprise features (Performance Replication, Seal automation) to support diverse engineering use cases.
3. Operational Excellence & Developer Enablement
Vault as a Service (VaaS): Operationalize the platform by building self-service mechanisms, distinct "paved road" onboarding procedures, and documentation that allows engineering teams to easily consume security services.
Observability: Implement comprehensive monitoring, alerting, and audit logging to ensure platform health, provide visibility into usage patterns, and satisfy audit requirements.
Lifecycle Management: Own the full operational lifecycle of the production environment, including patching, version upgrades, backup/restore procedures, and incident response runbooks.
Required Qualifications
6+ years (or equivalent) hands-on experience in cloud security, DevOps, or infrastructure engineering.
Deep expertise and proven track record deploying and managing HashiCorp Vault in an enterprise environment (experience with the Enterprise edition is highly preferred).
Expert-level knowledge of Secrets Management, X.509 PKI (Public Key Infrastructure), Certificate Authority Operations, and Cryptography concepts.
Strong experience with Google Cloud Platform (GCP) and cloud native identity and access management (IAM).
Proficiency with Infrastructure as Code (IaC) tools, especially Terraform, for automating the deployment and configuration of Vault and its dependent infrastructure.
Technical Skills
Fluent in at least one programming language (ideally Go or Python).
Demonstrable experience with Kubernetes and container security principles, especially integrating secrets into microservices architectures.
Strong understanding of network security concepts (IP addressing, IP routing, firewalls, segmentation, Zero Trust).
Benefits:
Industry competitive pay
Restricted Stock Units in a fast growing, well-funded technology company
Health insurance package options that include HDHP and PPO, vision, and dental for you and your dependents
Employer contributions to HSA accounts
Paid Parental Leave
Paid life insurance, short-term and long-term disability
Teladoc
401(k) with a 100% match up to 4% of salary
Generous paid time off and holiday schedule
Cell phone reimbursement
Tuition reimbursement
Subscription to the Calm app
MetLife Legal
Company paid commuter benefit; $300 per month
Crusoe is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, disability, genetic information, pregnancy, citizenship, marital status, sex/gender, sexual preference/ orientation, gender identity, age, veteran status, national origin, or any other status protected by law or regulation.
$126k-179k yearly est. Auto-Apply 49d ago
Staff Infrastructure Security Engineer
Crusoe 4.1
Sunnyvale, CA jobs
Job Description
Crusoe's mission is to accelerate the abundance of energy and intelligence. We're crafting the engine that powers a world where people can create ambitiously with AI - without sacrificing scale, speed, or sustainability.
Be a part of the AI revolution with sustainable technology at Crusoe. Here, you'll drive meaningful innovation, make a tangible impact, and join a team that's setting the pace for responsible, transformative cloud infrastructure.
We are seeking a highly skilled Staff Infrastructure SecurityEngineer to architect, deploy, and operationalize the foundational security services that will underpin our shift to a Zero Trust model.
In this strategic role, you will define and establish the "roots of trust" for our organization, serving as a technical leader in Secrets Management and Identity architecture. While your immediate focus is to serve as the Subject Matter Expert (SME) driving our enterprise HashiCorp Vault platform from Proof-of-Concept (PoC) to global production readiness, your long-term scope is far broader. You will be responsible for evolving our credentials management strategy, onboarding engineering teams to secure self-service workflows, and designing scalable trust patterns across our hybrid multi-cloud environment.
Key Responsibilities
1. Strategic Architecture & Governance
Zero Trust Architecture: Architect a highly available, disaster-resilient, and scalable multi-cluster secrets management platform that serves as the foundation for the organization's Zero Trust strategy.
Technical Leadership: Drive consensus across Cloud Engineering, DevOps, and SRE teams to define standardized secret management workflows and integrate security patterns into the SDLC.
Compliance & Governance: Ensure the platform design meets rigorous internal policies and external compliance frameworks (e.g., SOX, ISO 27001).
