Information Security Engineer jobs at Wells Fargo - 960 jobs
Lead Information Security Engineer - Cryptographic Products and Services
Wells Fargo 4.6
Information security engineer job at Wells Fargo
**About this role:** Wells Fargo is seeking a motivated Lead InformationSecurityEngineer to join an exciting, fast paced team working on cutting edge encryption, tokenization and key management technologies that are leveraged to protect information companywide. This role will provide technical leadership, and be an individual contributor, to teams that design, deploy, and operationally maintain cryptographic products and services including Hardware Security Modules (HSMs) and security appliances.
The ideal candidate will have demonstrated experience in the design and deployment of cryptographic products in physical, virtual, and containerized environments. The ideal candidate will also have demonstrated experience in automating processes including product builds, operational maintenance, and customer integration and onboarding. This role reports directly to the Senior Manager for the Encryption, Tokenization and Key Management team.
**In this role, you will:**
+ Drive design, deployment and automation strategies for encryption, tokenization and key management products and services including Hardware Security Modules, security appliances and security applications deploying in physical, virtual, and containerized environments.
+ Provide technical guidance and oversight to teams and team members responsible for product delivery and operational maintenance.
+ Develop and maintain documentation including design and build guides, deployment strategies, automation guides and operational processes.
+ Participate in research, analysis and evaluation of new cryptographic products and services.
+ Participate in Proof of Concept (POC) testing and demonstrations for new cryptographic products and services.
+ Support company driven audits, gather evidence of compliance to company policies, and drive product enhancements, when needed, to remediate findings.
+ Conduct technical investigation of incidents to identify causes and recommend future mitigation strategies.
+ Collaborate across Wells Fargo teams, including compliance, security architecture and security evaluation teams to ensure cryptographic products are compliant to company policies.
+ Work with vendors to understand the technology vendor's roadmap, help to influence that roadmap, and ensure requests for technology/product enhancements are meeting the needs of Wells Fargo.
+ Work with partner engineering teams on identification and remediation of security vulnerabilities and may also conduct risk assessments of infrastructure to ensure compliance with corporate security policies and adherence to best practices.
+ Support incident response, root cause analysis and corrective action activities.
+ Oversee team of engineers and influence design/architecture decisions regarding encryption infrastructure to support our line of business customers.
+ Ensure design decisions consider blast radius and business resiliency requirements to reduce / eliminate impact during service changes or DDOS type events, among others.
**Required Qualifications:**
+ 5+ years of InformationSecurityEngineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education.
+ 4+ years of intermediate to advanced level experience with scripting/automation using tools such as: Bash, PowerShell, Python, Ansible, VBScript, or JavaScript, UI path, etc.
+ 4+ years of Linux and Windows server experience
**Desired Qualifications:**
+ Experience with encryption or tokenization and key management technologies.
+ Advanced Knowledge of Cryptographic protocols & algorithms.
+ Subject Matter Expert experience designing solutions using Hardware Security Modules (HSMs) or security appliance devices
+ Experience with DevOps and CI/CD automated build and deployment processes.
+ Advanced scripting skills specifically around log rotation, data collection, error collection and alerting.
+ Experience designing, developing, and implementing synthetic transactions for the monitoring of applications and/or infrastructure.
+ Experience with Puppet/Chef/Ansible or similar automation tools.
+ Experience with Agile Scrum or Kanban methodologies.
+ Application development experience.
+ Experience with application support in Linux and Windows server environments.
+ Experience performing technical product assessments, including development of implementation plans, in a large enterprise.
+ Experience mentoring/guiding less experienced staff.
+ Strong analytical skills with high attention to detail and accuracy.
+ Advanced critical thinking, problem solving and technical troubleshooting abilities.
+ Knowledge and understanding of implementing infrastructure upgrades, security patches, or version upgrades.
+ Knowledge and understanding of monitoring and reporting tools.
+ Experience with and the ability to thrive in a complex and fast-paced technology and/or informationsecurity organization, within a large enterprise environment.
+ Strong verbal, written, and interpersonal communication skills.
+ Knowledge and understanding of implementing infrastructure upgrades, security patches, version upgrades for systems, appliances and HSM's
+ Proven experience with change and incident management practices in medium to large enterprise environments.
+ Knowledge and understanding of implementing infrastructure upgrades, security patches, version upgrades for systems, appliances and HSM's
+ Experience with coding/scripting against Cyber security tools and products
**Job Expectations:**
+ Ability to travel up to 10% of the time.
+ Ability to work onsite in the office in a hybrid model, 3 days per week on-site/in-office and 2 days per week remote
+ Remote work is not available for this position
+ This position is not eligible for Visa Sponsorship.
**Locations:**
+ 401 W Las Collinas Blvd. Bldg A, Irving, TX
+ 3075 Loyalty Cir, Columbus, OH
+ 1751 Pinnacle Drive, Arlington, VA
+ 300 South Brevard, Charlotte
**Pay Range**
119,000.00 - 187,000.00 USD Annual
**Benefits:**
+ Information about Wells Fargo's US employee benefits (***************************************************************
+ Information about Wells Fargo's International employee benefits
**Posting End Date:**
23 Jan 2026
***** **_Job posting may come down early due to volume of applicants_**
**Pay Range**
Reflected is the base pay range offered for this position. Pay may vary depending on factors including but not limited to achievements, skills, experience, or work location. The range listed is just one component of the compensation package offered to candidates.
$119,000.00 - $224,000.00
**Benefits**
Wells Fargo provides eligible employees with a comprehensive set of benefits, many of which are listed below. Visit Benefits - Wells Fargo Jobs (*************************************************************** for an overview of the following benefit plans and programs offered to employees.
+ Health benefits
+ 401(k) Plan
+ Paid time off
+ Disability benefits
+ Life insurance, critical illness insurance, and accident insurance
+ Parental leave
+ Critical caregiving leave
+ Discounts and savings
+ Commuter benefits
+ Tuition reimbursement
+ Scholarships for dependent children
+ Adoption reimbursement
**Posting End Date:**
22 Jan 2026
***** **_Job posting may come down early due to volume of applicants._**
**We Value Equal Opportunity**
Wells Fargo is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other legally protected characteristic.
Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company. They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions. There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit's risk appetite and all risk and compliance program requirements.
**Applicants with Disabilities**
To request a medical accommodation during the application or interview process, visit Disability Inclusion at Wells Fargo (****************************************************************** .
**Drug and Alcohol Policy**
Wells Fargo maintains a drug free workplace. Please see our Drug and Alcohol Policy (********************************************************************** to learn more.
**Wells Fargo Recruitment and Hiring Requirements:**
a. Third-Party recordings are prohibited unless authorized by Wells Fargo.
b. Wells Fargo requires you to directly represent your own experiences during the recruiting and hiring process.
**Req Number:** R-513380
$74k-97k yearly est. 15d ago
Looking for a job?
Let Zippia find it for you.
Senior Red Team Engineer - Finance Security & Adversarial Testing
Robinhood 4.7
Menlo Park, CA jobs
A leading financial technology company based in Menlo Park, CA seeks an Offensive SecurityEngineer to enhance security and build resilience across their products. This role involves mentoring, conducting Red Team exercises, and collaborating on security findings with various teams. Ideal candidates have 5+ years of experience and strong communication skills. Attractive compensation includes health insurance and support for personal wellness. Join us to help democratize finance for all.
#J-18808-Ljbffr
$152k-212k yearly est. 1d ago
Senior Red Team Engineer - Finance Security & Adversarial Testing
Robinhood 4.7
Bellevue, WA jobs
A leading financial technology company based in Menlo Park, CA seeks an Offensive SecurityEngineer to enhance security and build resilience across their products. This role involves mentoring, conducting Red Team exercises, and collaborating on security findings with various teams. Ideal candidates have 5+ years of experience and strong communication skills. Attractive compensation includes health insurance and support for personal wellness. Join us to help democratize finance for all.
#J-18808-Ljbffr
A financial services company in San Francisco is seeking an experienced security professional to assess access controls and mentor peers in security best practices. The candidate should have over 6 years of experience in security operations and a Bachelor's degree. The role offers competitive compensation ranging from $157,000 to $200,000, along with a hybrid work model and comprehensive benefits.
#J-18808-Ljbffr
$157k-200k yearly 5d ago
Prin Security Analyst
Compeer Financial 4.1
Bloomington, IL jobs
Empowered to live. Inspired to work. Compeer Financial is a member-owned cooperative located in Illinois, Minnesota and Wisconsin. We bring together team members with a variety of backgrounds and experiences to help provide financial services to support agriculture and rural communities. Join us in a culture that not only promotes meaningful work and professional development, but provides a flexible, hybrid work environment and excellent benefits, which empower you to thrive both personally and professionally.
How we support you:
Hybrid model - up to 50% work from home
Flexible schedules including ample flexibility in the summer months
Up to 9% towards 401k (3% fixed Compeer contribution plus up to 6% match)
Benefits: medical, dental, vision, HSA/FSA, life & AD&D insurance, short-term and long-term disability, wellness program & EAP
Vacation, sick leave, holidays/floating holidays, parental leave, and volunteer paid time off
Learning and development programs
Mentorship programs
Cross-functional committee opportunities (i.e. Inclusion Council, emerging professional groups, etc.)
Professional membership/certification reimbursement and more!
Casual/seasonal & intern team members are not eligible for benefits except for state-mandated programs.
To learn more about Compeer Financial visit************************
Where you will work: This position offers a hybrid work option up to 50% remote and is based out of any of Compeer's office locations.
The contributions you will make:
This position creates, implements and maintains corporate-wide security programs that assist in improving overall security posture of the organization. Provides guidance, assurance and information protection to maintain the confidentiality, integrity, and availability of Compeer critical resources. Contributes knowledge and expertise to ensure that information assets are protected and secure. In this position, you will guide solutions to promote secure business-to-business initiatives, third-part relationships, outsourced solutions and vendors. Provides mentorship and guidance to less experienced team members.
A typical day:
Remains current with new security threats and assess systems and solutions to ensure they can defend the business.
Researches capabilities of current and new disruptive solutions on the market and makes recommendations to security group on a consistent basis.
Develops security team standards, policies, procedures and processes.
Support and provide direction for use of technical systems, monitors for unusual and suspicious activity across a wide range of products, data centers, and cloud systems.
Partners with Business Technology on security configuration standards for systems and business applications.
Participates in technical and non-technical projects requiring informationsecurity oversight and to ensure policies and procedures are met.
Provides cybersecurity guidance to leadership.
Ensures that cybersecurity-enabled products or other compensating security control technologies or processes reduce identified risk to an acceptable level.
Performs security reviews, identifies gaps in security architecture, and develops a security risk management plan.
Implements security measures to resolve vulnerabilities, mitigate risks, and recommend security changes to system or system components as needed.
Analyzes and reports system security posture trends.
Analyzes cyber defense policies and configurations and evaluates compliance with regulations and organizational directives.
Prepares audit reports that identify technical and procedural findings and provide recommended remediation strategies/solutions.
Leads the Incident Response Team during activations for security or operational events.
Coordinates, leads and conducts adversary simulation, hunt teaming, assumed breaches and whitebox penetration tests. Develops and executes attack plans, scripts, tools and methodologies to strengthen the offensive operations.
Plans and coordinates the delivery of classroom techniques and formats (e.g., lectures, demonstrations, interactive exercises, and multimedia presentations) for the most effective learning environment.
