Sr. Information Security Automation Engineer
Security architect job at Western Union
Senior Information Security Automation Engineer - Austin, TX or Denver, CO Are you Cybersecurity professional who thrives in securing hybrid environments in a global organization? Do you excel in automation? Are you interested in joining a globally diverse organization where our unique contributions are recognized and celebrated, allowing each of us to thrive? Then it's time to join Western Union as a Senior Information Security Automation Engineer!
Applicants must be currently authorized to work in the United States on a full-time basis. Western Union will not sponsor applicants for work visas for this position.
Applications will be assessed for Python coding skills and experience.
Western Union powers your pursuit.
In this role, you will lead the design, implementation, and continuous improvement of secure cloud-based systems and infrastructure. This role will be responsible for securing cloud platforms, managing identity and access solutions, and driving automation across a diverse set of environments. You will play a critical role in ensuring the integrity, confidentiality, and availability of our cloud infrastructure.
Role Responsibilities
* Develop and implement security automation using scripting and programming languages.
* Identify opportunities to streamline and automate security operations.
* Research emerging technologies and security trends to inform architecture and strategy.
* Develop and maintain technical specifications for security tools and platforms.
* Define and report on key performance indicators (KPIs) and security metrics.
* Participate in incident response exercises and API security initiatives.
* Engineer and transition security solutions to operational teams
Role Requirements
* Strong scripting and automation ability (e.g., Python, PowerShell, Bash) without the aid of AI.
* Bachelor's degree in information technology or related field OR equivalent work experience.
* Minimum of 6 years of experience in cybersecurity, with at least 5 years focused on Security Automation Engineering.
* Strong understanding of security best practices and evolving threat landscapes.
* Deep knowledge of networking, APIs, and enterprise technologies.
* Experience with Windows and Linux operating systems.
* Strong written and verbal communication skills.
* Proven ability to work independently and solve complex problems.
Preferred Qualifications
* Expertise in secure coding and automation practices.
* Familiarity with IT audit frameworks and lifecycles.
* Experience with hardening techniques across multiple operating systems.
* Knowledge of change control processes and test-driven development.
* Advanced understanding of cloud-native security tools and DevSecOps practices.
* Experience with container security, IAM protections, data protection, and API security.
* Background in cybersecurity disciplines such as threat hunting, forensics, penetration testing, and data loss prevention.
* Mastery in network security and cloud architecture
We make financial services accessible to humans everywhere. Join us for what's next.
As part of the application process, all applicants are required to take assessments. Western Union has partnered with a 3rd party provider to administer these tests. Applicants will need to provide their name and email address in order to process the assessments. If you have any questions, you may reach out to ************************.
We are passionate about honoring our employee's identity and fostering a feeling of belonging. Our commitment is to provide an inclusive culture that celebrates the unique backgrounds and perspectives of our global teams while reflecting the communities we serve. We do not discriminate based on race, color, national origin, religion, political affiliation, sex (including pregnancy), sexual orientation, gender identity, age, disability, marital status, or veteran status. The company will provide accommodation to applicants, including those with disabilities, during the recruitment process, following applicable laws.
Salary
Annual base salary range is $150,000 - 180,000 USD per year. Total on-target compensation includes a base salary and both short-term and long-term incentives that align with individual and company performance. Actual salaries will vary based on candidates' qualifications, skills, and competencies.
Benefits
You will also have access to short-term incentives, multiple health insurance options, accident and life insurance, and access to best-in-class development platforms, to name a few
(*************************************************** Please see the location-specific benefits below and note that your Recruiter may share additional role-specific benefits during your interview process or in an offer of employment.
Your United States - Specific Benefits Include
* Paid Time Off
* Medical, Dental and Life Insurance
* Tuition Assistance Program
* Student Loan Repayment (below manager level only)
* Parental Leave
* One day volunteer time off
* $0 Money Transfer Fee Discount Code - Quarterly
* Recognition Program "Game Changers"
* Employee Discount Program
* Global Adoption Assistance
* Global Scholarship Awards Program
* 401K plan
Our Hybrid Work Model categorizes each role into one of three categories. Western Union has determined the category of this role to be Hybrid. This is defined as a flexible working arrangement that enables employees to divide their time between working from home and working from an office location. The expectation is to work from the office a minimum of three days a week.
For residents of Colorado, California, Connecticut, Delaware, Minnesota, and Pennsylvania: Please do not respond to any questions on this initial application that may seek age-identifying information such as age, date of birth, or dates of school attendance or graduation. You may also redact this information from any materials you submit during the application process. You will not be penalized for redacting or removing this information."
#LI-HD1
#LI-Hybrid
Estimated Job Posting End Date:
01-09-2026
This application window is a good-faith estimate of the time that this posting will remain open. This posting will be promptly updated if the deadline is extended or the role is filled.
Auto-ApplyInformation Security Analyst
Jacksonville, FL jobs
Job Title Information Security Analyst
Corporate Title Associate
Deutsche Bank Chief Security Office (CSO) is looking for an Information Security Analyst to support the Bank's Information Security Threat Operations (ISTO) - Data Leakage Monitoring (DLM) capabilities.
The DLM Analyst is responsible for timely acting on data leakage events and incidents, taking decisions to ensure the corresponding course of action for rapid containment and mitigation, as well as ensuring all applicable steps in the Bank's DLM process get timely implemented (e.g. impact assessment. consequence management) and accurately documented.
Besides operations tasks, he/she will be supporting to evaluate and adjust processes, tools, and reporting, as well as wider ISTO initiatives or projects.
What We Offer You
A diverse and inclusive environment that embraces change, innovation, and collaboration
A hybrid working model, allowing for in-office / work from home flexibility, generous vacation, personal and volunteer days
Employee Resource Groups support an inclusive workplace for everyone and promote community engagement
Competitive compensation packages including health and wellbeing benefits, retirement savings plans, parental leave, and family building benefits
Educational resources, matching gift and volunteer programs
What You'll Do
Monitor and analyze data activities to detect and prevent unauthorized data transfers and leaks
Utilize metadata logged by DLP solutions to support incident management and forensic investigations
Ensure timely response and containment of data leakage incidents
Ensure proper information security incident documentation and hand over to other colleagues within ISTO as needed
Provide accurate information and reporting with regards to DLM incidents to the relevant stakeholders and timely escalate to other relevant teams/roles as needed, Support the assessment of financial, reputational, client, market or regulatory impact associated with data leakage security incidents
Contribute to data leakage monitoring process improvements as well as detection rules tuning
Skills You'll Need
Bachelor's degree or equivalent required
Previous experience in a similar position, or background on incident management, or SOC related roles
Familiar with the MITTRE ATT&CK framework as well as CISSP, CISM, GCIH or other relevant certifications in the field
Knowledge of industry standards and best practices for data protection
Reasonable understanding/background with Security Incident and Event Management (SIEM) systems, and detection tools, ideally on Splunk, McAfee, Symantec, Microsoft Sentinel & Purview
Skills That Will Help You Excel
Fluent in English, very good communication skills and confident assuming timely decisions
Independent way of working with strong decision making and problem-solving ability
Appetite for continuous learning
Comfortable with working in international & multicultural teams
Expectations
It is the Bank's expectation that employees hired into this role will work in the Jacksonville office in accordance with the Bank's hybrid working model.
Deutsche Bank provides reasonable accommodations to candidates and employees with a substantiated need based on disability and/or religion.
The salary range for this position in Jacksonville, FL is $60,000 to $86,000. Actual salaries may be based on a number of factors including, but not limited to, a candidate's skill set, experience, education, work location and other qualifications. Posted salary ranges do not include incentive compensation or any other type of remuneration.
Deutsche Bank Benefits
At Deutsche Bank, we recognize that our benefit programs have a profound impact on our colleagues. That's why we are focused on providing benefits and perks that enable our colleagues to live authenti cally and be their whole selves, at every stage of life. We provide access to physical, emotional, and financial wellness benefits that allow our colleagues to stay financially secure and strike balance between work and home. Click here to learn more!
Learn more about your life at Deutsche Bank through the eyes of our current employees ***************************
The California Consumer Privacy Act outlines how companies can use personal information. If you are interested in receiving a copy of Deutsche Bank's California Privacy Notice please email ****************.
Salesforce Architect
Roswell, GA jobs
OTR Solutions is an innovator in the transportation industry providing a suite of supply chain financial products including factoring, fuel, and business management focused solutions. We help new and established companies get fast access to the funds they need for daily operations. As a Private Equity backed FinTech company, we are looking to grow our best-in-class financial organization. We continue to evolve our Cloud-Native platform that will drive the next wave of innovation in the industry and fuel OTR's growth. We are looking for growth minded, collaborative technologist who love to create, innovate, and learn cutting-edge solutions on the latest and greatest technology.
OTR has been recognized as a “Top Workplace” by the Atlanta Journal-Constitution since 2016!
The Salesforce Architect will own the strategy, design, and delivery of scalable Salesforce solutions that align with OTR Solutions' business goals. This role blends technical leadership with a product management mindset-collaborating across Sales, Marketing, Underwriting, and IT teams to translate business needs into robust, integrated Salesforce capabilities.
Please note: We do not sponsor work-related visas.**
Responsibilities:
Own and evolve the Salesforce platform architecture and roadmap to support business initiatives
Lead solution design and technical oversight throughout the Salesforce implementation lifecycle, including discovery, development, integration, testing, and deployment
Collaborate with cross-functional teams to translate complex business requirements into scalable Salesforce solutions and integrations with ERP, data warehouses, and external systems
Define and enforce Salesforce best practices for data modeling, security, automation, and deployment
Develop and maintain documentation including user stories, process flows, technical specifications, and integration designs
Facilitate demos and workshops to align stakeholders, gather feedback, and ensure successful adoption of Salesforce capabilities
Stay current on Salesforce platform releases, tools, and emerging technologies to drive continuous innovation
What we look for:
5+ years' experience working in Agile/Scrum environments delivering Salesforce or enterprise cloud solutions
Strong technical understanding of Salesforce architecture, integrations, and data management (certifications preferred but not required)
Proven ability to work effectively with technical teams, product owners, and business stakeholders
Skilled in writing clear user stories, defining acceptance criteria, and managing solution delivery
Strong communication, problem-solving, and organizational skills with a balance of technical depth and business acumen
Bachelor's degree in Computer Science, Engineering, Business, or related field
Perks and Benefits:
OTR provides a competitive, comprehensive compensation package for our full-time employees:
Paid Certifications
Certification Bonus
Eligibility for Individual and Company bonus programs
Medical, Dental, Vision, Life/ AD&D Insurance, Short-Term Disability
Pet Insurance, Paid Family Leave, Employee Assistance Program
Fully Paid Maternity Leave
401(k) with Company Matching
Generous PTO, Sick/Mental Health Days, Flex Holidays + Company Paid Holidays
Travel Stipend to support Work Life Balance
Leadership Development and Training
Continuous Learning + Professional enhancements
Weekly Catered Lunches + Casual Dress Code
Company Paid Fitness Membership
Volunteer Days and Opportunities with Company-Partnered Charities
Internal Inclusion programs
OTR's mission is to create exceptional value for our clients by providing industry leading financing and back-office solutions. Three pillars that are crucial to supporting that mission are outstanding customer service, technology that creates efficiency for ourselves and our customers, and a culture that provides the opportunity for employees to achieve greatness.