Policy as Code: Design and implement advanced governance controls, including Sentinel Policy as Code, to automate security guardrails and access decisions.
2. Platform Engineering & Implementation
Infrastructure as Code (IaC): Lead the engineering of the Vault infrastructure using Terraform, ensuring all deployments are reproducible, version-controlled, and automated.
Identity Integration: Architect the integration between the secrets platform, Identity Providers (Okta), and workload identities (Kubernetes Service Accounts) to establish robust machine-to-machine authentication.
Advanced Secrets Capabilities: Configure and tune essential secrets engines (KV, Transit, KMIP) and Enterprise features (Performance Replication, Seal automation) to support diverse engineering use cases.
3. Operational Excellence & Developer Enablement
Vault as a Service (VaaS): Operationalize the platform by building self-service mechanisms, distinct "paved road" onboarding procedures, and documentation that allows engineering teams to easily consume security services.
Observability: Implement comprehensive monitoring, alerting, and audit logging to ensure platform health, provide visibility into usage patterns, and satisfy audit requirements.
Lifecycle Management: Own the full operational lifecycle of the production environment, including patching, version upgrades, backup/restore procedures, and incident response runbooks.
Required Qualifications
6+ years (or equivalent) hands-on experience in cloud security, DevOps, or infrastructure engineering.
Deep expertise and proven track record deploying and managing HashiCorp Vault in an enterprise environment (experience with the Enterprise edition is highly preferred).
Expert-level knowledge of Secrets Management, X.509 PKI (Public Key Infrastructure), Certificate Authority Operations, and Cryptography concepts.
Strong experience with Google Cloud Platform (GCP) and cloud native identity and access management (IAM).
Proficiency with Infrastructure as Code (IaC) tools, especially Terraform, for automating the deployment and configuration of Vault and its dependent infrastructure.
Technical Skills
Fluent in at least one programming language (ideally Go or Python).
Demonstrable experience with Kubernetes and container security principles, especially integrating secrets into microservices architectures.
Strong understanding of network security concepts (IP addressing, IP routing, firewalls, segmentation, Zero Trust).
Benefits:
Industry competitive pay
Restricted Stock Units in a fast growing, well-funded technology company
Health insurance package options that include HDHP and PPO, vision, and dental for you and your dependents
Employer contributions to HSA accounts
Paid Parental Leave
Paid life insurance, short-term and long-term disability
Teladoc
401(k) with a 100% match up to 4% of salary
Generous paid time off and holiday schedule
Cell phone reimbursement
Tuition reimbursement
Subscription to the Calm app
MetLife Legal
Company paid commuter benefit; $300 per month
Crusoe is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, disability, genetic information, pregnancy, citizenship, marital status, sex/gender, sexual preference/ orientation, gender identity, age, veteran status, national origin, or any other status protected by law or regulation.
$126k-178k yearly est. 17d ago
Staff Infrastructure Security Engineer
Crusoe 4.1
Seattle, WA jobs
Job Description
Crusoe's mission is to accelerate the abundance of energy and intelligence. We're crafting the engine that powers a world where people can create ambitiously with AI - without sacrificing scale, speed, or sustainability.
Be a part of the AI revolution with sustainable technology at Crusoe. Here, you'll drive meaningful innovation, make a tangible impact, and join a team that's setting the pace for responsible, transformative cloud infrastructure.
We are seeking a highly skilled Staff Infrastructure SecurityEngineer to architect, deploy, and operationalize the foundational security services that will underpin our shift to a Zero Trust model.
In this strategic role, you will define and establish the "roots of trust" for our organization, serving as a technical leader in Secrets Management and Identity architecture. While your immediate focus is to serve as the Subject Matter Expert (SME) driving our enterprise HashiCorp Vault platform from Proof-of-Concept (PoC) to global production readiness, your long-term scope is far broader. You will be responsible for evolving our credentials management strategy, onboarding engineering teams to secure self-service workflows, and designing scalable trust patterns across our hybrid multi-cloud environment.
