Information Systems Security Officer jobs at Vencore - 2809 jobs
AWS Security Engineer
Perspecta 4.5
Information systems security officer job at Vencore
Responsibilities
We are seeking an experienced AWS Security Engineer to ensure the security, compliance, and protection of our cloud-based infrastructure. The ideal candidate will have strong hands-on experience with AWS security services, cloud risk assessments, incident response, and continuous security monitoring. This role collaborates closely with Cloud Engineering, DevOps, and Application teams to maintain a secure, compliant, and resilient cloud environment.
What you will do:
Lead and support vulnerability scanning and remediation efforts for cloud resources
Manage IAM roles/policies, identity federation, encryption, KMS, and secrets management
Provision and manage AWS infrastructure using Infrastructure as Code (IaC) tools such as Terraform
Develop custom scripts for CloudWatch metrics and alarms based on application-specific probes
Implement alerting and automated remediation workflows
Assist with incident response, investigations, and root cause analysis of cloud security events
Develop and maintain security architecture documentation, runbooks, and procedures
Conduct AWS security posture assessments using automated tools
Monitor and maintain AWS security controls using cloud-native detection and monitoring tools
Partner with DevOps and engineering teams to embed security best practices into CI/CD pipelines and IaC
Implement and enhance AWS security controls, guardrails, and baseline configurations
Continuously evaluate AWS environments for cost-effective security improvements
Conduct threat modeling, vulnerability analysis, and remediation coordination
Support internal and external audits by gathering evidence and preparing documentation
Maintain compliance with NIST, FISMA, and FedRAMP requirements
Assist in risk assessments and security control testing
Support change control processes and ensure accurate system/process documentation
Evaluate emerging cloud security tools and recommend improvements
Participate in on-call rotations to support 24/7 production systems
Qualifications
Required Qualifications:
Bachelor's degree and 8 years or 6 years with a Master's degree.
Proficiency with Python and Bash scripting
Hands-on experience with ECS, EKS, EC2, and Lambda
Strong experience with Git and CI/CD pipelines
Advanced Terraform skills, including modules, variables, and workspaces
Deep knowledge of AWS security services: IAM, KMS, GuardDuty, Security Hub, CloudTrail, Config Rules
Ability to conduct IAM policy/permissions audits and enforce least privilege
Skilled at interpreting access logs, cloud configurations, and IAM policies
Excellent written and verbal communication skills
Strong analytical and problem-solving abilities
Must be a U.S. Citizen
Must be able to obtain and maintain the required Agency clearance
Preferred Qualifications:
AWS certifications such as Cloud Practitioner or Security Specialty
Security compliance or audit certifications (e.g., CISA, Security+, etc.)
Peraton Overview
Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can't be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we're keeping people around the world safe and secure.
Target Salary Range $80,000 - $128,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. EEO EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.
A leading software company in Chicago seeks a Senior Functional Consultant specializing in Human Capital Management to assist customers with HR technology challenges. The ideal candidate will have over 5 years of experience with Workday and must excel in communication and project management skills. This role involves providing customer service, supporting multiple projects, and partnering with engagement managers. Competitive salary range between $122,800 and $184,200, with flexibility for remote work.
#J-18808-Ljbffr
$122.8k-184.2k yearly 2d ago
Senior Privacy & Security Platform Architect
Databricks Inc. 3.8
San Francisco, CA jobs
A leading data and AI company in San Francisco is seeking a Senior Security Engineer to enhance the safety of its platform. The role demands extensive experience in Data Security and distributed systems. The ideal candidate will have strong leadership and communication skills, with a focus on filling critical gaps in infrastructure. Expected salary range is $220,400 to $297,400 annually. Join us to make impactful changes and attract top talent while representing the security engineering discipline across the organization.
#J-18808-Ljbffr
$220.4k-297.4k yearly 2d ago
Cyber ML Engineer: Real-Time Threat Detection
Phase2 Technology 3.9
McLean, VA jobs
A leading technology firm is seeking a Cyber Machine Learning Engineer to build and improve machine learning models for detecting cyber threats. The ideal candidate has significant experience in cyber threat hunting and proficiency in Python and MLOps practices. This position offers a competitive compensation range of $99,000 to $225,000 annually, along with comprehensive benefits including health, life, and professional development opportunities. The job supports flexible work arrangements.
#J-18808-Ljbffr
$99k-225k yearly 3d ago
Senior Security Engineer - Public Sector, Honolulu Onsite
Google Inc. 4.8
Urban Honolulu, HI jobs
A leading technology company is seeking a Senior Security Engineer for the Google Public Sector team in Honolulu, Hawaii. This role requires strong expertise in security assessments and engineering, along with 5 years of relevant experience. The engineer will implement security monitoring and incident response plans while collaborating closely with various teams. A Bachelor's degree and active Security Clearance are mandatory, as well as the ability to conduct client-facing work five days a week. Competitive salary up to $244,000 plus benefits.
#J-18808-Ljbffr
$244k yearly 4d ago
Senior Security Engineer, Google Public Sector
Google Inc. 4.8
Urban Honolulu, HI jobs
Apply
Must be a US Citizen to meet customer and compliance requirements, including potential access to classified information. This position requires onsite client-facing work 5 days a week in Honolulu, Hawaii.
Bachelor's degree in Computer Science, IT, or related field or equivalent practical experience.
5 years of experience with security assessments, security design reviews, or threat modeling.
5 years of experience with security engineering, computer and network security, and security protocols.
Experience delivering comprehensive security solutioning through design, coding, configuration, and deployment.
Must possess an active Top Secret/SCI Security Clearance.
Must currently have or be able to obtain advanced DoD 8140 DCWF certification.
Preferred qualifications
Certifications in CISSP, CISM, GCIH, GCIA, or OSCP.
Experience in a regulated industry (e.g., finance, healthcare, government).
Experience securing cloud environments (Cloud Computing Platform, Google Cloud Platform).
Understanding of cloud security principles and best practices.
About the job
Security is at the core of Google's design and development process: it is built into the DNA of our products. The same is true of our offices. You're an expert who shares our seriousness about security and our commitment to confidentiality. You'll collaborate with our Facilities Management team to create innovative security strategies, investigate breaches and create risk assessment plans for the future. You believe that providing effective security doesn't come at the expense of customer service - you will be our bodyguard (and our long lost pal).
The GPS Cyber Defense and Security Operations Group leads our Security Operations (SECOPs) function for a range of GPS platforms and services. Combining Mandiant's deep security experience with Google technologies, our team sets the standard in Security Engineering, Assessment, and Operations across Government Cloud programs.