OTR Solutions is an Equal Opportunity Employer
Gen AI Architect
Sunnyvale, CA jobs
8-15 years of experience in implementing AI/ML models in enterprise systems
In-depth understanding of AI/ML concepts, including supervised and unsupervised learning, deep learning, anomaly detection, and large language models(Gemini, GPT etc).
Experience leading and working with Agentic AI Frameworks(Langchain, Langraph, CrewAI)
Proficiency in Python and experience with relevant libraries and frameworks (Pandas, Numpy, Tensorflow etc.)
At least 5 years of relevant experience in design, development, and deployment of conversational bots
Experience working with Observability tools like Prometheus, Splunk, Datadog & Grafana.
Experience in NLP (Natural Language Processing) & NLU (Natural Language Understanding), ML (Machine Learning), Conversational AI
Integrate bot systems seamlessly with backend systems, databases, and APIs to facilitate smooth data exchange and interactions.
Experience with web services integration
Excellent troubleshooting and analytical skills in a complex, distributed environment.
Excellent communication, presentation and collaboration skills.
Self-starter with ability to work independently
Experiment and Develop: Candidate will drive the end to end machine learning project lifecycle using best practices and well managed software delivery
Lead the design and development of virtual assistants using Conversational AI platforms
Leads efforts to foster innovative ideas for developing high impact solutions.
Helps in design and develop advanced analytic solutions across functional areas as per requirement/opportunities.
Participate in discussions with business stakeholders to identify business challenges that can be solved with AI/ML.
Use LLM technologies for projects and provide technical assistance for others regarding LLM and GenAI usage.
Support and advise teams on best practices regarding LLM usage and Mainly in the Area of AIOps - Clustering, classification, Anomaly detection, capacity prediction
Understand the requirements and design the conversational flows.
Develop Intent and Entities for chatbot
TCS Employee Benefits Summary:
Discretionary Annual Incentive.
Comprehensive Medical Coverage: Medical & Health, Dental & Vision, Disability Planning & Insurance, Pet Insurance Plans.
Family Support: Ma ternal & Parental Leaves.
Insurance Options: Auto & Home Insurance, Identity Theft Protection.
Convenience & Professional Growth: Commute r Benefits & Certification & Training Reimbursement.
Time Off: Vacation, Time Off, Sick Leave & Holidays.
Legal & Financial Assistance: Legal Assistance, 401K Plan, Performance Bonus, College Fund, Student Loan Refinancing.
Enterprise Information Security Architect
Tampa, FL jobs
It's an exciting time to join Fisher Investments; we're investing in the future of our firm's technology and information security. Our business is growing internationally, which emphasizes the need to build an unparalleled team that promotes future global growth through strategic solutions and progress. We are important to supporting our firm's diverse businesses, and we're excited to continue solidifying that foundation as we add more experienced technologists to our Technology team.
The Opportunity:
As Enterprise Information Security Architect you will report to the VP of Enterprise Architecture and Standards to design and evolve our information security architecture across the enterprise. In this strategic role, you will provide technical expertise, resolve complex architectural challenges, and drive alignment on security principles and standards. You will collaborate with cross-functional teams to ensure our security capabilities are scalable, resilient, and aligned with business objectives, including our enterprise AI initiatives.
The Day-to-Day:
Partner with interdepartmental teams to improve information security management processes and controls
Drive alignment between security architecture, enterprise architecture, and business objectives
Work closely with project teams in an Agile/Scrum environment to integrate security by design
Foster collaboration across Technology, Risk, Compliance, and business units
Identify opportunities for process automation and optimization within security operations
Lead implementation of security improvements in partnership with Information Security and Technology project teams
Analyze business needs and translate them into scalable security architectural solutions
Ensure security capabilities align with and enable enterprise AI and innovation goals
Manage the quality and consistency of security architecture deliverables
Document and maintain security standards, procedures, policies, and architectural patterns
Provide strategic input to Information Security leadership for roadmap planning and prioritization
Conduct risk assessments and develop mitigation strategies for security architecture decisions
Your Qualifications:
7+ years of hands-on experience in identity and access management and information security architecture
Proven track record designing and implementing enterprise security solutions at scale
Demonstrated expertise in risk assessment and mitigation within complex IT environments
Experience working in Agile/Scrum delivery methodologies
Deep technical knowledge of Identity & Access Management platforms (Okta, SailPoint, Azure AD/Entra ID)
Proficiency with enterprise systems including Salesforce CRM, Active Directory, PowerShell scripting, and Group Policy
Strong understanding of IT systems architecture, design principles, and security frameworks
Knowledge of security architecture patterns for cloud, hybrid, and on-premise environments
Bachelor's degree in information security, Information Technology, Computer Science, or related field required
Why Fisher Investments:
We work for a bigger purpose: bettering the investment universe. We take great pride in our inclusive culture, our learning and development framework customized for every employee, and our Great Place to Work Certification. It's the people that make the Fisher purpose possible, and we invest in them by offering exceptional benefits like:
100% paid medical, dental and vision premiums for you and your qualifying dependents
A 50% 401(k) match, up to the IRS maximum
20 days of PTO, plus 10 paid holidays
Family Support programs including 8 week Paid Primary Caregiver Leave, $10,000 fertility, family forming, and hormonal health assistance, and back-up child, adult, and elder care
This is an in-office role. Based on your role, tenure, and performance eligibility you may have the opportunity to participate in our hybrid work from home program. This program is subject to change.
FISHER INVESTMENTS IS AN EQUAL OPPORTUNITY EMPLOYER
Auto-ApplyPrincipal Security Architect
Palo Alto, CA jobs
About the Hiring Team Tencent Overseas IT has the mission to empower Tencent's rapid global growth with future ready, global IT platforms, applications and services. We are chartered to lead the Overseas IT strategy, architecture, roadmap and execution. Satisfying our internal/external customers and becoming a world class global IT team are our top aspirations.
What the Role Entails
Tencent Overseas IT is committed to accelerating Tencent's international business growth and enabling its success through the deployment of cutting-edge technology platforms in IT services, cloud, security, and DevOps. As leaders in IT technology, we are responsible for defining and executing on Tencent's Overseas IT strategy, architecture, and roadmap. Our primary focus is to deliver exceptional value to satisfy the diverse needs of our internal and external customers, while striving to build a world-class global IT team.
Responsibilities
We're seeking a Principal Security Architect to drive the overall security architecture of Tencent overseas business. This role will work closely with foundation IT and Business teams to ensure compliance with security best practices, regulatory requirements, and internal policies. Key responsibilities include:
* Security Strategy and Planning: Defining and implementing the organization's security strategy, roadmaps, and long-term vision.
* Security Architecture Design: Developing and maintaining the overall security architecture, including defining security frameworks, standards, and controls.
* Incident Response: Participating in incident response activities, providing expertise in identifying, containing, and recovering from security incidents.
* Risk Management: Identifying and assessing security risks, developing mitigation strategies, and ensuring alignment with business objectives.
* Security Compliance: Ensuring compliance with relevant security regulations, industry standards (e.g., NIST, ISO 27001, HIPAA), and internal policies.
Who We Look For
Key Skills
* Security Architecture Design: Ability to design and implement secure and scalable architectures across various environments (e.g., cloud, containerized, on-premises), including developing and maintaining threat models and security reference architectures, with a strong emphasis on Zero Trust principles.
* Security Operations & Incident Response: Experience with Security Information & Event Management (SIEM) systems, vulnerability scanners, malware analysis, and handling security incidents. The ability to lead threat modeling activities and support penetration testing is also important.
* Networking: In-depth knowledge of networking principles, including routers, switches, firewalls, load balancers, and wireless devices, as well as network security protocols and technologies like VLANs, VPNs, IDS/IPS, and network segmentation.
* Cloud Security: Expertise in cloud security principles and technologies across major platforms like AWS, Azure, and GCP, including implementing security controls and best practices in cloud environments.
* Identity and Access Management (IAM): Strong understanding of enterprise IAM systems, including platforms like Okta, SailPoint, and Active Directory (AD), and the ability to implement and manage secure access controls based on the principle of least privilege.
* Data Protection: Knowledge of data protection methods like encryption, pseudonymization, and shuffling, and how to apply them effectively to safeguard against data corruption, compromise, and loss.
* Security Testing & Analysis: Experience in conducting penetration testing, vulnerability assessments, ethical hacking, and risk analysis to identify and mitigate security risks.
* Security Automation & DevSecOps: Hands-on experience with security automation tools and scripting languages (e.g., Python, Lambda, Terraform) to streamline security processes and embed security into CI/CD workflows and Infrastructure-as-Code (IaC) processes.
* Security Tools & Technologies: Proficiency in using various security tools and technologies, including SIEM platforms, XDR, cloud-native threat detection tools, vulnerability scanners, and encryption tools.
* Operating Systems: Experience with various operating systems, including Windows, Linux, and UNIX.
* Application Security: Experience in web application security, OWASP, API security, and secure design and testing.
* SaaS Security: Experience with SaaS permission management, experience with SSPM (SaaS Security Posture Management)
* AI for Security: real word experience with AI/LLM/Agentic for security, especially adopt LLM in SIEM rule, SOAR optimization.
* Scripting skills in Python, PowerShell or Bash
Qualifications
* Education: Typically, a master's degree in computer science, Information Security, or a related technical field is required.
* Minimum of 10-12+ years of progressive experience in cybersecurity, including at least 5-7 years in a security architecture or senior-level engineering role.
* Experience securing workspace and key enterprise systems, including IAM, e-mail, DevSecOps, SaaS, and back-office systems.