The skills and experience we prefer you have:
Bachelor's degree in security management, cybersecurity, computer science, management information systems, or business with technical training in networking, technical support or security or an equivalent combination of education and experience sufficient to perform the essential functions of the job.
Expert-level experience in physical asset security, information technology, risk management, security services, or infrastructure technology.
CISSP certification preferred.
Ability to adapt and stay a step ahead of cyber attackers and stay up to date on the latest attack methods.
Expert experience driving measurable improvement in monitoring and response capabilities at scale.
Expert ability to identify and resolve problems, utilizing strong analytical skills.
Advanced experience in cloud computing technologies, including software, infrastructure and platform-as-a-service, as well as public, private and hybrid environments.
Expert knowledge of traditional security controls and technologies, such as SecurityInformation and Event Management (SIEM) systems, intrusion detection/prevention systems (IDS/IPS), public key infrastructure (PKI), identity and access management (IDAM) systems, antivirus and firewalls, in addition to endpoint detection and response (EDR), threat intelligence platforms, data loss prevention (DLP), security automation and orchestration, deception technologies, application controls, and other network and system monitoring tools.
Experience with purple teaming (red and blue) to train, identify and remediate issues cohesively.
Advanced experience with Amazon Web Services (AWS) or Microsoft Azure.
Expert experience conducting risk analysis to protect the business and adhere with compliance requirements and privacy laws.
Expert experience with vulnerability and penetration testing engagements.
Advanced knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
Expert knowledge of what constitutes a network attack and a network attack's relationship to both threats and vulnerabilities.
Knowledge of multiple cognitive domains and tools and methods applicable for learning in each domain.
Knowledge of media production, communication, and dissemination techniques and methods, including alternative ways to inform via written, oral, and visual media.
Knowledge of training and education principles and methods for curriculum design, teaching and instruction for individuals and groups, and the measurement of training and education effects.
How we will take care of you:
Our job titles may span more than one career level (associate, senior, principal, etc.). The actual title and base pay offered is dependent upon many factors, such as: training, transferable skills, work experience, business needs and market demands. The base pay range is subject to change and may be modified in the future. This role is eligible for variable compensation and other benefits.
Base Pay$103,100-$156,400 USD
Compeer Financial is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law.
Must be authorized to work for any employer in the United States. Compeer is unable to sponsor or take over sponsorship of an employment visa at this time.
Click here to view federal employment laws applicable for applicants.
$103.1k-156.4k yearly 2d ago
Lead AI Security Engineer
Capital Group 4.4
San Antonio, TX jobs
"I can be myself at work."
You are more than a job title. We want you to feel comfortable doing great work and bringing your best, authentic self to everything you do. We value your talents, traditions, and uniqueness-and we're committed to fostering a strong sense of belonging in a respectful workplace.
We intentionally seek diverse perspectives, experiences, and backgrounds, investing in a culture designed to celebrate differences. We believe that belonging leads to better outcomes and a stronger community of associates united by our mission. At Capital, we live our core values every day: Integrity, Client Focus, Diverse Perspectives, Long-Term Thinking, and Community.
"I can influence my income."
You want to feel recognized at work. Your performance will be reviewed annually, and your compensation will be designed to motivate and reward the value that you provide. You'll receive a competitive salary, bonuses and benefits. Your company-funded retirement contribution will factor in salary and variable pay, including bonuses.
"I can lead a full life."
You bring unique goals and interests to your job and your life. Whether you're raising a family, you're passionate about where you volunteer, or you want to explore different career paths, we'll give you the resources that can set you up for success.
Enjoy generous time-away and health benefits from day one, with the opportunity for flexible work options
Receive 2-for-1 matching gifts for your charitable contributions and the opportunity to secure annual grants for the organizations you love
Access on-demand professional development resources that allow you to hone existing skills and learn new ones
"I can succeed as a Lead AI SecurityEngineer at Capital Group"
As aLeadAISecurity Engineer, you willbe responsible forsecuring Capital Group's enterprise AI Platforms.You willhelp enable Capital Group's AIstrategy bybuilding and/orprocuringsolutions toprotecta diverse set of enterprise AI platforms being built and deployed at Capital Group.You'llcollaborate with platformengineering, securityengineering, and risk teams toensure their solutions support scalable, secureadoption of AI.
Additionally,you'llbe expected toprovidementoring,advising diverse teams across the organization, andpromoting AI Securityprinciples across Capital Group.
AISecurityProcurementManagements:You willprocureand/or build technical solutionsto reducethe riskof misconfiguration, exploitation, andother security issues formultipleenterprise AI platforms.
Embedding Security in the AIPlatform Ecosystem:Working closely withplatform teams tointegrate securityintoeverycomponentof the AI Platform.
Implementing Security Controls & "Guardrails" for GenAI:Designing, deploying, andoperatingtechnical controls to prevent misuse of AI systems.Guardrails designincludescontent filtering systems, usage policies, and safety checks that mitigate issues like prompt injection attacks, unauthorized data extraction, model bias or hallucinations, and other misuse of generative AIplatforms.
AI Runtime Security:Engineer continually tests and updatestothe guardrails, replacing weaker controls with more robust solutions as threats evolve.
AI Governance:You will work cross functionally with architecture and platform teams tomonitoralignment of solutions to AI Governance processes
Contribute to Standards and Policies:You will providethought leadership for InformationSecurity policies and standards for AIin collaboration with technology risk
AI/Agent SME:Youwill provide AI/Agent subject matterexpertisefor AI Incidentsand Security Reviews, and helpdevelop incident response playbooks for AI-related security incidents
"I am the person Capital Group is looking for."
You have 8+yearsof experience in informationsecurity, application security, platform security, or penetration testing,DevSecOps, networksecurityand other security disciplines.
You have experience securing AI platforms, whetherinternal AIplatforms or offerings such as CoPilot Studio, Amazon Bedrock, and/or Azure AI Gateway
Proficient in Programming & ML Tool.Strong Python skillsrequired, with experience in AI/ML frameworks.Abilityto review and write ML code to implement security measures (e.g., model validation, adversarial testing) isdesired.
You have5+ years of relevant professional experience ordemonstrated anequivalent level ofexpertisein securityengineering, such as cloud, API, or platform security.
You have3+ years of experience embedded identity, network, and encryption controls into enterprise platforms
Youcaneffectively partner and collaborate with stakeholder teams.
You have effective communication skills andthe abilityto outline security riskstoleadership.
You are familiar with cloud and API security vendors and managed services providers.
Preferred Qualifications:
You have knowledge and experience with technologies including Kubernetes, Containers, CI/CD, and Cloud Service Providers
You are familiar withfunctionand purpose of key AI platform components such as AI gateways (Kong, Databricks Mosaic AI Gateway, custom API orchestration), Model Orchestration (ExamplesLangChain,LlamaIndex, etc.)
You are familiar with key AI regulatory frameworks such as NIST AI RMF, MITRE ATLAS, GDPR, EU AI Act,etc
You have informationSecurity certifications (CISSP, SANS GIAC, CISA, etc.)
"I can apply in less than 4 minutes."
You've reviewed this job posting and you're ready to start the candidate journey with us. Apply now to move to the next step in our recruiting process. If this role isn't what you're looking for, check out our other opportunities and join our talent community.
"I can learn more about Capital Group."
At Capital Group, the success of the people who invest with us depends on the people in whom we invest. That's why we offer a culture, compensation and opportunities that empower our associates to build successful and prosperous careers. Through nine decades, our goal has been to improve people's lives through successful investing. We know that our history is a testament to the strength of the people we hire. More than 9,000 associates in 30+ offices around the world help our clients and each other grow and thrive every day. Find us on LinkedIn, Instagram, YouTube and Glassdoor.
Southern California Base Salary Range: $179,273-$286,837San Antonio Base Salary Range: $147,378-$235,805New York Base Salary Range: $190,040-$304,064
In addition to a highly competitive base salary, per plan guidelines, restrictions and vesting requirements, you also will be eligible for an individual annual performance bonus, plus Capital's annual profitability bonus plus a retirement plan where Capital contributes 15% of your eligible earnings.
You can learn more about our compensation and benefits
here
.
* Temporary positions in the United States are excluded from the above mentioned compensation and benefit plans.
We are an equal opportunity employer, which means we comply with all federal, state and local laws that prohibit discrimination when making all decisions about employment. As equal opportunity employers, our policies prohibit unlawful discrimination on the basis of race, religion, color, national origin, ancestry, sex (including gender and gender identity), pregnancy, childbirth and related medical conditions, age, physical or mental disability, medical condition, genetic information, marital status, sexual orientation, citizenship status, AIDS/HIV status, political activities or affiliations, military or veteran status, status as a victim of domestic violence, assault or stalking or any other characteristic protected by federal, state or local law.
$190k-304.1k yearly 2d ago
Lead AI Security Engineer
Capital Group 4.4
Irvine, CA jobs
"I can be myself at work."
You are more than a job title. We want you to feel comfortable doing great work and bringing your best, authentic self to everything you do. We value your talents, traditions, and uniqueness-and we're committed to fostering a strong sense of belonging in a respectful workplace.
We intentionally seek diverse perspectives, experiences, and backgrounds, investing in a culture designed to celebrate differences. We believe that belonging leads to better outcomes and a stronger community of associates united by our mission. At Capital, we live our core values every day: Integrity, Client Focus, Diverse Perspectives, Long-Term Thinking, and Community.
"I can influence my income."
You want to feel recognized at work. Your performance will be reviewed annually, and your compensation will be designed to motivate and reward the value that you provide. You'll receive a competitive salary, bonuses and benefits. Your company-funded retirement contribution will factor in salary and variable pay, including bonuses.
"I can lead a full life."
You bring unique goals and interests to your job and your life. Whether you're raising a family, you're passionate about where you volunteer, or you want to explore different career paths, we'll give you the resources that can set you up for success.
Enjoy generous time-away and health benefits from day one, with the opportunity for flexible work options
Receive 2-for-1 matching gifts for your charitable contributions and the opportunity to secure annual grants for the organizations you love
Access on-demand professional development resources that allow you to hone existing skills and learn new ones
"I can succeed as a Lead AI SecurityEngineer at Capital Group"
As aLeadAISecurity Engineer, you willbe responsible forsecuring Capital Group's enterprise AI Platforms.You willhelp enable Capital Group's AIstrategy bybuilding and/orprocuringsolutions toprotecta diverse set of enterprise AI platforms being built and deployed at Capital Group.You'llcollaborate with platformengineering, securityengineering, and risk teams toensure their solutions support scalable, secureadoption of AI.
Additionally,you'llbe expected toprovidementoring,advising diverse teams across the organization, andpromoting AI Securityprinciples across Capital Group.
AISecurityProcurementManagements:You willprocureand/or build technical solutionsto reducethe riskof misconfiguration, exploitation, andother security issues formultipleenterprise AI platforms.
Embedding Security in the AIPlatform Ecosystem:Working closely withplatform teams tointegrate securityintoeverycomponentof the AI Platform.
Implementing Security Controls & "Guardrails" for GenAI:Designing, deploying, andoperatingtechnical controls to prevent misuse of AI systems.Guardrails designincludescontent filtering systems, usage policies, and safety checks that mitigate issues like prompt injection attacks, unauthorized data extraction, model bias or hallucinations, and other misuse of generative AIplatforms.
AI Runtime Security:Engineer continually tests and updatestothe guardrails, replacing weaker controls with more robust solutions as threats evolve.