Google Public Sector brings the magic of Google to the mission of government and education with solutions purpose-built for enterprises. We focus on helping United States public sector institutions accelerate their digital transformations, and we continue to make significant investments and grow our team to meet the complex needs of local, state and federal government and educational institutions.
The US base salary range for this full-time position is $166,000-$244,000 + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.
Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.
Responsibilities
Implement security monitoring strategies, incident response plans, and security awareness programs.
Oversee the deployment and operation of securityinformation and event management (SIEM) systems, intrusion detection/prevention systems (IDS/IPS) and other security tools.
Leverage cyber threat intelligence to conduct ongoing network hunt activities and identify active and dormant threats within the environment.
Develop and implement custom-built AI-driven security detections and workflows.
Google is proud to be an equal opportunity and affirmative action employer. We are committed to building a workforce that is representative of the users we serve, creating a culture of belonging, and providing an equal employment opportunity regardless of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), expecting or parents-to-be, criminal histories consistent with legal requirements, or any other basis protected by law. See also Google's EEO Policy, Know your rights: workplace discrimination is illegal, Belonging at Google, and How we hire.
Google is a global company and, in order to facilitate efficient collaboration and communication globally, English proficiency is a requirement for all roles unless stated otherwise in the job posting.
To all recruitment agencies: Google does not accept agency resumes. Please do not forward resumes to our jobs alias, Google employees, or any other organization location. Google is not responsible for any fees related to unsolicited resumes.
#J-18808-Ljbffr
$123k-155k yearly est. 4d ago
Lead Security Engineer, GovCloud
Salesforce, Inc. 4.8
San Francisco, CA jobs
*To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.*Job CategorySoftware EngineeringJob Details****About Salesforce****Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn't a buzzword - it's a way of life. The world of work as we know it is changing and we're looking for Trailblazers who are passionate about bettering business and the world through AI, driving innovation, and keeping Salesforce's core values at the heart of it all.**About the team** Salesforce is looking to hire a Lead Security Engineer for Government Cloud Services. We prioritize security and data protection to ensure the confidentiality, integrity, and availability of our systems and information. As we continue to expand our operations, we are seeking a skilled and experienced Lead Security Analyst to join our dynamic team and play a pivotal role in safeguarding our organization against evolving cyber threats. As the Lead Security Engineer, you will be responsible for driving the overall security posture of our organization. You will work closely with cross-functional teams to assess risks, implement security measures, monitor securitysystems, and respond to security incidents. Your expertise in security frameworks, technologies, and best practices will be critical in developing and executing strategies to protect our critical assets and infrastructure. **What you will be doing:*** Apply security policies to meet security objectives of the system.* Assess adequate access controls based on principles of least privilege and need-to-know.* Assess all the configuration management (change configuration/release management) processes.* Assess the effectiveness of security controls.* Ensure cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level.* Develop and implement comprehensive security policies, procedures, and guidelines to ensure the protection of company assets and compliance with applicable regulations.* Conduct (or coordinate with third party partners) regular security risk assessments, vulnerability assessments, and penetration tests to identify potential weaknesses in systems, networks, and applications and coordinate remediation of findings. Drive related mitigations.* Collaborate with stakeholders to design and implement security controls, including firewalls, intrusion detection systems, access controls, and encryption technologies.* Conduct analysis of logs and events, identify gaps for deeper analysis as needed, and coordinate with Detection and Response teams on detection and alerting betterment efforts and uplift.* Stay up-to-date with the latest security trends, vulnerabilities, and threat intelligence, and provide recommendations to proactively address emerging risks.* Liaison with Incident Response teams on incidents and response efforts, recommend and/or instigate remediation actions to prevent future occurrences.* Develop and deliver security awareness and training programs to educate employees on security best practices and promote a culture of security across the organization.* Collaborate with external vendors, partners, and auditors to ensure compliance with security standards and regulations. Further, implement systemsecurity measures in accordance with established procedures to ensure confidentiality, integrity, availability, authentication, and non-repudiation* Maintain documentation of security procedures, incident response plans, and security incident reports.**What you should have:*** Experience with using cloud infrastructure as code (IaC), including Terraform, CloudFormation, or Azure Resource Manager to deploy secure cloud infrastructure, and using version control based on Git* Professional certifications such as CISSP, CISM, CEH, or similar are highly desirable.* Proven experience (5+ years) in a security analyst role, with a focus on informationsecurity, incident response, and vulnerability management.* Must be US Citizen operating on US Soil and pass both enhanced background check as long as Criminal Justice background check.* Strong understanding of security frameworks such as ISO 27001, NIST, or CIS Controls, and their practical application.* Extensive knowledge of security technologies, including firewalls, IDS/IPS, SIEM, DLP, antivirus, and endpoint protection systems.* Hands-on experience with vulnerability assessment tools, network scanning tools, and penetration testing methodologies.* Experience with using cloud infrastructure as code (IaC), including Terraform, CloudFormation, or Azure Resource Manager to deploy secure cloud infrastructure, and using version control based on Git“* Proficiency in log analysis, incident response, and forensic investigation techniques.* Excellent communication skills, both written and verbal, with the ability to articulate complex security concepts to technical and non-technical stakeholders.* Demonstrated leadership abilities, with the capacity to motivate and inspire a team.* Strong analytical and problem-solving skills, with the ability to think strategically and develop innovative solutions to security challenges.Joining Salesforce Government Cloud as a Lead Security Engineer provides an exciting opportunity to make a significant impact on the organization's security posture and contribute to its overall success. If you are passionate about security, possess strong leadership skills, and thrive in a fast-paced environment, we encourage you to apply for this challenging and rewarding position.Unleash Your PotentialWhen you join Salesforce, you'll be limitless in all areas of your life. Our benefits and resources support you to find balance and *be your best*, and our AI agents accelerate your impact so you can *do your best*. Together, we'll bring the power of Agentforce to organizations of all sizes and deliver amazing experiences that customers love. Apply today to not only shape the future - but to redefine what's possible - for yourself, for AI, and the world.AccommodationsIf you require assistance due to a disability applying for open positions please submit a request via this .Posting StatementAny employee or potential employee will be assessed on the basis of merit, competence and qualifications - without regard to race, religion, color, national origin, sex, sexual orientation, gender expression or identity, transgender status, age, disability, veteran or marital status, political viewpoint, or other classifications protected by law. This policy applies to current and prospective employees, no matter where they are in their Salesforce employment journey. It also applies to recruiting, hiring, job assignment, compensation, promotion, benefits, training, assessment of job performance, discipline, termination, and everything in between. Recruiting, hiring, and promotion decisions at Salesforce are fair and based on merit. The same goes for compensation, benefits, promotions, transfers, reduction in workforce, recall, training, and education.In the United States, compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for incentive compensation, equity, and benefits. Salesforce offers a variety of benefits to help you live well including: time off programs, medical, dental, vision, mental health support, paid parental leave, life and disability insurance, 401(k), and an employee stock purchasing program. More details about company benefits can be found at the following link: ******************************************* to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, Salesforce will consider for employment qualified applicants
#J-18808-Ljbffr
The Amazon Web Services Professional Services (ProServe) team is seeking a skilled Delivery Consultant to join our team at Amazon Web Services (AWS). In this role, you will work closely with customers to design, implement, and manage AWS solutions that meet their technical requirements and business objectives. You will be a key player in driving customer success through their cloud journey, providing technical expertise and best practices throughout the project lifecycle. Possessing a deep understanding of AWS products and services, you will be proficient in architecting complex, scalable, and secure solutions tailored to meet the specific needs of each customer. You will work closely with stakeholders to gather requirements, assess current infrastructure, and propose effective migration strategies to AWS. As a trusted advisor to our customers, you will provide guidance on industry trends, emerging technologies, and innovative solutions, and you will be responsible for leading the implementation process, ensuring adherence to best practices, optimizing performance, and managing risks throughout the project.