* Essential soft skills: Analytical Thinking; Problem-Solving; Risk Management; Adaptability & Continuous Learning;Attention to Detail
* Experience working with remote, globally distributed teams
* Previous experience in the gaming industry is a plus.
* Relevant certifications:
* Certified Information Systems Security Professional (CISSP)
* Certified Cloud Security Professional (CCSP)
* Certified Information Security Manager (CISM)
* AWS Certified Security - Specialty
* Other certifications like AWS Certified SA, Certified Ethical Hacker (CEH), CompTIA Security+, and GIAC Security Essentials Certification (GSEC) can also be beneficial.
Location State(s)
US-California-Palo Alto
The expected base pay range for this position in the location(s) listed above is $141,200.00 to $328,400.00 per year. Actual pay may vary depending on job-related knowledge, skills, and experience.
Employees hired for this position may be eligible for a sign on payment, relocation package, and restricted stock units, which will be evaluated on a case-by-case basis.
Subject to the terms and conditions of the plans in effect, hired applicants are also eligible for medical, dental, vision, life and disability benefits, and participation in the Company's 401(k) plan. The Employee is also eligible for up to 15 to 25 days of vacation per year (depending on the employee's tenure), up to 13 days of holidays throughout the calendar year, and up to 10 days of paid sick leave per year.
Your benefits may be adjusted to reflect your location, employment status, duration of employment with the company, and position level. Benefits may also be pro-rated for those who start working during the calendar year.
Equal Employment Opportunity at Tencent
As an equal opportunity employer, we firmly believe that diverse voices fuel our innovation and allow us to better serve our users and the community. We foster an environment where every employee of Tencent feels supported and inspired to achieve individual and common goals.
Auto-ApplySenior Security Operations Analyst
Berkeley, CA jobs
Job DescriptionVoleon is a technology company that applies state-of-the-art AI and machine learning techniques to real-world problems in finance. For nearly two decades, we have led our industry and worked at the frontier of applying AI/ML to investment management. We have become a multibillion-dollar asset manager, and we have ambitious goals for the future. Your colleagues will include internationally recognized experts in artificial intelligence and machine learning research as well as highly experienced finance and technology professionals. The people who shape our company come from other backgrounds, including concert music performances, humanitarian aid, opera singing, sports writing, and BMX racing. You will be part of a team that loves to succeed together.
In addition to our enriching and collegial working environment, we offer highly competitive compensation and benefits packages, technology talks by our experts, a beautiful modern office, daily catered lunches, and more.
As a Senior Security Operations Analyst, you will be a key contributor to Voleon's security operations, bringing experience and leadership to our SOC. You will handle complex security incidents, mentor junior team members, and help drive strategic improvements to our security posture. This role offers significant growth opportunities and the chance to shape the future of security operations at a leading quantitative investment firm.
This role is open to remote work in the US or hybrid in our Berkeley office.Responsibilities
Lead complex security incident investigations and coordinate response efforts across multiple teams
Perform advanced threat hunting, detection engineering, and security analytics to identify sophisticated attacks
Mentor junior analysts and contribute to training programs and knowledge sharing initiatives
Design and implement security monitoring improvements, playbooks, and automation solutions
Collaborate with Security Engineers to enhance detection capabilities and reduce false positives
Participate in security architecture discussions and provide operational input on security tool selection
Lead on-call rotation responsibilities and serve as escalation point for complex security events
Contribute to threat intelligence analysis and help develop proactive defense strategies
Support compliance and audit activities, ensuring proper documentation and evidence collection
Drive continuous improvement initiatives to enhance SOC efficiency and effectiveness
Requirements
5+ years of experience in security operations, incident response, or related cybersecurity roles
Strong expertise with SIEM platforms, EDR solutions, and security orchestration tools
Proven experience in threat hunting, malware analysis, and advanced persistent threat investigation
Proficiency in scripting and automation (Python, PowerShell, Bash) for security operations
Deep understanding of network protocols, operating systems, and attack methodologies
Experience with cloud security monitoring and incident response (AWS, GCP, Azure)
Strong leadership and mentoring capabilities with excellent communication skills
Ability to work effectively under pressure and manage multiple complex investigations simultaneously
Preferred Qualifications
Advanced security certifications such as GCIH, GCFA, GNFA, CISSP, or equivalent
Experience with threat intelligence platforms and frameworks (MITRE framework, STIX/TAXII)
Background in digital forensics, reverse engineering, or red team/purple team activities
Experience with security compliance frameworks (SOC 2, ISO 27001, NIST)
Knowledge of financial services security requirements and regulations
Bachelor degree in Computer Science, Information Security, or related field
CompensationThe base salary range for this position is $175,000 to $185,000 in the location(s) of this posting. Individual salaries are determined through a variety of factors, including, but not limited to, education, experience, knowledge, skills, and geography. Base salary does not include other forms of total compensation, such as bonus compensation and other benefits. Our benefits package includes medical, dental, and vision coverage, life and AD&D insurance, 20 days of paid time off, 9 sick days, and a 401(k) plan with a company match.
“Friends of Voleon” Candidate Referral ProgramIf you have a great candidate in mind for this role and would like to have the potential to earn $15,000 if your referred candidate is successfully hired and employed by The Voleon Group, please use this form to submit your referral. For more details regarding eligibility, terms, and conditions, please review the Voleon Referral Bonus Program. Equal Opportunity EmployerThe Voleon Group is an Equal Opportunity employer. Applicants are considered without regard to race, color, religion, creed, national origin, age, sex, gender, marital status, sexual orientation and identity, genetic information, veteran status, citizenship, or any other factors prohibited by local, state, or federal law. #LI-JA1
We may use artificial intelligence (AI) tools to support parts of the hiring process. These tools assist our recruitment team but do not replace human judgement. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Senior Security Operations Analyst
Berkeley, CA jobs
Voleon is a technology company that applies state-of-the-art AI and machine learning techniques to real-world problems in finance. For nearly two decades, we have led our industry and worked at the frontier of applying AI/ML to investment management. We have become a multibillion-dollar asset manager, and we have ambitious goals for the future. Your colleagues will include internationally recognized experts in artificial intelligence and machine learning research as well as highly experienced finance and technology professionals. The people who shape our company come from other backgrounds, including concert music performances, humanitarian aid, opera singing, sports writing, and BMX racing. You will be part of a team that loves to succeed together.
In addition to our enriching and collegial working environment, we offer highly competitive compensation and benefits packages, technology talks by our experts, a beautiful modern office, daily catered lunches, and more.
As a Senior Security Operations Analyst, you will be a key contributor to Voleon's security operations, bringing experience and leadership to our SOC. You will handle complex security incidents, mentor junior team members, and help drive strategic improvements to our security posture. This role offers significant growth opportunities and the chance to shape the future of security operations at a leading quantitative investment firm.
This role is open to remote work in the US or hybrid in our Berkeley office.Responsibilities
Lead complex security incident investigations and coordinate response efforts across multiple teams
Perform advanced threat hunting, detection engineering, and security analytics to identify sophisticated attacks
Mentor junior analysts and contribute to training programs and knowledge sharing initiatives
Design and implement security monitoring improvements, playbooks, and automation solutions
Collaborate with Security Engineers to enhance detection capabilities and reduce false positives
Participate in security architecture discussions and provide operational input on security tool selection
Lead on-call rotation responsibilities and serve as escalation point for complex security events
Contribute to threat intelligence analysis and help develop proactive defense strategies
Support compliance and audit activities, ensuring proper documentation and evidence collection
Drive continuous improvement initiatives to enhance SOC efficiency and effectiveness
Requirements
5+ years of experience in security operations, incident response, or related cybersecurity roles
Strong expertise with SIEM platforms, EDR solutions, and security orchestration tools
Proven experience in threat hunting, malware analysis, and advanced persistent threat investigation
Proficiency in scripting and automation (Python, PowerShell, Bash) for security operations
Deep understanding of network protocols, operating systems, and attack methodologies
Experience with cloud security monitoring and incident response (AWS, GCP, Azure)
Strong leadership and mentoring capabilities with excellent communication skills
Ability to work effectively under pressure and manage multiple complex investigations simultaneously
Preferred Qualifications
Advanced security certifications such as GCIH, GCFA, GNFA, CISSP, or equivalent
Experience with threat intelligence platforms and frameworks (MITRE framework, STIX/TAXII)
Background in digital forensics, reverse engineering, or red team/purple team activities
Experience with security compliance frameworks (SOC 2, ISO 27001, NIST)
Knowledge of financial services security requirements and regulations
Bachelor degree in Computer Science, Information Security, or related field
CompensationThe base salary range for this position is $175,000 to $185,000 in the location(s) of this posting. Individual salaries are determined through a variety of factors, including, but not limited to, education, experience, knowledge, skills, and geography. Base salary does not include other forms of total compensation, such as bonus compensation and other benefits. Our benefits package includes medical, dental, and vision coverage, life and AD&D insurance, 20 days of paid time off, 9 sick days, and a 401(k) plan with a company match.
“Friends of Voleon” Candidate Referral ProgramIf you have a great candidate in mind for this role and would like to have the potential to earn $15,000 if your referred candidate is successfully hired and employed by The Voleon Group, please use this form to submit your referral. For more details regarding eligibility, terms, and conditions, please review the Voleon Referral Bonus Program. Equal Opportunity EmployerThe Voleon Group is an Equal Opportunity employer. Applicants are considered without regard to race, color, religion, creed, national origin, age, sex, gender, marital status, sexual orientation and identity, genetic information, veteran status, citizenship, or any other factors prohibited by local, state, or federal law. #LI-JA1
Auto-ApplyLead Information Security Architect
Chicago, IL jobs
Job Description
Act as a senior technical advisor to the organization partnering with cross-functional teams to define information security requirements for enterprise information technology systems and internally developed applications. Proactively define security requirements for assigned applications, whether purchased or developed in-house.