AI Governance:You will work cross functionally with architecture and platform teams tomonitoralignment of solutions to AI Governance processes
Contribute to Standards and Policies:You will providethought leadership for InformationSecurity policies and standards for AIin collaboration with technology risk
AI/Agent SME:Youwill provide AI/Agent subject matterexpertisefor AI Incidentsand Security Reviews, and helpdevelop incident response playbooks for AI-related security incidents
"I am the person Capital Group is looking for."
You have 8+yearsof experience in informationsecurity, application security, platform security, or penetration testing,DevSecOps, networksecurityand other security disciplines.
You have experience securing AI platforms, whetherinternal AIplatforms or offerings such as CoPilot Studio, Amazon Bedrock, and/or Azure AI Gateway
Proficient in Programming & ML Tool.Strong Python skillsrequired, with experience in AI/ML frameworks.Abilityto review and write ML code to implement security measures (e.g., model validation, adversarial testing) isdesired.
You have5+ years of relevant professional experience ordemonstrated anequivalent level ofexpertisein securityengineering, such as cloud, API, or platform security.
You have3+ years of experience embedded identity, network, and encryption controls into enterprise platforms
Youcaneffectively partner and collaborate with stakeholder teams.
You have effective communication skills andthe abilityto outline security riskstoleadership.
You are familiar with cloud and API security vendors and managed services providers.
Preferred Qualifications:
You have knowledge and experience with technologies including Kubernetes, Containers, CI/CD, and Cloud Service Providers
You are familiar withfunctionand purpose of key AI platform components such as AI gateways (Kong, Databricks Mosaic AI Gateway, custom API orchestration), Model Orchestration (ExamplesLangChain,LlamaIndex, etc.)
You are familiar with key AI regulatory frameworks such as NIST AI RMF, MITRE ATLAS, GDPR, EU AI Act,etc
You have informationSecurity certifications (CISSP, SANS GIAC, CISA, etc.)
"I can apply in less than 4 minutes."
You've reviewed this job posting and you're ready to start the candidate journey with us. Apply now to move to the next step in our recruiting process. If this role isn't what you're looking for, check out our other opportunities and join our talent community.
"I can learn more about Capital Group."
At Capital Group, the success of the people who invest with us depends on the people in whom we invest. That's why we offer a culture, compensation and opportunities that empower our associates to build successful and prosperous careers. Through nine decades, our goal has been to improve people's lives through successful investing. We know that our history is a testament to the strength of the people we hire. More than 9,000 associates in 30+ offices around the world help our clients and each other grow and thrive every day. Find us on LinkedIn, Instagram, YouTube and Glassdoor.
Southern California Base Salary Range: $179,273-$286,837San Antonio Base Salary Range: $147,378-$235,805New York Base Salary Range: $190,040-$304,064
In addition to a highly competitive base salary, per plan guidelines, restrictions and vesting requirements, you also will be eligible for an individual annual performance bonus, plus Capital's annual profitability bonus plus a retirement plan where Capital contributes 15% of your eligible earnings.
You can learn more about our compensation and benefits
here
.
* Temporary positions in the United States are excluded from the above mentioned compensation and benefit plans.
We are an equal opportunity employer, which means we comply with all federal, state and local laws that prohibit discrimination when making all decisions about employment. As equal opportunity employers, our policies prohibit unlawful discrimination on the basis of race, religion, color, national origin, ancestry, sex (including gender and gender identity), pregnancy, childbirth and related medical conditions, age, physical or mental disability, medical condition, genetic information, marital status, sexual orientation, citizenship status, AIDS/HIV status, political activities or affiliations, military or veteran status, status as a victim of domestic violence, assault or stalking or any other characteristic protected by federal, state or local law.
$190k-304.1k yearly 2d ago
Lead AI Security Engineer
Capital Group 4.4
New York, NY jobs
"I can be myself at work."
You are more than a job title. We want you to feel comfortable doing great work and bringing your best, authentic self to everything you do. We value your talents, traditions, and uniqueness-and we're committed to fostering a strong sense of belonging in a respectful workplace.
We intentionally seek diverse perspectives, experiences, and backgrounds, investing in a culture designed to celebrate differences. We believe that belonging leads to better outcomes and a stronger community of associates united by our mission. At Capital, we live our core values every day: Integrity, Client Focus, Diverse Perspectives, Long-Term Thinking, and Community.
"I can influence my income."
You want to feel recognized at work. Your performance will be reviewed annually, and your compensation will be designed to motivate and reward the value that you provide. You'll receive a competitive salary, bonuses and benefits. Your company-funded retirement contribution will factor in salary and variable pay, including bonuses.
"I can lead a full life."
You bring unique goals and interests to your job and your life. Whether you're raising a family, you're passionate about where you volunteer, or you want to explore different career paths, we'll give you the resources that can set you up for success.
Enjoy generous time-away and health benefits from day one, with the opportunity for flexible work options
Receive 2-for-1 matching gifts for your charitable contributions and the opportunity to secure annual grants for the organizations you love
Access on-demand professional development resources that allow you to hone existing skills and learn new ones
"I can succeed as a Lead AI SecurityEngineer at Capital Group"
As aLeadAISecurity Engineer, you willbe responsible forsecuring Capital Group's enterprise AI Platforms.You willhelp enable Capital Group's AIstrategy bybuilding and/orprocuringsolutions toprotecta diverse set of enterprise AI platforms being built and deployed at Capital Group.You'llcollaborate with platformengineering, securityengineering, and risk teams toensure their solutions support scalable, secureadoption of AI.
Additionally,you'llbe expected toprovidementoring,advising diverse teams across the organization, andpromoting AI Securityprinciples across Capital Group.
AISecurityProcurementManagements:You willprocureand/or build technical solutionsto reducethe riskof misconfiguration, exploitation, andother security issues formultipleenterprise AI platforms.
Embedding Security in the AIPlatform Ecosystem:Working closely withplatform teams tointegrate securityintoeverycomponentof the AI Platform.
Implementing Security Controls & "Guardrails" for GenAI:Designing, deploying, andoperatingtechnical controls to prevent misuse of AI systems.Guardrails designincludescontent filtering systems, usage policies, and safety checks that mitigate issues like prompt injection attacks, unauthorized data extraction, model bias or hallucinations, and other misuse of generative AIplatforms.
AI Runtime Security:Engineer continually tests and updatestothe guardrails, replacing weaker controls with more robust solutions as threats evolve.
AI Governance:You will work cross functionally with architecture and platform teams tomonitoralignment of solutions to AI Governance processes
Contribute to Standards and Policies:You will providethought leadership for InformationSecurity policies and standards for AIin collaboration with technology risk
AI/Agent SME:Youwill provide AI/Agent subject matterexpertisefor AI Incidentsand Security Reviews, and helpdevelop incident response playbooks for AI-related security incidents
"I am the person Capital Group is looking for."
You have 8+yearsof experience in informationsecurity, application security, platform security, or penetration testing,DevSecOps, networksecurityand other security disciplines.
You have experience securing AI platforms, whetherinternal AIplatforms or offerings such as CoPilot Studio, Amazon Bedrock, and/or Azure AI Gateway
Proficient in Programming & ML Tool.Strong Python skillsrequired, with experience in AI/ML frameworks.Abilityto review and write ML code to implement security measures (e.g., model validation, adversarial testing) isdesired.
You have5+ years of relevant professional experience ordemonstrated anequivalent level ofexpertisein securityengineering, such as cloud, API, or platform security.
You have3+ years of experience embedded identity, network, and encryption controls into enterprise platforms
Youcaneffectively partner and collaborate with stakeholder teams.
You have effective communication skills andthe abilityto outline security riskstoleadership.
You are familiar with cloud and API security vendors and managed services providers.
Preferred Qualifications:
You have knowledge and experience with technologies including Kubernetes, Containers, CI/CD, and Cloud Service Providers
You are familiar withfunctionand purpose of key AI platform components such as AI gateways (Kong, Databricks Mosaic AI Gateway, custom API orchestration), Model Orchestration (ExamplesLangChain,LlamaIndex, etc.)
You are familiar with key AI regulatory frameworks such as NIST AI RMF, MITRE ATLAS, GDPR, EU AI Act,etc
You have informationSecurity certifications (CISSP, SANS GIAC, CISA, etc.)
"I can apply in less than 4 minutes."
You've reviewed this job posting and you're ready to start the candidate journey with us. Apply now to move to the next step in our recruiting process. If this role isn't what you're looking for, check out our other opportunities and join our talent community.
"I can learn more about Capital Group."
At Capital Group, the success of the people who invest with us depends on the people in whom we invest. That's why we offer a culture, compensation and opportunities that empower our associates to build successful and prosperous careers. Through nine decades, our goal has been to improve people's lives through successful investing. We know that our history is a testament to the strength of the people we hire. More than 9,000 associates in 30+ offices around the world help our clients and each other grow and thrive every day. Find us on LinkedIn, Instagram, YouTube and Glassdoor.
Southern California Base Salary Range: $179,273-$286,837San Antonio Base Salary Range: $147,378-$235,805New York Base Salary Range: $190,040-$304,064
In addition to a highly competitive base salary, per plan guidelines, restrictions and vesting requirements, you also will be eligible for an individual annual performance bonus, plus Capital's annual profitability bonus plus a retirement plan where Capital contributes 15% of your eligible earnings.
You can learn more about our compensation and benefits
here
.
* Temporary positions in the United States are excluded from the above mentioned compensation and benefit plans.
We are an equal opportunity employer, which means we comply with all federal, state and local laws that prohibit discrimination when making all decisions about employment. As equal opportunity employers, our policies prohibit unlawful discrimination on the basis of race, religion, color, national origin, ancestry, sex (including gender and gender identity), pregnancy, childbirth and related medical conditions, age, physical or mental disability, medical condition, genetic information, marital status, sexual orientation, citizenship status, AIDS/HIV status, political activities or affiliations, military or veteran status, status as a victim of domestic violence, assault or stalking or any other characteristic protected by federal, state or local law.
$190k-304.1k yearly 2d ago
Lead AI Security Engineer
Capital Group 4.4
Los Angeles, CA jobs
"I can be myself at work."
You are more than a job title. We want you to feel comfortable doing great work and bringing your best, authentic self to everything you do. We value your talents, traditions, and uniqueness-and we're committed to fostering a strong sense of belonging in a respectful workplace.
We intentionally seek diverse perspectives, experiences, and backgrounds, investing in a culture designed to celebrate differences. We believe that belonging leads to better outcomes and a stronger community of associates united by our mission. At Capital, we live our core values every day: Integrity, Client Focus, Diverse Perspectives, Long-Term Thinking, and Community.
"I can influence my income."
You want to feel recognized at work. Your performance will be reviewed annually, and your compensation will be designed to motivate and reward the value that you provide. You'll receive a competitive salary, bonuses and benefits. Your company-funded retirement contribution will factor in salary and variable pay, including bonuses.
"I can lead a full life."
You bring unique goals and interests to your job and your life. Whether you're raising a family, you're passionate about where you volunteer, or you want to explore different career paths, we'll give you the resources that can set you up for success.
Enjoy generous time-away and health benefits from day one, with the opportunity for flexible work options
Receive 2-for-1 matching gifts for your charitable contributions and the opportunity to secure annual grants for the organizations you love
Access on-demand professional development resources that allow you to hone existing skills and learn new ones
"I can succeed as a Lead AI SecurityEngineer at Capital Group"
As aLeadAISecurity Engineer, you willbe responsible forsecuring Capital Group's enterprise AI Platforms.You willhelp enable Capital Group's AIstrategy bybuilding and/orprocuringsolutions toprotecta diverse set of enterprise AI platforms being built and deployed at Capital Group.You'llcollaborate with platformengineering, securityengineering, and risk teams toensure their solutions support scalable, secureadoption of AI.