Key Responsibilities
1. Strategic Architecture & Governance
Zero Trust Architecture: Architect a highly available, disaster-resilient, and scalable multi-cluster secrets management platform that serves as the foundation for the organization's Zero Trust strategy.
Technical Leadership: Drive consensus across Cloud Engineering, DevOps, and SRE teams to define standardized secret management workflows and integrate security patterns into the SDLC.
Compliance & Governance: Ensure the platform design meets rigorous internal policies and external compliance frameworks (e.g., SOX, ISO 27001).
Policy as Code: Design and implement advanced governance controls, including Sentinel Policy as Code, to automate security guardrails and access decisions.
2. Platform Engineering & Implementation
Infrastructure as Code (IaC): Lead the engineering of the Vault infrastructure using Terraform, ensuring all deployments are reproducible, version-controlled, and automated.
Identity Integration: Architect the integration between the secrets platform, Identity Providers (Okta), and workload identities (Kubernetes Service Accounts) to establish robust machine-to-machine authentication.
Advanced Secrets Capabilities: Configure and tune essential secrets engines (KV, Transit, KMIP) and Enterprise features (Performance Replication, Seal automation) to support diverse engineering use cases.
3. Operational Excellence & Developer Enablement
Vault as a Service (VaaS): Operationalize the platform by building self-service mechanisms, distinct "paved road" onboarding procedures, and documentation that allows engineering teams to easily consume security services.
Observability: Implement comprehensive monitoring, alerting, and audit logging to ensure platform health, provide visibility into usage patterns, and satisfy audit requirements.
Lifecycle Management: Own the full operational lifecycle of the production environment, including patching, version upgrades, backup/restore procedures, and incident response runbooks.
Required Qualifications
6+ years (or equivalent) hands-on experience in cloud security, DevOps, or infrastructure engineering.
Deep expertise and proven track record deploying and managing HashiCorp Vault in an enterprise environment (experience with the Enterprise edition is highly preferred).
Expert-level knowledge of Secrets Management, X.509 PKI (Public Key Infrastructure), Certificate Authority Operations, and Cryptography concepts.
Strong experience with Google Cloud Platform (GCP) and cloud native identity and access management (IAM).
Proficiency with Infrastructure as Code (IaC) tools, especially Terraform, for automating the deployment and configuration of Vault and its dependent infrastructure.
Technical Skills
Fluent in at least one programming language (ideally Go or Python).
Demonstrable experience with Kubernetes and container security principles, especially integrating secrets into microservices architectures.
Strong understanding of network security concepts (IP addressing, IP routing, firewalls, segmentation, Zero Trust).
Benefits:
Industry competitive pay
Restricted Stock Units in a fast growing, well-funded technology company
Health insurance package options that include HDHP and PPO, vision, and dental for you and your dependents
Employer contributions to HSA accounts
Paid Parental Leave
Paid life insurance, short-term and long-term disability
Teladoc
401(k) with a 100% match up to 4% of salary
Generous paid time off and holiday schedule
Cell phone reimbursement
Tuition reimbursement
Subscription to the Calm app
MetLife Legal
Company paid commuter benefit; $300 per month
Crusoe is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, disability, genetic information, pregnancy, citizenship, marital status, sex/gender, sexual preference/ orientation, gender identity, age, veteran status, national origin, or any other status protected by law or regulation.
$111k-157k yearly est. 17d ago
Product Security Engineer - AI
Crusoe 4.1
San Francisco, CA jobs
Job Description
Crusoe's mission is to accelerate the abundance of energy and intelligence. We're crafting the engine that powers a world where people can create ambitiously with AI - without sacrificing scale, speed, or sustainability.
Be a part of the AI revolution with sustainable technology at Crusoe. Here, you'll drive meaningful innovation, make a tangible impact, and join a team that's setting the pace for responsible, transformative cloud infrastructure.