Essential Responsibilities
Analyze various technology environments such as on-prem, cloud, SaaS to detect critical security deficiencies and recommend solutions for improvement. Advise various teams such as Information Security and Information Technology as well as collaborate cross-functionally to develop solutions that ensure compliance with security requirements, best practices, applicable state and federal laws, company procedures, and policies
Develop an implementation plan for enterprise security architecture based on business requirements and varying strategies for project-driven or product-driven delivery teams. Advise various teams such as Information Security and Information Technology teams as well as collaborate cross-functionally to implement solutions
Conduct detailed threat modeling and security testing of enterprise systems and their interactions to resolve problems cost effectively and enable business objectives
Ensure secure development lifecycle of applications including design, implementation, testing and maintenance of simple to highly complex computer programs and subsystems. Conduct secure code review to ensure compliance with security requirements, best practices, applicable state and federal laws, company procedures, and policies
Education
Preferred - 4 Year Bachelors Degree in Computer Science or Related
Preferred - Graduate Degree in Computer Science or Related
Years of Experience
Minimum - 5 Years Information Technology or Related
Minimum - 5 Years Information Security, Application Security, or Related
In Lieu of Education
8 Years Information Security or Related
License/Certifications/Training
Preferred: CISSP
Compensation & Benefits:
Typical hiring range: $119,400 - $204,600 Annually. Actual compensation will be determined using factors such as experience, skills & knowledge.
Additional Compensation: Annual performance bonus
Benefits: Alliant provides a benefits package including health care, vision, dental, and 401k with employer match.
Additional Benefits:
Work from home up to 3 days a week
Paid parental leave
Employee discount programs
Time off including paid personal and sick days
11 paid holidays
Education reimbursement
*Note that eligibility and cost of benefits can vary depending on the number of regularly scheduled hours, and job status such as regular full-time, regular part-time, or temporary employment.
Adhere to and ensure compliance of all business transactions with policy and process of the Bank Secrecy Act. Ensures compliance with all applicable state and federal laws, company procedures and policies. Maintains integrity and ethics in all actions and conversations with or regarding credit union members and their accounts; complies with Privacy Act directives.
The responsibilities listed do not contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this position. Duties, responsibilities and activities may change at any time with or without notice.
Sr Principal AI Security Architect
Chicago, IL jobs
Northern Trust, a Fortune 500 company, is a globally recognized, award-winning financial institution that has been in continuous operation since 1889.
Northern Trust is proud to provide innovative financial services and guidance to the world's most successful individuals, families, and institutions by remaining true to our enduring principles of service, expertise, and integrity. With more than 130 years of financial experience and over 22,000 partners, we serve the world's most sophisticated clients using leading technology and exceptional service.
As artificial intelligence transforms the financial services sector, the need for robust and forward-looking security architecture has never been more critical. We are seeking a Principal AI Security Architect to lead the secure design, integration, and governance of AI systems across the enterprise.
This role is responsible for defining AI security strategies that span internal LLM deployments, Microsoft Copilot, and managed third-party AI platforms provided by SaaS providers and other counterparties. You will drive architecture, risk governance, and security enforcement for AI adoption across the organization-balancing innovation with regulatory, operational, and reputational risk.
The successful candidate will serve as a trusted advisor to Security & Technology Leadership, internal governance boards, and senior business stakeholders to ensure AI is adopted securely, accountably, and in alignment with industry-leading standards.
Key Responsibilities
Enterprise AI Security Architecture
- Define and enforce enterprise-wide AI security architecture patterns across:
- First-party AI/LLM deployments
- Microsoft Copilot and GitHub Copilot
- Azure OpenAI and plugin architectures
- Third-party managed AI platforms (e.g., Workday, ServiceNow, Solytics, and other integrated AI services)
- Ensure AI systems and plugins are securely integrated with Microsoft 365, Entra ID, Defender suite, Purview, and Azure services.
- Architect Model Context Protocol (MCP) patterns for safe containerized deployments:
- Secure pod-to-pod communication via microsegmentation
- API gateway authentication and rate limiting
- Container image integrity validation
- Grounding data access policy enforcement
- Centralized monitoring and logging for auditability
AI Governance & Risk Management
- Develop and maintain enterprise-wide AI security policy frameworks
- Partner with Data Protection, Legal, Procurement, and Business Units
- Design and implement policy-as-code and workflow-based governance controls
Threat Modeling, Detection & Mitigation
- Build and maintain AI-specific threat models
- Design AI-aware detection and response strategies
- Support red teaming, abuse case development, and adversarial testing
Integration with Microsoft and Third-Party Ecosystems
- Enable seamless and secure integration of Microsoft and third-party AI platforms
- Ensure data classification and DLP enforcement using Microsoft Purview
- Ensure AI interactions respect network boundaries
Controls Alignment & Regulatory Compliance
- Map AI-specific controls to CRI v2.1, NIST AI RMF, and OWASP Top 10 for LLMs
- Enforce end-to-end controls across the AI lifecycle
- Implement controls to protect confidentiality, integrity, and availability
Executive Influence & Cross-Functional Leadership
- Act as a recognized authority on AI security
- Advise Security Leadership, Technology Leadership, and governance boards
- Present AI security strategy and posture to stakeholders
- Mentor security architects, engineers, and data scientists
Qualifications
Required:
- 10+ years in enterprise security architecture or engineering
- Expertise in Microsoft security ecosystem
- Strong scripting and query experience with PowerShell, KQL
- Experience securing AI pipelines and plugin-based architectures
- Proven leadership in AI-specific threat modeling and risk treatment
- Familiarity with model lifecycle governance
- Regulatory alignment: CRI v2.1, NIST AI RMF, OWASP LLM Top 10, FFIEC, GDPR, Basel III
Desired:
- Experience with a Global Systemically Important Bank (G-SIB)
- Experience with Solytics, Snowflake integrations, or other third-party platforms
- Knowledge of shadow principal, token abuse, and adversary tactics
- Recognition as an industry expert
Salary Range:
$164,600 - 288,000 USD
Salary range is a good faith estimate of base pay. Northern Trust provides a comprehensive benefits package including retirement benefits (401k and pension), health and welfare benefits (medical, dental, vision, spending accounts and disability), paid time off, parental and caregiver leave, life & accident insurance, and other voluntary and well-being benefits. Northern Trust also provides a discretionary bonus program that may include an equity component.
Working with Us:
As a Northern Trust partner, greater achievements await. You will be part of a flexible and collaborative work culture in an organization where financial strength and stability is an asset that emboldens us to explore new ideas.
Movement within the organization is encouraged, senior leaders are accessible, and you can take pride in working for a company committed to assisting the communities we serve! Join a workplace with a greater purpose.
We'd love to learn more about how your interests and experience could be a fit with one of the world's most admired and sustainable companies! Build your career with us and apply today. #MadeForGreater
Reasonable accommodation
Northern Trust is committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation for any part of the employment process, please email our HR Service Center at *****************.
We hope you're excited about the role and the opportunity to work with us. We value an inclusive workplace and understand flexibility means different things to different people.
Apply today and talk to us about your flexible working requirements and together we can achieve greater.
Auto-ApplySr Lead, Security Architect - CIAM
Chicago, IL jobs
Northern Trust, a Fortune 500 company, is a globally recognized, award-winning financial institution that has been in continuous operation since 1889.
Northern Trust is proud to provide innovative financial services and guidance to the world's most successful individuals, families, and institutions by remaining true to our enduring principles of service, expertise, and integrity. With more than 130 years of financial experience and over 22,000 partners, we serve the world's most sophisticated clients using leading technology and exceptional service.
Summary:
The Sr Lead, Security Architect role is responsible leading the design and implementation of secure customer identity and access management (CIAM) solutions. This role partners with security, product and development teams to help drive the strategic CIAM architecture vision while enabling secure, scalable user experiences and compliance with regulatory standards.
Responsibilitiess
Design and maintain CIAM architecture and roadmaps aligned with business and regulatory needs
Collaborate with customer experience and product teams to balance usability with security
Provide architectural guidance for API security, mobile app integration, and federated identity (OAuth2, OIDC, SAML)
Ensure secure design and integration of identity services including registration, login, MFA, identity proofing, and access control.
Experience :
• Minimum of 7+ years of experience working in an information security engineering or development role in a large, complex environment.
• Bachelor's or Master's degree in Computer Science or other IT related field.
• Self-motivated, proactive and able to work independently.
• Strong communication skills.
Salary Range:
$114,500 - 194,700 USD
Salary range is a good faith estimate of base pay. Northern Trust provides a comprehensive benefits package including retirement benefits (401k and pension), health and welfare benefits (medical, dental, vision, spending accounts and disability), paid time off, parental and caregiver leave, life & accident insurance, and other voluntary and well-being benefits. Northern Trust also provides a discretionary bonus program that may include an equity component.
Working with Us:
As a Northern Trust partner, greater achievements await. You will be part of a flexible and collaborative work culture in an organization where financial strength and stability is an asset that emboldens us to explore new ideas.
Movement within the organization is encouraged, senior leaders are accessible, and you can take pride in working for a company committed to assisting the communities we serve! Join a workplace with a greater purpose.
We'd love to learn more about how your interests and experience could be a fit with one of the world's most admired and sustainable companies! Build your career with us and apply today. #MadeForGreater
Reasonable accommodation
Northern Trust is committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation for any part of the employment process, please email our HR Service Center at *****************.
We hope you're excited about the role and the opportunity to work with us. We value an inclusive workplace and understand flexibility means different things to different people.
Apply today and talk to us about your flexible working requirements and together we can achieve greater.
Auto-ApplyLead Cyber Security Architect
Plano, TX jobs
Join one of the world's most influential companies and leverage your skills in cybersecurity to have a real impact on the financial industry. As a Lead Cybersecurity Architect at JPMorganChase within Cybersecurity and Technology Controls, you are an integral part of a team that works to develop high-quality cybersecurity solutions for various software applications on modern cloud-based technologies. As a core technical contributor, you are responsible for carrying out critical cybersecurity architecture solutions by identifying, creating, and communicating risk, mitigation options, and solutions across multiple technical areas within various business functions in support of project goals.
**Job responsibilities**
+ Partnering with the Engineering & Architecture teams to integrate security controls into platforms e.g. AWS, Application architecture, AI Solutions, etc.
+ Creating and propagating (developing ) security design patterns to support building consistent and secure technology solutions
+ Assisting and guiding engineering teams in the secure development of infrastructure services and products
+ Ensure security considerations are delivered in compliance with firm wide technology controls from the start and throughout the Software Development Lifecycle.
+ Developing extensible security solutions aligned to the product strategy in future developments.
+ Conduct security assessments, threat modeling, and vulnerability assessments of products and features to identify and prioritize security risks.
**Required qualifications, capabilities, and skills**
+ Formal training or certification and 5+ years 0f experience in Cybersecurity Architecture or related field.
+ Hands-on practical experience delivering enterprise-level cybersecurity solutions and controls . Advanced in one or more programming languages
+ Proficiency in automation and continuous delivery methods . Proficiency in all aspects of the Software Development Life Cycle
+ Advanced understanding of agile methodologies such as continuous integration and delivery, application resiliency, and security
+ Demonstrated proficiency in software applications and technical processes within a technical discipline (e.g., public cloud, artificial intelligence, machine learning, mobile, etc.)