Additionally,you'llbe expected toprovidementoring,advising diverse teams across the organization, andpromoting AI Securityprinciples across Capital Group.
AISecurityProcurementManagements:You willprocureand/or build technical solutionsto reducethe riskof misconfiguration, exploitation, andother security issues formultipleenterprise AI platforms.
Embedding Security in the AIPlatform Ecosystem:Working closely withplatform teams tointegrate securityintoeverycomponentof the AI Platform.
Implementing Security Controls & "Guardrails" for GenAI:Designing, deploying, andoperatingtechnical controls to prevent misuse of AI systems.Guardrails designincludescontent filtering systems, usage policies, and safety checks that mitigate issues like prompt injection attacks, unauthorized data extraction, model bias or hallucinations, and other misuse of generative AIplatforms.
AI Runtime Security:Engineer continually tests and updatestothe guardrails, replacing weaker controls with more robust solutions as threats evolve.
AI Governance:You will work cross functionally with architecture and platform teams tomonitoralignment of solutions to AI Governance processes
Contribute to Standards and Policies:You will providethought leadership for InformationSecurity policies and standards for AIin collaboration with technology risk
AI/Agent SME:Youwill provide AI/Agent subject matterexpertisefor AI Incidentsand Security Reviews, and helpdevelop incident response playbooks for AI-related security incidents
"I am the person Capital Group is looking for."
You have 8+yearsof experience in informationsecurity, application security, platform security, or penetration testing,DevSecOps, networksecurityand other security disciplines.
You have experience securing AI platforms, whetherinternal AIplatforms or offerings such as CoPilot Studio, Amazon Bedrock, and/or Azure AI Gateway
Proficient in Programming & ML Tool.Strong Python skillsrequired, with experience in AI/ML frameworks.Abilityto review and write ML code to implement security measures (e.g., model validation, adversarial testing) isdesired.
You have5+ years of relevant professional experience ordemonstrated anequivalent level ofexpertisein securityengineering, such as cloud, API, or platform security.
You have3+ years of experience embedded identity, network, and encryption controls into enterprise platforms
Youcaneffectively partner and collaborate with stakeholder teams.
You have effective communication skills andthe abilityto outline security riskstoleadership.
You are familiar with cloud and API security vendors and managed services providers.
Preferred Qualifications:
You have knowledge and experience with technologies including Kubernetes, Containers, CI/CD, and Cloud Service Providers
You are familiar withfunctionand purpose of key AI platform components such as AI gateways (Kong, Databricks Mosaic AI Gateway, custom API orchestration), Model Orchestration (ExamplesLangChain,LlamaIndex, etc.)
You are familiar with key AI regulatory frameworks such as NIST AI RMF, MITRE ATLAS, GDPR, EU AI Act,etc
You have informationSecurity certifications (CISSP, SANS GIAC, CISA, etc.)
"I can apply in less than 4 minutes."
You've reviewed this job posting and you're ready to start the candidate journey with us. Apply now to move to the next step in our recruiting process. If this role isn't what you're looking for, check out our other opportunities and join our talent community.
"I can learn more about Capital Group."
At Capital Group, the success of the people who invest with us depends on the people in whom we invest. That's why we offer a culture, compensation and opportunities that empower our associates to build successful and prosperous careers. Through nine decades, our goal has been to improve people's lives through successful investing. We know that our history is a testament to the strength of the people we hire. More than 9,000 associates in 30+ offices around the world help our clients and each other grow and thrive every day. Find us on LinkedIn, Instagram, YouTube and Glassdoor.
Southern California Base Salary Range: $179,273-$286,837San Antonio Base Salary Range: $147,378-$235,805New York Base Salary Range: $190,040-$304,064
In addition to a highly competitive base salary, per plan guidelines, restrictions and vesting requirements, you also will be eligible for an individual annual performance bonus, plus Capital's annual profitability bonus plus a retirement plan where Capital contributes 15% of your eligible earnings.
You can learn more about our compensation and benefits
here
.
* Temporary positions in the United States are excluded from the above mentioned compensation and benefit plans.
We are an equal opportunity employer, which means we comply with all federal, state and local laws that prohibit discrimination when making all decisions about employment. As equal opportunity employers, our policies prohibit unlawful discrimination on the basis of race, religion, color, national origin, ancestry, sex (including gender and gender identity), pregnancy, childbirth and related medical conditions, age, physical or mental disability, medical condition, genetic information, marital status, sexual orientation, citizenship status, AIDS/HIV status, political activities or affiliations, military or veteran status, status as a victim of domestic violence, assault or stalking or any other characteristic protected by federal, state or local law.
$190k-304.1k yearly 2d ago
Network and Security Engineer - VP
Natixis Corporate & Investment Banking 4.9
New York, NY jobs
Natixis CIB is seeking a dynamic and experienced Vice President of Network Security to lead and enhance our network security infrastructure across the AMER region. This strategic leadership role requires a deep technical understanding of network security and the ability to drive initiatives that protect our systems while mentoring a talented engineering team.
The job responsibilities include, but are not limited, to the following:
Infrastructure Oversight: Lead the design and administration of Natixis CIB AMER's network security infrastructure, focusing on critical components including DNS, F5 Load Balancers, Fortinet and Palo Alto firewalls, VPNs, proxies, Remote Access and DMZ connectivity.
Technology Initiatives: Drive technology projects aimed at enhancing cybersecurity and improving network performance in alignment with organizational goals.
Continuous Monitoring: Ensure optimal network performance through continuous monitoring, dashboard creation, promptly addressing any security incidents.
Documentation Management: Maintain comprehensive documentation, including network security asset inventories, diagrams, procedures and vendor contacts, to support operational efficiency and facilitate effective communication.
Cross-Department Collaboration: Collaborate with infrastructure teams to resolve network-related challenges and ensure seamless operations across departments.
Audit and Security Coordination: Work closely with audit and IT Security teams in both AMER and BPCE-IT to provide necessary documentation and implement remediation plans as required.
Staff Mentorship and Training: Mentor and train junior engineering staff, fostering a culture of growth and skill development within the network team.
Vulnerability Assessments: Conduct vulnerability assessments and manage patching processes to effectively mitigate and report security risks across the AMER region.
Security Reporting: Develop and deliver regular security reports to Leadership, highlighting key metrics, incidents, and trends to inform strategic decision-making.
LOD1 Security Management: Manage Line of Defense 1 (LOD1) network security controls and request as specified by the IT Risk Department.
Strategy Alignment: Coordinate with AMER and Head Office IT Security teams to assure alignment on security strategies and policies.
Tool Proficiency: Profiecent knowledge of security tools such as SIEM, Splunk, Centreon and Qualys for effective monitoring and incident response.
Bachelor's degree in computer science, Information Technology, Cybersecurity, or a related field; Master's preferred.
6+ years of hands-on experience in network security management, preferably within the financial services industry.
Extensive experience managing Cisco Firepower, Fortinet and Palo Alto firewalls, including DMZ design implementation.
Relevant certifications such as Fortinet NSE 4/5, Palo Alto Networks Certified Network SecurityEngineer (PCNSE), Cisco CCNP Enterprise and CCNP Security is a plus. Highly desirable CISSP, CISM.
Strong project management and leadership experience.
Excellent communication and problem-solving skills, with a focus on collaboration and teamwork.
Extensive understanding of network technologies - L2, L3, VXLAN, BGP, LAN/WAN/VPN
Extensive understanding of security technologies such as firewall, load balancing, proxy, authentication methods
Strong knowledge of DNS/DHCPWSG (Web Security Gateways), Proxy-pac scripting
Troubleshooting knowledge of network and security systems with minimal guidance is required.
OSI Layer 4 and Layer 7 protocol analysis and troubleshooting experience is required.
Excellent oral and written communication and documentation skills are essential.
Ideal candidate must have a strong understanding of Zero Trust Architecture and Network Access Control design for enterprise network infrastructure design, and troubleshooting.
Among these technologies, knowledge of Arista and Cisco design, configuration and automation is a definite plus
Knowledge of scripting languages such as Python, PoweShell, or Ansible.
The individual will need to be very organized, flexible, results oriented and able to multi-task to meet the demands of our dynamic environment
The candidate should be a self-starter, be able to work with minimal supervision, properly and effectively report project/work status to management and peers, take full ownership and responsibility of the tasks assigned to her/him and work them through completion.
The candidate should be able to demonstrate both technical capabilities and in-depth knowledge of various security and network concepts, technologies, and best practices
The candidate should have the ability to convey in non-technical terms complex technical explanations related to problems, designs, etc.
Knowledge of Ansible Scripting is a plus
Knowledge of micro segmentation tools such as Illumio or VM Ware NSX is a plus
Natixis is an equal opportunity employer, committed to a workplace free of discrimination. Natixis will not tolerate any form of discrimination based on age, color, mental or physical handicap or disability, pregnancy, marital status, sexual orientation, national origin, alienage, ancestry or citizenship status, race, religion, sex (including sex stereotyping, gender identity, gender expression or transgender status), veteran status, creed, genetic information or carrier status, or any other protected characteristic as established by law.
Respect for all means that we deal with each person as an individual and not as a member of any group. All qualified applicants will receive consideration for employment. Management is expected to provide leadership in supporting the firms EEO program by taking steps to promote EEO in all facets of employment including recruitment, hiring, retention, promotion, performance assessment, and career-development opportunities.
The salary range for the VP position will be between $150,000 - $180,000. Natixis is required by law to include a reasonable estimate of the compensation range for this role. Actual base salary will vary and will be based on several factors including, but not limited to, relevant experience, education, skills set, applicable licensure and certifications, and other business and organizational needs. Base salary is only one component of our total rewards package. Natixis also offers a generous benefits package, and you may be eligible for a discretionary incentive award depending on company and individual performance.
$150k-180k yearly 2d ago
Prin Security Analyst
Compeer Financial 4.1
Lakeville, MN jobs
Empowered to live. Inspired to work. Compeer Financial is a member-owned cooperative located in Illinois, Minnesota and Wisconsin. We bring together team members with a variety of backgrounds and experiences to help provide financial services to support agriculture and rural communities. Join us in a culture that not only promotes meaningful work and professional development, but provides a flexible, hybrid work environment and excellent benefits, which empower you to thrive both personally and professionally.
How we support you:
Hybrid model - up to 50% work from home
Flexible schedules including ample flexibility in the summer months
Up to 9% towards 401k (3% fixed Compeer contribution plus up to 6% match)
Benefits: medical, dental, vision, HSA/FSA, life & AD&D insurance, short-term and long-term disability, wellness program & EAP
Vacation, sick leave, holidays/floating holidays, parental leave, and volunteer paid time off
Learning and development programs
Mentorship programs
Cross-functional committee opportunities (i.e. Inclusion Council, emerging professional groups, etc.)
Professional membership/certification reimbursement and more!
Casual/seasonal & intern team members are not eligible for benefits except for state-mandated programs.
To learn more about Compeer Financial visit************************
Where you will work: This position offers a hybrid work option up to 50% remote and is based out of any of Compeer's office locations.