The AWS Professional Services organization is a global team of experts that help customers realize their desired business outcomes when using the AWS Cloud. We work together with customer teams and the AWS Partner Network (APN) to execute enterprise cloud computing initiatives. Our team provides assistance through a collection of offerings that help customers achieve specific outcomes related to enterprise cloud adoption. We also deliver focused guidance through our global specialty practices, which cover a variety of solutions, technologies, and industries.
This position requires an active US Government security clearance of TS/SCI with Polygraph.
Key Job Responsibilities
Design and implement complex, scalable, and secure AWS solutions tailored to customer needs.
Provide technical guidance and troubleshooting support throughout project delivery.
Collaborate with stakeholders to gather requirements and propose effective migration strategies.
Act as a trusted advisor to customers on industry trends and emerging technologies.
Share knowledge within the organization through mentoring, training, and creating reusable artifacts.
About the Team
AWS values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed below, we encourage candidates to apply. If your career is just starting, hasn't followed a traditional path, or includes alternative experiences, don't let it stop you from applying.
Why AWS? Amazon Web Services (AWS) is the world's most comprehensive and broadly adopted cloud platform. We pioneered cloud computing and never stopped innovating - that's why customers from the most successful startups to Global 500 companies trust our robust suite of products and services to power their businesses.
Inclusive Team Culture - Here at AWS, it's in our nature to learn and be curious. Our employee-led affinity groups foster a culture of inclusion that empower us to be proud of our differences. Ongoing events and learning experiences, including our Conversations on Race and Ethnicity (CORE) and AmazeCon (diversity) conferences, inspire us to never stop embracing our uniqueness.
Mentorship & Career Growth - We're continuously raising our performance bar as we strive to become Earth's Best Employer. That's why you'll find endless knowledge-sharing, mentorship and other career-advancing resources here to help you develop into a better-rounded professional.
Work/Life Balance - We value work‑life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there's nothing we can't achieve in the cloud.
Basic Qualifications
7+ years of technical specialist, design and architecture experience.
5+ years of database (SQL, NoSQL, Hadoop, Spark, Kafka, Kinesis) experience.
7+ years of consulting, design and implementation of serverless distributed solutions experience.
5+ years of software development with object‑oriented language experience.
3+ years of cloud‑based solution (AWS or equivalent), system, network and operating system experience.
7+ years of external or internal customer‑facing, complex and large‑scale project management experience.
5+ years of cloud architecture and solution implementation experience.
Bachelor's degree, or 7+ years of professional or military experience.
Current, active US Government Security Clearance of TS/SCI with Polygraph.
Preferred Qualifications
Degree in advanced technology, or AWS Professional level certification.
Knowledge of AWS services including compute, storage, networking, security, databases, machine learning, and serverless technologies.
Knowledge of security and compliance standards including HIPAA and GDPR.
Experience in performance optimization and cost management for cloud environments.
Experience communicating technical concepts to diverse audiences in pre‑sales environments.
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit ********************************************************* for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $138,200/year in our lowest geographic market up to $239,000/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job‑related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign‑on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit ******************************************************** This position will remain posted until filled. Applicants should apply via our internal or external career site.
Share this job
Important FAQs for current Government employees
Before proceeding, please review the following FAQs: ************************************************************
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
#J-18808-Ljbffr
$138.2k-239k yearly 4d ago
Cloud Security Delivery Architect
Amazon 4.7
San Francisco, CA jobs
A leading tech company is looking for a Delivery Consultant specialized in Security and Compliance in San Francisco. This role involves collaborating with customers on AWS migrations, designing secure cloud infrastructures, and providing advisory services for security automation. Candidates should have extensive experience with cloud environments, including AWS and DevSecOps practices. The team focuses on delivering high-quality professional services and requires travel to client locations. Join a diverse group and make an impact in the cloud security field.
#J-18808-Ljbffr
$145k-188k yearly est. 3d ago
Senior Systems Security Engineer
Nava 4.0
Washington, DC jobs
Be Challenged and Make a Difference
In a world of technology, people make the difference. We believe if we invest in great people, then great things will happen. At AnaVation, we provide unmatched value to our customers and employees through innovative solutions and an engaging culture.
Description of Task to be Performed:
AnaVation is looking for a Sr. SystemsSecurity Engineer to assist the customer with engineering and administration tasks. The ideal candidate will be comfortable engaging with client leadership on a regular basis and interacting with senior level team members.
Responsibilities
Perform hands-on engineering, administration, and securing of multiple operating systems (e.g., Windows, RHEL, Unix variants), and applying DISA STIGs across diverse vendor technologies, including virtualization platforms (VMWare, Hyper-V), cloud environments (AWS, Azure, Google Cloud), and enterprise applications.
Perform system administration tasks to include audit and log management, availability monitoring and remediation, account management and access reviews, and configuration update scheduling and performance.
Contribute to the design and development of securesystem architectures, ensuring security is integrated through system and network lifecycles.