About This Role:
At Crusoe, the AI SecurityEngineer is central to ensuring the safety, integrity, and resilience of our rapidly evolving AI ecosystem. You will serve as the technical authority on securing Large Language Models (LLMs), AI-powered platforms, and the infrastructure that supports them-driving both strategy and execution for our next generation of secure AI systems.
What You'll Be Working On:
AI Security SME & Strategic Partner: Act as the technical leader and SME on the practical security of our AI and LLM ecosystem and define the long-term technical roadmap for AI security architecture and drive high-impact cross-functional initiatives.
LLM Architecture & Design Ownership: Lead the design and implementation of highly secure Generative AI solutions for security applications, focusing on architectural patterns like Retrieval-Augmented Generation (RAG)
AI-Powered Tooling & Automation: Architect and implement custom, AI-powered security tooling that automates threat detection, vulnerability analysis, and data access control, moving from proof-of-concept to production at scale.
Secure MLOps & Governance: Establish governance and processes for secure MLOps pipelines. Define standards for model versioning, deployment, and monitoring, ensuring they meet rigorous compliance and security requirements.
Threat Mitigation & Mentorship: Lead threat modeling exercises for novel AI systems. Apply advanced security and privacy best practices, and mentor senior engineers on secure development practices in the GenAI domain.
System-Level Ownership: Drive the entire lifecycle of critical AI security projects.
What You'll Bring to the Team:
3+ years of professional experience building and maintaining production systems, with strong Python programming skills and experience across the stack (backend/frontend).
Deep expertise in advanced Generative AI techniques, including implementing Retrieval-Augmented Generation (RAG), designing AI Agents and Multi-step Cognitive Processes (MCP), and building with workflow orchestration frameworks.
Proven ability to own the entire model lifecycle by designing and managing robust MLOps pipelines; experience with containerization (Docker), virtualization (VMs), and cloud platforms (AWS, GCP, Azure) is a plus.
Experience in designing, implementing, and fine-tuning custom LLMs, coupled with a strong understanding of NLP fundamentals, transformer architectures, PyTorch/TensorFlow, and data structures.
Strong curiosity about security, privacy, and threat modeling; a desire to safely "break" systems to secure them and apply best practices to AI pipelines and deployments.
Strong product sense for rapid iteration and refinement based on data, combined with a collaborative mindset to work closely with engineers, product managers, and security analysts in a fast-paced environment.
Benefits:
Industry competitive pay
Restricted Stock Units in a fast growing, well-funded technology company
Health insurance package options that include HDHP and PPO, vision, and dental for you and your dependents
Employer contributions to HSA accounts
Paid Parental Leave
Paid life insurance, short-term and long-term disability
Teladoc
401(k) with a 100% match up to 4% of salary
Generous paid time off and holiday schedule
Cell phone reimbursement
Tuition reimbursement
Subscription to the Calm app
MetLife Legal
Company paid commuter benefit; $300 per month
Compensation:
Compensation will be paid in the range of $135,000 - $150,000. Restricted Stock Units are included in all offers. Compensation to be determined by the applicant's education, experience, knowledge, skills, and abilities, as well as internal equity and alignment with market data.
Crusoe is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, disability, genetic information, pregnancy, citizenship, marital status, sex/gender, sexual preference/ orientation, gender identity, age, veteran status, national origin, or any other status protected by law or regulation.
$135k-150k yearly 26d ago
Product Security Engineer - AI
Crusoe 4.1
San Francisco, CA jobs
Crusoe's mission is to accelerate the abundance of energy and intelligence. We're crafting the engine that powers a world where people can create ambitiously with AI - without sacrificing scale, speed, or sustainability.
Be a part of the AI revolution with sustainable technology at Crusoe. Here, you'll drive meaningful innovation, make a tangible impact, and join a team that's setting the pace for responsible, transformative cloud infrastructure.