The contributions you will make:
This position creates, implements and maintains corporate-wide security programs that assist in improving overall security posture of the organization. Provides guidance, assurance and information protection to maintain the confidentiality, integrity, and availability of Compeer critical resources. Contributes knowledge and expertise to ensure that information assets are protected and secure. In this position, you will guide solutions to promote secure business-to-business initiatives, third-part relationships, outsourced solutions and vendors. Provides mentorship and guidance to less experienced team members.
A typical day:
Remains current with new security threats and assess systems and solutions to ensure they can defend the business.
Researches capabilities of current and new disruptive solutions on the market and makes recommendations to security group on a consistent basis.
Develops security team standards, policies, procedures and processes.
Support and provide direction for use of technical systems, monitors for unusual and suspicious activity across a wide range of products, data centers, and cloud systems.
Partners with Business Technology on security configuration standards for systems and business applications.
Participates in technical and non-technical projects requiring informationsecurity oversight and to ensure policies and procedures are met.
Provides cybersecurity guidance to leadership.
Ensures that cybersecurity-enabled products or other compensating security control technologies or processes reduce identified risk to an acceptable level.
Performs security reviews, identifies gaps in security architecture, and develops a security risk management plan.
Implements security measures to resolve vulnerabilities, mitigate risks, and recommend security changes to system or system components as needed.
Analyzes and reports system security posture trends.
Analyzes cyber defense policies and configurations and evaluates compliance with regulations and organizational directives.
Prepares audit reports that identify technical and procedural findings and provide recommended remediation strategies/solutions.
Leads the Incident Response Team during activations for security or operational events.
Coordinates, leads and conducts adversary simulation, hunt teaming, assumed breaches and whitebox penetration tests. Develops and executes attack plans, scripts, tools and methodologies to strengthen the offensive operations.
Plans and coordinates the delivery of classroom techniques and formats (e.g., lectures, demonstrations, interactive exercises, and multimedia presentations) for the most effective learning environment.
The skills and experience we prefer you have:
Bachelor's degree in security management, cybersecurity, computer science, management information systems, or business with technical training in networking, technical support or security or an equivalent combination of education and experience sufficient to perform the essential functions of the job.
Expert-level experience in physical asset security, information technology, risk management, security services, or infrastructure technology.
CISSP certification preferred.
Ability to adapt and stay a step ahead of cyber attackers and stay up to date on the latest attack methods.
Expert experience driving measurable improvement in monitoring and response capabilities at scale.
Expert ability to identify and resolve problems, utilizing strong analytical skills.
Advanced experience in cloud computing technologies, including software, infrastructure and platform-as-a-service, as well as public, private and hybrid environments.
Expert knowledge of traditional security controls and technologies, such as SecurityInformation and Event Management (SIEM) systems, intrusion detection/prevention systems (IDS/IPS), public key infrastructure (PKI), identity and access management (IDAM) systems, antivirus and firewalls, in addition to endpoint detection and response (EDR), threat intelligence platforms, data loss prevention (DLP), security automation and orchestration, deception technologies, application controls, and other network and system monitoring tools.
Experience with purple teaming (red and blue) to train, identify and remediate issues cohesively.
Advanced experience with Amazon Web Services (AWS) or Microsoft Azure.
Expert experience conducting risk analysis to protect the business and adhere with compliance requirements and privacy laws.
Expert experience with vulnerability and penetration testing engagements.
Advanced knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
Expert knowledge of what constitutes a network attack and a network attack's relationship to both threats and vulnerabilities.
Knowledge of multiple cognitive domains and tools and methods applicable for learning in each domain.
Knowledge of media production, communication, and dissemination techniques and methods, including alternative ways to inform via written, oral, and visual media.
Knowledge of training and education principles and methods for curriculum design, teaching and instruction for individuals and groups, and the measurement of training and education effects.
How we will take care of you:
Our job titles may span more than one career level (associate, senior, principal, etc.). The actual title and base pay offered is dependent upon many factors, such as: training, transferable skills, work experience, business needs and market demands. The base pay range is subject to change and may be modified in the future. This role is eligible for variable compensation and other benefits.
Base Pay$103,100-$156,400 USD
Compeer Financial is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law.
Must be authorized to work for any employer in the United States. Compeer is unable to sponsor or take over sponsorship of an employment visa at this time.
Click here to view federal employment laws applicable for applicants.
$103.1k-156.4k yearly 2d ago
Prin Security Analyst
Compeer Financial 4.1
Sun Prairie, WI jobs
Empowered to live. Inspired to work. Compeer Financial is a member-owned cooperative located in Illinois, Minnesota and Wisconsin. We bring together team members with a variety of backgrounds and experiences to help provide financial services to support agriculture and rural communities. Join us in a culture that not only promotes meaningful work and professional development, but provides a flexible, hybrid work environment and excellent benefits, which empower you to thrive both personally and professionally.
How we support you:
Hybrid model - up to 50% work from home
Flexible schedules including ample flexibility in the summer months
Up to 9% towards 401k (3% fixed Compeer contribution plus up to 6% match)
Benefits: medical, dental, vision, HSA/FSA, life & AD&D insurance, short-term and long-term disability, wellness program & EAP
Vacation, sick leave, holidays/floating holidays, parental leave, and volunteer paid time off
Learning and development programs
Mentorship programs
Cross-functional committee opportunities (i.e. Inclusion Council, emerging professional groups, etc.)
Professional membership/certification reimbursement and more!
Casual/seasonal & intern team members are not eligible for benefits except for state-mandated programs.
To learn more about Compeer Financial visit************************
Where you will work: This position offers a hybrid work option up to 50% remote and is based out of any of Compeer's office locations.
The contributions you will make:
This position creates, implements and maintains corporate-wide security programs that assist in improving overall security posture of the organization. Provides guidance, assurance and information protection to maintain the confidentiality, integrity, and availability of Compeer critical resources. Contributes knowledge and expertise to ensure that information assets are protected and secure. In this position, you will guide solutions to promote secure business-to-business initiatives, third-part relationships, outsourced solutions and vendors. Provides mentorship and guidance to less experienced team members.
A typical day:
Remains current with new security threats and assess systems and solutions to ensure they can defend the business.
Researches capabilities of current and new disruptive solutions on the market and makes recommendations to security group on a consistent basis.
Develops security team standards, policies, procedures and processes.
Support and provide direction for use of technical systems, monitors for unusual and suspicious activity across a wide range of products, data centers, and cloud systems.
Partners with Business Technology on security configuration standards for systems and business applications.
Participates in technical and non-technical projects requiring informationsecurity oversight and to ensure policies and procedures are met.
Provides cybersecurity guidance to leadership.
Ensures that cybersecurity-enabled products or other compensating security control technologies or processes reduce identified risk to an acceptable level.
Performs security reviews, identifies gaps in security architecture, and develops a security risk management plan.
Implements security measures to resolve vulnerabilities, mitigate risks, and recommend security changes to system or system components as needed.
Analyzes and reports system security posture trends.
Analyzes cyber defense policies and configurations and evaluates compliance with regulations and organizational directives.
Prepares audit reports that identify technical and procedural findings and provide recommended remediation strategies/solutions.
Leads the Incident Response Team during activations for security or operational events.
Coordinates, leads and conducts adversary simulation, hunt teaming, assumed breaches and whitebox penetration tests. Develops and executes attack plans, scripts, tools and methodologies to strengthen the offensive operations.
Plans and coordinates the delivery of classroom techniques and formats (e.g., lectures, demonstrations, interactive exercises, and multimedia presentations) for the most effective learning environment.
The skills and experience we prefer you have:
Bachelor's degree in security management, cybersecurity, computer science, management information systems, or business with technical training in networking, technical support or security or an equivalent combination of education and experience sufficient to perform the essential functions of the job.
Expert-level experience in physical asset security, information technology, risk management, security services, or infrastructure technology.
CISSP certification preferred.
Ability to adapt and stay a step ahead of cyber attackers and stay up to date on the latest attack methods.
Expert experience driving measurable improvement in monitoring and response capabilities at scale.
Expert ability to identify and resolve problems, utilizing strong analytical skills.
Advanced experience in cloud computing technologies, including software, infrastructure and platform-as-a-service, as well as public, private and hybrid environments.
Expert knowledge of traditional security controls and technologies, such as SecurityInformation and Event Management (SIEM) systems, intrusion detection/prevention systems (IDS/IPS), public key infrastructure (PKI), identity and access management (IDAM) systems, antivirus and firewalls, in addition to endpoint detection and response (EDR), threat intelligence platforms, data loss prevention (DLP), security automation and orchestration, deception technologies, application controls, and other network and system monitoring tools.
Experience with purple teaming (red and blue) to train, identify and remediate issues cohesively.
Advanced experience with Amazon Web Services (AWS) or Microsoft Azure.
Expert experience conducting risk analysis to protect the business and adhere with compliance requirements and privacy laws.
Expert experience with vulnerability and penetration testing engagements.
Advanced knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
Expert knowledge of what constitutes a network attack and a network attack's relationship to both threats and vulnerabilities.
Knowledge of multiple cognitive domains and tools and methods applicable for learning in each domain.
Knowledge of media production, communication, and dissemination techniques and methods, including alternative ways to inform via written, oral, and visual media.
Knowledge of training and education principles and methods for curriculum design, teaching and instruction for individuals and groups, and the measurement of training and education effects.
How we will take care of you:
Our job titles may span more than one career level (associate, senior, principal, etc.). The actual title and base pay offered is dependent upon many factors, such as: training, transferable skills, work experience, business needs and market demands. The base pay range is subject to change and may be modified in the future. This role is eligible for variable compensation and other benefits.
Base Pay$103,100-$156,400 USD
Compeer Financial is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law.
Must be authorized to work for any employer in the United States. Compeer is unable to sponsor or take over sponsorship of an employment visa at this time.
Click here to view federal employment laws applicable for applicants.
$103.1k-156.4k yearly 2d ago
Prin Security Analyst
Compeer Financial 4.1
Mankato, MN jobs
Empowered to live. Inspired to work. Compeer Financial is a member-owned cooperative located in Illinois, Minnesota and Wisconsin. We bring together team members with a variety of backgrounds and experiences to help provide financial services to support agriculture and rural communities. Join us in a culture that not only promotes meaningful work and professional development, but provides a flexible, hybrid work environment and excellent benefits, which empower you to thrive both personally and professionally.
How we support you:
Hybrid model - up to 50% work from home
Flexible schedules including ample flexibility in the summer months
Up to 9% towards 401k (3% fixed Compeer contribution plus up to 6% match)
Benefits: medical, dental, vision, HSA/FSA, life & AD&D insurance, short-term and long-term disability, wellness program & EAP
Vacation, sick leave, holidays/floating holidays, parental leave, and volunteer paid time off
Learning and development programs
Mentorship programs
Cross-functional committee opportunities (i.e. Inclusion Council, emerging professional groups, etc.)
Professional membership/certification reimbursement and more!
Casual/seasonal & intern team members are not eligible for benefits except for state-mandated programs.
To learn more about Compeer Financial visit************************
Where you will work: This position offers a hybrid work option up to 50% remote and is based out of any of Compeer's office locations.
The contributions you will make:
This position creates, implements and maintains corporate-wide security programs that assist in improving overall security posture of the organization. Provides guidance, assurance and information protection to maintain the confidentiality, integrity, and availability of Compeer critical resources. Contributes knowledge and expertise to ensure that information assets are protected and secure. In this position, you will guide solutions to promote secure business-to-business initiatives, third-part relationships, outsourced solutions and vendors. Provides mentorship and guidance to less experienced team members.