Evaluate, implement, and document security architecture solutions, aligning with compliance requirements and organizational mission needs.
Ensure technical compliance with applicable security frameworks, standards, and regulations (e.g., DISA SITGs, NIST 800-53, RMF).
Conducting, configuring, and managing vulnerability scans.
Conducting vulnerability remediations, patching, and system hardening.
Collaborate with ISSOs, Assessors, System Owners, and other stakeholders to implement security controls.
Support security assessments, audits, and accreditation/authorization (ATO) activities.
Document security configurations, engineering solutions, and compliance evidence.
Troubleshoot and resolve security-related technical issues in a timely manner.
Understanding and advising the client regarding critical application data and vulnerability points, coordinating with industry partners to advise the government regarding those security vulnerabilities, and providing recommendations and advice on incident response and recovery plans.
Providing Incident Response (IR) activities including triage, investigation, interviewing, resolving, and reporting on events.
Promoting informationsecurity awareness across the program, ensuring security controls and processes are implemented.
Presenting vulnerability analysis to system owners and leadership.
Required Qualifications
5-10 years of experience in informationsystem engineering and configuration management.
5 years of experience in control implementation and securesystem engineering or design.
Excellent communication skills.
Hands on experience with:
Security monitoring and evaluation, including audits, assessments, and risk management
SIEM tools (e.g., Splunk)
Vulnerability Scanning tools (e.g., Tenable, Nessus)
EDR tools (e.g., Crowdstrike)
Web App Scanning tools (e.g., Burpsuite, Acunetix)
Active Directory
SANs
VMWare
Networking Devices
Expertise in batch, bash, and/or PowerShell scripting
Able to deliver and present security compliance to a wide range of audiences (i.e., system owners, division leadership).
Experience configuring and operating enterprise storage across networks (SAN)
Server visualization - design solutions and configuration (VMWare, VSphere, Hyper-V, etc)
Experience with:
Linux (RHEL 7/8), Windows Operating Systems, and Oracle/SQL Databases
Agile Methodologies
GRC Tools (e.g., CSAM)
Strong desire to learn, grow and be highly motivated.
Certifications: OS specific certifications, Security +
Personnel assigned to this task shall possess a blend of strong technical skills (networking, operating systems, security tools, programming, encryption) and essential soft skills (problem-solving, critical thinking, communication, collaboration) to design, implement, and maintain an informationsystem's security control implementation.
Desired Qualifications
Knowledgeable on different cloud providers: AWS, Azure, Oracle, GCP
Understanding of servers and security tools
Education: Bachelor's degree in Engineering, Computer Science, or InformationSystems
Certifications: CompTIA Server+, Cloud certifications (AWS, Azure, Google), Network+, CCNA, RHCSA, Azure (AZ-104, AZ-204, AZ-500, AZ-305), AWS Solutions Architect
Benefits
Generous cost sharing for medical insurance for the employee and dependents
100% company paid dental insurance for employees and dependents
100% company paid long-term and short-term disability insurance
100% company paid vision insurance for employees and dependents
401k plan with generous match and 100% immediate vesting
Competitive Pay
Generous paid leave and holiday package
Tuition and training reimbursement
Life and AD&D Insurance
About AnaVation
AnaVation is the leader in solving the most complex technical challenges for collection and processing in the U.S. Federal Intelligence Community. We are a US owned company headquartered in Chantilly, Virginia. We deliver groundbreaking research with advanced software and systems engineering that provides an information advantage to contribute to the mission and operational success of our customers. We offer complex challenges, a top-notch work environment, and a world-class, collaborative team.
If you want to grow your career and make a difference while doing it, AnaVation is the perfect fit for you!
AnaVation is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law.
#J-18808-Ljbffr
$74k-97k yearly est. 1d ago
Senior Systems Security Engineer - Cloud, IR & Compliance Lead
Nava 4.0
Washington, DC jobs
A leading technology solutions provider in Washington, DC is seeking a Senior SystemsSecurity Engineer. This role involves hands-on engineering and securing multiple operating systems, managing vulnerabilities, and ensuring compliance with security frameworks. Ideal candidates will have 5-10 years of experience in system engineering and strong communication skills. The position offers competitive pay and extensive benefits including paid medical and dental insurance.
#J-18808-Ljbffr
$74k-97k yearly est. 1d ago
Senior Security Engineer
OSI Engineering 4.6
Mountain View, CA jobs
A globally leading consumer device company headquartered in Mountain View, CA is looking for a Senior Offensive Security Engineer to proactively identify, exploit, and help eliminate security weaknesses across our web platforms and AI/ML systems. In this role, you will think like an attacker, operate with engineering rigor, and work closely with product, platform, and AI teams to raise the security bar across the organization. You will lead complex penetration tests, design novel attack techniques for web and modern AI-powered applications, and influence secure-by-design architecture at scale.
Responsibilities:
• Conduct offensive security assessments on large-scale web applications, REST APIs, and cloud-backed services.
• Identify and validate vulnerabilities including injection flaws, access control
issues, authentication/authorization weaknesses, SSRF, deserialization, and logic
bugs.
• Evaluate LLM-based systems and AI agents for prompt injection, data exfiltration, model abuse and jailbreaks
• Design and execute red team-style engagements simulating real-world adversaries.
• Develop custom exploitation tools, PoCs, and fuzzers for web and AI attack surfaces.
• Identify systemicsecurity weaknesses and collaborate with engineering teams to drive long-term mitigations.
• Review architectures and designs for new products with an attacker mindset.
• Produce clear, actionable security reports and present findings to technical and executive stakeholders.
Minimum Qualifications:
• Master's degree in Computer Science, Computer Engineering, InformationSecurity, or a closely related technical field.
• Doctorate (PhD) in a relevant field is a plus but not required.
• 5+ years of experience in offensive security, penetration testing, or red teaming.
• Deep expertise in web application security.
• Strong understanding of API security.
• Hands-on experience testing AI/ML or LLM-based systems, or strong motivation with demonstrated research in this area.
• Proficiency in at least one scripting or programming language (Python, Go, JavaScript, or similar).
• Strong knowledge of common exploitation techniques and attacker tooling.
Preferred Qualifications:
• Prior work on adversarial ML, red-teaming AI systems, or secure LLM pipeline
design.
• Experience with cloud security (AWS, GCP, Azure) and containerized environments.
• Background in security research, published CVEs, CTF experience, blog posts, or conference talks.
• OSCP, OSEP, OSWE, CRTO, or similar.