+ Practical cloud native experience . Deep knowledge of one or more software and applications
+ Ability to evaluate current and emerging technologies to recommend the best solutions for the future state architecture
+ Experience effectively communicating with senior business leaders
**Preferred qualifications, capabilities, and skills**
+ Proven experience in a product security role with a track record of driving security initiatives. Strong knowledge of secure software development practices and common vulnerabilities (e.g., OWASP Top Ten).
+ Experience with threat modeling, risk assessment, and vulnerability management.
+ Familiarity with security frameworks (e.g., NIST Cybersecurity Framework), ATTACK MITRE and industry regulations (e.g., GDPR, HIPAA)
+ Certifications such as CISSP, CISSP-ISSAP, AWS Solutions Architect Associate, etc.
+ Bachelor's or Master's degree in Computer Science, Information Security, or a related field (or equivalent work experience).
\#CTC
JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world's most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.
We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans
Lead Cyber Security Architect
Plano, TX jobs
Join one of the world's most influential companies and leverage your skills in cybersecurity to have a real impact on the financial industry.
As a Lead Cybersecurity Architect at JPMorganChase within Cybersecurity and Technology Controls, you are an integral part of a team that works to develop high-quality cybersecurity solutions for various software applications on modern cloud-based technologies. As a core technical contributor, you are responsible for carrying out critical cybersecurity architecture solutions by identifying, creating, and communicating risk, mitigation options, and solutions across multiple technical areas within various business functions in support of project goals.
Job responsibilities
Partnering with the Engineering & Architecture teams to integrate security controls into platforms e.g. AWS, Application architecture, AI Solutions, etc.
Creating and propagating (developing ) security design patterns to support building consistent and secure technology solutions
Assisting and guiding engineering teams in the secure development of infrastructure services and products
Ensure security considerations are delivered in compliance with firm wide technology controls from the start and throughout the Software Development Lifecycle.
Developing extensible security solutions aligned to the product strategy in future developments.
Conduct security assessments, threat modeling, and vulnerability assessments of products and features to identify and prioritize security risks.
Required qualifications, capabilities, and skills
Formal training or certification and 5+ years 0f experience in Cybersecurity Architecture or related field.
Hands-on practical experience delivering enterprise-level cybersecurity solutions and controls . Advanced in one or more programming languages
Proficiency in automation and continuous delivery methods . Proficiency in all aspects of the Software Development Life Cycle
Advanced understanding of agile methodologies such as continuous integration and delivery, application resiliency, and security
Demonstrated proficiency in software applications and technical processes within a technical discipline (e.g., public cloud, artificial intelligence, machine learning, mobile, etc.)
Practical cloud native experience . Deep knowledge of one or more software and applications
Ability to evaluate current and emerging technologies to recommend the best solutions for the future state architecture
Experience effectively communicating with senior business leaders
Preferred qualifications, capabilities, and skills
Proven experience in a product security role with a track record of driving security initiatives. Strong knowledge of secure software development practices and common vulnerabilities (e.g., OWASP Top Ten).
Experience with threat modeling, risk assessment, and vulnerability management.
Familiarity with security frameworks (e.g., NIST Cybersecurity Framework), ATTACK MITRE and industry regulations (e.g., GDPR, HIPAA)
Certifications such as CISSP, CISSP-ISSAP, AWS Solutions Architect Associate, etc.
Bachelor's or Master's degree in Computer Science, Information Security, or a related field (or equivalent work experience).
Auto-ApplyLead Cyber Security Architect
Plano, TX jobs
JobID: 210672620 JobSchedule: Full time JobShift: : Join one of the world's most influential companies and leverage your skills in cybersecurity to have a real impact on the financial industry. As a Lead Cybersecurity Architect at JPMorganChase within Cybersecurity and Technology Controls, you are an integral part of a team that works to develop high-quality cybersecurity solutions for various software applications on modern cloud-based technologies. As a core technical contributor, you are responsible for carrying out critical cybersecurity architecture solutions by identifying, creating, and communicating risk, mitigation options, and solutions across multiple technical areas within various business functions in support of project goals.
Job responsibilities
* Partnering with the Engineering & Architecture teams to integrate security controls into platforms e.g. AWS, Application architecture, AI Solutions, etc.
* Creating and propagating (developing ) security design patterns to support building consistent and secure technology solutions
* Assisting and guiding engineering teams in the secure development of infrastructure services and products
* Ensure security considerations are delivered in compliance with firm wide technology controls from the start and throughout the Software Development Lifecycle.
* Developing extensible security solutions aligned to the product strategy in future developments.
* Conduct security assessments, threat modeling, and vulnerability assessments of products and features to identify and prioritize security risks.
Required qualifications, capabilities, and skills
* Formal training or certification and 5+ years 0f experience in Cybersecurity Architecture or related field.
* Hands-on practical experience delivering enterprise-level cybersecurity solutions and controls . Advanced in one or more programming languages
* Proficiency in automation and continuous delivery methods . Proficiency in all aspects of the Software Development Life Cycle
* Advanced understanding of agile methodologies such as continuous integration and delivery, application resiliency, and security
* Demonstrated proficiency in software applications and technical processes within a technical discipline (e.g., public cloud, artificial intelligence, machine learning, mobile, etc.)
* Practical cloud native experience . Deep knowledge of one or more software and applications
* Ability to evaluate current and emerging technologies to recommend the best solutions for the future state architecture
* Experience effectively communicating with senior business leaders
Preferred qualifications, capabilities, and skills
* Proven experience in a product security role with a track record of driving security initiatives. Strong knowledge of secure software development practices and common vulnerabilities (e.g., OWASP Top Ten).
* Experience with threat modeling, risk assessment, and vulnerability management.
* Familiarity with security frameworks (e.g., NIST Cybersecurity Framework), ATTACK MITRE and industry regulations (e.g., GDPR, HIPAA)
* Certifications such as CISSP, CISSP-ISSAP, AWS Solutions Architect Associate, etc.
* Bachelor's or Master's degree in Computer Science, Information Security, or a related field (or equivalent work experience).
#CTC
Auto-ApplySenior Advanced Cloud Security Architect/Engineer
Atlanta, GA jobs
Innovate to solve the world's most important challenges The future is what you make it. When you join Honeywell, you become a member of our global team of thinkers, innovators, dreamers and doers who make the things that make the future. That means changing the way we fly, fueling jets in an eco-friendly way, keeping buildings smart and safe and even making it possible to breathe on Mars.
Working at Honeywell isn't just about developing cool things. That's why all of our employees enjoy access to dynamic career opportunities across different fields and industries.
Are you ready to help us make the future?
Honeywell Connected Enterprise (HCE) is a global leader for products and technologies that are installed in more than 10 million buildings, aircraft, and facilities worldwide. We are a pioneer in the Internet of Things, developing the next generation of connected offerings.
Are you someone who wants to drive real improvements into real products in an environment which has a strong organizational support for product security?
In the role of Senior Advanced Cloud Security Architect for Honeywell Connected Enterprise, you will join a growing Product Security team overseeing the posture of HCE Cloud offerings and driving security by design across cloud-based products. The Senior Advanced Cloud Security Architect will report to the HCE Cloud Security Manager and will drive secure cloud posture and risk reduction across software products through standardized and defined processes by partnering with Honeywell Global Security and collaboration with team members.
* Innovate by developing new solutions and identifying industry-leading practices in secure cloud environments.
* Collaborate with team members to advance state-of-the-art cloud security practices.
* Support and work alongside the CTO and SRE to enhance best-in-class cloud posture in a multi-cloud environment.
* Partner with Honeywell Global Security to understand and influence cloud security baselines, providing practical solutions that incorporate engineering considerations without introducing risk.
* Drive the establishment of cloud security baselines through policy initiatives in a multi-cloud environment, primarily focusing on Azure, utilizing automation.
* Identify metrics that will promote behavioral changes in the cloud, such as untagged cloud resources, cloud built without IaC, and overall cloud risk.
* Implement dashboards to offer insights into cloud risk and facilitate risk reduction activities.
* Support security incident and response activities by performing analysis, collaborating with stakeholders, and driving the resolution of incidents.
* Promote and apply Zero Trust architecture and principles across cloud and edge environments.
* Assist in the management and deployment of cloud baseline policies at scale through automation.
In addition to a competitive salary, leading-edge work, and developing solutions side-by-side with dedicated experts in their fields, Honeywell employees are eligible for a comprehensive benefits package. This package includes employer subsidized Medical, Dental, Vision, and Life Insurance; Short-Term and Long-Term Disability; 401(k) match, Flexible Spending Accounts, Health Savings Accounts, EAP, and Educational Assistance; Parental Leave, Paid Time Off (for vacation, personal business, sick time, and parental leave), and 12 Paid Holidays. For more Honeywell Benefits information visit: *******************************
The application period for the job is estimated to be 40 days from the job posting date; however, this may be shortened or extended depending on business needs and the availability of qualified candidates. Job Posting Date: September 17th, 2025.
YOU MUST HAVE
* 5 years of experience with a public cloud such as AWS, Azure, GCP
* Ability to perform threat modeling of cloud-based systems
WE VALUE
* Bachelor's Degree
* Master's Degree
* Ability to identity and define project scope and level of effort
* Experience with programming and automation
* Ability to identify and remediate issues early, analyze, and propose alternative solutions
* Strong interpersonal skills with the ability to facilitate diverse groups, help negotiate priorities, and resolve conflicts among stakeholders
* Passion for achieving results and continual self-improvement
* Experience and knowledge of Public Cloud Provider (e.g., Azure, AWS, GCP) security controls and capabilities (e.g., DDoS, Firewalls, WAF, Network Segregation)
* Understanding of secure networking design and principles
* Experience of multi-layer cloud security controls ensuring confidentiality, integrity, and availability
* Understanding of Internet of Things (IOT) security concerns, architecture, and controls
* Experience with Identity and Access Management security solutions and protocols (e.g., SAML, OpenID, and OAuth)
* Experience and understanding of Container/Kubernetes security and controls
* Understanding of security by design principles, architecture level security, API security, and Zero Trust security concepts
* Up to date knowledge of current and emerging security threats and techniques for exploiting security weaknesses
* Understanding of National and International regulatory and compliance standards
* Certifications in security demonstrating deep practical knowledge such as CCSP, or CISSP
Due to compliance with U.S. export control laws and regulations, candidate must be a U.S. Person, which is defined as, a U.S. citizen, a U.S. permanent resident, or have protected status in the U.S. under asylum or refugee status or have the ability to obtain an export authorization.