About This Role:
At Crusoe, the AI SecurityEngineer is central to ensuring the safety, integrity, and resilience of our rapidly evolving AI ecosystem. You will serve as the technical authority on securing Large Language Models (LLMs), AI-powered platforms, and the infrastructure that supports them-driving both strategy and execution for our next generation of secure AI systems.
What You'll Be Working On:
AI Security SME & Strategic Partner: Act as the technical leader and SME on the practical security of our AI and LLM ecosystem and define the long-term technical roadmap for AI security architecture and drive high-impact cross-functional initiatives.
LLM Architecture & Design Ownership: Lead the design and implementation of highly secure Generative AI solutions for security applications, focusing on architectural patterns like Retrieval-Augmented Generation (RAG)
AI-Powered Tooling & Automation: Architect and implement custom, AI-powered security tooling that automates threat detection, vulnerability analysis, and data access control, moving from proof-of-concept to production at scale.
Secure MLOps & Governance: Establish governance and processes for secure MLOps pipelines. Define standards for model versioning, deployment, and monitoring, ensuring they meet rigorous compliance and security requirements.
Threat Mitigation & Mentorship: Lead threat modeling exercises for novel AI systems. Apply advanced security and privacy best practices, and mentor senior engineers on secure development practices in the GenAI domain.
System-Level Ownership: Drive the entire lifecycle of critical AI security projects.
What You'll Bring to the Team:
3+ years of professional experience building and maintaining production systems, with strong Python programming skills and experience across the stack (backend/frontend).
Deep expertise in advanced Generative AI techniques, including implementing Retrieval-Augmented Generation (RAG), designing AI Agents and Multi-step Cognitive Processes (MCP), and building with workflow orchestration frameworks.
Proven ability to own the entire model lifecycle by designing and managing robust MLOps pipelines; experience with containerization (Docker), virtualization (VMs), and cloud platforms (AWS, GCP, Azure) is a plus.
Experience in designing, implementing, and fine-tuning custom LLMs, coupled with a strong understanding of NLP fundamentals, transformer architectures, PyTorch/TensorFlow, and data structures.
Strong curiosity about security, privacy, and threat modeling; a desire to safely "break" systems to secure them and apply best practices to AI pipelines and deployments.
Strong product sense for rapid iteration and refinement based on data, combined with a collaborative mindset to work closely with engineers, product managers, and security analysts in a fast-paced environment.
Benefits:
Industry competitive pay
Restricted Stock Units in a fast growing, well-funded technology company
Health insurance package options that include HDHP and PPO, vision, and dental for you and your dependents
Employer contributions to HSA accounts
Paid Parental Leave
Paid life insurance, short-term and long-term disability
Teladoc
401(k) with a 100% match up to 4% of salary
Generous paid time off and holiday schedule
Cell phone reimbursement
Tuition reimbursement
Subscription to the Calm app
MetLife Legal
Company paid commuter benefit; $300 per month
Compensation:
Compensation will be paid in the range of $135,000 - $150,000. Restricted Stock Units are included in all offers. Compensation to be determined by the applicant's education, experience, knowledge, skills, and abilities, as well as internal equity and alignment with market data.
Crusoe is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, disability, genetic information, pregnancy, citizenship, marital status, sex/gender, sexual preference/ orientation, gender identity, age, veteran status, national origin, or any other status protected by law or regulation.
$135k-150k yearly Auto-Apply 56d ago
Staff Infrastructure Security Engineer
Crusoe 4.1
Denver, CO jobs
Job Description
Crusoe's mission is to accelerate the abundance of energy and intelligence. We're crafting the engine that powers a world where people can create ambitiously with AI - without sacrificing scale, speed, or sustainability.
Be a part of the AI revolution with sustainable technology at Crusoe. Here, you'll drive meaningful innovation, make a tangible impact, and join a team that's setting the pace for responsible, transformative cloud infrastructure.
We are seeking a highly skilled Staff Infrastructure SecurityEngineer to architect, deploy, and operationalize the foundational security services that will underpin our shift to a Zero Trust model.