What We Look For:
• An attacker-first mindset with strong engineering discipline.
• Ability to go beyond scanners and find novel, high-impact vulnerabilities.
• Clear communicator who can translate complex exploits into actionable fixes.
• Curiosity about emerging threats, especially in AI security.
• Ownership mentality and comfort operating in ambiguous problem spaces.
Type: Contract
Duration: 12 months with extension
Work Location: Mountain View, CA (on site)
Pay Range: $ 85.00 - $ 100.00 (DOE)
$85-100 hourly 1d ago
Staff Cyber Security Engineer
Infovision Inc. 4.4
Dallas, TX jobs
As a Staff Cyber Security Engineer, you will collaborate closely with the Engineering Organization, IT, InformationSecurity, Software Engineers, and our DevOps departments.
Your team will ensure our embedded platforms, back-end and front-end services, cloud infrastructure, DevOps pipelines, data pipelines, and software are secured in the most efficient manner.
You will work to develop new systems and procedures to counteract threat vectors that arise within our cloud and embedded environments.
The ideal candidate is passionate about understanding complex architectures they work in and is adept at translating non-functional security requirements to red-team actions.
The ideal candidate is also a meticulous problem solver who can work under pressure when required and remains current with the latest attack trends and technologies.
Preferred Qualifications:
Master's degree in Computer Science or relevant field of study.
Cyber related certifications such as CompTIA CySA+, CISSP, CHFI, OSCP.
Experience in digital forensics.
Working experience within a DevSecOps environment.
Minimum Qualifications
Expertise in secure API integration design and implementation
Expertise in the OWASP top 10 for web applications, and LLMs along with mitigation and remediation techniques
Bachelor's degree in Computer Science, Information Technology, or a related field.
Extensive experience in cybersecurity within software engineering environments.
Experience with a programming language (C/C++, Python, Go, JavaScript / TypeScript, Rust)
Proficiency in cloud security, threat detection, data analysis, and incident response.
Expertise with security tools such as BurpSuite, PyRIT, Garak, MitM, Metasploit, Wireshark, Wiz, Sonarqube
Experience standing up Security tooling to automate security hygiene, analysis, reporting or otherwise host tools or enhance intel capabilities
Strong technical knowledge of microservice architecture, content distribution networks, data lakes, serverless functions, and databases.
Familiarity with various cloud platforms and DevOps tools.
Excellent analytical and problem-solving skills.
Strong communication skills, both written and verbal.
Ability to independently develop and implement security solutions.
Experience in developing and implementing automated security testing functions.
$77k-100k yearly est. 3d ago
Information Security Analyst
Supermicro 4.7
San Jose, CA jobs
Supermicro is a Top Tier provider of advanced server, storage, and networking solutions for Data Center, Cloud Computing, Enterprise IT, Hadoop/ Big Data, Hyperscale, HPC and IoT/Embedded customers worldwide. We are the #5 fastest growing company among the Silicon Valley Top 50 technology firms. Our unprecedented global expansion has provided us with the opportunity to offer a large number of new positions to the technology community. We seek talented, passionate, and committed engineers, technologists, and business leaders to join us.
Job Summary:
Supermicro is looking for an experienced and knowledgeable InformationSecurity Analyst to join our informationsecurity team. As a gatekeeper that keeps track to the high-volume data over the cyberspace for the company, the security analyst must possess knowledge of every aspect of informationsecurity, with its main focus on analyzing the security measures of a company and determine how effective they are, and assess risks and provide recommendations for remediation. The security analyst must work with business administrators as well as IT professionals in communicating flaws in securitysystems, and recommend changes that will improve every aspect of company security. This position will be based in our headquarters located in San Jose, CA.
Essential Duties and Responsibilities:
The responsibilities will include, but not limited to:
Design, implement and enforce informationsecurity policy including asset management and system hardening.
Insuring all networks have adequate security to prevent unauthorized access.
Develop reports to share with administrators about the efficiency of security policies and recommend any changes.
Organize and conduct training for all employees regarding company security and information safeguarding.
Ensure that all securitysystems are current with any software or hardware changes in the company.
Perform penetration tests and security scanning on hosts and networks.
Follow up on security mitigations.
Qualifications:
Basic Qualifications:
Bachelor's degree in Computer Science, Management InformationSystems or equivalent experiences.
Experience with system and network administration and able to perform networking penetration tests using software tools.
Preferred Qualifications:
Master's degree in Computer Science or Management InformationSystems.
2-4+ years of hands-on experience in informationsecurity environment, with prior experiences in high-tech corporate environment.
Solid understanding in security framework and best practices.
Strong analytical, troubleshooting and problem-solving skills.
Excellent communication skills in both verbal and written.
Certifications in the following is highly preferred - GIAC, CISSP, SSCP, etc.
Salary Range
$90,000 - $100,000
The salary offered will depend on several factors, including your location, level, education, training, specific skills, years of experience, and comparison to other employees already in this role. In addition to a comprehensive benefits package, candidates may be eligible for other forms of compensation, such as participation in bonus and equity award programs.
EEO Statement
Supermicro is an Equal Opportunity Employer and embraces diversity in our employee population. It is the policy of Supermicro to provide equal opportunity to all qualified applicants and employees without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status or special disabled veteran, marital status, pregnancy, genetic information, or any other legally protected status.
$90k-100k yearly 2d ago
Director Information Security
Celestica 4.5
Richardson, TX jobs
We are seeking an experienced and strategic Director of Data Security and Governance to lead our comprehensive data protection program. This critical role involves establishing and enforcing data security policies to meet stringent regulatory requirements, including the International Traffic in Arms Regulations (ITAR), and fulfilling complex data security obligations within commercial contracts. You will be responsible for building our data governance framework from the ground up, including implementing a robust data classification program and deploying modern security solutions like Data Security Posture Management (DSPM) and Data Rights Management (DRM)., in addition to managing the DLP program.
Detailed Description
Performs tasks such as, but not limited to, the following:
Strategy & Policy Development: Design, implement, and oversee the enterprise-wide data security and governance strategy, policies, and standards.
Compliance & Regulatory Oversight: Serve as the primary expert on data security requirements for ITAR and other government regulations. Ensure all data handling processes and systems are compliant with contractual and legal obligations.
Data Classification Program: Develop and manage a corporate data classification policy and program. Work with business units to identify, classify, and protect sensitive and regulated data throughout its lifecycle.
Technology Implementation: Lead the selection, implementation, and operationalization of a Data Security Posture Management (DSPM) solution to provide visibility and control over our data landscape.