SAP - Security Administrator
Plano, TX jobs
Who we are Collaborative. Respectful. A place to dream and do. These are just a few words that describe what life is like at Toyota. As one of the world's most admired brands, Toyota is growing and leading the future of mobility through innovative, high-quality solutions designed to enhance lives and delight those we serve. We're looking for talented team members who want to Dream. Do. Grow. with us.
An important part of the Toyota family is Toyota Financial Services (TFS), the finance and insurance brand for Toyota and Lexus in North America. While TFS is a separate business entity, it is an essential part of this world-changing company- delivering on Toyota's vision to move people beyond what's possible. At TFS, you will help create best-in-class customer experience in an innovative, collaborative environment.
To save time applying, Toyota does not offer sponsorship of job applicants for employment-based visas or any other work authorization for this position at this time.
Who we're looking for
This role is responsible of the design, implementation, and maintenance of SAP security across multiple platforms. This role is critical to ensure secure access, compliance, and operational integrity of our SAP landscape, including S/4 HANA, Fiori, and MDG.
What you'll be doing
* Design and manage SAP security roles and authorizations across S/4 HANA, Fiori, Solution Manager, MDG.
* Configure and maintain SAP GRC Access Control modules (ARA, ARM, BRM).
* Implement and monitor segregation of duties (SOD) policies and controls.
* Troubleshoot and resolve authorization issues across SAP modules.
* Collaborate with functional and technical teams to align security with business processes.
* Support SAP upgrades, migrations, and transformation initiatives.
* Conduct periodic audits and ensure compliance with internal and external regulations.
* Document security procedures, role matrices, and access control policies.
What you bring
* Bachelor's degree in computer science, Information Systems, or related field.
* 10+ years of hands-on SAP security experience.
* Strong knowledge of SAP GRC, Fiori authorization concepts, and HANA DB security.
* Experience with SAP Activate methodology and UI/UX aspects of SAP Security.
* Familiarity with compliance frameworks (SOX, GDPR, etc.).
* Excellent problem-solving, communication, and documentation skills.
Added bonus if you have
* SAP Certified Technology Associate - System Security.
* Experience with SAP BTP and cloud-based security models.
* Knowledge of identity management tools and integration.
What We Bring
During your interview process, our team can fill you in on all the details of our industry-leading benefits and career development opportunities. A few highlights include:
* A work environment built on teamwork, flexibility, and respect.
* Professional growth and development programs to help advance your career, as well as tuition reimbursement.
* Team Member Vehicle Purchase Discount.
* Toyota Team Member Lease Vehicle Program (if applicable).
* Comprehensive health care and wellness plans for your entire family.
* Toyota 401(k) Savings Plan featuring a company match, as well as an annual retirement contribution from Toyota regardless of whether you contribute.
* Paid holidays and paid time off.
* Referral services related to prenatal services, adoption, childcare, schools, and more.
* Tax-Advantaged Accounts (Health Savings Account, Health Care FSA, Dependent Care FSA).
* Relocation assistance (if applicable).
Belonging at Toyota
Our success begins and ends with our people. We embrace all perspectives and value unique human experiences. Respect for all is our North Star. Toyota is proud to have 10+ different Business Partnering Groups across 100 different North American chapter locations that support team members' efforts to dream, do and grow without questioning that they belong.
Applicants for our positions are considered without regard to race, ethnicity, national origin, sex, sexual orientation, gender identity or expression, age, disability, religion, military or veteran status, or any other characteristics protected by law.
Have a question, need assistance with your application or do you require any special accommodations? Please send an email to *****************************.
Auto-ApplyDirector, Information Security - Regulatory & Controls
Chicago, IL jobs
We're building a relationship-oriented bank for the modern world. We need talented, passionate professionals who are dedicated to doing what's right for our clients.
At CIBC, we embrace your strengths and your ambitions, so you are empowered at work. Our team members have what they need to make a meaningful impact and are truly valued for who they are and what they contribute.
To learn more about CIBC, please visit CIBC.com
What you'll be doing: As the US Region Information Security Director of Regulatory and Controls, you will be responsible for the department's efforts in ensuring compliance with relevant regulations and effectiveness of information security controls.
You will monitor relevant laws, regulations, and standards to ensure CIBC US security practices align with regulatory requirements and you will own regulatory compliance programs such as NY-DFS, GLBA and FFIEC.
You will serve as primary point of contract for regulatory bodies during audits and be responsible for creation of materials for and participation in exams and quarterly briefings.
You will be responsible for Information Security control management and providing oversight of controls that impact the US team.
This includes conducting the Risk and Control SelfAssessment (RCSA) for Information Security and provide input into RCSA's for all other lines of business.
Work Arrangement: At CIBC we enable the work environment most optimal for you to thrive in your role. You'll have the flexibility to manage your work activities within a hybrid work arrangement where you'll spend 1-3 days per week on-site, while other days will be remote.
Key Duties:
Regulatory and Reporting:
Monitor relevant laws, regulations and standards to ensure organization's security practices align with regulatory requirements.
Own regulatory compliance programs such as NY-DFS, GLBA and FFIEC assessments.
Serve as primary point of contract for regulatory bodies during audits.
Creation of materials for and participation in regulatory exams and quarterly briefings to regulators as required.
Develop responses and drive resolution of Issues, Deficiencies, Matters Requiring Attention (MRAs), and Supervisory Recommendations (SR's) assigned to US Region Information Security.
Work closely with US TI&I Risk & Controls Team, Regulatory Affairs, Operational Risk Management (ORM) and Internal Audit as required.
Assist with creation of materials for Annual Cyber Security Board Review and Quarterly Board Risk Committee Meetings.
Creation of materials for various reporting committees and forums, including weekly status.
Creation of materials for various reporting committees and forums, including weekly reports, business unit reviews and horizontal review.
Control Management:
Conduct Risk and Control Self-Assessment (RCSA) for Information Security and provide input into RCSA for all other lines of business. .
Mapping of controls to industry frameworks (e.g. NIST, PCI, MITRE) • Work closely with controls testing teams.
Drive remediation of ineffective controls owned by the US and provide oversight of control effectiveness for enterprise controls impacting the US. • Act as secretary for the Cyber Security Controls Oversight Council.
Leadership and Cross-Functional Relationships:
Recruiting and hiring of Information Security professionals to support target operating model changes.
Provides ongoing advice and direction on a variety of complex conceptual or interpretative issues.
Establishing and leveraging peer's relationships within the US Region and Parent bank organizations.
Will be required to foster relationships with middle to senior management, and senior executives across a range of functions including Risk Management and Technology.
Who You Are:
You can demonstrate experience at a financial institution of similar scope and scale with direct experience working with regulators and regulatory compliance programs.
It's an asset if you have advanced knowledge of applicable US laws and regulations as they relate to Information Security and the effective management of Information Security Risks.
You are a caring and accountable leader.
You have experience developing and implementing strategic team goals. You have experience coaching employees and inspiring successful team performance.
You know that details matter. You notice things that others don't. Your critical thinking skills help to inform your decision-making.
Values matter to you. You bring your real self to work, and you live our values - trust, teamwork, and accountability
This role is Hybrid and requires 2-3 days on-site per week.
At CIBC, we offer a competitive total rewards package. This role has an expected salary range of $190,000.00 - $230,000.00 for the Chicago market based on experience, qualifications, and location of the position. The successful candidate may be eligible to participate in the relevant business unit's incentive compensation plan, which may also include a discretionary bonus component. CIBC offers a full range of benefits and programs to meet our employee's needs; including Medical, Dental, Vision, Health Savings Account, Life Insurance, Disability, and Other Insurance Plans, Paid Time Off (including Sick Leave, Parental Leave and Vacation), Holidays and 401(k), in addition to other special perks reserved for our team members.
This position does not offer visa sponsorship.
#LI-TA
What CIBC Offers
At CIBC, your goals are a priority. We start with your strengths and ambitions as an employee and strive to create opportunities to tap into your potential. We aspire to give you a career, rather than just a paycheck.
We work to recognize you in meaningful, personalized ways including a competitive salary, incentive pay, banking benefits, a benefits program*, a vacation offering, wellbeing support, and MomentMakers, our social, points-based recognition program.
Our spaces and technological toolkit will make it simple to bring together great minds to create innovative solutions that make a difference for our clients.
We cultivate a culture where you can express your ambition through initiatives like Purpose Day; a paid day off dedicated for you to use to invest in your growth and development.
*Subject to plan and program terms and conditions
What you need to know
CIBC is committed to creating an inclusive environment where all team members and clients feel like they belong. We seek applicants with a wide range of abilities and we provide an accessible candidate experience. If you need accommodation, please contact **********************************
You need to be legally eligible to work at the location(s) specified above and, where applicable, must have a valid work or study permit.
We may ask you to complete an attribute-based assessment and other skills tests (such as simulation, coding, MS Office). Our goal for the application process is to get to know more about you, all that you have to offer, and give you the opportunity to learn more about us.
Job Location
IL-70 W Madison St, 9th Fl
Employment Type
Regular
Weekly Hours
40
Skills
Analytical Thinking, Information Management, Information Security, Leadership, Long Term Planning, People Management, Security Risk, Security Trainings
Auto-ApplyManager, U.S. Information Security & Control
Dallas, TX jobs
Salary Range: 76,600.00 - 142,300.00
Please note that the Salary Range shown is a guideline only. Salary offered may vary based on factors, including, but not limited to, the successful candidate's relevant knowledge, skills, and experience.
Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.
Global Banking and Markets
Global Banking and Markets (GBM) is a leading Canadian Capital Markets and Investment Banking business with a growing platform in the US and Latin America, operating globally for over 100 years. Scotiabank's strong U.S. presence provides our clients an important bridge to this key global market for trade and investment flows across the Americas and the world.
Global Banking & Markets provides a full range of investment banking, credit and risk management products and services relevant to the financing and strategic development needs of our clients. Our products include debt and equity financing, mergers & acquisitions, corporate banking, institutional equity sales, trading and research, fixed income products, derivatives, energy, foreign exchange and precious & metals. We also cross-sell the full range of wholesale products and services offered by the Scotiabank Group.
Be part of an innovative, Global Capital Markets and Investment Banking business with a unique geographic footprint that puts capital to work for our clients across industries! We work together to drive ambition for every future!