In this strategic role, you will define and establish the "roots of trust" for our organization, serving as a technical leader in Secrets Management and Identity architecture. While your immediate focus is to serve as the Subject Matter Expert (SME) driving our enterprise HashiCorp Vault platform from Proof-of-Concept (PoC) to global production readiness, your long-term scope is far broader. You will be responsible for evolving our credentials management strategy, onboarding engineering teams to secure self-service workflows, and designing scalable trust patterns across our hybrid multi-cloud environment.
Key Responsibilities
1. Strategic Architecture & Governance
Zero Trust Architecture: Architect a highly available, disaster-resilient, and scalable multi-cluster secrets management platform that serves as the foundation for the organization's Zero Trust strategy.
Technical Leadership: Drive consensus across Cloud Engineering, DevOps, and SRE teams to define standardized secret management workflows and integrate security patterns into the SDLC.
Compliance & Governance: Ensure the platform design meets rigorous internal policies and external compliance frameworks (e.g., SOX, ISO 27001).
Policy as Code: Design and implement advanced governance controls, including Sentinel Policy as Code, to automate security guardrails and access decisions.
2. Platform Engineering & Implementation
Infrastructure as Code (IaC): Lead the engineering of the Vault infrastructure using Terraform, ensuring all deployments are reproducible, version-controlled, and automated.
Identity Integration: Architect the integration between the secrets platform, Identity Providers (Okta), and workload identities (Kubernetes Service Accounts) to establish robust machine-to-machine authentication.
Advanced Secrets Capabilities: Configure and tune essential secrets engines (KV, Transit, KMIP) and Enterprise features (Performance Replication, Seal automation) to support diverse engineering use cases.
3. Operational Excellence & Developer Enablement
Vault as a Service (VaaS): Operationalize the platform by building self-service mechanisms, distinct "paved road" onboarding procedures, and documentation that allows engineering teams to easily consume security services.
Observability: Implement comprehensive monitoring, alerting, and audit logging to ensure platform health, provide visibility into usage patterns, and satisfy audit requirements.
Lifecycle Management: Own the full operational lifecycle of the production environment, including patching, version upgrades, backup/restore procedures, and incident response runbooks.
Required Qualifications
6+ years (or equivalent) hands-on experience in cloud security, DevOps, or infrastructure engineering.
Deep expertise and proven track record deploying and managing HashiCorp Vault in an enterprise environment (experience with the Enterprise edition is highly preferred).
Expert-level knowledge of Secrets Management, X.509 PKI (Public Key Infrastructure), Certificate Authority Operations, and Cryptography concepts.
Strong experience with Google Cloud Platform (GCP) and cloud native identity and access management (IAM).
Proficiency with Infrastructure as Code (IaC) tools, especially Terraform, for automating the deployment and configuration of Vault and its dependent infrastructure.
Technical Skills
Fluent in at least one programming language (ideally Go or Python).
Demonstrable experience with Kubernetes and container security principles, especially integrating secrets into microservices architectures.
Strong understanding of network security concepts (IP addressing, IP routing, firewalls, segmentation, Zero Trust).
Benefits:
Industry competitive pay
Restricted Stock Units in a fast growing, well-funded technology company
Health insurance package options that include HDHP and PPO, vision, and dental for you and your dependents
Employer contributions to HSA accounts
Paid Parental Leave
Paid life insurance, short-term and long-term disability
Teladoc
401(k) with a 100% match up to 4% of salary
Generous paid time off and holiday schedule
Cell phone reimbursement
Tuition reimbursement
Subscription to the Calm app
MetLife Legal
Company paid commuter benefit; $300 per month
Crusoe is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, disability, genetic information, pregnancy, citizenship, marital status, sex/gender, sexual preference/ orientation, gender identity, age, veteran status, national origin, or any other status protected by law or regulation.
$79k-110k yearly est. 17d ago
Learn more about Ukpeagvik IOoOupiat Corporation jobs