Data Rights Management (DRM): Implement and manage a DRM solution to control access to and usage of sensitive data, ensuring that only authorized individuals can access and interact with protected information according to defined policies.
Risk Management: Conduct regular data security risk assessments, identify vulnerabilities, and oversee remediation efforts to mitigate risks.
Incident Response: Develop and lead the data-focused components of the incident response plan, including containment, investigation, and reporting of data breaches.
Collaboration & Training: Partner closely with Legal, IT, Engineering, and business stakeholders to embed data security principles into their operations. Develop and deliver training programs to raise awareness about data governance and security best practices.
Typical Experience
Minimum of 10 years of experience in cybersecurity and data governance, with at least 4 years in a leadership role.
Proven track record of successfully implementing a data classification program across an enterprise.
Direct experience with the procurement and deployment of DSPM and DRM technologies.
Skills & Knowledge:
Deep understanding of data protection principles, including encryption, access control, data loss prevention (DLP), and data discovery.
Expert knowledge of security frameworks such as NIST Cybersecurity Framework, NIST 800-171, and ISO 27001.
Excellent project management skills and the ability to lead cross-functional teams.
Strong communication skills, with the ability to articulate complex security concepts to technical and non-technical audiences.
Certifications (Preferred):
Certified InformationSystemsSecurity Professional (CISSP)
Certified InformationSecurity Manager (CISM)
Certified Information Privacy Professional (CIPP)
Typical Education
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field, or equivalent experience.
A Master's degree is a plus.
Educational requirements may vary by geography.
Physical Demands
Duties of this position are performed in a normal office environment.
Duties may require extended periods of sitting and sustained visual concentration on a computer monitor or on numbers and other detailed data. Repetitive manual movements (e.g., data entry, using a computer mouse, using a calculator, etc.) are frequently required.
Notes
This job description is not intended to be an exhaustive list of all duties and responsibilities of the position. Employees are held accountable for all duties of the job. Job duties and the % of time identified for any function are subject to change at any time.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Celestica's policy on equal employment opportunity prohibits discrimination based on race, color, creed, religion, national origin, gender, sexual orientation, gender identity, age, marital status, veteran or disability status, or other characteristics protected by law.
This policy applies to hiring, promotion, discharge, pay, fringe benefits, job training, classification, referral and other aspects of employment and also states that retaliation against a person who files a charge of discrimination, participates in a discrimination proceeding, or otherwise opposes an unlawful employment practice will not be tolerated. All information will be kept confidential according to EEO guidelines.
COMPANY OVERVIEW:
Celestica (NYSE, TSX: CLS) enables the world's best brands. Through our recognized customer-centric approach, we partner with leading companies in Aerospace and Defense, Communications, Enterprise, HealthTech, Industrial, Capital Equipment and Energy to deliver solutions for their most complex challenges. As a leader in design, manufacturing, hardware platform and supply chain solutions, Celestica brings global expertise and insight at every stage of product development - from drawing board to full-scale production and after-market services for products from advanced medical devices, to highly engineered aviation systems, to next-generation hardware platform solutions for the Cloud. Headquartered in Toronto, with talented teams spanning 40+ locations in 13 countries across the Americas, Europe and Asia, we imagine, develop and deliver a better future with our customers.
Celestica would like to thank all applicants, however, only qualified applicants will be contacted.
Celestica does not accept unsolicited resumes from recruitment agencies or fee based recruitment services.
This location is a US ITAR facility and these positions will involve the release of export controlled goods either directly to employees or through the employee's movement within the facility. As such, Celestica will require necessary information from all applicants upon an applicant's acceptance of employment to determine if any export control exemptions or licenses must be filed.
$100k-124k yearly est. 3d ago
Senior Security Engineer
Loft Orbital, Inc. 4.0
San Francisco, CA jobs
Loft Orbital is revolutionizing access to space by building reliable, shareable satellites that drastically reduce the time and complexity traditionally required to get to orbit. We operate satellites, fly customer payloads, and handle entire missions from end‑to‑end. We're a close‑knitted team of space enthusiasts, software experts, and cutting‑edge technologists, all working together to make space simple for our customers.
As a Senior Security Engineer on our Security and Compliance Team, your mission will be to ensure that our highly automated, containerized, and globally distributed infrastructure remains secure throughout its lifecycle, from architecture to incident response. You'll be at the heart of our DevSecOps efforts, collaborating directly with infrastructure, software, product, and solution teams to scale Loft's security maturity while embracing our startup agility and culture.
This is a hands‑on, deeply collaborative role, offering broad scope, rapid growth opportunities, and yes, a chance to contribute to space missions.
About the Role:
Champion DevSecOps best practices by designing and implementing security controls directly into our CI/CD pipelines (e.g., GitLab CI).
Lead and automate application and infrastructure security assessments, including threat modeling and code review.
Partner with developers and SREs to identify, remediate, and prevent vulnerabilities through secure design and practical guidance.
Design, build, and maintain secure architecture patterns for containerized, cloud‑native, and distributed workloads.
Develop and maintain automated security tooling, such as container image scanning, IaC validation, and policy‑as‑code.
Collaborate on automated security tooling for container image scanning, IaC validation, and RBAC compliance.
Support incident response workflows, including detection, forensics, root cause analysis, and post‑mortems.
Provide technical mentorship and real‑time enablement to help teams adopt a “secure‑by‑default” mindset.
Contribute to internal security tools and automation using Python, Go, or other modern languages.
Continuously improve how we measure and scale security across our SRE and infrastructure platforms.
Must Haves:
Deep experience with cloud security in AWS, Azure, or GCP environments.
Strong knowledge of container and Kubernetes security in production environments.
Proficiency in at least one modern programming language (e.g., Python, Go, C++).
Hands‑on experience with zero‑trust architecture, service mesh, and software‑defined networking.
Solid understanding of DevSecOps pipelines, IaC tools, and secure build processes.
Hands‑on experience with vulnerability scanning, SAST/DAST tools, and automated security testing.
Proven success in fast‑paced, highly collaborative environments, ideally at a startup or scale‑up.
Comfortable working closely with developers and SREs in an enablement‑first security culture.
Clear, concise communication and documentation skills.
Ability to thrive in a multicultural, globally distributed engineering team.
Nice to Haves:
Practical experience with policy‑as‑code (OPA, Sentinel, etc.).
Understanding of software‑defined networking and security policy enforcement in mesh environments.
Familiarity with modern SRE practices, observability, and resilience engineering.