A typical day:
Remains current with new security threats and assess systems and solutions to ensure they can defend the business.
Researches capabilities of current and new disruptive solutions on the market and makes recommendations to security group on a consistent basis.
Develops security team standards, policies, procedures and processes.
Support and provide direction for use of technical systems, monitors for unusual and suspicious activity across a wide range of products, data centers, and cloud systems.
Partners with Business Technology on security configuration standards for systems and business applications.
Participates in technical and non-technical projects requiring informationsecurity oversight and to ensure policies and procedures are met.
Provides cybersecurity guidance to leadership.
Ensures that cybersecurity-enabled products or other compensating security control technologies or processes reduce identified risk to an acceptable level.
Performs security reviews, identifies gaps in security architecture, and develops a security risk management plan.
Implements security measures to resolve vulnerabilities, mitigate risks, and recommend security changes to system or system components as needed.
Analyzes and reports system security posture trends.
Analyzes cyber defense policies and configurations and evaluates compliance with regulations and organizational directives.
Prepares audit reports that identify technical and procedural findings and provide recommended remediation strategies/solutions.
Leads the Incident Response Team during activations for security or operational events.
Coordinates, leads and conducts adversary simulation, hunt teaming, assumed breaches and whitebox penetration tests. Develops and executes attack plans, scripts, tools and methodologies to strengthen the offensive operations.
Plans and coordinates the delivery of classroom techniques and formats (e.g., lectures, demonstrations, interactive exercises, and multimedia presentations) for the most effective learning environment.
The skills and experience we prefer you have:
Bachelor's degree in security management, cybersecurity, computer science, management information systems, or business with technical training in networking, technical support or security or an equivalent combination of education and experience sufficient to perform the essential functions of the job.
Expert-level experience in physical asset security, information technology, risk management, security services, or infrastructure technology.
CISSP certification preferred.
Ability to adapt and stay a step ahead of cyber attackers and stay up to date on the latest attack methods.
Expert experience driving measurable improvement in monitoring and response capabilities at scale.
Expert ability to identify and resolve problems, utilizing strong analytical skills.
Advanced experience in cloud computing technologies, including software, infrastructure and platform-as-a-service, as well as public, private and hybrid environments.
Expert knowledge of traditional security controls and technologies, such as SecurityInformation and Event Management (SIEM) systems, intrusion detection/prevention systems (IDS/IPS), public key infrastructure (PKI), identity and access management (IDAM) systems, antivirus and firewalls, in addition to endpoint detection and response (EDR), threat intelligence platforms, data loss prevention (DLP), security automation and orchestration, deception technologies, application controls, and other network and system monitoring tools.
Experience with purple teaming (red and blue) to train, identify and remediate issues cohesively.
Advanced experience with Amazon Web Services (AWS) or Microsoft Azure.
Expert experience conducting risk analysis to protect the business and adhere with compliance requirements and privacy laws.
Expert experience with vulnerability and penetration testing engagements.
Advanced knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
Expert knowledge of what constitutes a network attack and a network attack's relationship to both threats and vulnerabilities.
Knowledge of multiple cognitive domains and tools and methods applicable for learning in each domain.
Knowledge of media production, communication, and dissemination techniques and methods, including alternative ways to inform via written, oral, and visual media.
Knowledge of training and education principles and methods for curriculum design, teaching and instruction for individuals and groups, and the measurement of training and education effects.
How we will take care of you:
Our job titles may span more than one career level (associate, senior, principal, etc.). The actual title and base pay offered is dependent upon many factors, such as: training, transferable skills, work experience, business needs and market demands. The base pay range is subject to change and may be modified in the future. This role is eligible for variable compensation and other benefits.
Base Pay$103,100-$156,400 USD
Compeer Financial is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law.
Must be authorized to work for any employer in the United States. Compeer is unable to sponsor or take over sponsorship of an employment visa at this time.
Click here to view federal employment laws applicable for applicants.
$103.1k-156.4k yearly 2d ago
System Security Analyst
American National Bank of Texas 3.7
Plano, TX jobs
A System Security Analyst analyzes and implements system(s) security measures to protect sensitive data and infrastructure.
Implement and maintain security software like firewalls, encryption programs, and intrusion detection systems
Identify vulnerabilities in systems and networks, conduct penetration testing, and recommend mitigation strategies
Work closely with the systems team and Info Sec team to implement and enforce security policies and procedures, ensuring compliance with industry standards
Stay informed about the latest IT security trends and threats, and research new security solutions
Verify the security of third-party vendors and collaboration to meet security requirements
Technical knowledge of enterprise-class technologies such as cloud (AWS and Azure), firewalls, routers, switches, wireless access points, VPNs, and desktop and server operating systems
Thorough understanding of Microsoft's enterprise technology platform, including Azure, Active Directory, SQL, Office 365, and the Windows server and desktop operating systems, patching and vulnerabilities analysis
Hands-on experience with the following technology vendors and products: CyberArk, Okta, CyberReason, Splunk, Vulnerability Scanners
Qualifications:
Bachelor's degree or equivalent with certifications related to InformationSecurity e.g. CISA, CISSP,
5-7 years of relevant experience
Preferred: Technical knowledge of enterprise-class technologies such as cloud (AWS and Azure), firewalls, routers, switches, wireless access points, VPNs, and desktop and server operating systems. Thorough understanding of Microsoft's enterprise technology platform, including Azure, Active Directory, SQL, Office 365, and the Windows server and desktop operating systems patching and vulnerabilities analysis
Skills:
CyberSecurity trends and latest threats and ethical hacker training
Working knowledge of Microsoft Excel and MS Word; basic keyboarding and calculator skills, must be able to do simple math and carry out written instructions
Travel to a variety of locations to perform work and/or attend meetings as required
Work occasionally requires more than 40 hours per week to perform the essential functions of the position
Lifting in an office setting may be required up to 30lbs.
ANBTX strongly encourages candidates that are fluent in English and Spanish to apply. Jobs that specifically require candidates to be bilingual will be posted as a requirement.
Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.
$78k-107k yearly est. 2d ago
Information Security Specialist
Federal Reserve Bank of Kansas City 4.7
Kansas City, MO jobs
CompanyFederal Reserve Bank of Kansas CityWhen you join the Federal Reserve-the nation's central bank-you'll play a key role, collaborating with leading tech professionals to strengthen and protect our economic, financial and payments systems. We invest in contemporary and emerging technology each year to support the Federal Reserve and our economy, and we're building a dynamic and diverse team for our future.
Important Information
Open to US citizens, Green Card holders or Permanent Residents with at least 3 years of residency, with the intent to become a US citizen.
No sponsorship is available. Candidates must have valid work authorization, without an end date, to be considered.
This position requires working on-site, in Kansas City, Denver, Oklahoma City, or Omaha, with 5 days per month remote work flexibility.
This position is not eligible to be remote and relocation assistance is not available.
We are seeking cybersecurity professionals to join our InformationSecurity team as a security specialist focused on operating our DevSecOps program according to standards and policies.
This will be done through close partnership with peers in FRB Kansas City and other Reserve Banks across the System. It will also require healthy relationship building and tight integration with development teams. Additionally, you'll partner with business areas, vendors, and our diverse network of professionals to identify, implement, and support security across the organization.
Candidates with strong understanding and experience in cloud environment deployments, informationsecurity, data management, low-code and no-code solutions, DevSecOps, and artificial intelligence will be ideal.
Key Activities
Interpret and evaluate policies in order to mature and implement the DevSecOps program.
Assess maturity of development teams' DevSecOps practices against an existing framework.
Proactively advocate for and drive enhancements into the program.
Identify gaps/opportunities for enhancements to workflows and processes for enhancing the software development lifecycle (SDLC).
Implement and consults on secure continuous integration and continuous delivery (CI/CD) pipelines, evaluating code and/or applications, or creating code to facilitate the process.
Monitors informationsecurity policy compliance using security tooling.
Evaluate and implement security products and/or processes to enhance productivity and effectiveness for various platforms and initiatives.
Provide technical expertise and support to internal teams on security-related matters.
Collaborate with cross-functional teams to integrate security measures into existing software applications and infrastructure.
Stay current with emerging technologies, industry trends, and best practices in cybersecurity to enhance our security posture.
Support leadership decision making through timely analysis and written communications.
Qualifications
Typically requires 3-6 years of relevant experience.
Bachelor's Degree in Technology, Engineering, Computer Science, Information Systems, Cybersecurity or other related field or equivalent work experience.
Strong competence in cloud technologies such as AWS, Azure, and other platforms.
Expert understanding of DevSecOps practices, frameworks, and tools.
Expertise with tool integration for the DevOps pipeline such as Git.
Combines and organizes information into meaningful patterns; identifies underlying relationships, causes and effects; and combines pieces of information to form conclusions or general rules.
Rapidly acquires new knowledge and learns new skills, and practices agile methodologies to planning and accomplishing work.
Conveys complex and technical issues to diverse audiences.
Demonstrated competencies with artificial intelligence are beneficial.
Working knowledge of Terraform, Ansible, Cloud Formations, AWS Config, AWS Inspector, Guard Duty and others.
Strong knowledge of software development languages, tools and techniques such as Python, JSON, YAML, and Java
Technical expertise in security tools and knowledge of security practices and procedures.
A learning mindset, proactiveness, collaboration, and strong attention to detail.
Additional Information
How We Work (HWW):
On-site: 5 days per month remote work flexibility
Locations: Kansas City, Denver, Oklahoma City, Omaha
Remote Eligible: No
Relocation Assistance: No
Salary:
$79,100 - $111,500 / Experienced Level
$98,600 - $139,000 / Senior Level
Final offers are determined by factors including the candidate's qualifications, internal alignment considerations, district assignment, and geographic location.
Screening: US citizens, permanent residents with the intent to become a US citizen with at least three or more years of United States residency from the date of legal entry to the United States is required for this position.This position has additional screening requirements due to the information accessed while performing the job. These additional screenings would be initiated at the time of offer acceptance and can take up to a couple of months to be completed. You can begin work before the screening is completed; however, continued employment is contingent on acceptable screening results. The areas screened may include education/employment verification, criminal history, credit history, and reference checks.
Sponsorship: The Federal Reserve Bank of Kansas City will not sponsor a new applicant for employment authorization for this position. Applicants must be currently authorized to work in the United States without the need for visa sponsorship now or in the future.
About Us
Total Rewards & Benefits
Who We Are
What We Do
Follow us on
LinkedIn
, Instagram,
X (formerly Twitter)
, and
YouTube
#KCFedIT
Full Time / Part TimeFull time Regular / TemporaryRegularJob Exempt (Yes / No) YesJob CategoryInformation Technology Family GroupWork ShiftFirst (United States of America)
The Federal Reserve Banks are committed to equal employment opportunity for employees and job applicants in compliance with applicable law and to an environment where employees are valued for their differences.
Always verify and apply to jobs on Federal Reserve System Careers (FRS) or through verified Federal Reserve Bank social media channels.
Privacy Notice
$98.6k-139k yearly 2d ago
Security Engineer
ITC Federal, Inc. 4.7
Rockville, MD jobs
ID 2026-1478 Remote No
JOB TITLE: Senior SecurityEngineer
POSITION INFORMATION: Full-Time Position
POSITION TIMING: Employment is contingent upon obtaining a Public Trust clearance prior to start; processing typically takes 2-3 months.