Purpose
The Cyber and Regulatory Audit Manager will participate and manage various aspects of information security, cyber risk assessments, and contribute to the overall success of the U.S. IS&C's governance, regulatory compliance, and risk program.
This role requires a seasoned professional with a strong background in information security, risk management, cybersecurity technology risk, compliance, policy, and governance. The IS&C Manager will assist with regulatory responses, audit requests, and participate in various cybersecurity risk assessments, risk mitigation strategies, and safeguard the Bank from potential informational security threats. The person will also play a role in reviewing and implementing security policies, procedures, and controls to protect the organization's data, systems, and networks.
The position will be expected to work closely with cross-functional teams to establish and maintain a robust cybersecurity and technology risk management program to proactively safeguard the organization from security threats by ensuring that vulnerabilities are identified, monitored, and treated, as well as assuring the Bank meets regulatory compliance.
What You'll Do
• Regulatory and Compliance Management (specific to cybersecurity):
- Participates in engagements with external regulatory and internal/3rd party auditors requests for information security and cybersecurity.
- Monitors, analyzes, and reports on cybersecurity requirements against relevant U.S. regulations and cybersecurity standards, such as NYSDFS, FFIEC, and NIST CSF.
- Provides support to IT&S auditors and compliance with respect to regulatory and audit information requests.
- Continuously monitors and assesses the effectiveness of security controls and processes.
- Reviews cybersecurity control library periodically and provides updates as needed.
- Participate in annual regulatory control testing exercises.
• Cybersecurity and Technology Risk Governance:
- Understand how the Bank's risk appetite and risk culture should be considered in day-to-day activities and decisions.
- Identifies and assesses cybersecurity and technology risks to ensure compliance with regulations and internal policies.
- Performs cybersecurity risk assessments and provide updates to US IS&C senior management.
• Risk and Issues Management:
- Reports and tracks all cybersecurity-related issues that pertain to audits, regulatory requirements, control testing, and other issues.
- Provides guidance to internal stakeholders on cybersecurity best practices.
- Prepares regular reports and presentation decks on risk management, gap assessment, cybersecurity-related issues for senior management and stakeholders.
- Monitors and tracks the progress of risk mitigation efforts related to cybersecurity.
- Participates in quarterly and annual Compliance Risk and Control Assessments for cybersecurity.
• Actively pursues effective and efficient operations of his/her respective areas in accordance with Scotiabank's Values, its Code of Conduct, and the Global Sales Principles, while ensuring the adequacy, adherence to and effectiveness of day-to-day business controls to meet obligations with respect to operational, compliance, AML/ATF/sanctions and conduct risk.
• Champions a high-performance environment and contributes to an inclusive work environment.
What You'll Bring
• Required 5+ years of experience as an Information Security Analyst or related cybersecurity field with technology risk background.
• Experience in IT key security controls/mechanisms and risk assessment concepts pertaining to complex data, application, and networking environments.
• Prior experience and knowledge with NYDFS, FFIEC, or other US financial regulatory audits.
• Have strong verbal and written communication skills in English with excellent individual project management and tracking skills.
• Cybersecurity related certification is preferred (CISSP, CCSP, CRISC, CISM).
• University degree or college diploma in a cybersecurity related field is preferred.
Interested?
If your experience is closely related but doesn't align perfectly with every qualification, we do encourage you to apply - you might be the right candidate for this or other roles at Scotiabank!
At Scotiabank, every employee is empowered to reach their fullest potential, respected for who they are and, embraced for their differences. That's why we work to grow and diversify talent and engage employees in a performance-oriented culture.
What's in it for you?
Scotiabank wants you to be able to bring your best self to work - and life, every day. With a focus on holistic well-being, our many flexible benefit programs are designed to help support your unique family, financial, physical, mental, and social health needs.
#Dallas
Location(s): United States : Texas : Dallas
Scotiabank is a leading bank in the Americas. Guided by our purpose: "for every future", we help our customers, their families and their communities achieve success through a broad range of advice, products and services, including personal and commercial banking, wealth management and private banking, corporate and investment banking, and capital markets.
At Scotiabank, we value the unique skills and experiences each individual brings to the Bank, and are committed to creating and maintaining an inclusive and accessible environment for everyone. If you require accommodation (including, but not limited to, an accessible interview site, alternate format documents, ASL Interpreter, or Assistive Technology) during the recruitment and selection process, please let our Recruitment team know. If you require technical assistance, please click here. Candidates must apply directly online to be considered for this role. We thank all applicants for their interest in a career at Scotiabank; however, only those candidates who are selected for an interview will be contacted.
Scotiabank is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other characteristic protected by federal, state, or local law.
Mgr Information Security - Pen Testing
Fort Lauderdale, FL jobs
Mount Laurel, New Jersey, United States of America **Hours:** 40 **Pay Details:** $87,000 - $151,000 USD TD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience at TD. Our compensation policies and practices have been designed to allow colleagues to progress through the salary range over time as they progress in their role. The base pay actually offered may vary based upon the candidate's skills and experience, job-related knowledge, geographic location, and other specific business and organizational needs.
As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.
**Line of Business:**
Technology Solutions
**:**
The Manager Information Security manages / leads a team of Technology Controls / Information Security experts in the development and/ or management of relevant strategies, programs, tools, frameworks and policies and provides specialized oversight / control / governance activities for a key business line/segment or transformational (change the bank) strategic initiative / program, liaising across the organization and primarily interfacing with executive and/or functional stakeholders to minimize overall technology risks to the Bank for own area.
**Job Description:**
This position manages junior level penetration testers, vendor coordination for multiple testing services, processes, procedures and scheduling for penetration, dynamic scanning, and manual code review testing services.
**Responsibilities:**
+ **Vendor Management:** Manage and coordinate penetration testing engagements with vendors.
+ **People Management:** Manage a team of Junior level penetration testers and their development.
+ **DAST:** Manage the DAST program and tooling. Familiarity with current industry tooling and technologies and those being introduced.
+ **Facilitate Penetration Tests:** Perform thorough and methodical penetration testing.
+ **Evaluate and Assign:** penetration tests to appropriate resources.
+ **Vulnerability Assessment:** Assess and analyze security weaknesses, and provide actionable recommendations to mitigate risks and improve overall security posture.
+ **Report Findings:** Document and communicate findings clearly and effectively to both technical and non-technical stakeholders. Prepare comprehensive reports with recommendations for remediation.
+ **Develop Test Procedures:** Design and execute detailed test requirements.
+ **Stay Current:** Keep up-to-date with the latest security trends, vulnerabilities, and tools to ensure testing methodologies are current and effective.
+ **Collaborate with Teams:** Work closely with IT and development teams to understand system architectures, provide guidance on security best practices, and support the implementation of security improvements; work closely with advisory and SDLC pipeline teams to ensure compliance; work closely with PCS team to manage PCI testing requirements. This position will collaborate with many application security teams.
+ **Perform Risk Assessments:** Evaluate and assess potential security risks related to new and existing systems and technologies.
+ **Compliance:** Ensure that penetration testing practices comply with relevant regulations, standards, and organizational policies.
+ **Incidents:** Act as a testing SME on incident calls; support testers on the calls.
**Depth & Scope:**
+ Advanced knowledge of Bank, technology standards and managing people / projects
+ Leads a small team of IT professionals; coaches/ educates, monitors and manages team members
+ Strong communication, negotiation and organizational skills specifically including the ability to present options in business terms to both IT and business staff including executives
**Education & Experience:**
+ Bachelor's degree preferred
+ Information security certification / accreditation an asset
+ 7+ years of relevant experience
**Preferred Qualifications :**
+ **Technical Skills:**
+ Proficiency in penetration testing tools such as Metasploit, Burp Suite, Nmap, and Kali.
+ Knowledge of common web application vulnerabilities (e.g., OWASP Top Ten) and network security principles.
+ Penetration testing, DAST, Manual Code Review knowledge.
+ **Analytical Skills:** Strong analytical and problem-solving abilities with attention to detail.
+ **Organizational Skills:** Manage documents and procedures for testing team.
+ **Multi-tasking** : This job requires exceptional ability to multi-task with multiple workstreams to manage daily.
+ **Communication:** Excellent verbal and written communication skills, with the ability to convey complex technical concepts to non-technical stakeholders.
+ **Ethical Standards:** Demonstrated understanding of ethical hacking principles and a commitment to maintaining high ethical standards.
+ Experience with penetration testing in AI, cloud environments (e.g., AWS, Azure) and PCI testing.
+ Familiarity with security standards and frameworks.
+ Previous experience managing and developing teams.
+ **Certifications:** Relevant certifications such as Offensive Security Certified Professional (OSCP), Certified Ethical Hacker (CEH), or GIAC Penetration Tester (GPEN) are highly desirable.
+ Provide support and consulting in preparation for Audits and in composing management responses and appropriate remediation activities
+ Participate in computer security incident responses relevant to business (or enterprise wide) and represent respective function and Enterprise position to the business, and business needs to incident response team
\#TDCyberSecurity #Hybrid
**Physical Requirements:**
Never: 0%; Occasional: 1-33%; Frequent: 34-66%; Continuous: 67-100%
+ Domestic Travel - Occasional
+ International Travel - Never
+ Performing sedentary work - Continuous
+ Performing multiple tasks - Continuous
+ Operating standard office equipment - Continuous
+ Responding quickly to sounds - Occasional
+ Sitting - Continuous
+ Standing - Occasional
+ Walking - Occasional
+ Moving safely in confined spaces - Occasional
+ Lifting/Carrying (under 25 lbs.) - Occasional
+ Lifting/Carrying (over 25 lbs.) - Never
+ Squatting - Occasional
+ Bending - Occasional
+ Kneeling - Never
+ Crawling - Never
+ Climbing - Never
+ Reaching overhead - Never
+ Reaching forward - Occasional
+ Pushing - Never
+ Pulling - Never
+ Twisting - Never
+ Concentrating for long periods of time - Continuous
+ Applying common sense to deal with problems involving standardized situations - Continuous
+ Reading, writing and comprehending instructions - Continuous
+ Adding, subtracting, multiplying and dividing - Continuous
The above statements are intended to describe the general nature and level of work being performed by people assigned to this job. They are not intended to be an exhaustive list of all responsibilities, duties and skills required. The listed or specified responsibilities & duties are considered essential functions for ADA purposes.