Contributions to open‑source security tools or frameworks.
Interest or experience in space operations or aerospace systems.
Some of Our Awesome Benefits:
100% company‑paid medical, dental, and vision insurance option for employees and dependents
Flexible Spending (FSA) and Health Savings (HSA) Accounts offered with an employer contribution to the HSA
100% employer paid Life, AD&D, Short‑Term, and Long‑Term Disability insurance
Flexible Time Off policy for vacation and sick leave, and 12 paid holidays
401(k) plan and equity options
Daily catered lunches and snacks in office
International exposure to our team in France
Fully paid parental leave; 14 weeks for birthing parent and 10 weeks for non‑birthing parent
Carrot Fertility provides comprehensive, inclusive fertility healthcare and family‑forming benefits with financial support
Off‑sites and many social events and celebrations
Relocation assistance when applicable
$140,250 - $190,000 a year
State law requires us to tell you the base compensation range for this role, which is $140,250- $190,000 per year. This is determined by your education, experience, knowledge, skills, and abilities. The salary range for this role is intentionally wide as we evaluate individuals based on their unique experience and abilities to fit our needs. Most importantly, we are excited to meet you, and see if you are a great fit for our team. What we can't quantify for you are the exciting challenges, supportive team, and amazing culture we enjoy.
* Research shows that while men apply to jobs where they meet an average of 60% of the criteria, women and other underrepresented people tend to only apply when they meet 100% of the qualifications. At Loft, we value respectful debate and people who aren't afraid to challenge assumptions. We strongly encourage you to apply, even if you don't check all the boxes.
Who We Are
Loft: Space Made Simple.
Founded in 2017, Loft provides governments, companies, and research institutions with a fast, reliable, and flexible way to deploy missions in orbit.
We integrate, launch, and operate spacecraft, offering end‑to‑end missions as a service across Earth observation, IoT connectivity, in‑orbit demonstrations, national security missions, and more. Leveraging our existing space infrastructure and an extensive inventory of satellite buses, Loft is reducing years‑long integration and launch timelines to months. With more than 25 missions flown, Loft's flight heritage and proven technologies enable customers to focus on their mission objectives.
At Loft, you'll be given the autonomy and ownership to solve significant challenges, but with a close‑knot and supportive team at your back. We believe that diversity and community are the foundation of an open culture. We are committed to hiring the best people regardless of background and make their time at Loft the most fulfilling period of their career.
We value kind, supportive and team‑oriented collaborators. It is also crucial for us that you are a problem solver and a great communicator. As our team is international, you will need strong English skills to better collaborate, easily communicate complex ideas and convey important messages.
With 4 satellites on‑orbit and a wave of exciting missions launching soon, we are scaling up quickly across our offices in San Francisco, CA | Golden, CO | and Toulouse, France.
As an international company your resume will be reviewed by people across our offices so please attach a copy in English.
#J-18808-Ljbffr
$139k-189k yearly est. 2d ago
Offensive Security Engineer, Hardware
Openai 4.2
San Francisco, CA jobs
Security is at the foundation of OpenAI's mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI's technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.
About the Role
We're seeking an exceptional Principal-level Offensive Security Engineer to challenge and strengthen OpenAI's security posture. This role isn't your typical red team job - it's an opportunity to engage broadly and deeply, craft innovative attack simulations, collaborate closely with defensive teams, and influence strategic security improvements across the organization.
You have the chance to not only find vulnerabilities but actively drive their resolution, automate offensive techniques with cutting-edge technologies, and use your unique attacker perspective to shape our security strategy. This role will be primarily focused on continuously testing our hardware products and related services.
In this role you will:
Collaborate proactively with engineering teams to enhance security and mitigate risks in hardware, firmware, and software.
Perform comprehensive penetration testing on our diverse suite of products.
Leverage advanced automation and OpenAI technologies to optimize your offensive security work.
Present insightful, actionable findings clearly and compellingly to inspire impactful change.
Influence security strategy by providing attacker-driven insights into risk and threat modeling.
You might thrive in this role if you have:
7+ years of hands‑on experience or exceptional accomplishments demonstrating equivalent expertise.
Exceptional skill in code review, identifying novel and subtle vulnerabilities.
Demonstrated mastery assessing complex technology stacks, including:
Proven ability to reverse engineer bootrom images, firmware, or silicon‑level components.
Deep familiarity with low‑level kernel operations, secure boot processes, and hardware‑software interactions.
Hands‑on experience building and validating secure boot chains and threat models.
Proficiency with hardware debugging tools (UART, JTAG, SWD, oscilloscopes, logic analyzers).
Solid programming skills in C/C++, Python, or assembly for embedded systems.
Industry experience securing consumer hardware (e.g., mobile devices, IoT, chipsets).
Excellent written and verbal communication skills for technical and non‑technical audiences.
Strong intuitive understanding of trust boundaries and risk assessment in dynamic contexts.
Excellent coding skills, capable of writing robust tools and automation for offensive operations.
Ability to communicate complex technical concepts effectively through compelling storytelling.
Proven track record of not just finding vulnerabilities but actively contributing to solutions in complex codebases.
Prior experience working in tech startups or fast‑paced technology environments.
Experience in related disciplines such as Software Engineering (SWE), Detection Engineering, Site Reliability Engineering (SRE), Security Engineering, or IT Infrastructure.
About OpenAI
OpenAI is an AI research and deployment company dedicated to ensuring that general‑purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.
We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.
Qualified applicants with arrest or conviction records will be considered for employment in accordance with applicable law, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non‑public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.
To notify OpenAI that you believe this job posting is non‑compliant, please submit a report through this form . No response will be provided to inquiries unrelated to job posting compliance.
We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link.
At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.
#J-18808-Ljbffr
$125k-175k yearly est. 5d ago
Principal Offensive Security Engineer, Hardware
Openai 4.2
San Francisco, CA jobs
A leading AI research company in San Francisco is hiring a Principal Offensive Security Engineer. In this role, you will craft attack simulations and collaborate with teams to strengthen security posture across products. The ideal candidate has over 7 years of experience, exceptional programming skills, and a strong background in identifying vulnerabilities. This position offers an opportunity to influence security strategy and contribute to innovative projects in a dynamic environment.
#J-18808-Ljbffr
$125k-175k yearly est. 5d ago
Cloud Security Architect
Axway 4.8
Scottsdale, AZ jobs
Job ID 2025-8109 Category Technical/Engineering
The Axway Cloud Security team is seeking a new Cloud Security Architect who will be critical to delivering secure cloud services to customers in government, banking, financial services, healthcare, life sciences, manufacturing, and other security-conscious industries.