BENEFITS: Health, Dental and Vision, 401(k), Flexible Spending Account (FSA), 11 Paid Federal Holidays, PTO, education reimbursement
ITC Federal is an information technology and consulting company focused on servicing the needs of the Federal Government. ITC's mission is to apply earned expertise in information technology and information assurance/security to assist this client in achieving its mission. ITC is located in Fairfax, VA and offers outstanding compensation and benefits plan and a challenging and rewarding professional work environment.
Responsibilities
RESPONSIBILITIES:
Develop and implement internal System Security Plan (SSP) and Security Assessment Plan (SAP)
Evaluate the effectiveness of security controls, and develop findings and remediation recommendations i.e. Plan of Action and Milestones (POA&Ms)
Develop and implement security and compliance audit logging and monitoring
Implement and maintain security compliance and security monitoring technologies
Monitor security events and respond and/or coordinate response and mitigation efforts
Perform system architecture security risk and waiver assessments and propose mitigation plans
Perform Security Impact Assessment (SIA) for proposed system change requests
Perform vulnerability assessment and vulnerability remediation/mitigation research
Monitor patch and security advisories releases and review and develop deployment plans
Develop and implement security policy, processes, procedures, and guidance documentation
Provide security guidance to drive infrastructure decisions in collaboration with other technical and management stakeholders to ensure security policies and principles are being upheld
Engage in ongoing research of new and emerging security technologies that may benefit the security posture of strategic goals
Work closely with senior management, systems operations staff, software development staff, support staff, 3
rd
parties and end-users to ensure rapid resolution of security issues.
Support others in analyzing and resolving difficult technical problems.
Conduct in-depth technical reviews of new and existing IT systems in order to identify the appropriate mitigation strategies required to bring these systems into compliance with established NIST policy and industry guidelines.
Performs other security related duties as required.
Qualifications
REQUIRED KNOWLEDGE, SKILLS AND ABILITIES:
Bachelor of Science in Computer Engineering / Computer Science with 4-7 years' experience.
3+ years of experience system architecture design with experience providing security integration.
2+ years of experience working with virtualization technologies.
1+ year of working with cloud services and/or collaboration with cloud service providers.
One or more of the following certification: MCSA/MCSE, CCNA Security, GSEC, GCIA, GCIH, CISA, CISM, CCSP, CAP and/or CISSP.
In-depth understanding of access control, authentication and authorization, security auditing, and security configuration technologies.
In-depth understanding of standard Internet protocols (i.e., FTP, HTTP, DNS, DHCP, RADIUS, SNMP, and SMTP).
In-depth understanding of security and compliance best practices and standard (i.e., FISMA, FedRAMP, CIS Benchmarks, DoD STIGs, SCAP, NIST SP800-53/39/37, ISO 27001/27002).
Recent hands-on experience or familiarity implementing IT security equipment (Governance Risk and Compliance Tools, Firewalls, Intrusion Detection Systems, Vulnerability Scanners, Virtual Private Networking, virus protection technologies, and Log Management solutions, SecurityInformation and Event Management Solutions).
Familiarity or experience with the following types of appliances/ tools a plus: Tenable Security Center/ Nessus, Web Inspect, LogRythm, BigFix, SentinelOne, Active Directory, Palo Alto Firewall, Juniper SRX Firewall, Cisco, Global Protect.
Ability to perform risk assessments and build risk mitigation plans.
Strong organization, written and oral communication skills.
Strong ability to function independently or as a part of a large, integrated cross-functional team.
Intellectual curiosity and a willingness to learn new things
Experience working in a dynamic lab environment preferred
Experience with FISMA Compliance/ NIST Risk Management Framework (RMF) contracts preferred
WORK ENVIRONMENT AND PHYSICAL DEMANDS: Candidate must be able to function in general office environment.
ITC Federal is an equal opportunity employer and will not discriminate against any application for employment on the basis of age, race, color, gender, national origin, religion, creed, disability, veteran status, marital status, sexual orientation, genetic information, military status, disability, or sex including pregnancy and childbirth or related medical condition or on any other basis prohibited by law.
$98k-137k yearly est. 2d ago
Information Security Specialist
Federal Reserve Bank of Kansas City 4.7
Denver, CO jobs
CompanyFederal Reserve Bank of Kansas CityWhen you join the Federal Reserve-the nation's central bank-you'll play a key role, collaborating with leading tech professionals to strengthen and protect our economic, financial and payments systems. We invest in contemporary and emerging technology each year to support the Federal Reserve and our economy, and we're building a dynamic and diverse team for our future.
Important Information
Open to US citizens, Green Card holders or Permanent Residents with at least 3 years of residency, with the intent to become a US citizen.
No sponsorship is available. Candidates must have valid work authorization, without an end date, to be considered.
This position requires working on-site, in Kansas City, Denver, Oklahoma City, or Omaha, with 5 days per month remote work flexibility.
This position is not eligible to be remote and relocation assistance is not available.
We are seeking cybersecurity professionals to join our InformationSecurity team as a security specialist focused on operating our DevSecOps program according to standards and policies.
This will be done through close partnership with peers in FRB Kansas City and other Reserve Banks across the System. It will also require healthy relationship building and tight integration with development teams. Additionally, you'll partner with business areas, vendors, and our diverse network of professionals to identify, implement, and support security across the organization.
Candidates with strong understanding and experience in cloud environment deployments, informationsecurity, data management, low-code and no-code solutions, DevSecOps, and artificial intelligence will be ideal.
Key Activities
Interpret and evaluate policies in order to mature and implement the DevSecOps program.
Assess maturity of development teams' DevSecOps practices against an existing framework.
Proactively advocate for and drive enhancements into the program.
Identify gaps/opportunities for enhancements to workflows and processes for enhancing the software development lifecycle (SDLC).
Implement and consults on secure continuous integration and continuous delivery (CI/CD) pipelines, evaluating code and/or applications, or creating code to facilitate the process.
Monitors informationsecurity policy compliance using security tooling.
Evaluate and implement security products and/or processes to enhance productivity and effectiveness for various platforms and initiatives.
Provide technical expertise and support to internal teams on security-related matters.
Collaborate with cross-functional teams to integrate security measures into existing software applications and infrastructure.
Stay current with emerging technologies, industry trends, and best practices in cybersecurity to enhance our security posture.
Support leadership decision making through timely analysis and written communications.
Qualifications
Typically requires 3-6 years of relevant experience.
Bachelor's Degree in Technology, Engineering, Computer Science, Information Systems, Cybersecurity or other related field or equivalent work experience.
Strong competence in cloud technologies such as AWS, Azure, and other platforms.
Expert understanding of DevSecOps practices, frameworks, and tools.
Expertise with tool integration for the DevOps pipeline such as Git.
Combines and organizes information into meaningful patterns; identifies underlying relationships, causes and effects; and combines pieces of information to form conclusions or general rules.
Rapidly acquires new knowledge and learns new skills, and practices agile methodologies to planning and accomplishing work.
Conveys complex and technical issues to diverse audiences.
Demonstrated competencies with artificial intelligence are beneficial.
Working knowledge of Terraform, Ansible, Cloud Formations, AWS Config, AWS Inspector, Guard Duty and others.
Strong knowledge of software development languages, tools and techniques such as Python, JSON, YAML, and Java
Technical expertise in security tools and knowledge of security practices and procedures.
A learning mindset, proactiveness, collaboration, and strong attention to detail.
Additional Information
How We Work (HWW):
On-site: 5 days per month remote work flexibility
Locations: Kansas City, Denver, Oklahoma City, Omaha
Remote Eligible: No
Relocation Assistance: No
Salary:
$79,100 - $111,500 / Experienced Level
$98,600 - $139,000 / Senior Level
Final offers are determined by factors including the candidate's qualifications, internal alignment considerations, district assignment, and geographic location.
Screening: US citizens, permanent residents with the intent to become a US citizen with at least three or more years of United States residency from the date of legal entry to the United States is required for this position.This position has additional screening requirements due to the information accessed while performing the job. These additional screenings would be initiated at the time of offer acceptance and can take up to a couple of months to be completed. You can begin work before the screening is completed; however, continued employment is contingent on acceptable screening results. The areas screened may include education/employment verification, criminal history, credit history, and reference checks.
Sponsorship: The Federal Reserve Bank of Kansas City will not sponsor a new applicant for employment authorization for this position. Applicants must be currently authorized to work in the United States without the need for visa sponsorship now or in the future.
About Us
Total Rewards & Benefits
Who We Are
What We Do
Follow us on
LinkedIn
, Instagram,
X (formerly Twitter)
, and
YouTube
#KCFedIT
Full Time / Part TimeFull time Regular / TemporaryRegularJob Exempt (Yes / No) YesJob CategoryInformation Technology Family GroupWork ShiftFirst (United States of America)
The Federal Reserve Banks are committed to equal employment opportunity for employees and job applicants in compliance with applicable law and to an environment where employees are valued for their differences.
Always verify and apply to jobs on Federal Reserve System Careers (FRS) or through verified Federal Reserve Bank social media channels.
Privacy Notice
$98.6k-139k yearly 2d ago
Information Security Specialist
Federal Reserve Bank of Kansas City 4.7
Omaha, NE jobs
CompanyFederal Reserve Bank of Kansas CityWhen you join the Federal Reserve-the nation's central bank-you'll play a key role, collaborating with leading tech professionals to strengthen and protect our economic, financial and payments systems. We invest in contemporary and emerging technology each year to support the Federal Reserve and our economy, and we're building a dynamic and diverse team for our future.
Important Information
Open to US citizens, Green Card holders or Permanent Residents with at least 3 years of residency, with the intent to become a US citizen.
No sponsorship is available. Candidates must have valid work authorization, without an end date, to be considered.
This position requires working on-site, in Kansas City, Denver, Oklahoma City, or Omaha, with 5 days per month remote work flexibility.
This position is not eligible to be remote and relocation assistance is not available.
We are seeking cybersecurity professionals to join our InformationSecurity team as a security specialist focused on operating our DevSecOps program according to standards and policies.
This will be done through close partnership with peers in FRB Kansas City and other Reserve Banks across the System. It will also require healthy relationship building and tight integration with development teams. Additionally, you'll partner with business areas, vendors, and our diverse network of professionals to identify, implement, and support security across the organization.
Candidates with strong understanding and experience in cloud environment deployments, informationsecurity, data management, low-code and no-code solutions, DevSecOps, and artificial intelligence will be ideal.
Key Activities
Interpret and evaluate policies in order to mature and implement the DevSecOps program.
Assess maturity of development teams' DevSecOps practices against an existing framework.
Proactively advocate for and drive enhancements into the program.
Identify gaps/opportunities for enhancements to workflows and processes for enhancing the software development lifecycle (SDLC).
Implement and consults on secure continuous integration and continuous delivery (CI/CD) pipelines, evaluating code and/or applications, or creating code to facilitate the process.
Monitors informationsecurity policy compliance using security tooling.
Evaluate and implement security products and/or processes to enhance productivity and effectiveness for various platforms and initiatives.
Provide technical expertise and support to internal teams on security-related matters.
Collaborate with cross-functional teams to integrate security measures into existing software applications and infrastructure.
Stay current with emerging technologies, industry trends, and best practices in cybersecurity to enhance our security posture.
Support leadership decision making through timely analysis and written communications.
Qualifications
Typically requires 3-6 years of relevant experience.
Bachelor's Degree in Technology, Engineering, Computer Science, Information Systems, Cybersecurity or other related field or equivalent work experience.