**Who We Are:**
TD is one of the world's leading global financial institutions and is the fifth largest bank in North America by branches/stores. Every day, we deliver legendary customer experiences to over 27 million households and businesses in Canada, the United States and around the world. More than 95,000 TD colleagues bring their skills, talent, and creativity to the Bank, those we serve, and the economies we support. We are guided by our vision to Be the Better Bank and our purpose to enrich the lives of our customers, communities and colleagues.
TD is deeply committed to being a leader in customer experience, that is why we believe that all colleagues, no matter where they work, are customer facing. As we build our business and deliver on our strategy, we are innovating to enhance the customer experience and build capabilities to shape the future of banking. Whether you've got years of banking experience or are just starting your career in financial services, we can help you realize your potential. Through regular leadership and development conversations to mentorship and training programs, we're here to support you towards your goals. As an organization, we keep growing - and so will you.
**Our Total Rewards Package**
Our Total Rewards package reflects the investments we make in our colleagues to help them and their families achieve their financial, physical and mental well-being goals. Total Rewards at TD includes base salary and variable compensation/incentive awards (e.g., eligibility for cash and/or equity incentive awards, generally through participation in an incentive plan) and several other key plans such as health and well-being benefits, savings and retirement programs, paid time off (including Vacation PTO, Flex PTO, and Holiday PTO), banking benefits and discounts, career development, and reward and recognition. Learn more (***************************************
**Additional Information:**
We're delighted that you're considering building a career with TD. Through regular development conversations, training programs, and a competitive benefits plan, we're committed to providing the support our colleagues need to thrive both at work and at home.
**Colleague Development**
If you're interested in a specific career path or are looking to build certain skills, we want to help you succeed. You'll have regular career, development, and performance conversations with your manager, as well as access to an online learning platform and a variety of mentoring programs to help you unlock future opportunities. Whether you have a passion for helping customers and want to expand your experience, or you want to coach and inspire your colleagues, there are many different career paths within our organization at TD - and we're committed to helping you identify opportunities that support your goals.
**Training & Onboarding**
We will provide training and onboarding sessions to ensure that you've got everything you need to succeed in your new role.
**Interview Process**
We'll reach out to candidates of interest to schedule an interview. We do our best to communicate outcomes to all applicants by email or phone call.
**Accommodation**
TD Bank is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, status as a protected veteran or any other characteristic protected under applicable federal, state, or local law.
If you are an applicant with a disability and need accommodations to complete the application process, please email TD Bank US Workplace Accommodations Program at *************** . Include your full name, best way to reach you and the accommodation needed to assist you with the applicant process.
Federal law prohibits job discrimination based on race, color, sex, sexual orientation, gender identity, national origin, religion, age, equal pay, disability and genetic information.
Mgr Information Security - Pen Testing
Fort Lauderdale, FL jobs
Hours: 40 Pay Details: $87,000 - $151,000 USD TD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience at TD. Our compensation policies and practices have been designed to allow colleagues to progress through the salary range over time as they progress in their role. The base pay actually offered may vary based upon the candidate's skills and experience, job-related knowledge, geographic location, and other specific business and organizational needs.
As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.
Line of Business:
Technology Solutions
:
The Manager Information Security manages / leads a team of Technology Controls / Information Security experts in the development and/ or management of relevant strategies, programs, tools, frameworks and policies and provides specialized oversight / control / governance activities for a key business line/segment or transformational (change the bank) strategic initiative / program, liaising across the organization and primarily interfacing with executive and/or functional stakeholders to minimize overall technology risks to the Bank for own area.
Job Description:
This position manages junior level penetration testers, vendor coordination for multiple testing services, processes, procedures and scheduling for penetration, dynamic scanning, and manual code review testing services.
Responsibilities:
* Vendor Management: Manage and coordinate penetration testing engagements with vendors.
* People Management: Manage a team of Junior level penetration testers and their development.
* DAST: Manage the DAST program and tooling. Familiarity with current industry tooling and technologies and those being introduced.
* Facilitate Penetration Tests: Perform thorough and methodical penetration testing.
* Evaluate and Assign: penetration tests to appropriate resources.
* Vulnerability Assessment: Assess and analyze security weaknesses, and provide actionable recommendations to mitigate risks and improve overall security posture.
* Report Findings: Document and communicate findings clearly and effectively to both technical and non-technical stakeholders. Prepare comprehensive reports with recommendations for remediation.
* Develop Test Procedures: Design and execute detailed test requirements.
* Stay Current: Keep up-to-date with the latest security trends, vulnerabilities, and tools to ensure testing methodologies are current and effective.
* Collaborate with Teams: Work closely with IT and development teams to understand system architectures, provide guidance on security best practices, and support the implementation of security improvements; work closely with advisory and SDLC pipeline teams to ensure compliance; work closely with PCS team to manage PCI testing requirements. This position will collaborate with many application security teams.
* Perform Risk Assessments: Evaluate and assess potential security risks related to new and existing systems and technologies.
* Compliance: Ensure that penetration testing practices comply with relevant regulations, standards, and organizational policies.
* Incidents: Act as a testing SME on incident calls; support testers on the calls.
Depth & Scope:
* Advanced knowledge of Bank, technology standards and managing people / projects
* Leads a small team of IT professionals; coaches/ educates, monitors and manages team members
* Strong communication, negotiation and organizational skills specifically including the ability to present options in business terms to both IT and business staff including executives
Education & Experience:
* Bachelor's degree preferred
* Information security certification / accreditation an asset
* 7+ years of relevant experience
Preferred Qualifications :
* Technical Skills:
* Proficiency in penetration testing tools such as Metasploit, Burp Suite, Nmap, and Kali.
* Knowledge of common web application vulnerabilities (e.g., OWASP Top Ten) and network security principles.
* Penetration testing, DAST, Manual Code Review knowledge.
* Analytical Skills: Strong analytical and problem-solving abilities with attention to detail.
* Organizational Skills: Manage documents and procedures for testing team.
* Multi-tasking: This job requires exceptional ability to multi-task with multiple workstreams to manage daily.
* Communication: Excellent verbal and written communication skills, with the ability to convey complex technical concepts to non-technical stakeholders.
* Ethical Standards: Demonstrated understanding of ethical hacking principles and a commitment to maintaining high ethical standards.
* Experience with penetration testing in AI, cloud environments (e.g., AWS, Azure) and PCI testing.
* Familiarity with security standards and frameworks.
* Previous experience managing and developing teams.
* Certifications: Relevant certifications such as Offensive Security Certified Professional (OSCP), Certified Ethical Hacker (CEH), or GIAC Penetration Tester (GPEN) are highly desirable.
* Provide support and consulting in preparation for Audits and in composing management responses and appropriate remediation activities
* Participate in computer security incident responses relevant to business (or enterprise wide) and represent respective function and Enterprise position to the business, and business needs to incident response team
#TDCyberSecurity #Hybrid
Physical Requirements:
Never: 0%; Occasional: 1-33%; Frequent: 34-66%; Continuous: 67-100%
* Domestic Travel - Occasional
* International Travel - Never
* Performing sedentary work - Continuous
* Performing multiple tasks - Continuous
* Operating standard office equipment - Continuous
* Responding quickly to sounds - Occasional
* Sitting - Continuous
* Standing - Occasional
* Walking - Occasional
* Moving safely in confined spaces - Occasional
* Lifting/Carrying (under 25 lbs.) - Occasional
* Lifting/Carrying (over 25 lbs.) - Never
* Squatting - Occasional
* Bending - Occasional
* Kneeling - Never
* Crawling - Never
* Climbing - Never
* Reaching overhead - Never
* Reaching forward - Occasional
* Pushing - Never
* Pulling - Never
* Twisting - Never
* Concentrating for long periods of time - Continuous
* Applying common sense to deal with problems involving standardized situations - Continuous
* Reading, writing and comprehending instructions - Continuous
* Adding, subtracting, multiplying and dividing - Continuous
The above statements are intended to describe the general nature and level of work being performed by people assigned to this job. They are not intended to be an exhaustive list of all responsibilities, duties and skills required. The listed or specified responsibilities & duties are considered essential functions for ADA purposes.
Who We Are:
TD is one of the world's leading global financial institutions and is the fifth largest bank in North America by branches/stores. Every day, we deliver legendary customer experiences to over 27 million households and businesses in Canada, the United States and around the world. More than 95,000 TD colleagues bring their skills, talent, and creativity to the Bank, those we serve, and the economies we support. We are guided by our vision to Be the Better Bank and our purpose to enrich the lives of our customers, communities and colleagues.
TD is deeply committed to being a leader in customer experience, that is why we believe that all colleagues, no matter where they work, are customer facing. As we build our business and deliver on our strategy, we are innovating to enhance the customer experience and build capabilities to shape the future of banking. Whether you've got years of banking experience or are just starting your career in financial services, we can help you realize your potential. Through regular leadership and development conversations to mentorship and training programs, we're here to support you towards your goals. As an organization, we keep growing - and so will you.
Our Total Rewards Package
Our Total Rewards package reflects the investments we make in our colleagues to help them and their families achieve their financial, physical and mental well-being goals. Total Rewards at TD includes base salary and variable compensation/incentive awards (e.g., eligibility for cash and/or equity incentive awards, generally through participation in an incentive plan) and several other key plans such as health and well-being benefits, savings and retirement programs, paid time off (including Vacation PTO, Flex PTO, and Holiday PTO), banking benefits and discounts, career development, and reward and recognition. Learn more
Additional Information:
We're delighted that you're considering building a career with TD. Through regular development conversations, training programs, and a competitive benefits plan, we're committed to providing the support our colleagues need to thrive both at work and at home.
Colleague Development
If you're interested in a specific career path or are looking to build certain skills, we want to help you succeed. You'll have regular career, development, and performance conversations with your manager, as well as access to an online learning platform and a variety of mentoring programs to help you unlock future opportunities. Whether you have a passion for helping customers and want to expand your experience, or you want to coach and inspire your colleagues, there are many different career paths within our organization at TD - and we're committed to helping you identify opportunities that support your goals.
Training & Onboarding
We will provide training and onboarding sessions to ensure that you've got everything you need to succeed in your new role.
Interview Process
We'll reach out to candidates of interest to schedule an interview. We do our best to communicate outcomes to all applicants by email or phone call.
Accommodation
TD Bank is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, status as a protected veteran or any other characteristic protected under applicable federal, state, or local law.
If you are an applicant with a disability and need accommodations to complete the application process, please email TD Bank US Workplace Accommodations Program at ***************. Include your full name, best way to reach you and the accommodation needed to assist you with the applicant process.
Auto-Apply