As a Cloud Security Architect, you will serve as a trusted advisor and thought leader, responsible for embedding security into the foundation of our cloud strategy and engineering practices.
Responsibilities
Lead the design and implementation of secure, scalable, and resilient cloud architectures across Customer Cloud Environments
Serve as the principal subject matter expert (SME) for security architecture, frameworks, and best practices.
Define and communicate security reference architectures, design patterns, and standards that align with organizational and regulatory requirements
Partner with development, product, and operations teams to embed security throughout the software development life cycle (SDLC) and infrastructure as code (IaC) pipelines
Conduct architectural risk assessments and threat modeling for new and existing cloud solutions
Develop and drive automation strategies for continuous compliance, configuration management, and security control validation
Evaluate and integrate cloud-native and third-party security technologies (e.g., SIEM, CSPM, CWPP, XDR, etc.) to strengthen Axway's security posture
Collaborate with governance and compliance teams to ensure alignment with frameworks such as ISO 27001, SOC 2, NIST, GDPR, and CIS Benchmarks
Provide strategic guidance for vulnerability management processes, ensuring architectural consistency and rapid mitigation of risks
Engage in incident response activities as a cloud security SME, assisting with investigation, containment, and remediation efforts, and documenting findings and lessons learned
Mentor other team members, and contribute to developing a security-first culture across all relevant teams
Represent the Cloud Security organization in design reviews, risk committees, and customer-facing engagements as needed
Contribute to Axway's Cloud Center of Excellence (CCoE) and help define secure reference patterns across Axway's SaaS, single-tenant, and hybrid cloud offerings
Committed to developing and honing skills via certifications, instructional courses, security news feeds, and/or research
Qualifications
8+ years of progressive informationsecurity experience, with at least 4 years focused on cloud security architecture and engineering
Deep expertise in AWS and Azure security services, controls, and architecture principles
Proven ability to translate complex business and technical requirements into secure cloud architectures and actionable designs
Experience developing security architectures for distributed systems, containerized environments (Kubernetes), and hybrid or multi-cloud ecosystems
Demonstrated experience with DevSecOps practices, CI/CD security integration, and automation using APIs, IaC, and scripting
Strong understanding of network security, identity and access management (IAM), secrets management, data protection, and logging/monitoring architectures
Experience assessing, implementing, and maintaining enterprise solutions such as CIEM, CSPM, vulnerability management, and identity governance tools
Working knowledge of compliance and risk frameworks (ISO 27001, NIST, SOC 2, GDPR, CIS, CSA) and their application in cloud environments
Excellent communication skills with the ability to engage both technical and executive stakeholders and influence architectural direction
Strategic mindset with the ability to balance innovation, security, and business needs
Nice to Have
Security certifications such as:
(ISC)2: CISSP, CCSP
SANS: GCLD, GCSA, GCIA, GCPN, GPYC, GCIH, GPCS
AWS: Solutions Architect Professional, Security Specialty
Azure: Security Engineer Associate, Solutions Architect Expert
Bachelor's or Master's degree in Cybersecurity, Computer Science, or related field - or equivalent industry experience
Prior experience contributing to or leading cloud security strategy, governance programs, or security architecture boards
Company Overview
At Axway, we're more than a company-we're a pioneer. For 25 years, we've been empowering organizations to achieve digital transformation and unlock innovation. With a presence in 100 countries, 11,000+ customers, and a global team of over 1,400+ passionate professionals, Axway is driving the future of enterprise integration.
We're on a mission to a be the leaderin our space, empowering our customers withsecure, mission-critical softwareto manage and deliver impactful business outcomes from all theirdigital business interactions.
Why Axway?
We believe in the power of togetherness. When you're part of Axway, you're part of a culturally rich and globally connected community that thrives on exchanging ideas and tackling challenges head-on. Whether working remotely or onsite, you'll find camaraderie, collaboration, and the support of leadership to inspire you daily.
Here, you'll grow, innovate, and succeed because we're better together. Each step forward in your personal journey is one we take as a team. Join us, and let's accomplish extraordinary things together.
Axway is a proud member of 74Software. Learn more about how Axway is transforming the future:en.
Ready to shape the future? Let's get started-because at Axway, together, we can. Together, we will.
Axway is an EEO and AA Employer
#LI-KJ1
#LI-Hybrid
Connect With Us!
Not ready to apply? Connect with us for general consideration.
$109k-143k yearly est. 5d ago
Sr. Information Assurance Analyst
Dkw Communications Inc. 4.6
California jobs
Come Join Our Team! DKW Communications, Inc. (DKW) is a government contractor providing professional and technical services to various government agencies i.e. defense, law enforcement and security. We are currently looking for an
Senior Information Assurance Analyst
to join our winning team. The individual hired for this position will provide support for our government customers located in the Greater San Diego area. This is an onsite position.
Overview
The IA Analyst will support our NAVY SWMFTS contract, and be responsible for duties such as (but not limited to):
Collect and maintain data needed to meet system cybersecurity reporting
Ensure that protection and detection capabilities are acquired or developed using the IS security engineering approach and are consistent with organization-level cybersecurity architecture.
Participate in an informationsecurity risk assessment during the Security Assessment and Authorization process.
Participate in the development or modification of the computer environment cybersecurity program plans and requirements.
Recognize a possible security violation and take appropriate action to report the incident, as required
Ensure plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc.
Provide technical documents, incident reports, and findings from computer examinations, summaries, and other situational awareness information to higher headquarters
Develop and maintain RMF Assess and Authorize documentation required to achieve an Authority to Operate (ATO). Prepare and maintain informationsystems ATO record on the Navy's Enterprise Mission Assurance Support Service (eMASS)
Run vulnerability assessment tools; ACAS vulnerability scanner, Security Content Automation Protocol (SCAP), STIG Viewe
Manage system/network vulnerabilities using the Vulnerability Remediation and Assets Manager (VRAM)
Qualifications/Requirements
MUST have or be able to obtain an active Secret Security Clearance.
Minimum of Bachelor's Degree in Computer Science, InformationSystems or a relevant technical discipline.
An Associate's degree + 3 years of experience may be substituted for degree requirement.
3-5 years of cyber security experience in secure network and system design, analysis, procedure/test generation, test execution and implementation of computer/network security mechanisms.
Must have an IAT Level II Certification or higher.
**All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status.**