Strong competence in cloud technologies such as AWS, Azure, and other platforms.
Expert understanding of DevSecOps practices, frameworks, and tools.
Expertise with tool integration for the DevOps pipeline such as Git.
Combines and organizes information into meaningful patterns; identifies underlying relationships, causes and effects; and combines pieces of information to form conclusions or general rules.
Rapidly acquires new knowledge and learns new skills, and practices agile methodologies to planning and accomplishing work.
Conveys complex and technical issues to diverse audiences.
Demonstrated competencies with artificial intelligence are beneficial.
Working knowledge of Terraform, Ansible, Cloud Formations, AWS Config, AWS Inspector, Guard Duty and others.
Strong knowledge of software development languages, tools and techniques such as Python, JSON, YAML, and Java
Technical expertise in security tools and knowledge of security practices and procedures.
A learning mindset, proactiveness, collaboration, and strong attention to detail.
Additional Information
How We Work (HWW):
On-site: 5 days per month remote work flexibility
Locations: Kansas City, Denver, Oklahoma City, Omaha
Remote Eligible: No
Relocation Assistance: No
Salary:
$79,100 - $111,500 / Experienced Level
$98,600 - $139,000 / Senior Level
Final offers are determined by factors including the candidate's qualifications, internal alignment considerations, district assignment, and geographic location.
Screening: US citizens, permanent residents with the intent to become a US citizen with at least three or more years of United States residency from the date of legal entry to the United States is required for this position.This position has additional screening requirements due to the information accessed while performing the job. These additional screenings would be initiated at the time of offer acceptance and can take up to a couple of months to be completed. You can begin work before the screening is completed; however, continued employment is contingent on acceptable screening results. The areas screened may include education/employment verification, criminal history, credit history, and reference checks.
Sponsorship: The Federal Reserve Bank of Kansas City will not sponsor a new applicant for employment authorization for this position. Applicants must be currently authorized to work in the United States without the need for visa sponsorship now or in the future.
About Us
Total Rewards & Benefits
Who We Are
What We Do
Follow us on
LinkedIn
, Instagram,
X (formerly Twitter)
, and
YouTube
#KCFedIT
Full Time / Part TimeFull time Regular / TemporaryRegularJob Exempt (Yes / No) YesJob CategoryInformation Technology Family GroupWork ShiftFirst (United States of America)
The Federal Reserve Banks are committed to equal employment opportunity for employees and job applicants in compliance with applicable law and to an environment where employees are valued for their differences.
Always verify and apply to jobs on Federal Reserve System Careers (FRS) or through verified Federal Reserve Bank social media channels.
Privacy Notice
$98.6k-139k yearly 2d ago
Information Security Analyst
Cathay Bank-Headquarters 4.4
Rancho Cucamonga, CA jobs
People Drive Our Success Are you enthusiastic, highly motivated, and have a strong work ethic? If yes, come join our team! At Cathay Bank - we strive to provide a caring culture that supports your aspirations and success. We believe people are our most valuable asset and we proudly foster growth and development empowering you to achieve your professional goals. We have thrived for 60 years and persevered through many economic cycles due to our team members' drive and optimism. Together we can make a difference in the financial future of our communities.
Apply today!
What our team members are saying:
Video Clip 1
Video Clip 2
Video Clip 3
Learn more about us at cathaybank.com
GENERAL SUMMARY
This position is responsible for ensuring that the Bank's Security operations and preventive controls are managed and maintained in accordance with established InformationSecurity policies, standards and procedures, published regulations and industry best practices.
Primarily responsible for the constant review of vendor security controls in comparison with policies and industry frameworks, risk assessments, determination of control gaps and their remediation.
ESSENTIAL FUNCTIONS
Performs vendor security risk assessments to determine inherent risk on proposed projects and assesses vendor security controls to determine residual risk.
Evaluates the potential exposure to application security risks and threats based on industry security frameworks and recommends appropriate mitigation.
Assesses security practices including InformationSecurity governance, Identity and access control, Incident monitoring and response, Vulnerability assessment and Penetration tests, Network Security and Endpoint Security, among others.
Acts as liaison with Third Party Risk Management, Information Technology and business department Relationship Managers related to vendor risk assessments.
Reports informationsecurity risks and follows-up remediations.
Remediates audit and regulatory findings and recommendations related to InformationSecurity and Vendor Risk Management.
QUALIFICATIONS
Education:
College degree in Information Technology or InformationSecurity or equivalent;
Security+, SSCP, CISSP, CISM or similar informationsecurity certifications preferred.
Experience:
Minimum two years of experience in InformationSecurity Risk, InformationSecurity Operations or Security Auditing.
Proven experience on third-party risk management and vendor security assessments.
Working knowledge of security practices such as Endpoint Security, Network Security, Security Operations and Security Governance required.
Experience working with Vendor Risk Management (VRM) applications preferred.
Skills/Ability:
Proven ability to initiate and manage projects.
Excellent communication and problem-solving skills.
Strong inter-personal communication and collaboration skills.
Self-starter, highly motivated, and able to work with general supervision.
OTHER DETAILS
$28.84 - $33.65 / hour
Pay determined based on job-related knowledge, skills, experience, and location.
This position may be eligible for a discretionary bonus.
Cathay Bank offers its full-time employees a competitive benefits package which is a significant part of their total compensation. It is our goal to provide employees with a comprehensive benefits package to fit their needs which includes, coverage for medical insurance, dental insurance, vision insurance, life insurance, long-term disability insurance, and flexible spending accounts (FSAs), health saving account (HSA) with company contributions, voluntary coverages, and 401(k).
Cathay Bank may collect personal information from potential job candidates and applicants. For more information on how we handle personal information and your applicable rights, please review our Privacy Policy.
Cathay Bank is an Equal Opportunity and Affirmative Action Employer. We welcome applications for employment from all qualified candidates, regardless of race, color, ethnicity, ancestry, citizenship, gender, national origin, religion, age, sex (including pregnancy and related medical conditions, childbirth and breastfeeding), reproductive health decision-making, sexual orientation, gender identity and expression, genetic information or characteristics, disability or medical condition, military status or status as a protected veteran, or any other status protected by applicable law.
Click here to view the "Know Your Rights: Workplace Discrimination is Illegal" Poster:
Poster- English
Poster- Spanish
Poster- Chinese Traditional
Poster- Chinese Simplified
Cathay Bank endeavors to make **************************** to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact, Mickey Hsu, FVP, Employee Relations Manager, at or . This contact information is for accommodation requests only and cannot be used to inquire about the status of applications.
$28.8-33.7 hourly 2d ago
Information Security Engineering Manager
Wells Fargo 4.6
Information security engineer job at Wells Fargo
**About this role:** Wells Fargo is seeking an InformationSecurityEngineering Manager. The Engineering Manager will lead a team of developers responsible for securing, modernizing, and evolving enterprise applications. This role oversees vulnerability management and application hardening efforts while driving the adoption of DevSecOps, automation, and standardized engineering practices. The manager will guide the team through modernization and transformation initiative, including refactoring legacy components, improving architecture, and preparing the platform for future cloud readiness.
**In this role, you will:**
+ Provide strategic and forward‑thinking leadership to define engineering direction, technology roadmaps, and long‑term platform evolution
+ Lead the team in managing vulnerabilities, applying secure coding practices, and implementing application hardening to protect critical systems
+ Drive modernization efforts by transforming applications through refactoring, re‑architecting, and adoption of modern engineering practices
+ Guide the team through DevSecOps, automation, and standardized delivery processes to improve reliability, security, and speed of delivery
+ Collaborate effectively across security, architecture, and product teams to deliver scalable, resilient, and compliant solutions aligned with organizational goals
+ Manage a team of engineers that design, document, test, maintain and provide issue resolution recommendations for highly complex security solutions related to networking, cryptography, cloud, authentication or directory services, email, internet, applications or endpoint security
+ Manage security consulting on large projects for internal clients to ensure conformity with corporate informationsecurity policy, and standards
+ Possess subject matter expertise at a mastery level in current and emerging security solutions and best practices
+ Conduct technical investigation of security-related incidents, and conduct post-incident digital forensics to identify causes and recommend future mitigation strategies
+ Manage implementation of informationsecurity such as availability, integrity, confidentiality, risk management, threat identification, modeling, monitoring, incident response, access management, and business continuity
+ Work with more experienced technologists and team
+ Interface with more experienced management
+ Manage allocation of people and financial resources for InformationSecurity Architecture
+ Mentor and guide talent development of direct reports and assist in hiring talent
**Required Qualifications:**
+ 4+ years of InformationSecurityEngineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
+ 2+ years of Leadership experience
**Desired Qualifications:**
+ Experience managing and developing high‑performing Agile teams of software engineers and platform developers
+ Strong knowledge of DevSecOps practices including secure CI/CD pipelines, automated testing, and integrated security controls
+ Hands‑on understanding of Kubernetes operations, container orchestration concepts, and cloud‑native deployment patterns
+ Proficiency with cloud‑based application architectures and modern cloud engineering practices
+ Ability to drive engineering excellence through automation, observability, and standardized delivery processes
+ Proven collaboration skills with security, architecture, and product teams to ensure resilient, compliant, and scalable solutions
+ Demonstrated leadership in **platform engineering** to build and operate developer platforms, pipelines, and self‑service tooling
+ Experience leading **application modernization** of home‑grown/legacy systems, including refactoring, re‑architecting, and reducing technical debt
+ Track record of **transformation leadership** and "clean‑sheet" solution design to establish new engineering patterns and operating models
+ Expertise in **CI/CD engineering and automation** across on‑prem and cloud environments, including policy‑as‑code and secrets management
+ Ability to develop a **cloud readiness** roadmap and guide teams through staged migration or hybrid adoption while maintaining uptime and compliance
**Job Expectations:**
+ Ability to work on-site in one of the listed locations in a hybrid environment
+ This position is not available for visa sponsorship
**Pay Range**
Reflected is the base pay range offered for this position. Pay may vary depending on factors including but not limited to achievements, skills, experience, or work location. The range listed is just one component of the compensation package offered to candidates.
$119,000.00 - $187,000.00
**Benefits**
Wells Fargo provides eligible employees with a comprehensive set of benefits, many of which are listed below. Visit Benefits - Wells Fargo Jobs (*************************************************************** for an overview of the following benefit plans and programs offered to employees.
+ Health benefits
+ 401(k) Plan
+ Paid time off
+ Disability benefits
+ Life insurance, critical illness insurance, and accident insurance
+ Parental leave
+ Critical caregiving leave
+ Discounts and savings
+ Commuter benefits
+ Tuition reimbursement
+ Scholarships for dependent children
+ Adoption reimbursement
**Posting End Date:**
23 Jan 2026
***** **_Job posting may come down early due to volume of applicants._**
**We Value Equal Opportunity**
Wells Fargo is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other legally protected characteristic.
Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company. They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions. There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit's risk appetite and all risk and compliance program requirements.
**Applicants with Disabilities**
To request a medical accommodation during the application or interview process, visit Disability Inclusion at Wells Fargo (****************************************************************** .
**Drug and Alcohol Policy**
Wells Fargo maintains a drug free workplace. Please see our Drug and Alcohol Policy (********************************************************************** to learn more.
**Wells Fargo Recruitment and Hiring Requirements:**
a. Third-Party recordings are prohibited unless authorized by Wells Fargo.
b. Wells Fargo requires you to directly represent your own experiences during the recruiting and hiring process.
**Req Number:** R-515850